- Effective:
- Last updated:
Introduction & scope
This Privacy Policy explains how WaiverForms, Inc. ("WaiverForms, Inc.," "we," or "us") collects, uses, discloses, and protects personal data when you visit https://clickwaiver.com (the "Site"), create or administer an organization account (each, an "Operator"), sign or are sent a waiver through the Site (each, a "Signer"), or otherwise interact with the digital‑waiver service (collectively, the "Service").
Operators and Signers play different roles, and the legal framework we apply differs accordingly. For an Operator's account data (name, email, billing), we act as a controller. For the waiver content an Operator collects from its own Signers (form‑field values, signature images, audit metadata), the Operator is the controller and we act as a processor on its behalf under a data‑processing agreement. Region‑specific terms (GDPR, UK GDPR, PIPEDA, CCPA/CPRA) appear in Section 11.
By using the Service you confirm that you have read and understand this Policy. If you do not agree, please do not use the Service.
Identity of the controller
The data controller responsible for personal data processed in connection with the Service is:
WaiverForms, Inc. (Registered office address to be inserted at launch.) Email: privacy@clickwaiver.com General contact: hello@clickwaiver.com
Where required by Article 27 of the UK / EU GDPR, our designated UK and EU representatives will be identified here following appointment prior to public launch.
Personal data we collect
We collect only the data the Service genuinely needs. The categories below are exhaustive at the date of this Policy. The Service does not run third‑party analytics, ad‑tech, fingerprint tracking, or behavioral profiling on the Site.
3.1 Operator account data
When you create or administer an Operator account, we collect:
- Identification & contact: name, email address, organization name, role (owner / admin / member), and optional profile photo or organization logo you upload.
- Authentication credentials: we use passwordless sign‑in — we do not collect or store passwords. You sign in either by a one‑time magic link sent to your email address, or via Google federated sign‑in, in which case we store the identifier issued by Google together with the OAuth access, refresh, and ID tokens used to maintain your session. Magic‑link tokens are short‑lived, single‑use, and stored only as a hash.
- Workspace configuration: organization slug, timezone, branding, retention preferences, jurisdiction defaults, integration secrets you have entered, and similar settings.
- Billing data: billing email, plan tier, and the limited token / status fields returned by our billing processor (Polar). Card numbers and full bank details are handled exclusively by the processor; we never receive or store them.
- Operational telemetry: IP address, user agent, and timestamps associated with sign‑ins, role‑changes, billing events, and API‑key creation, rotation, and revocation, retained for security and audit.
3.2 Signer waiver data
When a Signer completes a waiver via the Service (whether on the web, in kiosk mode, by email link, or via QR code), the following data is created on the Operator's behalf and stored by us as processor:
- Form‑field values: whatever data the template requested — typically the Signer's legal name, date of birth, email, phone, address, and any additional fields the Operator added (medical notes, emergency contacts, participant lists, etc.). Each Signer decides what to put in.
- Signature image: a PNG of the handwritten‑style signature drawn on screen.
- Audit metadata: for each event in the signing flow we record the event type, UTC timestamp, IP address, browser user agent, and approximate country/region derived from the IP. This is the legal record required by U.S. ESIGN, UETA, eIDAS, UK ECA 2000, and PIPEDA to make the signature enforceable.
- Generated documents: a signed‑waiver PDF and a certificate‑of‑completion PDF, both rendered from the data above and stored in our object‑storage tier.
- Optional uploads: a photo, ID, or other file the Signer attaches at the Operator's request.
Form‑field values that may contain sensitive personal data are encrypted in our database with AES‑256‑GCM using a per‑organization key derived via HKDF‑SHA‑256 from a master key never exposed to our application code. See Section 9.
3.3 Site‑visit data
When you visit the Site without signing in we receive standard server‑log information (IP address, user agent, request timestamp, path requested, referrer). This is retained only as long as needed for security monitoring and then rotated out. We do not place advertising cookies, run social‑media trackers, or fingerprint visitors. See Section 14 for the small number of strictly‑necessary cookies we use.
