Skip to main content
NEW Didit KYC Identity Verification is live, verify signers with government ID & biometrics for eIDAS Advanced signatures Learn more

Privacy Policy

How we handle data across our website, account portal, store, documentation, mobile app, and self-hosted WordPress plugin.

Last updated: September 3, 2026

On this page

1. Scope and controller

Nubesti LLC, doing business as WPsigner, is responsible for personal data collected directly through wpsigner.com, app.wpsigner.com, docs.wpsigner.com, our store, account portal, licensing service, support channels, and the WPsigner mobile apps on the Apple App Store and Google Play.

Business address: 1111B S Governors Ave STE 23840, Dover, Delaware, United States. Privacy requests may be sent to support@wpsigner.com or through our contact page.

This policy does not make Nubesti the controller of documents and signer data that a customer processes inside their own WordPress installation, including data processed through the mobile app against that installation.

2. The self-hosted product and our role

WPsigner is self-hosted. Documents, templates, signatures, signer details, audit trails, and workflow records created with the plugin or the mobile app are stored in the customer's WordPress environment. They are not routinely copied to or synchronized with Nubesti.

When a licensed site checks in with our licensing service, the plugin may send an aggregate count of completed (signed) documents for that site. That metric is a number only. It does not include document titles, PDF files, signer names, email addresses, signature images, audit-trail details, or other document content.

The customer operating that WordPress site decides why and how signer data is processed and is normally the controller of that data. Nubesti only receives document or signer information when a customer voluntarily sends it to us or grants temporary access for support. Customers should remove unnecessary personal or sensitive information before sharing support materials.

Optional services such as KYC, SMS, WhatsApp, cloud storage, or automation connect to third parties only when the customer configures and enables them. Those providers' terms and privacy notices apply to data sent through the integration.

3. Mobile app

The WPsigner mobile app for iOS and Android is published by Nubesti LLC.

The app is a companion to the self-hosted WordPress plugin. It does not create a WPsigner cloud account and it does not store signed documents on Nubesti servers. You sign in with a WordPress username and password, or by scanning a QR code issued by an administrator on a licensed site.

When you use the app:

  • On the device: the app stores the WordPress site URL and a session token so you can stay signed in. Uninstalling the app removes that local data.
  • On the connected WordPress site: name, email, user identifiers, optional phone numbers, photos, files, documents, signature drawings, field values, and other user-generated content you enter are sent to that site so the plugin can run the signing workflow.
  • Camera: camera access is used to scan a login QR code. The image is processed on the device to read the code. Nubesti does not receive the camera feed.
  • What we do not collect through the app: precise location, device advertising identifiers, contacts, financial account numbers, or in-app advertising or analytics SDKs.

Apple and Google may process download, crash, purchase, and store-account data under their own policies when you install the app from the App Store or Google Play.

The customer operating the connected WordPress site is normally the controller of signing data processed through the app. Nubesti is the controller of store, license, support, and website data described elsewhere in this policy, and of any app-related requests you send to support@wpsigner.com.

For step-by-step deletion, see the WPsigner data deletion page.

4. Data we collect

  • Account and order data: name, email address, username, company and billing details, tax fields when applicable, orders, license entitlements, payment status, and transaction references.
  • License and update data: license key, website domain or URL, and the installed versions of WordPress, PHP, and WPsigner. Licensed sites may also report an aggregate count of completed (signed) documents. Standard security logs may also contain an IP address, timestamp, and user agent.
  • Mobile-app data: as described in section 3, the app keeps a site URL and session token on the device and sends signing data only to the WordPress site you connect. Nubesti does not receive those documents through the app.
  • Support and contact data: name, email, subject, message, correspondence, and files or technical details that you choose to provide.
  • Website and consent data: IP address, browser and device information, referring page, pages visited, and interaction events. Non-essential analytics and advertising data is collected only after consent, and not when Global Privacy Control is enabled.
  • Affiliate attribution: if you arrive through an affiliate link, we may store a first-party referral code and the landing-page URL. The licensing service may also record a hashed IP address and approximate country so a later purchase can be attributed. This is not used to build an advertising profile.
  • Marketing data: email address, subscription status, and campaign interactions when you opt in to promotional communications.

