This Privacy Policy describes how eLink Signature, operated by Central Media LLC ("eLink Signature," "we," "us," or "our"), a Florida limited liability company located in Orlando, Florida, collects, uses, maintains, and discloses information from users of the elinksignature.com website, our web application, our browser extensions and marketplace applications, and all related products and services (collectively, the "Service").
1. Scope of This Policy
This Policy applies to the Service in its entirety, including the marketing website, the signature application at app.elinksignature.com, and any integrations, extensions, or applications we distribute.
Where you use the Service as an individual, we act as the controller of your personal information. Where your employer or organization deploys the Service and configures signatures on your behalf, that organization is the controller of the employee data it supplies, and we act as its processor, handling that data according to the organization's instructions and our agreement with it. Employees whose details are placed into a signature by their employer should direct access and deletion requests to their employer in the first instance.
2. Personal Identification Information
We collect personal identification information in the following ways:
Information you provide. When you register for an account, subscribe to a plan, contact support, respond to a survey, or otherwise interact with the Service, we may collect your name, email address, phone number, job title, company name, mailing address, and the contact and profile details you choose to place into a signature.
Account credentials. Where you register with an email address and password, we store your email address and a cryptographic hash of your password. We never store your password itself, and we cannot recover or display it to you or to anyone else, including our own staff. Where you register using Google Sign-In, no password is created or stored at all.
Payment information. Subscription payments are processed by Stripe, Inc., a PCI DSS Level 1 certified payment service provider. Card details are collected directly by Stripe through its hosted payment fields and are transmitted to Stripe, not to us. We receive only confirmation of payment, the last four digits and brand of the card, the card expiry, billing country and postal code, and subscription status. We do not collect, process, or store full payment card numbers, magnetic stripe data, or card security codes on our systems. Stripe's handling of your payment information is governed by the Stripe Privacy Policy.
Information collected automatically. Certain information is collected automatically when you use the Service and is not "voluntarily submitted." See Sections 3, 6, and 7.
Information from your organization. Where an administrator deploys the Service across a domain, we may receive employee names, email addresses, job titles, departments, phone numbers, and profile photographs from your organization's directory in order to generate signatures.
3. Non-Personal Identification Information
We collect technical information whenever you interact with the Service, including browser name and version, device and operating system type, screen and viewport dimensions, IP address, referring URL, pages viewed, session duration, and general connection information. Depending on jurisdiction, IP addresses may be treated as personal information, and we handle them accordingly.
4. Content You Upload
When you use the Service you may upload logos, photographs, brand assets, illustrations, and other files ("User Content").
- You retain ownership of your User Content. We store and process it only to provide the Service to you.
- We do not use your User Content to train artificial intelligence or machine learning models, and we do not license, sell, or share it with third parties for that purpose.
- Hosted assets are served from public URLs. For a signature to display in a recipient's email client, the image or animation must be retrievable over the public internet. Signature assets are therefore stored at unguessable but publicly addressable URLs on our content delivery network. They are not indexed or listed, but they are not access-controlled. Do not upload material you are unwilling to have retrievable by anyone holding the URL.
- Retention of hosted assets after deletion. See Section 11, which explains what happens to these URLs when you cancel or delete your account.
5. Google Workspace and Microsoft 365 Data
Where you connect a Google Workspace or Microsoft 365 account, we request only the permissions needed to install and manage signatures. Depending on the integration and the permissions you or your administrator grant, this may include the ability to read and update signature settings on the mailbox, and, for organization-wide deployments, to read directory information about users on your domain.
Limited Use commitment. eLink Signature's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We do not use data obtained from Google Workspace APIs to develop, improve, or train generalized artificial intelligence or machine learning models.
- We do not retain, store, or repurpose Google Workspace API data for any AI-related process.
- We do not transfer, sell, or share Google Workspace API data with third parties except as necessary to provide the user-facing functionality you have requested, to comply with applicable law, or as part of a merger or acquisition with notice to you.
- We do not read, index, store, or analyze the body content of your email messages.
- All data accessed through these APIs is used strictly to deliver the functionality you have explicitly requested, such as creating, installing, and updating email signatures.
An account created with Google Sign-In can only ever be accessed with Google. No password exists on such an account and none can be added, by you or by us. If you lose access to your Google account, you lose access to your eLink Signature account. This is a deliberate security decision.
6. Information About Email Recipients
This section describes information collected about people who receive email containing a signature created with the Service. Recipients are not users of the Service and have not agreed to this Policy, so we describe this activity plainly.
What happens. Signature images and animations are hosted on our servers. When a recipient opens an email and their email client loads the signature image, that client makes a request to our servers. That request necessarily transmits the recipient's IP address, user agent string, and the time of the request. This is how images work on the internet and is inherent to any hosted email signature.