3.4 Support & communications
When you email us, fill in a contact form, or chat with our team, we receive the contents of those communications and any attachments you send. We keep them for the period needed to resolve the matter and as required for our own records.
How we receive personal data
The Service is configured so that personal data reaches us only in three ways:
- Directly from you — when you sign up, configure an Operator account, send a waiver, or sign a waiver delivered through the Service.
- From an Operator who has invited you — when a Signer follows an email link, scans a QR code, or completes a kiosk waiver, the Operator is the one who distributed the invitation; we store the resulting data on the Operator's behalf.
- From our infrastructure providers — limited metadata such as TLS‑handshake telemetry, request timestamps, and billing‑processor event payloads.
We do not buy personal data, scrape it, or receive it from data brokers.
Why we process it (purposes & lawful bases)
We process personal data only for the purposes listed below. Where GDPR or UK GDPR applies, the relevant lawful basis under Article 6 (and Article 9 where special‑category data is involved) is named alongside each purpose.
| Purpose | Data used | Lawful basis (EU / UK GDPR) |
|---|---|---|
| Provide the Service (account, signing flow, PDFs) | Account & waiver data | Art. 6(1)(b) — performance of contract |
| Maintain the legal record of a signed waiver | Audit metadata, signature image, signed PDF | Art. 6(1)(c) — legal obligation (ESIGN / eIDAS) + Art. 6(1)(f) legitimate interest in defending claims |
| Bill the Operator, handle taxes | Billing email, plan, processor tokens | Art. 6(1)(b) — contract + Art. 6(1)(c) — tax law |
| Security, fraud prevention, abuse monitoring | IPs, user agents, rate‑limit metrics, audit logs | Art. 6(1)(f) — legitimate interest in system integrity |
| Respond to your support requests | Contact data + content of the request | Art. 6(1)(b) / Art. 6(1)(f) |
| Send service announcements (account‑related, not marketing) | Operator email | Art. 6(1)(b) — contract |
| Comply with legal obligations & respond to lawful requests | As required by the request | Art. 6(1)(c) |
| Improve, debug, and develop the Service | Aggregate, de‑identified telemetry where feasible | Art. 6(1)(f) |
Under PIPEDA, the equivalent identification of purpose and consent obligation is satisfied by this Policy together with the consent flow shown to Signers at signing time. Under CCPA/CPRA, the corresponding "business purposes" under §1798.140(e) are: providing the Service, security, debugging, quality assurance, account management, processing payments, and compliance with legal obligations.
We do not use personal data for behavioral advertising, do not sell personal data, and do not share personal data for cross‑context behavioral advertising as those terms are defined under CCPA/CPRA §1798.140.
Recipients & subprocessors
We share personal data only with the recipients listed below. We execute a written processor / subprocessor agreement with each of them; each is bound by appropriate confidentiality and security obligations.
| Provider | Purpose | Region |
|---|---|---|
| Hetzner Online GmbH | Application + database hosting (managed via Coolify) | US (Ashburn, Virginia) |
| Cloudflare, Inc. (R2) | Object storage for PDFs, signature images, and uploads | Operator‑configurable region; EU pinning available |
| Cloudflare, Inc. (Email) | Transactional email delivery (sign‑in magic links, signing invites, notifications, DSAR magic links) | US / global edge |
| Polar Software AS | Subscription billing & tax handling | EU (Norway) + US |
| Google LLC | Optional federated sign‑in ("Sign in with Google") — only for Operators who choose it | US |
| OpenRouter, Inc. | Cloud fallback for Operator‑only AI template drafting (see note below) | US |
| Unsplash, Inc. | Stock industry photography used as decorative imagery on template pages; fetched server‑side, receives no personal data | US |
AI template drafting is an Operator‑only feature and its prompts contain only the natural‑language description and template context the Operator provides — never Signer data. Most template generation runs on a self‑hosted model on our own infrastructure (no third party receives the prompt); OpenRouter is used only as a cloud fallback. Signer waiver data is never sent to any AI provider.
