Privacy policy

Last updated 2 September 2026

PactaHQ is an electronic signature service. Signing a document means creating a record of who signed what and when, so this policy is mostly about what that record contains and how long we keep it.

Who we are

PactaHQ is operated by VZNEXT LLC, 5000 Thayer Center, Suite C, Oakland, MD 21550, United States. For anything about your data, write to privacy@pactahq.com.

There are two kinds of people in this policy. Senders hold a PactaHQ account and send documents. Signers receive a document from a sender. For a signer’s data, the sender decides what is collected and why; we process it on their behalf.

What we store

If you have an account:

  • Your name and email address.
  • Your password, stored only as a scrypt hash. We cannot read it, and neither can anyone who obtains the database.
  • Your organisation, the people in it, and their roles.
  • A session identifier in a cookie, so you stay signed in.

For every document sent through PactaHQ:

  • The document itself, as uploaded, and the completed version once everyone has signed.
  • The name and email address of each recipient.
  • Each signature, either as an image of what was drawn or as the typed name and the typeface chosen.
  • A verification code sent by email, stored only as a hash and only until it expires.

And an audit trail, which is the point of the product:

  • Every event in a document's life: created, sent, opened, verified, signed, declined, sealed.
  • The date and time of each event, to the second.
  • The IP address and browser user agent of whoever caused it.

Why the audit trail cannot be edited

Each audit event contains a hash of the one before it, forming a chain. Altering or removing an event breaks the chain visibly, which is exactly what makes a signed document defensible later.

The consequence for privacy is real and we would rather state it plainly: the audit trail is not editable, including by us. Once an event is recorded, it stays, for as long as the document does. If that is not acceptable for a particular document, do not send it through PactaHQ.

What we do not do

  • We do not sell or rent personal data. There is no arrangement under which we would.
  • We do not use advertising trackers, analytics scripts, or third-party cookies. The site loads no scripts from anyone else, which its Content Security Policy enforces rather than merely promises.
  • We do not read your documents, or train anything on them.
  • We do not send marketing email to signers. A signer's address is used for their document and nothing else.

Cookies

One cookie, holding a session identifier, set when you sign in and cleared when you sign out. It is httpOnly, so scripts cannot read it, and it expires after thirty days. It is strictly necessary for the service to function, and there is nothing to opt out of because there is nothing else being set.

Who else sees your data

  • Our email provider, which delivers signing requests, verification codes and completed documents. They see recipient email addresses, the message content, and any attached completed document.
  • Our hosting provider, which runs the server and stores the disk the database and documents sit on.
  • Other people in your organisation, who can see documents the organisation owns. This is deliberate: it is what lets a colleague pick up your work.

We will also disclose data where the law requires it. If we receive such a request and are permitted to tell you, we will.

Where your data is held

On servers in the United States. If you are outside the United States, using PactaHQ means your data is transferred there.

How long we keep it

  • Documents and their audit trails: for as long as your account exists, because a signed document with no audit trail is worth less than no document at all.
  • Verification codes: ten minutes, then they are unusable, and only ever as a hash.
  • Sessions: thirty days, or until you sign out.
  • Accounts created by signing without an account: removed if you never come back to claim them.

Your choices

You can ask us for a copy of your data, ask for corrections, or ask us to delete your account and its documents. Write to privacy@pactahq.com.

Deletion has one limit worth knowing before you rely on it. Where a document has been signed by someone else, that person and the organisation that sent it have their own interest in the record, and a signature you can unilaterally erase is not much of a signature. In those cases we will remove what we can and tell you plainly what remains and why.

Depending on where you live you may have further rights, including under the California Consumer Privacy Act or the UK and EU GDPR. We honour those requests regardless of where you are.

Security

Passwords are hashed with scrypt and never stored in a readable form. Sign-in attempts are rate limited and lock out after repeated failures. Documents are served only to members of the organisation that owns them, or to a recipient holding their own signing link, and are never publicly readable.

Completed documents are signed with an Ed25519 key held by the server, so any later change to the file can be detected. No system is beyond compromise, and we do not claim otherwise. If something happens that affects your data, we will tell you.

Children

PactaHQ is not intended for anyone under 18, and we do not knowingly collect their data.

Changes

If this policy changes in a way that affects you, we will say so before it takes effect rather than quietly changing the date at the top.

See also the terms of service.