Privacy Policy

Pacts records who accepted which terms, when, and from where. That means we handle personal data about our customers, the people they send terms to, and visitors to our website, under two different roles. This page explains exactly what we hold and why.

Version 1.5 · Last updated 4 October 2026

1.Who we are

Pacts is operated by Vorcu Labs, LLC, a Delaware limited liability company (“we”, “us”). You can reach us about anything on this page at privacy@pacts.io, or by post at 2 Blue Slip, #31L, Brooklyn, NY 11222, United States.

2.Two roles, and why the difference matters

We handle personal data in two distinct capacities, and your rights differ depending on which applies to you.

  • As a controller, for the account data of our own customers — the people who sign up to send terms, and the members they invite — and for the email address a visitor to our website gives us to get a download or change alerts. We decide what to collect and why. This policy governs that data.
  • As a processor, for data about recipients — the people our customers ask to accept terms — and for the contents of agreements our customers import, which may name other people. We only hold that data because a customer put it there and instructed us to. That customer is the controller, and their own privacy notice governs it. Our obligations to them are set out in our Data Processing Addendum.

If you were sent terms to accept, the page tells you before you click. When you click Accept, Pacts records your name, email address, the time, your IP address and browser, and a fingerprint (SHA-256) of the exact text, and gives the sender a record of it. Where the sender has verification on, we first email you a one-time code to confirm it is you; the code is kept only as a hash and expires after ten minutes. The sender is responsible for your data and decides what is collected; we store it on their behalf.

If you gave us your email address on our website, to get a download or to be told when a page changes, we are responsible for it and this policy governs it. Section 3 says what we keep, section 5 how long, and every change alert carries a one-click unsubscribe link.

If you received a link asking you to accept terms and want your data corrected or removed, contact the organisation that sent it to you — they control that record. If you contact us directly, we will confirm it is you, pass the request to them and support them in answering it. We act on their instruction, or where the law requires us to act ourselves.

3.What we collect

We collect the least we can while still producing a record that stands up as evidence. We do not buy data and we do not enrich profiles. We run analytics trackers only with your consent. We measure which of our advertisements lead to a sign-up (Google Ads), and you can turn that off at any time (section 7). Neither ever runs on recipient signing pages.

DataWho it concernsWhy we hold it
Email address and passwordCustomersAuthenticating your account. Passwords are handled by Firebase Authentication and are never visible to us. Google sign-in is available as an alternative.
Your name and workspace nameCustomersIdentifying you in the app and on the terms your recipients see.
Logo file and accent colourCustomersOptional branding on your public acceptance pages. The logo file is stored with your workspace.
Terms acceptance recordCustomersWhich version of these documents you accepted, when, and how (sign-up, Google sign-in, invitation, or in-app re-acceptance), with the IP address and browser used at the time.
InvitationsCustomersThe email addresses you invite to your workspace, held in a single-use invitation that expires after 7 days.
Email address, for account emailsCustomersSending you account emails about the workspace you created: getting started, trial status, security and legal notices. You can turn getting-started emails off in Settings → Account or with the link in each one.
Email address, for downloads and change alertsWebsite visitorsWhen you enter your email address in a form on our website. We keep it with the page and form you used and the campaign details of the link you arrived by (for example which advertisement or site sent you, including an advertising click identifier if the link carried one), to understand which pages people find useful. Asking for a download sends you no email and does not add you to a mailing list. Change alerts start only after you confirm with a link we email you. We then email you when that page changes in a way we judge matters to its readers, never automatically when it is edited. Each alert links to the page and to the Pacts sign-up page; we count clicks on those links without connecting them to your address.
Contact name and email addressRecipientsAddressing terms to a specific named person and sending them their personal link. Entered by our customer, not by us.
IP address and browser user-agentRecipientsCaptured by our servers at the moment of acceptance. This is the evidentiary core of the product: it records what our systems observed, so an acceptance can be attributed to a particular session rather than merely asserted.
Acceptance timestamp, terms version, and content hashRecipientsProving which exact version of a document was accepted, and that its content has not been altered since.
One-time verification codesRecipientsEmail verification before acceptance, on by default for each workspace. Codes are stored only as a cryptographic hash, are single-use, allow five attempts, and expire after 10 minutes.
Imported agreements and their detailsCustomers, and the people named in the agreementAgreements you executed elsewhere and upload as PDF files are stored with your workspace, sealed after upload, with a fingerprint of the file. When your workspace's AI setting is on, the whole PDF is sent to Google Cloud's Vertex AI to suggest the counterparty, agreement type and dates; you review every suggestion before anything is recorded. The file may name people who never receive a Pacts link.
Who imported an agreementCustomersThe workspace member who imported an agreement, the source of each recorded date (suggested by AI or entered by a person), and any later correction, so the record's provenance can be reconstructed.
Verification linksRecipients, indirectlyA random token per certificate that resolves to its record. The public page it opens shows the verification result, the document and version, the accepting company, the acceptance time and the issuer — not the accepted text and not the accepting person's details.
Email delivery eventsRecipients, customers and website visitorsFor each email we send: the address, the kind of email, and the delivery events our email provider reports (delivered, bounced). Never the subject or body. Deleted after 30 days.
IP address or email address, brieflyEveryoneRate limiting, to stop automated abuse of the public acceptance and sign-in endpoints and of the forms on our website. Counters are keyed by IP address, or by email address where a limit applies per address, and expire automatically shortly after their window.
Operational logsEveryoneWhen something goes wrong, our servers log the error with a request reference, the page or endpoint and a stack trace, at our hosting provider. Our hosting provider's request logs may include your IP address and the page requested. Used only to keep the service running and to investigate faults.
Staff access recordsEveryoneWhen our staff open a workspace or a record in the internal console, and every change they make there, is written to a tamper-evident log with the staff member's identity.
Billing details and subscription statusCustomersManaging paid plans. Payments are processed by Stripe — card details are entered directly with Stripe and never reach our servers. We store only a Stripe customer and subscription reference, your current plan, and the billing country/postal code needed for tax.
API request metadata and external_idCustomers / RecipientsWhen the API is available on your plan: the request data our customer sends us and the customer-chosen external_id that links records to their own systems. This is customer-provided data for which the customer is the controller; webhook destinations are endpoints the customer controls.