We will publish an updated subprocessor list (including any additions or replacements) at this page or a sub‑page linked from it. Operators on plans with a Data Processing Agreement may, where commercially reasonable, receive advance notice of material changes via email; otherwise, the published subprocessor list is the authoritative source.
Beyond the subprocessors above, we disclose personal data only: (i) to comply with law, lawful subpoena, or court order; (ii) to enforce or protect our rights, the rights of an Operator, or the safety of any person; and (iii) in connection with a corporate transaction (merger, acquisition, financing), provided the recipient is bound by terms no less protective than this Policy.
International data transfers
The Service's application and database are hosted in the United States, and some subprocessors operate in the United States or the European Union (see the subprocessor table in Section 6). Where personal data of EU, UK, or Swiss residents is transferred outside the European Economic Area, the United Kingdom, or Switzerland — including to our US hosting and US subprocessors — we rely on the European Commission's Standard Contractual Clauses (SCCs, 2021/914) and the UK International Data Transfer Addendum where applicable. Where a transfer recipient is covered by the EU‑U.S. Data Privacy Framework, we additionally rely on that adequacy decision.
Operators may, on supported plans, restrict where their Signer waiver documents are stored by enabling the EU storage‑residency setting in workspace configuration. When enabled, that workspace's signed PDFs, signature images, and uploads are written exclusively to the EU region of our object‑storage tier (Cloudflare R2). This setting controls document storage only; account and audit metadata remain in our primary (US) region.
How long we keep it
Different categories of data are kept for different periods:
- Operator account data: for the life of the account plus a reasonable wind‑down window after closure.
- Organization‑closure record: when an Operator deletes an entire workspace, we keep a minimal, permanent record that the closure occurred and that a specific account holder directed it (the workspace name, the closure date, and — until that account holder later deletes their own personal account — their email; after personal‑account deletion the email is replaced with an irreversible keyed fingerprint that lets us confirm a specific identity in a dispute without retaining the address itself). This record is kept to defend against a claim that signed‑waiver records were destroyed unlawfully, for no longer than such a claim remains legally possible (the applicable waiver‑retention and limitation window). It contains no waiver content.
- Signer waiver data & legal record: for the period the Operator has configured for their workspace (default ten (10) years, calibrated to the longest practical U.S. statute‑of‑limitations window plus a minor‑tolling buffer). The Operator can raise or lower this within statutory minimums, and is responsible for setting a retention value lawful for its jurisdiction and operations.
- Audit‑event records: retained as part of the legal record. Where the underlying envelope is deleted under retention policy, the audit row remains with the envelope reference set to
null, preserving the records‑of‑processing trail required under GDPR Art. 30 even after the personal data itself is purged. - Billing records: for the period required by applicable tax and accounting law (typically seven (7) years in the U.S. and six (6) years in the U.K.).
- Support communications: for two (2) years from the date of resolution unless we are required to keep them longer.
- Site server logs: rotated and discarded within ninety (90) days unless retained longer for security investigation.
A Signer can request a copy or deletion of their data using the rights described in Section 10 regardless of where the issuing Operator's retention window sits. Where deletion would conflict with the Operator's legitimate need to retain the record (for example, to defend an existing or imminent legal claim), we will narrow the deletion to what is lawfully permitted and explain the basis for the carve‑out.
Security and encryption
We take security seriously and rely on layered safeguards. Specifically:
- Transport: all connections to the Service use TLS 1.2 or higher.
- Object storage: PDFs, signature images, and uploads are stored in Cloudflare R2 with server‑side AES‑256 encryption at rest.
- Application‑level field encryption: Signer form‑field values are additionally encrypted at the application layer with AES‑256‑GCM using a per‑organization subkey derived via HKDF‑SHA‑256 from a master key held in a managed secret store. Cipher records carry the organization identifier as authenticated additional data so a record cannot be replayed against the wrong organization.
- Database: Postgres connections use TLS; database snapshots are encrypted at rest by the hosting provider.
