Privacy Policy
Pacts records who accepted which terms, when, and from where. That means we handle personal data about our customers, the people they send terms to, and visitors to our website, under two different roles. This page explains exactly what we hold and why.
Version 1.5 · Last updated 4 October 2026
1.Who we are
Pacts is operated by Vorcu Labs, LLC, a Delaware limited liability company (“we”, “us”). You can reach us about anything on this page at privacy@pacts.io, or by post at 2 Blue Slip, #31L, Brooklyn, NY 11222, United States.
2.Two roles, and why the difference matters
We handle personal data in two distinct capacities, and your rights differ depending on which applies to you.
- As a controller, for the account data of our own customers — the people who sign up to send terms, and the members they invite — and for the email address a visitor to our website gives us to get a download or change alerts. We decide what to collect and why. This policy governs that data.
- As a processor, for data about recipients — the people our customers ask to accept terms — and for the contents of agreements our customers import, which may name other people. We only hold that data because a customer put it there and instructed us to. That customer is the controller, and their own privacy notice governs it. Our obligations to them are set out in our Data Processing Addendum.
If you were sent terms to accept, the page tells you before you click. When you click Accept, Pacts records your name, email address, the time, your IP address and browser, and a fingerprint (SHA-256) of the exact text, and gives the sender a record of it. Where the sender has verification on, we first email you a one-time code to confirm it is you; the code is kept only as a hash and expires after ten minutes. The sender is responsible for your data and decides what is collected; we store it on their behalf.
If you gave us your email address on our website, to get a download or to be told when a page changes, we are responsible for it and this policy governs it. Section 3 says what we keep, section 5 how long, and every change alert carries a one-click unsubscribe link.
3.What we collect
We collect the least we can while still producing a record that stands up as evidence. We do not buy data and we do not enrich profiles. We run analytics trackers only with your consent. We measure which of our advertisements lead to a sign-up (Google Ads), and you can turn that off at any time (section 7). Neither ever runs on recipient signing pages.
| Data | Who it concerns | Why we hold it |
|---|---|---|
| Email address and password | Customers | Authenticating your account. Passwords are handled by Firebase Authentication and are never visible to us. Google sign-in is available as an alternative. |
| Your name and workspace name | Customers | Identifying you in the app and on the terms your recipients see. |
| Logo file and accent colour | Customers | Optional branding on your public acceptance pages. The logo file is stored with your workspace. |
| Terms acceptance record | Customers | Which version of these documents you accepted, when, and how (sign-up, Google sign-in, invitation, or in-app re-acceptance), with the IP address and browser used at the time. |
| Invitations | Customers | The email addresses you invite to your workspace, held in a single-use invitation that expires after 7 days. |
| Email address, for account emails | Customers | Sending you account emails about the workspace you created: getting started, trial status, security and legal notices. You can turn getting-started emails off in Settings → Account or with the link in each one. |
| Email address, for downloads and change alerts | Website visitors | When you enter your email address in a form on our website. We keep it with the page and form you used and the campaign details of the link you arrived by (for example which advertisement or site sent you, including an advertising click identifier if the link carried one), to understand which pages people find useful. Asking for a download sends you no email and does not add you to a mailing list. Change alerts start only after you confirm with a link we email you. We then email you when that page changes in a way we judge matters to its readers, never automatically when it is edited. Each alert links to the page and to the Pacts sign-up page; we count clicks on those links without connecting them to your address. |
| Contact name and email address | Recipients | Addressing terms to a specific named person and sending them their personal link. Entered by our customer, not by us. |
| IP address and browser user-agent | Recipients | Captured by our servers at the moment of acceptance. This is the evidentiary core of the product: it records what our systems observed, so an acceptance can be attributed to a particular session rather than merely asserted. |
| Acceptance timestamp, terms version, and content hash | Recipients | Proving which exact version of a document was accepted, and that its content has not been altered since. |
| One-time verification codes | Recipients | Email verification before acceptance, on by default for each workspace. Codes are stored only as a cryptographic hash, are single-use, allow five attempts, and expire after 10 minutes. |
| Imported agreements and their details | Customers, and the people named in the agreement | Agreements you executed elsewhere and upload as PDF files are stored with your workspace, sealed after upload, with a fingerprint of the file. When your workspace's AI setting is on, the whole PDF is sent to Google Cloud's Vertex AI to suggest the counterparty, agreement type and dates; you review every suggestion before anything is recorded. The file may name people who never receive a Pacts link. |
| Who imported an agreement | Customers | The workspace member who imported an agreement, the source of each recorded date (suggested by AI or entered by a person), and any later correction, so the record's provenance can be reconstructed. |
| Verification links | Recipients, indirectly | A random token per certificate that resolves to its record. The public page it opens shows the verification result, the document and version, the accepting company, the acceptance time and the issuer — not the accepted text and not the accepting person's details. |
| Email delivery events | Recipients, customers and website visitors | For each email we send: the address, the kind of email, and the delivery events our email provider reports (delivered, bounced). Never the subject or body. Deleted after 30 days. |
| IP address or email address, briefly | Everyone | Rate limiting, to stop automated abuse of the public acceptance and sign-in endpoints and of the forms on our website. Counters are keyed by IP address, or by email address where a limit applies per address, and expire automatically shortly after their window. |
| Operational logs | Everyone | When something goes wrong, our servers log the error with a request reference, the page or endpoint and a stack trace, at our hosting provider. Our hosting provider's request logs may include your IP address and the page requested. Used only to keep the service running and to investigate faults. |
| Staff access records | Everyone | When our staff open a workspace or a record in the internal console, and every change they make there, is written to a tamper-evident log with the staff member's identity. |
| Billing details and subscription status | Customers | Managing paid plans. Payments are processed by Stripe — card details are entered directly with Stripe and never reach our servers. We store only a Stripe customer and subscription reference, your current plan, and the billing country/postal code needed for tax. |
| API request metadata and external_id | Customers / Recipients | When the API is available on your plan: the request data our customer sends us and the customer-chosen external_id that links records to their own systems. This is customer-provided data for which the customer is the controller; webhook destinations are endpoints the customer controls. |
4.Legal bases
Where the UK GDPR or EU GDPR applies, we rely on the following bases for the data we control:
- Performance of a contract — operating your account and providing the service you signed up for, including service emails about your account (trial status, security and legal notices).