We do not intentionally collect the contents of customers' signed documents through the licensing service or the mobile app, and we do not receive complete payment card or PayPal credentials. Through the website, licensing service, and mobile app we do not collect Social Security numbers, government ID numbers, precise geolocation, or signer biometric templates.

5. Why we process data

We use personal data to create and secure accounts, process orders, issue licenses, deliver updates, provide support, operate the mobile app connection to a licensed WordPress site, prevent fraud and abuse, maintain our services, meet tax and accounting duties, understand website performance, measure product usage such as aggregate signed-document counts, measure campaigns, and send requested marketing.

License checks, site activations, and the aggregate signed-document count are required to provide and enforce the commercial license you purchased. We use them to activate sites, deliver updates, apply plan limits, and detect unauthorized key sharing or abuse. We do not use that telemetry for advertising or sell it.

Where laws such as the GDPR, UK GDPR, or LGPD require a legal basis, we rely on: contract to provide purchased services, including license activation, the mobile app, and abuse prevention; legal obligation for tax, accounting, and valid legal requests; legitimate interests for service security, fraud prevention, product analytics based on aggregate usage metrics, and business operations; and consent for non-essential analytics, advertising tags, and promotional email.

6. Store and payments

Our account portal and store run on WooCommerce. Payments may be processed by Stripe, WooPayments, or PayPal, depending on the option selected at checkout. Payment providers collect and process payment credentials under their own privacy notices and security obligations.

Nubesti receives the information needed to fulfill the order, such as payment confirmation or failure, transaction reference, payment method, billing information, refunds, and fraud or dispute information. We do not store complete card numbers or security codes.

Downloading the mobile app from the App Store or Google Play is free. Any in-store billing, refunds, or family-sharing rules for a paid store item, if offered later, are handled by Apple or Google under their terms.

7. Cookies, analytics, and advertising

We use essential storage to operate the site and remember your cookie choice. If you arrive with an affiliate parameter such as ?ref=, we may set a first-party cookie named wpslm_ref for up to 60 days so a later purchase can be attributed to that partner. That cookie is not used to show ads.

Google Tag Manager is loaded only after you select Accept All, and only if your browser is not sending a Global Privacy Control (GPC) opt-out signal. It may then load Google Analytics 4, Google Ads, Meta Pixel, and Microsoft Clarity. These services may receive online identifiers, IP and device information, page and event data, and campaign attribution information.

You can refuse these tags by choosing Reject All or change your decision later through Cookie Preferences in the footer. We honor GPC as an opt-out of sale, sharing, and targeted advertising on this website: advertising and analytics tags will not load. Withdrawing consent prevents future non-essential collection but does not undo prior lawful processing. We do not currently respond to the older browser “Do Not Track” signal.

The mobile app does not load these website advertising or analytics tags. We do not sell personal data for money. We do not sell or share license telemetry. Google Ads and Meta Pixel may be considered “sharing” or targeted advertising under California and other U.S. state laws when those tags are active. Rejecting non-essential cookies or enabling GPC is the opt-out for this website.

8. Service providers and disclosures

We disclose only the data reasonably necessary for each service. Depending on context, a provider may act as our processor or as an independent controller:

  • Infrastructure and security: Cloudflare, Cloudways, DigitalOcean, SiteGround, and Amazon Web Services.
  • Forms and communications: Formspree, Google Workspace, and Zoho ZeptoMail.
  • Commerce and payments: WooCommerce/Automattic, Stripe, WooPayments, and PayPal.
  • App distribution: Apple (App Store) and Google (Google Play) process install, update, crash, and store-account data under their own notices.
  • Consent-based analytics and advertising: Google Tag Manager, Google Analytics, Google Ads, Meta, and Microsoft Clarity.

