Privacy should be understandable.

This is the working draft of the Maple eSign Privacy Policy, published for review. Bracketed items, including retention periods and the provider inventory, are confirmed before the effective date.

The Maple eSign Privacy Policy.

01
Who this policy covers

Maple eSign is operated by [LEGAL ENTITY NAME], located at [BUSINESS ADDRESS] ("Maple", "we", "us", or "our"). This policy explains how we handle personal information when you visit mapleesign.ca, use a Maple account or integration, receive a signing invitation, complete a document, or contact us.

Our privacy contact is [PRIVACY OFFICER TITLE], reachable at [PRIVACY EMAIL] or the address above.

For account administration, website operation, security, and our own support activities, Maple determines the purposes for handling personal information. When an organization uses Maple to send and manage agreements, that organization generally determines the document's purpose, recipients, and required information, and Maple processes that information on its behalf. Legal responsibilities depend on the activity and applicable law.

If you receive an agreement, the sender's privacy practices also apply. Ask the sender about its document requirements, use of your information, and retained copies. You may contact Maple about our own handling of your information or for help directing a request.

Information we handle

The information involved depends on your role and the features used.

Documents and attachments can contain sensitive personal information. The sender chooses what it requests. Only provide information necessary for the agreement. Do not send signing links, passwords, one-time codes, identity documents, signature images, or complete agreements in an ordinary support message. The public marketing website does not collect signing documents through its informational pages. Its technical traffic and analytics are separate from information submitted inside the signing application.
InformationExamples and sourcePurpose
Account and organization detailsName, email address, team membership, permissions, and account identifiers provided by you or an administratorEstablish access, administer the account, and communicate about the Service
Recipient and routing detailsNames, email addresses, roles, signing order, and telephone numbers supplied by the sender or recipientDeliver invitations, route agreements, send reminders, and perform optional SMS verification
Document and signing contentUploaded PDFs, templates, completed fields, signatures, initials, dates, and attachments supplied by senders and recipientsDisplay and complete the agreement, generate final records, and make them available to authorized participants
Workflow and evidence recordsDocument identifiers, event timestamps, consent records, verification outcomes, completion or decline status, document hashes, and audit eventsTrack progress, record signing actions, detect tampering, and support disputes or investigations
Network and device informationIP address, browser and device information, request and error logs, and session information generated during accessAuthenticate access, protect the Service, investigate errors, and operate the website and application
Integration informationAPI requests, integration identifiers, webhook destinations, delivery status, and authorized payloadsOperate connections configured by account holders and investigate delivery failures
Support communicationsContact details, messages, timestamps, and redacted troubleshooting information you provideRespond to questions, resolve problems, and maintain support records

The Maple eSign Privacy Policy, continued.

01
Why we use information and how consent works

We use personal information for the purposes described above, to comply with legal obligations, and to investigate misuse or protect the rights and security of users and the Service. We limit collection and use to what is appropriate for those purposes.

Where consent is required, we seek consent appropriate to the information and its sensitivity. The sender is responsible for the notices and permissions needed to supply recipient information and request signatures. Signing consent is recorded in the signing process. Accepting terms or visiting a website does not by itself authorize every possible use of personal information.

You may decline to provide optional information or contact us to withdraw consent, subject to legal or contractual restrictions. If you withhold information required to authenticate access, deliver an invitation, or complete a document, that feature may not work. Withdrawing consent does not automatically invalidate a completed agreement or erase records that must lawfully be retained.

Any optional promotional communications must have the permissions required by applicable law and an unsubscribe method. Operational invitations, verification messages, and service notices are distinct from marketing. Contact the sender if you no longer wish to participate in a particular signing workflow.

02
Who receives information

We disclose information only for the purposes described in this policy, with appropriate consent or another lawful basis:

1. Senders, authorized organization administrators, signers, approvers, and copied recipients receive information appropriate to their role and the configured workflow. A completed agreement or certificate may contain personal information visible to other authorized participants. Ask the sender who will receive it before signing. 2. Service providers process information needed for hosting, storage, security, communications, support, and other service functions. Providers acting on our behalf must be subject to appropriate confidentiality, security, and purpose restrictions. 3. Integrations selected by an organization receive the information that organization authorizes, including configured webhook events and retrieved documents. The organization is responsible for its downstream use and connected services. 4. Authorities or other recipients may receive information where disclosure is required or permitted by law, including a valid legal process or a necessary response to fraud or a security threat. 5. Information may be involved in a proposed or completed business transfer where permitted by law, with safeguards limiting its use and any required notice or consent.

[CONFIRM AND INSERT THE POLICY ON SALE OF PERSONAL INFORMATION, ADVERTISING USE, AND USE OF DOCUMENT CONTENT FOR AI TRAINING.]

Service providers and processing locations

Core production resources are configured in a Canadian Google Cloud region. This describes the core deployment location. It is not a guarantee that every processing activity, communication, support interaction, backup, or provider operates exclusively in Canada.

