LEGAL
Privacy Policy
Last updated: January 2026
fixSignatures (“we”, “our”, or “us”) provides email signature management solutions for Microsoft 365. This Privacy Policy explains how we collect, use, protect, and share information when you use our services at fixsignatures.com and the fixSignatures application.
Important: Your emails stay private. fixSignatures only accesses the compose window to insert signatures—we cannot read your inbox, sent items, or any email content.
Table of Contents
01 Information We Collect
We collect different types of information to provide and improve our service. Here’s exactly what we collect and why:
Account Information
When you create an account, we collect:
- Name and email address — For account identification and communication
- Password — Stored using bcrypt hashing (12 rounds), never in plain text
- MFA secrets — If you enable two-factor authentication, stored encrypted
Organization & Billing Information
For organizations using our service, we collect:
- Company name and billing email
- Billing address — Street address, city, state/province, postal code, country
- Company registration number (optional)
- VAT/Tax ID (optional, for EU businesses)
Microsoft 365 Directory Data
When you connect your Microsoft 365 tenant, we sync the following user profile data via the Microsoft Graph API:
- Basic profile — Display name, email address, job title
- Contact details — Mobile phone, business phone, office location
- Extension attributes — Custom fields like LinkedIn URL, booking URL (from Entra ID)
- Group memberships — Group names and member associations for signature assignment
Usage & Analytics Data
We collect usage data to improve our service:
- Signature insertion logs — When signatures are applied, which platform (Outlook Web, Desktop, Mobile), whether automatic or manual
- Technical data — IP address, user agent, browser information
- Session data — Login timestamps, session duration
Uploaded Content
Images you upload to our gallery (logos, headshots, banners) including file metadata (filename, size, dimensions, MIME type) and alt text.
02 How We Use Your Information
We use the information we collect for the following purposes:
- Service delivery — To create and deploy personalized email signatures using your directory data
- Account management — To authenticate you, manage your subscription, and provide customer support
- Billing — To process payments and manage your subscription through Stripe
- Analytics — To understand how signatures are being used across your organization
- Service improvement — To identify issues, improve features, and optimize performance
- Security — To detect and prevent fraud, abuse, and unauthorized access
- Communication — To send service updates, security alerts, and support messages
03 Microsoft 365 Integration
fixSignatures integrates with Microsoft 365 to sync user directory information for signature personalization. Here’s exactly what we access:
Your Emails Stay Private
fixSignatures cannot read, access, or store your email messages. Our add-in operates exclusively in the compose window to insert your signature—nothing more. We have no access to your inbox, sent items, drafts, or any email content. Your email data never touches our servers.
Data We Access
- User profiles — Name, email, job title, department, phone numbers, office location
- Directory extension attributes — Custom attributes stored in Entra ID (e.g., LinkedIn URL)
- Groups — Group names and memberships for signature assignment rules
How We Use This Data
Directory data is used exclusively for:
- Personalizing email signatures with user-specific information
- Assigning signatures to users based on group membership
- Keeping user information synchronized with your directory
Credential Storage
Your Microsoft Entra ID client credentials (Tenant ID, Client ID, Client Secret) are stored encrypted using AES-256-CBC encryption. We never store credentials in plain text.
04 Data Sharing & Third Parties
We do not sell your personal data. We share data only with the following service providers who are essential to operating our service:
Stripe (Payment Processing)
We share the following with Stripe to process payments:
- Email address and name
- Company name and billing address
- Company registration number and VAT/Tax ID (if provided)
- Organization and package identifiers (for subscription management)
Stripe’s privacy policy: stripe.com/privacy
Microsoft (Microsoft Entra ID Integration)
We use Microsoft Graph API to sync directory data. Microsoft processes API requests according to their privacy policy. Your Microsoft Entra ID credentials allow us to read directory data from your tenant.
Microsoft’s privacy policy: privacy.microsoft.com
05 Data Security
We implement industry-standard security measures to protect your data:
Encryption & Authentication
- Passwords: Bcrypt hashed with 12 rounds
- Azure credentials: AES-256-CBC encrypted at rest
- MFA secrets: Encrypted storage with recovery codes
- API tokens: SHA-256 hashed before storage
- Transport: TLS 1.2+ for all connections
Access Controls
- Two-factor authentication (MFA) — Available for all accounts using TOTP authenticator apps
- Session management — Database-backed sessions with IP and user agent tracking
- Rate limiting — API rate limits to prevent abuse
- Multi-tenant isolation — Organization data is strictly isolated
06 Data Retention
We retain your data for as long as necessary to provide our services:
- Account data — Retained while your account is active, deleted upon account closure
- Sessions — Expire after 120 minutes of inactivity
- Password reset tokens — Expire after 60 minutes
- Temporary tokens — Automatically deleted after 7 days
- Signature insertion logs — Retained for analytics purposes
Account Deletion
When you delete your organization account, we perform a cascading deletion of all associated data including:
- User accounts and profiles
- Microsoft Entra ID configuration and synced user data
- Signature templates and assignments
- Uploaded images and gallery items
- Usage logs and analytics data
- Billing records (subject to legal retention requirements)
07 Your Rights
Under GDPR, CCPA, and other privacy regulations, you have the following rights regarding your personal data:
Right to Access
Request a copy of the personal data we hold about you.
Right to Rectification
Request correction of inaccurate personal data.
Right to Erasure
Request deletion of your personal data (account deletion).
Right to Portability
Request your data in a machine-readable format.
To exercise any of these rights, contact us at info@fixsignatures.com. We will respond to your request within 30 days.
08 Cookies & Tracking
We use cookies and similar technologies for:
- Essential cookies — Session management, authentication, and security
- Preference cookies — Remembering your settings and preferences
We do not use third-party advertising cookies. You can control cookies through your browser settings.
09 Children’s Privacy
fixSignatures is a business service not intended for individuals under 16 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.
10 Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by:
- Posting the new Privacy Policy on this page
- Updating the “Last updated” date at the top
- Sending an email notification for material changes
11 Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
fixSignatures
For privacy and data protection inquiries
Email: info@fixsignatures.com
Website: fixsignatures.com