Privacy & Data Handling
How sign2close handles your data today. This reflects our current practices and is updated as the product evolves. Last updated: September 18, 2026.
Who is responsible for your data
sign2close is operated by sign2close, LLC, a limited liability company organized in the State of Georgia, United States. sign2close, LLC decides how the data described below is handled and is the company to contact about it — "we" and "our" on this page mean that company.
What we collect
- Account details you provide (name, email, role, brokerage, phone, license number).
- Transaction data you enter (property addresses, client names, prices, dates, deadlines).
- Documents you upload to a transaction (contracts and related files).
- CRM leads, tasks, and professional contacts you create.
- Mobile push-notification tokens, if you enable notifications.
Google user data & email integration
sign2close allows users to optionally connect their Google Account to send transaction communications directly from their own email address. This section outlines our practices regarding Google user data in accordance with the Google API Services User Data Policy.
1. What Google user data is accessed
Our application will access the data you have authorized through Google OAuth, specifically:
-
Account identity: Your primary Google Account email address
(
.../auth/userinfo.email) and basic public profile information (.../auth/userinfo.profile) to authenticate and associate your connected account. -
Email dispatch permissions: The permission to compose and send emails on your behalf
(
.../auth/gmail.send). - Data we do NOT access: sign2close does not request or access scopes to read, search, index, download, modify, or delete any messages or drafts in your inbox, and we do not access your Google Contacts.
2. How your application uses Google user data
We will use your data solely to provide you with the services you requested. Specifically, the gmail.send scope
is used exclusively to dispatch transaction notifications, milestone updates, document requests, and client communications that you explicitly compose or
trigger within sign2close. This allows your clients to receive critical transaction updates from your recognizable email address rather than an automated system domain.
3. How we share, transfer, or disclose Google user data
We do not sell your Google user data to third parties, nor do we transfer or disclose your information to third parties for purposes other than providing the core functionality of our application. Specifically, our policy prohibits the transfer of Google user data to third parties for any of the following reasons:
- Targeted advertising, personalized advertisements, retargeted advertisements, or interest-based advertisements
- Selling to data brokers or providing to information resellers
- Determining credit-worthiness or lending purposes
- Creating databases or external marketing lists
- Developing, improving, or training generalized machine-learning (ML) or artificial intelligence (AI) models
4. Data protection mechanisms for sensitive data
Security procedures are in place to protect the confidentiality and integrity of your data. We use encryption to protect your information: all network communications are secured using TLS encryption in transit, and Google OAuth access and refresh tokens are encrypted at rest using AES-256 encryption. Database access is strictly isolated using PostgreSQL Row-Level Security (RLS). Furthermore, humans (employees or contractors) are not permitted to read your Google user data or emails, unless you provide explicit affirmative consent for a specific technical troubleshooting request, it is required for security investigations (such as investigating system abuse), or it is required by law.
5. Data retention and deletion
We store your personal information and Google OAuth tokens for a period of time that is consistent with our business purposes, specifically for the length of time needed to fulfill the email integration features outlined in this policy while your account remains active.
- Immediate disconnect & token destruction: When the data retention period expires or you disconnect the integration, we delete or destroy the stored credentials. You may disconnect at any time in Settings → Email Integration → Disconnect, which immediately and permanently purges your stored OAuth tokens from our database.
- Google Security Settings: You can revoke sign2close's access to your Google account at any time through Google Security Settings.
- Full account deletion requests: You may request complete deletion of your account and all associated data by emailing us at privacy@sign2close.com.
6. Artificial intelligence & machine learning
We explicitly affirm that Google Workspace APIs (including data accessed through the Gmail API) are never used to develop, improve, or train non-personalized AI and/or ML models.
sign2close's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How we protect your general data
- In transit: all traffic is encrypted with TLS.
- At rest: data is stored in Supabase (on AWS) with AES-256 encryption at rest.
- Access control: every record is protected by Postgres Row-Level Security, so you can only read or write data you're authorized for.
- Mobile hardening: the native apps block jailbroken/rooted devices and unauthorized emulators, keep local credentials in hardware-backed secure storage (iOS Keychain / Android Keystore), and wipe local keys if tampering is detected.
Contract auto-fill (AI processing)
When you use contract auto-fill, the uploaded PDF is sent to Anthropic's Claude API to extract the details shown in the form. Anthropic processes this data as our service provider under its Commercial Terms and Data Processing Addendum, and does not use it to train AI models. sign2close does not store the document during this process — only the extracted fields you review are saved, and only when you save the transaction.
Service providers we use
We rely on reputable third parties to operate the service. We do not sell your data.
- Supabase — database, authentication, and file storage.
- Google APIs — user authentication and optional Gmail sending integration.
- Anthropic — AI extraction for contract auto-fill (above).
- Resend — sending transactional and notification emails.
- Vercel — hosting the web application.
- Google Firebase — mobile push notifications.
Retention & deletion
We keep your data while your account is active. To request a copy of, or the deletion of, your data, email us at privacy@sign2close.com and we'll handle it manually.
Changes to this notice
As we add features, we'll update this page and revise the "last updated" date above. We only describe practices that are actually in place.
Contact
Questions about your data? Email privacy@sign2close.com.