Analytics features. If the sender's plan includes analytics and the sender has enabled them, we may use these requests to count signature impressions, and we may route links within a signature through our servers to count clicks. Where analytics are enabled, we may retain aggregated counts and limited technical metadata associated with the sender's account.
What we do not do. We do not build advertising profiles of recipients, we do not sell or share recipient data with advertisers or data brokers, we do not attempt to identify recipients by name from these requests, and we do not track recipients across unrelated websites.
Roles and responsibility. With respect to recipient data generated by analytics, the sending user or their organization is the controller and eLink Signature acts as processor. The sender is responsible for providing any notice and obtaining any consent required by law in their jurisdiction and their recipients' jurisdictions. Consent requirements for email tracking pixels are significantly stricter in the European Union and the United Kingdom than in the United States, and enforcement in that area has been increasing.
Controls. Senders can disable analytics and link tracking from the account dashboard. Recipients can prevent this collection by configuring their email client to block remote images, which most major clients support.
Retention. Raw request logs containing recipient IP addresses are retained for no more than thirty (30) days and are then deleted or irreversibly aggregated.
7. Cookies and Tracking Technologies
We use cookies and similar technologies on our website and application.
Strictly necessary cookies support authentication, session management, security, load balancing, and core site functionality. These are required for the Service to work and are set without consent, as permitted by law.
Preference cookies remember settings such as language, theme, and dashboard layout.
Analytics cookies help us understand how the site is used so we can improve it. We currently use Google Analytics for this purpose.
Your choices. Where required by law, including in the EU, UK, and certain other jurisdictions, we request your consent before setting any non-essential cookie, and we do not set analytics cookies until you have consented. You can change or withdraw your cookie preferences at any time through the cookie preference link in the site footer. You may also configure your browser to refuse cookies, though this may impair site functionality. We honor Global Privacy Control (GPC) signals where applicable law requires it.
We do not use cookies for cross-context behavioral advertising.
8. How We Use Collected Information
We use the information we collect to:
- Provide and operate the Service — create, render, host, and deploy your signatures;
- Process payments — bill subscriptions and custom design fees through our payment processor;
- Provide customer support — respond to inquiries, troubleshoot, and resolve issues;
- Improve the Service — analyze aggregate usage patterns to understand how the Service is used and where it can be improved;
- Communicate with you — send transactional messages, service announcements, security notices, and, where you have opted in, marketing communications you can unsubscribe from at any time;
- Secure the Service — detect, investigate, and prevent fraud, abuse, credential compromise, and unauthorized access;
- Comply with legal obligations — meet applicable laws, regulations, tax requirements, and lawful requests from authorities.
9. Artificial Intelligence Processing
Certain features use AI to animate logos and generate design elements from material you supply.
- Your uploaded content is not used to train our models or any third party's models.
- Where processing is performed by a third-party AI vendor, that vendor is contractually bound to process the content solely to return the requested output, not to retain it beyond what is needed for that purpose, and not to use it for model training. Vendors are listed in the sub-processor table below.
- AI-generated output belongs to you, as described in our Terms of Use.
10. Sharing Your Information and Service Providers
We do not sell, rent, or trade your personal information. We do not share personal information for cross-context behavioral advertising as those terms are defined under U.S. state privacy laws.
We share information only in these circumstances:
Service providers (sub-processors). We use vendors to operate the Service. Each is bound by contract to handle data securely and only for the purposes we specify.
| Sub-processor | Purpose | Data handled | Location |
|---|---|---|---|
| Stripe, Inc. | Subscription billing, payment processing, fraud prevention | Name, email, billing address, card details (collected directly by Stripe), transaction history | United States (Stripe Payments Europe, Ltd., Ireland, for EEA/UK customers) |
| Cloudflare, Inc. | Application hosting, data storage, and delivery of signature assets | All account data, uploaded assets, request logs | United States, with a global edge network |
| Google LLC | Google Sign-In; Google Workspace integration where you connect one | Email address, name, profile picture URL, and directory data you authorize | United States |
| Google Analytics | Website analytics | Usage data, IP (truncated) | United States |
| Email delivery provider | Transactional and marketing email | Name, email address | To be named here before any such vendor begins processing |
| AI / animation vendor | Logo animation processing | Uploaded logo files | To be named here before any such vendor begins processing |
Aggregated information. We may share aggregated or de-identified statistics that cannot reasonably be used to identify any individual.
Legal requirements. We may disclose information where required by law, subpoena, court order, or other legal process, or where we reasonably believe disclosure is necessary to protect our rights, the safety of any person, or to investigate fraud.
Business transfers. If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction. We will notify you before your information becomes subject to a materially different privacy policy.
