Privacy Policy
Version 2.0 · Effective 3 September 2026
On this page
1. Overview 2. Who We Are and How to Contact Us 3. Scope of This Policy 4. Definitions 5. Information We Collect 6. Google User Data and Limited Use 7. Microsoft 365 and Entra ID Data 8. How We Use Information 9. Legal Bases for Processing 10. How We Share Information 11. International Data Transfers 12. Data Retention 13. Deleting Your Data and Revoking Access 14. How We Protect Your Information 15. Data Breach Notification 16. Your Privacy Rights 17. Notice to California Residents 18. Cookies and Tracking Technologies 19. Children's Privacy 20. Automated Decision-Making and AI 21. Third-Party Links and Services 22. Changes to This Policy 23. Contact and Complaints1. Overview
This Privacy Policy describes how Xpert Group FZE-LLC ("SignSyncer", "we", "us", "our") collects, uses, stores, shares, and protects information when you visit https://signsyncer.com or use the SignSyncer web application at https://app.signsyncer.com (together, the "Service").
SignSyncer is an email signature management platform. Organisations use it to design, standardise, and deploy email signatures and disclaimers across their employees' mailboxes. To do that, the Service reads a limited set of employee profile fields from your organisation's directory and writes a signature into each connected mailbox. This policy explains exactly what that involves.
By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please do not use the Service.
2. Who We Are and How to Contact Us
SignSyncer is owned and operated by Xpert Group FZE-LLC, a company registered in the United Arab Emirates. For the purposes of the EU and UK General Data Protection Regulation ("GDPR"), Xpert Group FZE-LLC acts as a Data Controller in respect of account and website data, and as a Data Processor in respect of the directory and mailbox data we process on behalf of our business customers.
| Legal entity | Xpert Group FZE-LLC |
|---|---|
| Registered address | Business Center, SPC Free Zone, Al Zahia, Sharjah, United Arab Emirates |
| Product | SignSyncer — https://signsyncer.com |
| Application portal | https://app.signsyncer.com |
| Privacy and data protection contact | support@signsyncer.com |
| Telephone | +971 50 433 4829 |
3. Scope of This Policy
This policy applies to:
- The SignSyncer marketing website at signsyncer.com, including our free tools (signature generator, banner maker, handwritten signature generator)
- The SignSyncer web application at app.signsyncer.com
- The SignSyncer application programming interfaces (APIs) used by the above
- Support, sales, and billing communications with us
This policy does not apply to third-party products that you connect to SignSyncer (such as Google Workspace or Microsoft 365), or to third-party websites we link to. Those services are governed by their own privacy policies.
4. Definitions
| Term | Meaning |
|---|---|
| Account | A unique account created for you to access the Service. |
| Administrator | A person authorised by a Customer to configure SignSyncer on the Customer's behalf, including connecting a directory. |
| Customer | The organisation or individual that subscribes to the Service. |
| Directory Data | Employee profile fields read from a connected directory, such as name, job title, department, phone number, and email address. |
| End User | An employee or member of a Customer whose mailbox receives a SignSyncer signature. |
| Google User Data | Any data obtained through Google APIs under the authorisation you grant to SignSyncer. |
| Personal Data | Any information relating to an identified or identifiable natural person. |
| Service Provider / Sub-processor | A third party that processes data on our behalf to help us deliver the Service. |
| Usage Data | Data collected automatically by the Service or its infrastructure, such as IP address and page views. |
5. Information We Collect
5.1 Information you provide directly
- Account information: full name, business email address, password (stored only as a salted hash), company name, country, and job title.
- Billing information: billing contact, company address, VAT/TRN number, and subscription plan. Card details are entered directly with our payment processor and are never stored on our systems.
- Signature content: the text, images, logos, banners, social links, disclaimers, and legal notices you add to signature templates.
- Support and sales content: messages, attachments, and contact details you send us through forms, email, or chat.
5.2 Directory Data
If an Administrator connects a directory (Google Workspace, Microsoft Entra ID, or an uploaded CSV), we read a limited set of employee profile fields so that signature templates can be populated automatically. We request read-only access to directory information. We do not request permission to modify, create, or delete directory records.
Typical fields read are: display name, given name, family name, primary email address, job title, department, office location, work telephone number, mobile telephone number, manager, and profile photo.
5.3 Mailbox signature settings
To deploy a signature, the Service writes to the signature setting of the connected mailbox. This is a narrow, setting-level write. SignSyncer does not read, download, index, or store the content of your emails. We do not access message bodies, subjects, attachments, contacts, or calendars.