- Access control: we enforce least‑privilege role‑based access (owner / admin / member) for every workspace, multi‑tenant isolation on every query path, and additional invariant tests that run in CI to prevent cross‑organization data exposure.
- Tamper‑evidence: each signed PDF carries a SHA‑256 hash recorded in the certificate of completion and available through a public verify endpoint, so any later byte‑level change to the document is detectable.
- Operational hygiene: short‑lived signed URLs for object downloads, capability tokens delivered in HTTP headers rather than query strings, rate‑limited public endpoints, hashed‑at‑rest API keys, and an append‑only audit log of security‑relevant events.
No system can be made perfectly secure. We continuously work to improve our posture and will notify affected users and regulators of a personal‑data breach where required by law, within the statutory time limits.
Your rights and how to use them
Depending on where you live and which role you play (Operator or Signer), you may have any of the following rights. We will honor every right that applies under the law of your jurisdiction.
| Right | Where it applies | How to use it |
|---|---|---|
| Access | EU/UK GDPR Art. 15; PIPEDA Principle 9; CCPA/CPRA §1798.110 | Signers: visit /dsar and follow the magic‑link flow. Operators: in‑app export from Settings → Data. |
| Rectification | EU/UK GDPR Art. 16; PIPEDA Principle 9 | Email privacy@clickwaiver.com. For Signer data, we forward the request to the Operator who collected it. |
| Erasure ("right to be forgotten") | EU/UK GDPR Art. 17; CCPA/CPRA §1798.105 | Email us. Subject to the legal‑record carve‑out in Section 8 and statutory minimums where applicable. |
| Restriction of processing | EU/UK GDPR Art. 18 | Email us. Will pause processing where lawful to do so. |
| Data portability | EU/UK GDPR Art. 20; PIPEDA Principle 9 (in practice) | Use the DSAR endpoint at /dsar — the export is a structured JSON manifest together with the signed PDFs. |
| Objection | EU/UK GDPR Art. 21 | Email us, stating the processing you object to. |
| Non‑discrimination | CCPA/CPRA §1798.125 | We will not deny service, charge a different price, or provide a different level of quality because you have exercised a privacy right. |
| Withdraw consent | Wherever consent is the lawful basis; PIPEDA Principle 3 | Email us. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. |
| Complain to a supervisory authority | EU GDPR Art. 77; UK ICO; provincial privacy commissioners in Canada | See Section 11 for the relevant contact in your region. |
The signer‑side magic link issued by the DSAR endpoint expires twenty‑four (24) hours after it is sent and can be redeemed once; submit a new request from /dsar if a link expires or has already been used.
We will respond within thirty (30) days for GDPR / UK GDPR requests (extendable by up to two further months for complex or numerous requests, with notice to you within the first thirty days, as permitted by GDPR Art. 12(3)), forty‑five (45) days for CCPA requests, and within a reasonable time for PIPEDA requests, in each case as required by the applicable law.
Region‑specific disclosures
The following sections supplement the rest of this Policy with disclosures specific to your jurisdiction. The general terms above continue to apply.
11.1 European Union (GDPR)
For residents of the EU, EEA, or Switzerland, the General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR") applies. The controller for personal data described in this Policy is identified in Section 2 above. Our EU Article 27 representative will be identified here once appointed prior to launch.
Where we rely on Article 6(1)(f) legitimate interests, we have completed a balancing test in each case and concluded that the processing does not override the rights and freedoms of data subjects. A summary of the balancing reasoning is available on request to privacy@clickwaiver.com.
You may lodge a complaint with the supervisory authority of the EU Member State in which you reside, work, or where the alleged infringement occurred. A directory is published by the European Data Protection Board at edpb.europa.eu.
11.2 United Kingdom (UK GDPR & DPA 2018)
For UK residents, the UK General Data Protection Regulation and the Data Protection Act 2018 apply. The Information Commissioner's Office (ICO) is the UK supervisory authority and complaints may be made at ico.org.uk. Our UK Article 27 representative will be identified here once appointed prior to launch.
