Privacy Policy

Last updated: April 23, 2026

Peekop helps professionals send documents for electronic signature through links shared over messaging apps, SMS, and email. This policy explains what we collect, how we use it, and the choices you have.

In plain language

We collect the information needed to deliver the signing service to you and your recipients, and nothing more. We do not sell your data or the documents you upload. You can email us at hello@peekop.com any time to access, correct, or delete your information.

1. Who we are

Peekop (“Peekop,” “we,” “us,” or “our”) is an electronic signature service operated out of the United States. This policy applies to peekop.com, our application at app.peekop.com, and the recipient-facing signing flow at sign.peekop.com.

If you are signing a document someone sent you through Peekop, this policy describes how the sender and we together handle the information you provide during signing. If you are the sender, this policy applies to your account and the documents you send.

2. Information we collect

We collect only what we need to operate the service.

Account information (senders)

When you create an account, we collect your name, email address, organization name, and industry vertical. If you choose a paid plan, our payment processor (Stripe) collects your payment details directly; we receive only the non-sensitive transaction metadata needed for billing.

Document content (senders and signers)

When you upload a document to send for signature, we store the document and its detected fields. When a recipient signs, we record the drawn or typed signature, signed values for each field, the timestamp, IP address, and user agent of the signing event. This information becomes part of the completion certificate that makes the signature legally defensible under the US ESIGN Act.

Usage and diagnostic information

We collect basic logs of how the service is used — such as which endpoints were called and whether they succeeded — to diagnose problems and prevent abuse. These logs include IP addresses and user agents and are retained for a limited period.

Cookies

We use a small number of strictly necessary cookies to keep you signed in and to route requests to the right backend. We do not use third-party advertising or cross-site tracking cookies.

3. How we use your information

  • To deliver the signing service — creating signing links, rendering the document to your recipient, capturing their signature, and returning the signed PDF and certificate to you.
  • To authenticate accounts and protect the service from abuse, including rate limiting, bot detection, and fraud prevention.
  • To communicate with you about your account — transactional emails such as confirmations, billing receipts, security alerts, and changes to the service.
  • To improve the product — analyzing aggregate patterns of use to understand what is working and what needs fixing. We do not train machine-learning models on your document contents.
  • To comply with legal obligations — responding to lawful subpoenas, court orders, and regulatory requests when required.

4. Service providers we rely on

We use a small number of trusted service providers to operate Peekop. Each of them processes data only on our instructions and under written data-protection commitments.

  • Supabase — database and object storage hosting our production data in the United States.
  • Railway — compute infrastructure running our API and background services.
  • Vercel — content delivery for our marketing and application front-ends.
  • Stripe — payment processing for paid plans.
  • Resend — transactional email delivery (signing links, receipts, account alerts).
  • Anthropic — AI-assisted detection of signature fields within the documents you upload. Content sent to Anthropic is processed under their commercial API terms and is not used to train their models.

We may add or replace providers over time. Material changes will be reflected in this policy and communicated to account owners.

5. When we share information

We do not sell your personal information or the contents of your documents. We share information only in these circumstances:

  • With recipients you choose. When you send a document, the recipient sees the document and the sender’s identifying information as part of normal signing.
  • With our service providers listed above, strictly to operate the service on our behalf.
  • For legal reasons, when we are required to comply with applicable law, lawful governmental requests, or to establish or defend legal rights.
  • In a business transfer, if Peekop is acquired or merges with another entity, in which case the acquirer inherits the same commitments described here.

6. How long we keep data

We keep your account information and completed documents for as long as your account is active. If you cancel your account, we will delete your account information and documents within 90 days of cancellation unless longer retention is required for legal, accounting, or fraud-prevention reasons.

Diagnostic logs are retained on a rolling basis for up to 90 days. Completed-document audit trails are retained for as long as the originating document exists, because they are part of what makes the signature legally defensible.

7. How we protect your data

Documents are encrypted in transit (TLS) and at rest. Signing links are signed with HMAC-SHA256 and carry an expiration. We use short-lived session tokens, timing-safe comparisons for sensitive checks, and standard access controls over production systems.

No system is perfectly secure, and we cannot guarantee the security of information you transmit to us. If we become aware of a breach affecting your personal information, we will notify you in accordance with applicable law.

8. Your rights and choices

You have the right to access the personal information we hold about you, correct it if it’s wrong, or request that we delete it. You can exercise these rights by emailing hello@peekop.com. We will respond within a reasonable period, typically 30 days.

If a deletion request would affect a document someone else sent you for signature, or a document you sent to someone else, we may need to retain a redacted record for the other party’s legal audit purposes. We will explain this if it comes up in your specific request.

9. Children

Peekop is not directed to children under 18, and we do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal information, please contact us so we can delete it.

10. International users

Peekop is operated from the United States and our service providers are primarily located in the United States. If you are accessing Peekop from outside the United States, you understand that your information will be transferred to and processed in the United States. At this time we do not market or sell to the European Economic Area or the United Kingdom, and we are not configured to act as a GDPR data controller for those regions.

11. Changes to this policy

We may update this policy as the product evolves. When we make material changes, we will update the “Last updated” date at the top and, where appropriate, notify account owners by email. Continued use of Peekop after an update means you accept the revised policy.

12. Contact us

If you have questions about this policy or about how we handle your information, please email hello@peekop.com. We read every message.

This is an initial version of our privacy policy. We will expand it as the product grows. If something here is unclear or you need a more detailed answer for a compliance review, please reach out.