Privacy policy
Last updated 6 September 2026. Plain language on purpose.
What Agreevo is
Agreevo lets you send documents for electronic signature, sign documents you receive, and keep the signed copies. This page explains what data that involves, where it lives, and who can see it.
Data we hold, and why
- Your account — email address, name, company name and an optional logo. Needed to sign you in and to put your name on the documents you send.
- Documents — the PDFs you upload or generate, the fields placed on them, and the completed, signed versions. Stored in private cloud storage; only your account can read them, and a recipient can read only the document they were sent.
- Recipients — the names and email addresses you enter for the people who sign. We use them only to deliver the signing link and the finished document.
- Signatures and the audit trail — the drawn or typed signature, the time of each step (sent, opened, signed), the signer's IP address and browser, and their explicit consent to sign electronically. This is what makes a signature stand up later; it is printed as the last page of every completed PDF and kept for as long as the document is.
- Contract data — if you use "Import with AI", the key terms extracted from a document (counterparty, dates, value, renewal terms) and the document's text, so reminders and questions can work without re-reading the PDF each time.
- Usage counters — how many documents and AI calls you have used this month, for your plan limits.
- Billing — handled by Stripe. We keep your Stripe customer id and plan; card details never reach us.
Integrations you connect
Your own email provider (Resend, SendGrid, Postmark or SMTP): the credentials you enter are encrypted at rest and used only to send your signing emails. They are never shown again in the browser.
HubSpot: when you connect a HubSpot account, we store an access token for it, encrypted at rest. We read a deal's name, amount, close date, company and contacts only when you choose to send a contract from that deal, and we write back a timeline note, a "Agreevo contract status" property and, on completion, the signed PDF — to that deal only. Disconnecting deletes the token. We never read your other HubSpot data.
Webhooks and API keys: you choose where events are sent; we send only the document's id, title, status and the event itself, signed so the receiver can verify us.
AI features
Drafting, contract import and "ask your contract" send the relevant text — your brief, or the document's text — to an AI model provider to produce the answer. The text is used to answer your request and is not used by us to train anything. The provider is configured by the operator of this deployment; if no provider is configured, these features are switched off and say so.
Who can see what
- You see your own documents and nothing else. This is enforced in the database itself (row level security), not only in the application.
- A recipient sees the one document they were sent, through a single-use link that stops working the moment it is used, expires with the document, and is stored only as a hash.
- Nobody browses your documents on our side. Operators can access the database for support and maintenance and are bound to confidentiality.
Where the data is
Database and file storage run on Supabase (PostgreSQL and object storage) in the EU (Ireland). Emails go through the provider you chose, or through our default sender. The application itself is hosted on Vercel.
How long we keep it
Documents and their audit trails stay until you delete them. Completed documents cannot be deleted from within the product — a signed agreement is a record both sides are entitled to — but you can ask us to remove your account and everything in it. Deleting your account deletes your documents, recipients, audit trails, integrations and keys.
Your rights
You can export your documents (each has a download link) and your contract data (CSV under Integrations) at any time. You can ask for a copy of everything we hold about you, ask us to correct it, or ask us to delete it, by writing to the address below. If you are in the EU/EEA or UK, the GDPR applies and you may also complain to your local supervisory authority.
Cookies
One session cookie to keep you signed in, and one for your light/dark theme choice. No advertising or tracking cookies.
Changes
If this policy changes in a way that matters, we update the date above and tell signed-in users on their dashboard.
Contact
Privacy questions: privacy@the-guy.business.