5.4 Usage and device data
Usage Data is collected automatically when you use the Service and may include your IP address, browser type and version, operating system, device identifiers, the pages you visit, referring URLs, the date and time of your visit, time spent on pages, and diagnostic or crash data.
5.5 Log and security data
We keep application and security logs, including authentication events, administrative actions, API requests, and signature deployment records. These logs support troubleshooting, abuse prevention, and our security obligations.
5.6 Cookies and similar technologies
See Section 18.
6. Google User Data and Limited Use
SignSyncer integrates with Google Workspace so that Administrators can deploy signatures across their organisation. This section describes that integration in detail.
6.1 Limited Use disclosure
SignSyncer's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6.2 Scopes we request and why
We request the minimum scopes necessary to deliver the features you enable. You are shown these scopes on the Google consent screen before you approve them.
| Google OAuth scope | Why SignSyncer needs it |
|---|---|
openid, .../auth/userinfo.email, .../auth/userinfo.profile | To sign you in with Google and identify your account. We store your name, email address, and profile picture URL for your SignSyncer profile. |
.../auth/gmail.settings.basic | To create and update the email signature on your Gmail account. This scope is used only to write the signature you or your Administrator has approved. |
.../auth/gmail.settings.sharing | To apply the signature to send-as aliases, so that signatures remain consistent when you send from an alias address. |
.../auth/admin.directory.user.readonly | To read employee profile fields (name, title, department, phone) so that signature templates populate automatically across the organisation. Read-only. |
.../auth/admin.directory.group.readonly | To read group membership so that different signature templates can be targeted to different teams or departments. Read-only. |
6.3 How we use, store, and share Google User Data
- Use: Google User Data is used solely to provide and improve the user-facing features described above — populating signature templates and deploying signatures to mailboxes.
- Storage: We store only the directory fields required to render signatures, along with the record of which signature was deployed to which mailbox and when. Data is encrypted in transit and at rest. OAuth tokens are stored encrypted and are used only to perform the actions you have authorised.
- Sharing: We do not transfer Google User Data to third parties except (a) to sub-processors strictly necessary to provide the Service, under contract and under our instruction; (b) where you or your Administrator direct us to; or (c) where required by law.
6.4 What we never do with Google User Data
- We do not sell, rent, or licence Google User Data.
- We do not use Google User Data for advertising, remarketing, ad targeting, or building advertising profiles.
- We do not use Google User Data to train, fine-tune, or develop generalised artificial intelligence or machine learning models.
- We do not allow humans to read Google User Data, except: with your explicit prior consent for a specific purpose (for example, to resolve a support ticket you raised); where necessary for security purposes such as investigating abuse; to comply with applicable law; or where the data has been aggregated and anonymised.
- We do not read, store, or process the content of your email messages.
6.5 Revoking Google access
You can revoke SignSyncer's access to your Google Account at any time from your Google Account permissions page at myaccount.google.com/permissions, or by disconnecting the integration inside SignSyncer. See Section 13 for deletion of the data already held.
7. Microsoft 365 and Entra ID Data
Where you connect Microsoft 365, we use Microsoft Graph permissions in the same minimised way. Typical permissions are read-only directory access to populate templates, and a mailbox settings permission to write the Outlook signature. As with Google, we do not read, store, or process the content of your email messages, contacts, or calendar.
| Microsoft Graph permission | Why SignSyncer needs it |
|---|---|
User.Read | To sign you in and read your basic profile. |
User.Read.All (read-only) | To read employee profile fields used to populate signature templates. |
Group.Read.All (read-only) | To target signature templates by group, team, or department. |
MailboxSettings.ReadWrite | To write the approved signature into the user's Outlook mailbox settings. |
offline_access | To refresh access without asking the Administrator to re-authenticate on every deployment. |
Administrators can revoke SignSyncer's access at any time from the Microsoft Entra admin center under Enterprise applications.
