Privacy policy
Last updated 10 August 2026
This explains what Strong Digital collects when you use SigFinch, why, and what you can do about it. It is written to be read rather than to be defensible, so where something is a design decision we have said so.
What we store
Account details. The name, email address and hashed password of anyone who signs in, plus the company name and workspace address you choose.
Staff details. Whatever goes into a signature: name, job title, department, phone numbers, email address, pronouns, a photo if one is uploaded, and any scheduling link. This is data about your employees that you have given us to process on your behalf — you decide what goes in, and you remain responsible for having told them.
Images. Logos, staff photos and campaign banners, together with the resized versions we generate from them.
Billing. Your plan, subscription status and the number of signatures in use. We never see or store card numbers — those are entered directly with Stripe.
What the banner endpoints do not record
Signatures embed image addresses that get fetched by the mail client of every person who receives an email from your team. That makes those endpoints the most privacy-sensitive part of the product, and they are built accordingly.
They sit outside the normal web session entirely. They set no cookies, start no session, and write no row per recipient. What we keep is a daily count of impressions and clicks per banner slot — a number that goes up. No IP addresses, no recipient identities, no tracking pixels, and nothing that could be used to work out who opened your email or when.
Personal signature links
Each staff member gets a long, unguessable link that lets them edit their own details without an account. Anyone holding that link can see and edit that one person's signature, which is why the links should be sent directly to the person. They can be regenerated at any time from the staff page, which immediately breaks the old one.
Why we hold it
To render and host signatures, to let your staff maintain their own details, to bill you, and to answer you when you ask us something. We do not sell data, we do not share it for advertising, and we do not use your staff details to market to them.
Who else sees it
Only the services needed to run the product:
- Stripe — Subscription billing and card payments. Card details are entered on Stripe and never reach our servers. Their privacy policy.
- Our hosting and storage providers — the servers the application runs on and the storage that holds uploaded images.
Images are served publicly by design: an address embedded in an email has to be reachable without a login, or it would not appear in anybody's inbox. Treat anything you upload as public.
How long we keep it
Staff you archive are retained so you can restore them, and are deleted with the workspace. When an account closes we keep the data for 30 days in case it was a mistake, then delete it. Billing records are kept for as long as tax law requires. Daily banner counts are aggregate and contain no personal information, so they are kept indefinitely.
Your rights
You can ask for a copy of what we hold, ask us to correct it, or ask us to delete it. Staff details can be exported from the staff page at any time without asking. If you are one of the staff rather than the customer, ask your own organisation first — it is their workspace and they can act immediately, where we would have to check with them anyway.
Security
Passwords are hashed. Traffic is encrypted in transit. Each workspace is scoped so one customer's data cannot be queried from another's, and that scoping is enforced in the application and covered by automated tests rather than left to care.
Changes
If this policy changes in a way that matters, we will tell account holders by email rather than quietly changing the date at the top.
Getting in touch
Privacy questions and requests go to Strong Digital.