We may also disclose information when required by law, to protect users or our services, to investigate fraud or security incidents, or as part of a merger, financing, acquisition, or sale of assets subject to appropriate safeguards. We do not sell customer or mailing lists.

9. International transfers

Nubesti is based in the United States and our providers operate in the United States and other countries. Your information may therefore be processed outside your country of residence.

Where required, we use legally recognized transfer mechanisms made available by our providers, such as adequacy decisions, the EU-U.S. Data Privacy Framework, or Standard Contractual Clauses, together with appropriate technical and organizational safeguards.

10. Data retention

We keep account, order, and license data while an account or license is active and afterward only as needed to provide support, maintain transaction history, enforce agreements, resolve disputes, prevent fraud, and meet tax, accounting, and legal requirements.

The mobile app keeps the site URL and session token on the device until you sign out or uninstall the app. Signing data sent to a WordPress site is retained under that site's own policies. Nubesti does not keep a copy of those files.

Support records are kept for as long as reasonably necessary to resolve and document the request. Marketing data is retained until you unsubscribe or withdraw consent. Affiliate visit records are kept only as needed to attribute commissions, prevent fraud, and administer the affiliate program, then deleted or aggregated. Analytics and advertising retention follows our configured settings and the relevant provider's controls. When data is no longer required, we delete or anonymize it unless the law requires continued retention.

11. Security

We use reasonable technical and organizational measures, including encrypted HTTPS connections, access restrictions, account authentication, updates, monitoring, backups, and safeguards supplied by our infrastructure and payment providers. The mobile app connects to the customer's WordPress site over HTTPS and stores the session token on the device. No internet service can guarantee absolute security.

Customers remain responsible for securing their own WordPress installation, hosting, administrator accounts, backups, plugin configuration, kiosk or shared-device use of the app, and any third-party integrations they enable.

12. Your privacy rights

If you are in the European Economic Area, the United Kingdom, or Switzerland, you may request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or information about recipients, and you may lodge a complaint with your local data protection authority.

If you live in California or another U.S. state with a comprehensive privacy law (including Virginia, Colorado, Connecticut, Utah, Oregon, Texas, and others as they apply), you may request to know, access, correct, delete, or obtain a copy of personal information, and to opt out of sale, sharing, or targeted advertising. We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising unless you accept non-essential cookies. We honor Global Privacy Control as that opt-out. We do not use or disclose sensitive personal information to infer characteristics about you. We will not discriminate against you for exercising a privacy right.

We typically respond within 45 days, or sooner if the applicable law requires it. You may use an authorized agent; we may need to verify your identity and the agent's authority. Privacy requests from any country, including California and the EEA, may be sent to support@wpsigner.com or our contact page. If we cannot fulfill a request, we will explain why when required by law.

For step-by-step deletion of data from the WPsigner mobile app, see the WPsigner data deletion page.

13. Marketing communications

We send newsletters and promotional campaigns only to people who have subscribed or otherwise consented. You can unsubscribe through the link in any marketing email or by contacting us. Transactional messages about purchases, licenses, security, support, or important service changes are not marketing and may still be sent when necessary.

14. Children

The WPsigner mobile app is intended for users who are 18 years of age or older. WPsigner websites and the WordPress plugin are business services and are not directed to children under 16. We do not knowingly collect personal data directly from children under 16. If you believe a child has provided data to us, contact us so we can investigate and delete it where appropriate.

15. Changes and contact

We may update this policy when our services, providers, or legal obligations change. We will update the date above and provide additional notice when a change materially affects your rights or our use of personal data.

Nubesti LLC (WPsigner)
1111B S Governors Ave STE 23840
Dover, Delaware, United States
Email: support@wpsigner.com
Web: Contact WPsigner