4.Legal bases

Where the UK GDPR or EU GDPR applies, we rely on the following bases for the data we control:

  • Performance of a contract — operating your account and providing the service you signed up for, including service emails about your account (trial status, security and legal notices).
  • Legitimate interests — keeping the service secure, preventing abuse, maintaining the integrity of acceptance records, sending a short series of getting-started emails to new workspace owners, which you can turn off at any time, and keeping a record of the downloads visitors request on our website so we know which pages are useful. We consider these interests to be balanced against your rights because the data involved is minimal and directly necessary to the purpose.
  • Consent — change alerts. You give it by confirming with the link we email you, and you can withdraw it at any time with the unsubscribe link in every alert. Withdrawing does not affect alerts already sent.
  • Legal obligation — where we must retain information to comply with the law.

For recipient data and for the contents of imported agreements, the legal basis is determined by our customer as controller, not by us.

5.How long we keep things

Account data is kept for as long as your account is open. The workspace owner can close the workspace from Settings › Account, after downloading an archive of everything in it. For 90 days after closure the workspace stays readable and the archive can still be downloaded; recipient links and verification links stop working immediately. When that period ends, a scheduled job deletes the workspace’s data — acceptance records, contacts, companies, published terms, imported files, logos, and the accounts of members who have no other workspace — unless a legal hold has been placed on it. We keep the payment event records we receive from Stripe and our staff audit log. We send a reminder seven days before deletion.

Acceptance records are protected against alteration during their retention period, and disposed under a schedule you control. The application has no function that edits one — for you or for us — and every certificate re-verifies the stored text against its fingerprint. By default records are kept for the life of the account; the workspace owner can instead instruct us, in Settings › Account, to dispose of them 3, 6 or 10 years after acceptance. A daily job disposes records past that date, never within 30 days of the instruction and never while a legal hold applies, and writes a log line that holds the record’s identifier, fingerprints, dates and the rule applied — never its content — which we keep for 7 years. A legal hold can be placed on a record, a company or the workspace by the workspace’s administrators, or by us for a legal requirement of our own; each names its purpose, who set it, a review date and the release criteria, and is visible in the workspace. On closure, records are kept for the 90-day retrieval period and then deleted with the rest of the workspace unless a legal hold applies.

Where a record is needed for the establishment, exercise or defence of legal claims, the right to erasure does not apply to it (UK/EU GDPR Article 17(3)(e)). A request to erase or restrict an acceptance record is assessed individually; the fact that a record evidences an agreement does not by itself require permanent retention. While a request is assessed we can restrict processing of the record: it is kept unchanged but left out of lists, exports and public verification. Write to privacy@pacts.io.

Contacts. Removing a contact from active use stops their links and reminders but does not erase their details or existing records. Erasing a contact’s personal data clears their name, email address, search entries and personal link from the contact record and every open request, campaign send and email-log entry that carried them; their acceptance records keep the details recorded at acceptance. Both actions are available to the customer in the app, and our staff can perform the erasure on the customer’s instruction.

Website visitors. An email address given for a download is deleted 12 months after you gave it. A change-alert request you do not confirm is deleted 30 days after we sent the confirmation email. Confirmed alerts last until you unsubscribe: no alert is sent after that, and your address is deleted 30 days later. If we retire a page, its alert subscriptions are deleted. To have your address deleted sooner, write to privacy@pacts.io.

One-time verification codes expire after 10 minutes and are deleted automatically. Rate-limiting counters expire shortly after their window closes. Email delivery records are deleted after 30 days. Workspace invitations expire after 7 days.

6.Who else processes this data

We use a small number of sub-processors. Vercel hosts the application; Google Cloud provides authentication, the database, file storage and, when your workspace setting is on, the AI extraction described in section 3. We do not sell personal data. Apart from Stripe, which acts as an independent controller for its own fraud-prevention and legal-compliance purposes, we do not share it with anyone for their own purposes.