8. How We Use Information
- To create, deploy, update, and manage email signatures and disclaimers
- To create and administer accounts, authenticate users, and enforce plan limits
- To provide customer support and respond to your requests
- To process payments, issue invoices, and manage subscriptions
- To operate, maintain, secure, monitor, and improve the Service
- To detect, investigate, and prevent fraud, abuse, and security incidents
- To send service communications such as security notices, billing notices, and material changes to this policy
- To send marketing communications about SignSyncer, where permitted and subject to your right to opt out at any time
- To produce aggregated, de-identified statistics that do not identify any individual
- To comply with legal, tax, accounting, and regulatory obligations
We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
9. Legal Bases for Processing
Where the GDPR applies, we rely on the following legal bases:
| Processing activity | Legal basis |
|---|---|
| Providing the Service to an account holder | Performance of a contract (Art. 6(1)(b)) |
| Processing Directory Data on behalf of a Customer | Performed as processor under the Customer's instructions and our data processing terms |
| Billing, tax, and accounting records | Legal obligation (Art. 6(1)(c)) |
| Security monitoring, fraud prevention, service improvement | Legitimate interests (Art. 6(1)(f)) |
| Marketing emails and non-essential cookies | Consent (Art. 6(1)(a)), withdrawable at any time |
10. How We Share Information
We share information only where it is necessary to run the Service, and only with parties bound by confidentiality and data protection obligations. We share with the following categories of recipient:
| Category | Purpose |
|---|---|
| Cloud hosting and infrastructure | Hosting the application, databases, and backups |
| Content delivery and DNS | Serving website assets and signature images securely |
| Transactional email delivery | Sending account, security, and billing notifications |
| Payment processing | Taking subscription payments and issuing receipts |
| Product analytics and error monitoring | Understanding usage and diagnosing faults |
| Customer support tooling | Managing and responding to your support requests |
| Professional advisers | Legal, accounting, audit, and insurance purposes |
A current list of our named sub-processors is available on request from support@signsyncer.com. We will give existing customers notice of any new sub-processor that processes their data.
We may also disclose information: (a) in connection with a merger, acquisition, financing, or sale of assets, with notice before your data becomes subject to a different privacy policy; (b) where required by law, court order, or a valid request from a public authority; and (c) where necessary to protect the rights, property, or safety of SignSyncer, our users, or the public.
11. International Data Transfers
SignSyncer is operated from the United Arab Emirates and uses infrastructure providers that may store or process data in other countries. This means your information may be transferred to, and maintained on, systems located outside your state, province, or country, where data protection laws may differ from those in your jurisdiction.
Where we transfer personal data out of the European Economic Area or the United Kingdom, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with supplementary technical measures such as encryption in transit and at rest. A copy of the relevant safeguards can be requested from support@signsyncer.com.
12. Data Retention
We retain personal data only for as long as necessary for the purposes set out in this policy, and then delete or anonymise it. Our standard retention periods are:
| Data category | Retention period |
|---|---|
| Account and profile data | For the life of the account, then deleted within 30 days of account closure |
| Directory Data and Google/Microsoft User Data | For as long as the integration is connected; deleted within 30 days of disconnection or account closure |
| OAuth access and refresh tokens | Revoked and deleted immediately on disconnection or account closure |
| Signature templates and assets | For the life of the account, then deleted within 30 days of account closure |
| Application and security logs | Up to 12 months |
| Support correspondence | Up to 24 months after the ticket is closed |
| Invoices and financial records | As required by UAE tax and accounting law, typically 5 years |
| Backups | Rolling backups, overwritten within 35 days |
13. Deleting Your Data and Revoking Access
You are in control of your data at all times. You can:
- Disconnect an integration. In app.signsyncer.com, open Settings → Integrations and disconnect Google Workspace or Microsoft 365. We revoke and delete the stored tokens immediately and delete the associated Directory Data within 30 days.
- Revoke access at the provider. For Google, visit myaccount.google.com/permissions and remove SignSyncer. For Microsoft, an Administrator can remove SignSyncer from Entra ID Enterprise applications.
- Delete your account. In app.signsyncer.com, open Settings → Account → Delete account. All account data, templates, and Directory Data are permanently deleted within 30 days, except records we are legally required to keep.
- Ask us to do it for you. Email support@signsyncer.com from the address on the account. We will verify your identity and complete the deletion within 30 days, and confirm to you in writing when it is done.
Deletion from live systems is immediate on completion of the request; residual copies in encrypted backups are removed as those backups expire, within 35 days.
