Skip to main content
NEW Didit KYC Identity Verification is live, verify signers with government ID & biometrics for eIDAS Advanced signatures Learn more

Privacy Policy

How we handle data across our website, account portal, store, documentation, and self-hosted WordPress plugin.

Last updated: July 21, 2026

On this page

1. Scope and controller

Nubesti LLC, doing business as WPsigner, is responsible for personal data collected directly through wpsigner.com, app.wpsigner.com, docs.wpsigner.com, our store, account portal, licensing service, and support channels.

Business address: 1111B S Governors Ave STE 23840, Dover, Delaware, United States. Privacy requests may be sent to support@wpsigner.com or through our contact page.

This policy does not make Nubesti the controller of documents and signer data that a customer processes inside their own WordPress installation.

2. The self-hosted product and our role

WPsigner is self-hosted. Documents, templates, signatures, signer details, audit trails, and workflow records created with the plugin are stored in the customer's WordPress environment. They are not routinely copied to or synchronized with Nubesti.

The customer operating that WordPress site decides why and how signer data is processed and is normally the controller of that data. Nubesti only receives document or signer information when a customer voluntarily sends it to us or grants temporary access for support. Customers should remove unnecessary personal or sensitive information before sharing support materials.

Optional services such as KYC, SMS, WhatsApp, cloud storage, or automation connect to third parties only when the customer configures and enables them. Those providers' terms and privacy notices apply to data sent through the integration.

3. Data we collect

  • Account and order data: name, email address, username, company and billing details, tax fields when applicable, orders, license entitlements, payment status, and transaction references.
  • License and update data: license key, website domain or URL, and the installed versions of WordPress, PHP, and WPsigner. Standard security logs may also contain an IP address, timestamp, and user agent.
  • Support and contact data: name, email, subject, message, correspondence, and files or technical details that you choose to provide.
  • Website and consent data: IP address, browser and device information, referring page, pages visited, and interaction events. Non-essential analytics and advertising data is collected only after consent.
  • Marketing data: email address, subscription status, and campaign interactions when you opt in to promotional communications.

We do not intentionally collect the contents of customers' signed documents through the licensing service, and we do not receive complete payment card or PayPal credentials.

4. Why we process data

We use personal data to create and secure accounts, process orders, issue licenses, deliver updates, provide support, prevent fraud and abuse, maintain our services, meet tax and accounting duties, understand website performance, measure campaigns, and send requested marketing.

Where laws such as the GDPR or UK GDPR require a legal basis, we rely on: contract to provide purchased services; legal obligation for tax, accounting, and valid legal requests; legitimate interests for service security, fraud prevention, and business operations; and consent for non-essential analytics, advertising tags, and promotional email.

5. Store and payments

Our account portal and store run on WooCommerce. Payments may be processed by Stripe, WooPayments, or PayPal, depending on the option selected at checkout. Payment providers collect and process payment credentials under their own privacy notices and security obligations.

Nubesti receives the information needed to fulfill the order, such as payment confirmation or failure, transaction reference, payment method, billing information, refunds, and fraud or dispute information. We do not store complete card numbers or security codes.

6. Cookies, analytics, and advertising

We use essential storage for site operation and to remember your cookie choice. Google Tag Manager is loaded only after you select Accept All. It may then load Google Analytics 4, Google Ads, Meta Pixel, and Microsoft Clarity. These services may receive online identifiers, IP and device information, page and event data, and campaign attribution information.

You can refuse these tags by choosing Reject All or change your decision later through Cookie Preferences in the footer. Withdrawing consent prevents future non-essential collection but does not undo prior lawful processing. Our site does not currently respond to browser “Do Not Track” signals.

We do not sell personal data for money. However, Google Ads and Meta Pixel activity may be considered “sharing” or targeted advertising under some U.S. state laws. Rejecting non-essential cookies is the available opt-out for this website.

7. Service providers and disclosures

We disclose only the data reasonably necessary for each service. Depending on context, a provider may act as our processor or as an independent controller:

  • Infrastructure and security: Cloudflare, Cloudways, DigitalOcean, SiteGround, and Amazon Web Services.
  • Forms and communications: Formspree, Google Workspace, and Zoho ZeptoMail.
  • Commerce and payments: WooCommerce/Automattic, Stripe, WooPayments, and PayPal.
  • Consent-based analytics and advertising: Google Tag Manager, Google Analytics, Google Ads, Meta, and Microsoft Clarity.

We may also disclose information when required by law, to protect users or our services, to investigate fraud or security incidents, or as part of a merger, financing, acquisition, or sale of assets subject to appropriate safeguards. We do not sell customer or mailing lists.

8. International transfers

Nubesti is based in the United States and our providers operate in the United States and other countries. Your information may therefore be processed outside your country of residence.

Where required, we use legally recognized transfer mechanisms made available by our providers, such as adequacy decisions, the EU-U.S. Data Privacy Framework, or Standard Contractual Clauses, together with appropriate technical and organizational safeguards.

9. Data retention

We keep account, order, and license data while an account or license is active and afterward only as needed to provide support, maintain transaction history, enforce agreements, resolve disputes, prevent fraud, and meet tax, accounting, and legal requirements.

Support records are kept for as long as reasonably necessary to resolve and document the request. Marketing data is retained until you unsubscribe or withdraw consent. Analytics and advertising retention follows our configured settings and the relevant provider's controls. When data is no longer required, we delete or anonymize it unless the law requires continued retention.

10. Security

We use reasonable technical and organizational measures, including encrypted HTTPS connections, access restrictions, account authentication, updates, monitoring, backups, and safeguards supplied by our infrastructure and payment providers. No internet service can guarantee absolute security.

Customers remain responsible for securing their own WordPress installation, hosting, administrator accounts, backups, plugin configuration, and any third-party integrations they enable.

11. Your privacy rights

Depending on where you live and which law applies, you may request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or information about recipients. You may also opt out of promotional email at any time and lodge a complaint with your local data protection authority.

Residents of certain U.S. states may have rights to know, correct, delete, obtain a copy, and opt out of sale, sharing, or targeted advertising. We will not discriminate against you for exercising a privacy right. We may need to verify your identity and retain limited information to document the request.

Send requests to support@wpsigner.com or use our contact page. If we cannot fulfill a request, we will explain why when required by law.

12. Marketing communications

We send newsletters and promotional campaigns only to people who have subscribed or otherwise consented. You can unsubscribe through the link in any marketing email or by contacting us. Transactional messages about purchases, licenses, security, support, or important service changes are not marketing and may still be sent when necessary.

13. Children

WPsigner is a business service and is not directed to children under 16. We do not knowingly collect personal data directly from children under 16. If you believe a child has provided data to us, contact us so we can investigate and delete it where appropriate.

14. Changes and contact

We may update this policy when our services, providers, or legal obligations change. We will update the date above and provide additional notice when a change materially affects your rights or our use of personal data.

Nubesti LLC (WPsigner)
1111B S Governors Ave STE 23840
Dover, Delaware, United States
Email: support@wpsigner.com
Web: Contact WPsigner