UK transfers to the United States rely on the UK Extension to the EU‑U.S. Data Privacy Framework where the recipient is certified, or otherwise on the International Data Transfer Addendum to the EU SCCs.
11.3 Canada (PIPEDA)
For Canadian residents, the Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5) applies. The Office of the Privacy Commissioner of Canada accepts complaints at priv.gc.ca. We do not currently support Quebec Law 25‑specific obligations beyond PIPEDA‑equivalent terms; full Law 25 compliance (bilingual interface, PIA workflow, named Privacy Officer) is on our roadmap. Until then, Operators with Quebec residents should evaluate suitability independently.
11.4 United States (CCPA/CPRA & state laws)
For California residents, the California Consumer Privacy Act as amended by the California Privacy Rights Act (collectively, "CCPA") applies. We have not collected or sold "sensitive personal information" within the meaning of CCPA §1798.140 in the preceding twelve months other than as expressly described in Section 3 (the health‑related fields an Operator may collect from a Signer on its template). We do not sell or share personal information for cross‑context behavioral advertising. California residents may submit verifiable requests under §1798.110, §1798.105, §1798.120, and §1798.121 by emailing privacy@clickwaiver.com. An authorized agent may make a request on your behalf with a signed permission and proof of identity.
Where other U.S. state privacy laws (Virginia, Colorado, Connecticut, Utah, and others) apply, the substantive rights in Section 10 satisfy the corresponding obligations of those statutes. We do not engage in "targeted advertising" or "profiling" producing legal or similarly significant effects within the meaning of those laws.
"Shine the Light" (California Civil Code §1798.83): we do not share California residents' personal information with third parties for those third parties' direct marketing purposes.
Children & minors
The Service is not directed at children under sixteen (16) in the European Union or under thirteen (13) in the United States and the United Kingdom, and we do not knowingly collect personal data from a child below those ages for our own purposes. Where an Operator collects waiver data from a minor (for example, a summer‑camp participant), the Operator is responsible for obtaining the appropriate parental or guardian consent under COPPA, GDPR Art. 8, or other applicable law and the Service provides a parent/guardian signing flow to facilitate that.
If you believe we have inadvertently collected personal data from a child outside the parent/guardian signing flow, please contact us and we will delete it.
Automated decision‑making
We do not engage in solely automated decision‑making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of GDPR Art. 22. The AI template‑generation feature available to Operators uses generative models to draft template content for human review; no waiver is sent or accepted automatically by an AI system.
Cookies and similar technologies
The Service uses a small set of cookies and similar storage mechanisms, all of which are necessary to deliver the Service and which are not used for advertising or cross‑site tracking:
- Session cookies issued by our authentication layer to keep you signed in.
- CSRF cookies to protect form submissions against cross‑site request forgery.
- Theme & preference cookies to remember your light/dark mode and other interface settings.
- Browser storage in the offline kiosk mode (IndexedDB) to queue offline signings until reconnection.
We do not use third‑party advertising cookies, analytics cookies, fingerprinting libraries, social‑media trackers, or any "Do Not Track"‑disrespecting technologies. Because we do not engage in cross‑site tracking, the Global Privacy Control signal is honored by default.
Changes to this policy
We may revise this Policy from time to time. When we do, we will update the "Last updated" date at the top of the page. For material changes affecting Operators (for example, the addition of a new subprocessor, a change to how we transfer data internationally, or a change to the retention defaults), we will provide reasonable advance notice by email or in‑app banner. Continued use of the Service after the effective date of a change constitutes acceptance of the revised Policy. If you do not agree to a change, you may close your account before it takes effect.
How to contact us
Questions, requests, or complaints about this Policy or our processing of personal data should be sent to:
WaiverForms, Inc. Attn: Privacy Email: privacy@clickwaiver.com
THIS IS NOT LEGAL ADVICE. This Policy is informational and describes our practices. It is not legal advice and does not establish a lawyer–client relationship. Operators should consult their own counsel regarding the regulatory framework that applies to their collection of waiver data.