Privacy Policy
What we collect, why, and who else sees it.
Version 2026.08.14.01 · Effective Aug 14, 2026
Privacy Policy
This policy explains what SMP Consulting LLC collects when you use SMP eSign, why, and who else sees it.
Where your data lives
All primary storage, all backups, all queue infrastructure and all log storage are in the United States. This is not a preference; it is an architectural commitment, and it includes any content delivery caching.
What we collect
From account holders: your name, email address, business name, IP address, and the security events on your account — sign-ins, failed sign-ins, multi-factor changes.
From signers: name, email address, IP address, browser user agent, the content you enter into a document, and the timestamps of every step. Much of this appears on the Certificate of Completion, which is the point: the certificate is evidence, and evidence that omits who did what and from where is weaker evidence.
Documents: the files you upload and the signed output.
Why the audit trail cannot be deleted
Our audit trail is immutable and retained for seven years. If you ask us to delete your data, we remove document content and personal detail from active systems, but we preserve the audit event record. An audit trail a party can delete is not an audit trail, and the whole evidentiary value of a signed document rests on it.
How long we keep things
| What | How long |
|---|---|
| Executed documents and certificates | Life of account plus your plan's post-termination window |
| Original uploads | 1 year after completion |
| Rendered page images | 30 days after completion |
| Audit events | 7 years, and not deleted on request |
| Backups | 35 days, rolling |
Who else sees it
We use a small number of subprocessors, all processing in the United States: a payment processor, a transactional email provider, and hosting and storage. Our current list is published on our trust page.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. Advertising cookies on our marketing pages are the one place third parties could receive anything, which is why they are off unless you turn them on. They never load on signing pages, on any page inside the application, or on any page showing document content.
Our own access
Our staff have no standing access to your document content. Support staff can see account metadata — status, timestamps, recipient email addresses — and that access is logged and visible to you. Reaching actual document content requires either a grant from you or a logged emergency procedure that alerts your account owner in real time.
Your choices
You can access and correct your account information in your settings, export your data, decline optional cookies at any time, and ask us to delete your account (subject to the audit trail carve-out above).
Children
The Service is not directed at anyone under 18 and we do not knowingly collect their information.