LEGAL

Privacy Policy

Last updated: January 2026

fixSignatures (“we”, “our”, or “us”) provides email signature management solutions for Microsoft 365. This Privacy Policy explains how we collect, use, protect, and share information when you use our services at fixsignatures.com and the fixSignatures application.

Important: Your emails stay private. fixSignatures only accesses the compose window to insert signatures—we cannot read your inbox, sent items, or any email content.

01 Information We Collect

We collect different types of information to provide and improve our service. Here’s exactly what we collect and why:

Account Information

When you create an account, we collect:

  • Name and email address — For account identification and communication
  • Password — Stored using bcrypt hashing (12 rounds), never in plain text
  • MFA secrets — If you enable two-factor authentication, stored encrypted

Organization & Billing Information

For organizations using our service, we collect:

  • Company name and billing email
  • Billing address — Street address, city, state/province, postal code, country
  • Company registration number (optional)
  • VAT/Tax ID (optional, for EU businesses)

Microsoft 365 Directory Data

When you connect your Microsoft 365 tenant, we sync the following user profile data via the Microsoft Graph API:

  • Basic profile — Display name, email address, job title
  • Contact details — Mobile phone, business phone, office location
  • Extension attributes — Custom fields like LinkedIn URL, booking URL (from Entra ID)
  • Group memberships — Group names and member associations for signature assignment

Usage & Analytics Data

We collect usage data to improve our service:

  • Signature insertion logs — When signatures are applied, which platform (Outlook Web, Desktop, Mobile), whether automatic or manual
  • Technical data — IP address, user agent, browser information
  • Session data — Login timestamps, session duration

Uploaded Content

Images you upload to our gallery (logos, headshots, banners) including file metadata (filename, size, dimensions, MIME type) and alt text.


02 How We Use Your Information

We use the information we collect for the following purposes:

  • Service delivery — To create and deploy personalized email signatures using your directory data
  • Account management — To authenticate you, manage your subscription, and provide customer support
  • Billing — To process payments and manage your subscription through Stripe
  • Analytics — To understand how signatures are being used across your organization
  • Service improvement — To identify issues, improve features, and optimize performance
  • Security — To detect and prevent fraud, abuse, and unauthorized access
  • Communication — To send service updates, security alerts, and support messages

03 Microsoft 365 Integration

fixSignatures integrates with Microsoft 365 to sync user directory information for signature personalization. Here’s exactly what we access:

Your Emails Stay Private

fixSignatures cannot read, access, or store your email messages. Our add-in operates exclusively in the compose window to insert your signature—nothing more. We have no access to your inbox, sent items, drafts, or any email content. Your email data never touches our servers.

Data We Access

  • User profiles — Name, email, job title, department, phone numbers, office location
  • Directory extension attributes — Custom attributes stored in Entra ID (e.g., LinkedIn URL)
  • Groups — Group names and memberships for signature assignment rules

How We Use This Data

Directory data is used exclusively for:

  • Personalizing email signatures with user-specific information
  • Assigning signatures to users based on group membership
  • Keeping user information synchronized with your directory

Credential Storage

Your Microsoft Entra ID client credentials (Tenant ID, Client ID, Client Secret) are stored encrypted using AES-256-CBC encryption. We never store credentials in plain text.


04 Data Sharing & Third Parties

We do not sell your personal data. We share data only with the following service providers who are essential to operating our service:

Stripe (Payment Processing)

We share the following with Stripe to process payments:

  • Email address and name
  • Company name and billing address
  • Company registration number and VAT/Tax ID (if provided)
  • Organization and package identifiers (for subscription management)

Stripe’s privacy policy: stripe.com/privacy

Microsoft (Microsoft Entra ID Integration)

We use Microsoft Graph API to sync directory data. Microsoft processes API requests according to their privacy policy. Your Microsoft Entra ID credentials allow us to read directory data from your tenant.

Microsoft’s privacy policy: privacy.microsoft.com


05 Data Security

We implement industry-standard security measures to protect your data:

Encryption & Authentication

  • Passwords: Bcrypt hashed with 12 rounds
  • Azure credentials: AES-256-CBC encrypted at rest
  • MFA secrets: Encrypted storage with recovery codes
  • API tokens: SHA-256 hashed before storage
  • Transport: TLS 1.2+ for all connections

Access Controls

  • Two-factor authentication (MFA) — Available for all accounts using TOTP authenticator apps
  • Session management — Database-backed sessions with IP and user agent tracking
  • Rate limiting — API rate limits to prevent abuse
  • Multi-tenant isolation — Organization data is strictly isolated

06 Data Retention

We retain your data for as long as necessary to provide our services:

  • Account data — Retained while your account is active, deleted upon account closure
  • Sessions — Expire after 120 minutes of inactivity
  • Password reset tokens — Expire after 60 minutes
  • Temporary tokens — Automatically deleted after 7 days
  • Signature insertion logs — Retained for analytics purposes

Account Deletion

When you delete your organization account, we perform a cascading deletion of all associated data including:

  • User accounts and profiles
  • Microsoft Entra ID configuration and synced user data
  • Signature templates and assignments
  • Uploaded images and gallery items
  • Usage logs and analytics data
  • Billing records (subject to legal retention requirements)

07 Your Rights

Under GDPR, CCPA, and other privacy regulations, you have the following rights regarding your personal data:

Right to Access

Request a copy of the personal data we hold about you.

Right to Rectification

Request correction of inaccurate personal data.

Right to Erasure

Request deletion of your personal data (account deletion).

Right to Portability

Request your data in a machine-readable format.

To exercise any of these rights, contact us at info@fixsignatures.com. We will respond to your request within 30 days.


08 Cookies & Tracking

We use cookies and similar technologies for:

  • Essential cookies — Session management, authentication, and security
  • Preference cookies — Remembering your settings and preferences

We do not use third-party advertising cookies. You can control cookies through your browser settings.


09 Children’s Privacy

fixSignatures is a business service not intended for individuals under 16 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.


10 Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by:

  • Posting the new Privacy Policy on this page
  • Updating the “Last updated” date at the top
  • Sending an email notification for material changes

11 Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

fixSignatures

For privacy and data protection inquiries

Email: info@fixsignatures.com

Website: fixsignatures.com