14. How We Protect Your Information
We maintain an Information Security Policy and apply administrative, technical, and physical safeguards appropriate to the risk, including:
- Encryption of all data in transit using TLS 1.2 or higher, and encryption of data at rest using AES-256
- Encrypted storage of OAuth tokens and secrets in a dedicated secrets manager, separate from application data
- Role-based access control, least-privilege access, and mandatory multi-factor authentication for all staff and administrative accounts
- Password hashing using a modern, salted, computationally expensive algorithm; passwords are never stored in reversible form
- Secure software development practices, peer code review, dependency scanning, and static analysis before release
- Centralised logging, monitoring, and alerting on authentication and administrative events
- Regular vulnerability scanning, patching, and periodic penetration testing
- Encrypted, regularly tested backups and a documented disaster recovery plan
- Confidentiality obligations and security awareness training for all personnel
You can read more on our Security page, our Information Security Policy, and our Vulnerability Disclosure Policy. No method of transmission over the Internet or method of electronic storage is completely secure, so while we strive to protect your personal data using commercially acceptable means, we cannot guarantee its absolute security.
15. Data Breach Notification
We maintain an Incident Response Policy that governs how we detect, contain, and respond to security incidents. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk, we will notify affected individuals and our business customers without undue delay, describing the nature of the breach, the likely consequences, and the measures taken.
16. Your Privacy Rights
Depending on where you live, you may have the following rights in relation to your personal data:
- Access — to obtain a copy of the personal data we hold about you
- Rectification — to have inaccurate or incomplete data corrected
- Erasure — to have your personal data deleted, subject to legal retention requirements
- Restriction — to limit how we process your data in certain circumstances
- Portability — to receive your data in a structured, commonly used, machine-readable format
- Objection — to object to processing based on our legitimate interests, and to object to direct marketing at any time
- Withdraw consent — where processing is based on consent, to withdraw it at any time without affecting prior processing
- Complain — to lodge a complaint with your local data protection authority
To exercise any of these rights, email support@signsyncer.com. We will verify your identity before acting and will respond within 30 days. We do not charge a fee for reasonable requests and we will not discriminate against you for exercising your rights.
If you are an End User whose signature is managed by your employer, your employer is the controller of that data. We will refer your request to them and support them in responding to it.
If you are in the United Arab Emirates, your rights under Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data are honoured in the same way as those set out above.
17. Notice to California Residents
If you are a California resident, the California Consumer Privacy Act as amended by the CPRA gives you additional rights, including the right to know, delete, correct, opt out of sale or sharing, and limit the use of sensitive personal information. We do not sell or share personal information as those terms are defined by the CCPA, and we have not done so in the preceding 12 months. Full details are set out in our CCPA Notice.
18. Cookies and Tracking Technologies
We use cookies and similar technologies such as tags, pixels, and local storage. Cookies may be "persistent" (they remain on your device until they expire or you delete them) or "session" cookies (deleted when you close your browser).
| Type | Purpose |
|---|---|
| Strictly necessary | Authentication, session management, security, load balancing, and CSRF protection. These cannot be switched off. |
| Preference | Remembering your language, plan currency, and interface settings. |
| Analytics | Understanding aggregate usage so we can improve the Service. Set only with your consent. |
| Marketing | Measuring campaign performance on our website. Set only with your consent, and never applied to Google User Data. |
You can control cookies through your browser settings and through the cookie banner on our website. If you refuse cookies, some parts of the Service may not function correctly. We honour Global Privacy Control signals where our systems receive them. Because there is still no common industry standard for Do Not Track, our website does not currently respond to DNT browser signals.
19. Children's Privacy
SignSyncer is a business product and is not directed at children. We do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us with personal data, contact support@signsyncer.com and we will delete it.
20. Automated Decision-Making and AI
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Where the Service offers AI-assisted features, such as suggesting signature copy, any content you submit to those features is used only to generate your result. We do not use Google User Data, Microsoft user data, Directory Data, or customer content to train generalised AI or machine learning models.
21. Third-Party Links and Services
The Service may contain links to third-party websites or embed third-party services. We are not responsible for their content or privacy practices, and we encourage you to read their privacy policies before providing them with any information.
22. Changes to This Policy
We review this policy at least annually and may update it to reflect changes in the Service, the law, or our practices. We will post the updated policy on this page and revise the version number and effective date above. Where changes are material, we will notify account holders by email or in-product notice before the change takes effect. Prior versions are available on request.
23. Contact and Complaints
If you have questions about this policy, wish to exercise your rights, or want to make a complaint about how we handle your data, contact us:
Xpert Group FZE-LLC
Business Center, SPC Free Zone, Al Zahia
Sharjah, United Arab Emirates
Phone: +971 50 433 4829
Email: support@signsyncer.com
We aim to acknowledge every privacy enquiry within 3 business days and to resolve it within 30 days. If you are not satisfied with our response, you have the right to complain to your local data protection authority.