NimbleSign Privacy Policy
NimbleSign Electronic Signature Service — Nimble Information Strategies Inc.
This Privacy Policy explains how Nimble Information Strategies Inc. (“Nimble”, “we” or “us”) collects, uses, discloses, and protects personal information in connection with the NimbleSign electronic signature service (the “Service”). It applies to the Service and its related web pages. Nimble’s corporate website (nimble.ca) is governed by the privacy policy posted there; where you interact with both, each policy governs its own scope.
Nimble is committed to handling personal information in accordance with the Personal Information Protection and Electronic Documents Act (Canada) (“PIPEDA”) and applicable provincial privacy legislation, including Quebec’s Act respecting the protection of personal information in the private sector.
1. Our Two Roles
1.1For account holders. When you create a NimbleSign account, Nimble is the organization accountable for the personal information we collect about you — your registration, billing, support, and usage information — and this Policy describes how we handle it.
1.2For signers and document content. When a NimbleSign customer sends a document for signature, Nimble processes the contents of that envelope — including signers’ and recipients’ personal information — on behalf of and under the instructions of that customer (the “sender”). The sender is the organization accountable for that information under privacy law. If you are a signer and wish to access, correct, or ask questions about personal information in a document you signed, contact the sender first; we will support the sender in responding, and Section 8 explains how to reach us.
2. Information We Collect
2.1Account information: name, business email address, organization name, phone number, language preference, and credentials (we store passwords in hashed form only).
2.2Billing information: plan, transaction history, and billing address. Payment card details are collected and processed by our payment processor; Nimble does not store full card numbers.
2.3Envelope and signer information (processed for the sender): the documents in an envelope; signer and recipient names, email addresses, and (where the sender selects SMS verification) mobile numbers; signature and initial images; and signing-event records such as timestamps, IP addresses, device and browser information, and the results of identity-verification steps. These records form the certificate of completion that gives a signed document its evidentiary value.
2.4Usage and log data: technical logs generated by operation of the Service, such as pages viewed, features used, and diagnostic events, used to operate, secure, and improve the Service.
2.5Support communications: messages you send us and related records.
2.6Cookies: the Service uses cookies that are necessary for it to function (such as session and security cookies) and, with your consent where required, analytics cookies to understand how the Service is used. We do not use advertising cookies in the Service. You can manage cookies through your browser; disabling necessary cookies may prevent the Service from working.
3. How We Use Personal Information
3.1We use personal information to: (a) provide, operate, and support the Service, including delivering envelopes, verifying signer identity as configured by the sender, and generating certificates of completion; (b) set up and administer accounts and process payments; (c) secure the Service, and prevent, detect, and investigate fraud, abuse, and security incidents; (d) communicate with you about the Service, including transactional and service notices; (e) improve the Service using de-identified and aggregated information; (f) comply with legal obligations; and (g) with your consent, send marketing communications about Nimble products and services, in compliance with Canada’s Anti-Spam Legislation. You can withdraw marketing consent at any time using the unsubscribe mechanism in any message or by contacting us; transactional messages necessary to the Service are not affected.
3.2We obtain consent for collection, use, and disclosure as required by law — express or implied depending on the sensitivity of the information and the reasonable expectations of the individual. Where we process signer information for a sender, the sender is responsible for the legal basis and any consents required for that processing.
4. Canadian Data Residency
4.1Personal information processed in the Service — including account information, documents, envelopes, signature records, audit trails, and backups — is stored and processed on infrastructure located in Canada and operated by or on behalf of Nimble. We do not use foreign hyperscale cloud providers to store Service data, and we do not transfer Service data outside Canada except with consent or where required by Canadian law.
4.2One practical exception: transactional notifications (the email or SMS message inviting a recipient to sign, or notifying a sender of completion) may transit third-party delivery networks in order to reach the recipient. These messages contain links and delivery metadata, not the documents themselves.
5. When We Disclose Personal Information
5.1We do not sell personal information. We disclose it only: (a) to service providers who help us operate the Service (such as payment processing and message delivery), under contracts that limit their use of the information to providing services to us and require appropriate safeguards; (b) within the envelope workflow itself — signers, senders, and other envelope participants see the information the workflow is designed to show them, including the completed document and certificate of completion; (c) where required or permitted by law, including to comply with a subpoena, warrant, or court order issued by a Canadian authority with jurisdiction, in which case we disclose only what we are legally required to disclose and, where permitted, notify the affected customer; and (d) in connection with a business transaction such as a merger or sale of assets, subject to appropriate confidentiality protections and applicable law.
6. Retention
6.1We retain account information for the duration of the account relationship and afterwards as needed to meet legal, accounting, and audit obligations. Envelope content and signing records are retained while the account is active, in accordance with the sender’s plan and instructions; following account closure, content is available for export for 30 days and is then deleted from active systems in accordance with our retention schedules, with backups aging out on a defined cycle. We retain records of marketing opt-outs so we can honour them.
7. Safeguards
7.1We protect personal information with administrative, technical, and physical safeguards appropriate to its sensitivity, including encryption in transit and at rest, role-based access controls, logging and monitoring, personnel confidentiality obligations, and physically secured Canadian facilities. Completed documents are sealed so that any subsequent alteration is detectable. No system is perfectly secure; if a breach of security safeguards creates a real risk of significant harm, we will notify affected individuals and the Office of the Privacy Commissioner of Canada as required by PIPEDA, and affected customers without undue delay.
8. Your Rights
8.1You may request access to and correction of your personal information in our custody, and may withdraw consent subject to legal and contractual restrictions (withdrawing consent required for the Service may mean we can no longer provide it). Account holders can view and update most account information directly in the Service. Signers should direct requests concerning document contents to the sender, who is the accountable organization; we will refer such requests to the sender and support its response. We respond to written requests within the time required by law and may require identity verification before acting on a request.
8.2If you are dissatisfied with our handling of your personal information, contact our Privacy Officer (Section 10). You also have the right to complain to the Office of the Privacy Commissioner of Canada or, where applicable, your provincial privacy regulator, including the Commission d’accès à l’information du Québec.
9. Children
9.1The Service is intended for business and professional use and is not directed at children. We do not knowingly collect personal information from anyone under 18 except as a named participant in a document sent by a customer, in which case the sender is responsible for the lawfulness of that processing.
10. Contact; Privacy Officer
10.1Nimble’s Privacy Officer (also the person in charge of the protection of personal information for the purposes of Quebec law) is responsible for compliance with this Policy: Privacy Officer, Nimble Information Strategies Inc., Unit 14, 145 Industrial Parkway South, Aurora, Ontario L4G 3V5 — privacy@nimble.ca.
11. Changes to this Policy
11.1We may update this Policy from time to time. We will post the updated version with a revised effective date and, for material changes, provide notice through the Service or by email before the changes take effect.
See also the NimbleSign Terms of Use, of which this Policy forms part.
Version 1.0 · Effective date: August 24, 2026