Google user data. Data obtained through Google APIs is never shared with third parties except as strictly necessary to deliver the functionality you requested, as required by law, or with your explicit authorization.
11. Retention and Deletion of Data
We retain data only as long as necessary to provide the Service, meet legal or regulatory obligations, resolve disputes, and enforce our agreements.
| Data type | Retention |
|---|---|
| Account and profile data | Duration of the account, then deleted within 30 days of closure |
| Google Workspace / Microsoft 365 data | Deleted within 30 days of service termination or revocation of permissions |
| Uploaded User Content and generated assets | Duration of the account, then deleted within 30 days of closure (see below) |
| Recipient request logs | Maximum 30 days, then deleted or irreversibly aggregated |
| Aggregated analytics counts | Duration of the account |
| Billing and tax records | Retained as required by applicable tax and accounting law, typically 7 years |
| Encrypted backups | Deleted data may persist in encrypted backups for up to 90 days, inaccessible for any other purpose |
Hosted signature assets after cancellation. When your account is closed or deleted, the hosted images and animations used in your signatures are deleted within thirty (30) days. Once deleted, those assets will no longer render — including in emails you have already sent, where the signature will appear as a broken or missing image. This is unavoidable given how hosted email signatures work. If you wish to preserve the appearance of previously sent mail, export your assets before closing your account.
Deletion requests. You may request deletion of your personal data, including any Google user data, by emailing giovann@mapmagnet.co. Upon verification of your identity, we will delete the data within thirty (30) days unless retention is required for legitimate business or legal reasons, and we will tell you if that is the case.
12. How We Protect Your Information
We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, alteration, disclosure, and destruction. These include:
- Encryption of data in transit using TLS 1.2 or higher;
- Encryption of data at rest for databases and stored files;
- Passwords stored only as salted PBKDF2-SHA256 hashes, never in recoverable form;
- Role-based access controls limiting employee access to what is needed for their role;
- Multi-factor authentication on administrative and infrastructure accounts;
- Logging and monitoring of administrative access;
- Regular application of security patches and dependency updates;
- Periodic review of access permissions and vendor security posture.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Breach notification. In the event of a data breach affecting your personal information, we will notify affected users and applicable regulators without undue delay and within the timeframes required by applicable law.
13. Your Rights
Subject to applicable law and verification of your identity, you have the right to:
- Access the personal data we hold about you;
- Correct inaccurate or incomplete data;
- Delete your personal data, as described in Section 11;
- Port your data by receiving a copy in a structured, machine-readable format;
- Restrict or object to certain processing;
- Withdraw consent at any time where processing is based on consent;
- Opt out of marketing communications;
- Be free from discrimination for exercising any of these rights.
To exercise any right, email giovann@mapmagnet.co. We will respond within thirty (30) days, and will tell you if we need an extension permitted by law. An authorized agent may submit a request on your behalf with proof of authorization.
Residents of California and other U.S. states with comprehensive privacy laws. We do not sell or share personal information as those terms are defined under the California Consumer Privacy Act as amended, and we do not process sensitive personal information for purposes requiring a right to limit. You may exercise your rights to know, delete, correct, and opt out through the address above, and you may appeal a denied request by replying to our response.
Residents of the European Economic Area and United Kingdom. Our lawful bases for processing are: performance of a contract (providing the Service), legitimate interests (security, fraud prevention, service improvement), consent (marketing communications and non-essential cookies), and legal obligation (tax and compliance records). You have the right to lodge a complaint with your local supervisory authority.
14. Children's Privacy
The Service is intended for business use and is not directed to individuals under 18. We do not knowingly collect personal information from children under 13, and we do not knowingly collect personal information from minors under 18 without appropriate consent.
If we learn that we have collected information from a child under 13, we will delete it promptly. Parents or guardians who believe we may hold such information should contact giovann@mapmagnet.co.
15. International Users
The Service is operated from the United States, and information we collect is processed and stored in the United States and in other countries where our service providers operate. If you access the Service from outside the United States, you understand that your information will be transferred to, stored in, and processed in the United States, where data protection laws may differ from those in your country.
Where we transfer personal data from the European Economic Area, United Kingdom, or Switzerland, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses, and we make those terms available to business customers on request. Payment data for customers in the EEA and United Kingdom is handled by Stripe Payments Europe, Ltd., established in Ireland, under Stripe's own data processing terms.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. For material changes affecting how we use your personal information, we will provide notice by email or through the Service at least fourteen (14) days before the change takes effect.
We encourage you to review this page periodically. Your continued use of the Service after a change takes effect constitutes acceptance of the updated Policy.
17. Contact Information
Questions, requests, or complaints regarding this Privacy Policy may be directed to:
eLink Signature
Central Media LLC
Orlando, Florida, United States
giovann@mapmagnet.co