ProviderWhat they doWhere
VercelApplication hosting: serves every page and request, runs our server code and scheduled jobs, and holds the operational logs those produce.United States
Google Cloud / FirebaseAuthentication (sign-in credentials and sessions) and the Firestore database where all records are stored.United States (us-central1)
Google Cloud StorageFile storage for agreements you import and for your workspace logo.United States (us-central1)
Google Vertex AIModel inference on agreements you import, when your workspace's AI setting is on: the PDF is sent to suggest the counterparty, agreement type and dates. Nothing is used to train models.United States (us-central1)
ResendDelivery of transactional email: acceptance links, reminders, one-time verification codes, and notifications, account emails to workspace owners, and confirmation and change-alert emails to website visitors who ask for them, plus delivery events (delivered, bounced) it reports back to us.United States
StripePayment processing for paid plans: subscriptions, checkout, invoicing and the billing portal. Card details are entered directly with Stripe and never reach Pacts' servers. Stripe also acts as an independent controller for its own fraud-prevention and legal-compliance purposes.United States
PostHogProduct analytics, event tracking, and session recording to understand user workflows and improve the application. Recipient signing surfaces (/a/* and /c/*) are completely excluded from tracking.United States

Our providers process this data in the United States. If you are in the UK, EEA or Switzerland, that means your data is transferred outside your home jurisdiction. These transfers rely on the Standard Contractual Clauses adopted by the European Commission, together with the providers’ own transfer frameworks.

7.Cookies

Pacts sets strictly necessary cookies used to keep you signed in, optional analytics cookies to help us improve the service, and advertising-measurement cookies that you can decline:

  • accord_session — strictly necessary: the session for a customer signed in to the app. Expires after 14 days; after 1 day for Vorcu Labs, LLC staff accounts.
  • pacts_contact — strictly necessary: the session for a recipient using an optional partner account. Expires after 14 days.
  • pacts_staff_mfa — strictly necessary: set only for Vorcu Labs, LLC staff after they confirm a second authentication factor. Expires after 12 hours.
  • pacts_consent — records your analytics and advertising cookie preferences (accepted or declined). Expires after 1 year.
  • ph_* — optional product analytics cookies set by PostHog only after you provide consent via our cookie banner, used to understand how visitors and customers use the platform.
  • _gcl_* — advertising measurement: set by Google Ads when you arrive from one of our advertisements, so that a later sign-up can be attributed to it. Not set if you press Decline in our cookie banner, or if your browser sends the Global Privacy Control signal, which we honour as a decline. Expire after 90 days.

Our advertising measurement sends Google the fact that a visit from one of our advertisements led to a sign-up, and later to a first set of terms sent; it never sends the content of your terms, your recipients, or anything about them. Under some US state privacy laws this may count as “sharing” for advertising purposes: Decline in the cookie banner, or the Global Privacy Control signal, is how you opt out, and we honour both. Advertising measurement is not used to build a profile of you or to show you advertisements elsewhere.

Authentication cookies are HTTP-only and sent only over HTTPS in production. Pages where a recipient reads and accepts terms (under /a/ and /c/) set no tracking cookies and load zero third-party analytics scripts. Fonts are served from our own domain, so viewing a page does not call out to a third party.

8.Security

No client application can read or write our database directly; every access goes through our servers. File uploads use short-lived, server-authorised addresses, and imported agreements are sealed after upload and checked against their fingerprint every time they are served. Our servers record the acceptance time and the network and browser information available to them; these details support the evidence record but do not on their own prove a person’s identity or authority. Verification codes are stored hashed and never in plain text. Pages carrying a personal link are excluded from search engines, cannot be embedded in a frame, and do not leak their address to sites they link to.

No system is perfectly secure. If you believe you have found a vulnerability, please write to support@pacts.io and we will respond.

Authorised Vorcu Labs, LLC staff may access workspace data to provide support and operate the service. They sign in to the internal console with a second authentication factor, privileged actions require that factor to have been confirmed within the previous ten minutes, and opening a workspace or a record and every change made there is written to a tamper-evident, hash-chained log.

9.Your rights

Depending on where you live, you may have the right to access, correct, delete, export, or restrict the processing of your personal data, and to object to it. To exercise any of these, write to privacy@pacts.io. We will respond within one month, or tell you within that time if the law allows us longer and why.

If you are unhappy with our response you may complain to your local data protection authority. If you are in California, we do not sell or share personal information as those terms are defined by the CCPA, and we do not discriminate against anyone for exercising their rights.

10.Children

Pacts is a business tool and is not directed at anyone under 16. We do not knowingly open accounts for them; if we learn that we have, we will close the account and delete its data. People named in a customer’s records or imported agreements are handled under that customer’s instructions, as described in section 2.

11.Changes

If we make a material change we will update the version and date at the top of this page and notify account holders by email before it takes effect. Account holders are asked to accept the new version the next time they use the app, and we keep a record of that acceptance.

Pacts is not a law firm and does not provide legal advice. These documents describe how the service operates; they are not advice about your own obligations.