Where information is processed outside your province or Canada, it may be subject to the laws and lawful access powers of that location. We remain responsible for information transferred to providers acting on our behalf and use appropriate contractual and other safeguards. We provide additional notices or obtain consent where required by applicable law.
Provider or functionKnown position and required detail
Google CloudCore application, database, and document storage use a Canadian regional deployment. [CONFIRM CONTRACTING ENTITY, REGION, BACKUPS, SUPPORT ACCESS, AND ANY OTHER PROCESSING LOCATIONS.]
CloudflareThe public homepage includes a Cloudflare analytics script. [CONFIRM ENABLED ANALYTICS, DELIVERY AND SECURITY SERVICES, DATA FIELDS, RETENTION, AND PROCESSING LOCATIONS.]
Email and optional SMS deliveryInvitations, reminders, and optional verification involve communication delivery. [INSERT PROVIDER NAMES, DATA SHARED, AND PROCESSING LOCATIONS.]
Other providers[COMPLETE THE PROVIDER INVENTORY, INCLUDING AUTHENTICATION, MONITORING, SUPPORT, AND BACKUP SERVICES WHERE USED.]

The Maple eSign Privacy Policy, continued.

01
Cookies, browser storage, and analytics

The website uses browser preferences for features such as theme selection and includes a Cloudflare analytics script. The application may require cookies or similar browser storage for authentication and session security. [CONFIRM THE ACTUAL COOKIE AND STORAGE INVENTORY, PURPOSES, LIFETIMES, AND AVAILABLE CONTROLS.]

You can manage cookies and stored website data through your browser. Blocking required storage may affect sign-in or signing. Any non-essential tracking that requires consent must remain optional and be controlled through [CONSENT SETTINGS OR OTHER ACTUAL CONTROL]. This draft does not claim that the site is cookie-free or free of analytics.

02
Retention, closure, and deletion

We retain personal information only as long as reasonably necessary for its identified purposes, legal obligations, and legitimate dispute or security needs. Retention must take account of the sender's instructions and agreement, subject to applicable law. Audit integrity alone is not a blanket reason to retain all personal information indefinitely.

[INSERT THE APPROVED RETENTION PERIODS OR CLEAR CRITERIA FOR DRAFTS, ATTACHMENTS, COMPLETED DOCUMENTS, AUDIT RECORDS, ACCOUNTS, SUPPORT RECORDS, SECURITY LOGS, AND BACKUPS, INCLUDING WHEN EACH PERIOD STARTS AND HOW DELETION IS CARRIED OUT.]

There is currently no self-service deletion or account-closure feature. Requests must be directed to [STAFFED PRIVACY REQUEST CONTACT]. Account closure does not automatically delete completed agreements, records subject to a legal hold, or copies already held by other participants.

Where deletion is required and permitted, information will be deleted or irreversibly anonymized through [CONFIRMED DELETION PROCESS AND BACKUP EXPIRY RULE]. If a legal obligation or justified hold prevents deletion, we will explain the applicable restriction where permitted and limit further use to the retained purpose.

03
Safeguards

We use technical and organizational measures appropriate to the sensitivity of the information. Published product controls include encrypted browser and API traffic, team-scoped access, optional recipient SMS verification, and tamper-evident signing records. Authorized access must be limited to the people and providers who need it for their duties.

No system guarantees complete security. Signing evidence and document hashes do not replace access controls or establish that a document is legally enforceable. If a security incident affects personal information, we will assess it and notify affected individuals, organizations, and regulators where required by applicable law.

04
Your rights and complaints

Depending on applicable law, you may request access to your personal information, correction of inaccuracies, information about its use or disclosure, withdrawal of consent, or deletion where available. Additional rights may apply in your jurisdiction. These rights are subject to legal exceptions and do not necessarily require alteration of a historical signed agreement. Corrections may need to preserve the original record and document the correction separately.

Contact [PRIVACY EMAIL] with a description of your request and enough information to locate the relevant account or workflow. Do not include a complete document or active signing link. We may request proportionate identity verification through a secure method. We will respond within applicable legal time limits and explain any permitted extension, refusal, or applicable fee.

For information managed on a sender's behalf, we may coordinate with or direct you to that organization, while addressing our own legal responsibilities. You may raise a complaint with our privacy contact or the relevant privacy regulator, including the Office of the Privacy Commissioner of Canada (www.priv.gc.ca/en/report-a-concern/) where it has jurisdiction.

05
Children and capacity

Maple account registration is intended for adults with legal capacity to use the Service. A sender must establish the appropriate authority and permissions before involving a minor's information or requesting action by a guardian. Contact our privacy officer if you believe information about a child has been provided without the required authority or consent.

06
Changes and contact

We will publish revisions with an updated effective date and version. For material changes, we will provide notice through an appropriate channel and obtain fresh consent where required before using previously collected information for a new purpose.

Privacy contact: [PRIVACY OFFICER TITLE], [LEGAL ENTITY NAME], [BUSINESS ADDRESS], [PRIVACY EMAIL].

Protect sensitive information while the notice is finalized.

Built into Maple
This public page does not collect document, recipient, signature, or identity information.
Recipients can ask the sender organization how it handles the agreement and recipient information.
Important context
Do not send a document, signing link, signature image, identity file, password, token, or one-time code through an unapproved channel.
This page does not receive deletion, access, or correction requests.
The technical summaries on this site do not establish a retention period or absolute residency guarantee.

Publication status

The final notice will be clear and versioned.

Maple will publish approved wording with an effective date, version record, contact path, and individual-request process when legal review is complete.