- Legitimate interests — keeping the service secure, preventing abuse, maintaining the integrity of acceptance records, sending a short series of getting-started emails to new workspace owners, which you can turn off at any time, and keeping a record of the downloads visitors request on our website so we know which pages are useful. We consider these interests to be balanced against your rights because the data involved is minimal and directly necessary to the purpose.
- Consent — change alerts. You give it by confirming with the link we email you, and you can withdraw it at any time with the unsubscribe link in every alert. Withdrawing does not affect alerts already sent.
- Legal obligation — where we must retain information to comply with the law.
For recipient data and for the contents of imported agreements, the legal basis is determined by our customer as controller, not by us.
5.How long we keep things
Account data is kept for as long as your account is open. The workspace owner can close the workspace from Settings › Account, after downloading an archive of everything in it. For 90 days after closure the workspace stays readable and the archive can still be downloaded; recipient links and verification links stop working immediately. When that period ends, a scheduled job deletes the workspace’s data — acceptance records, contacts, companies, published terms, imported files, logos, and the accounts of members who have no other workspace — unless a legal hold has been placed on it. We keep the payment event records we receive from Stripe and our staff audit log. We send a reminder seven days before deletion.
Where a record is needed for the establishment, exercise or defence of legal claims, the right to erasure does not apply to it (UK/EU GDPR Article 17(3)(e)). A request to erase or restrict an acceptance record is assessed individually; the fact that a record evidences an agreement does not by itself require permanent retention. While a request is assessed we can restrict processing of the record: it is kept unchanged but left out of lists, exports and public verification. Write to privacy@pacts.io.
Contacts. Removing a contact from active use stops their links and reminders but does not erase their details or existing records. Erasing a contact’s personal data clears their name, email address, search entries and personal link from the contact record and every open request, campaign send and email-log entry that carried them; their acceptance records keep the details recorded at acceptance. Both actions are available to the customer in the app, and our staff can perform the erasure on the customer’s instruction.
Website visitors. An email address given for a download is deleted 12 months after you gave it. A change-alert request you do not confirm is deleted 30 days after we sent the confirmation email. Confirmed alerts last until you unsubscribe: no alert is sent after that, and your address is deleted 30 days later. If we retire a page, its alert subscriptions are deleted. To have your address deleted sooner, write to privacy@pacts.io.
One-time verification codes expire after 10 minutes and are deleted automatically. Rate-limiting counters expire shortly after their window closes. Email delivery records are deleted after 30 days. Workspace invitations expire after 7 days.
6.Who else processes this data
We use a small number of sub-processors. Vercel hosts the application; Google Cloud provides authentication, the database, file storage and, when your workspace setting is on, the AI extraction described in section 3. We do not sell personal data. Apart from Stripe, which acts as an independent controller for its own fraud-prevention and legal-compliance purposes, we do not share it with anyone for their own purposes.
| Provider | What they do | Where |
|---|---|---|
| Vercel | Application hosting: serves every page and request, runs our server code and scheduled jobs, and holds the operational logs those produce. | United States |
| Google Cloud / Firebase | Authentication (sign-in credentials and sessions) and the Firestore database where all records are stored. | United States (us-central1) |
| Google Cloud Storage | File storage for agreements you import and for your workspace logo. | United States (us-central1) |
| Google Vertex AI | Model inference on agreements you import, when your workspace's AI setting is on: the PDF is sent to suggest the counterparty, agreement type and dates. Nothing is used to train models. | United States (us-central1) |
| Resend | Delivery of transactional email: acceptance links, reminders, one-time verification codes, and notifications, account emails to workspace owners, and confirmation and change-alert emails to website visitors who ask for them, plus delivery events (delivered, bounced) it reports back to us. | United States |
| Stripe | Payment processing for paid plans: subscriptions, checkout, invoicing and the billing portal. Card details are entered directly with Stripe and never reach Pacts' servers. Stripe also acts as an independent controller for its own fraud-prevention and legal-compliance purposes. | United States |
| PostHog | Product analytics, event tracking, and session recording to understand user workflows and improve the application. Recipient signing surfaces (/a/* and /c/*) are completely excluded from tracking. | United States |
Our providers process this data in the United States. If you are in the UK, EEA or Switzerland, that means your data is transferred outside your home jurisdiction. These transfers rely on the Standard Contractual Clauses adopted by the European Commission, together with the providers’ own transfer frameworks.
7.Cookies
Pacts sets strictly necessary cookies used to keep you signed in, optional analytics cookies to help us improve the service, and advertising-measurement cookies that you can decline:
accord_session— strictly necessary: the session for a customer signed in to the app. Expires after 14 days; after 1 day for Vorcu Labs, LLC staff accounts.pacts_contact— strictly necessary: the session for a recipient using an optional partner account. Expires after 14 days.pacts_staff_mfa— strictly necessary: set only for Vorcu Labs, LLC staff after they confirm a second authentication factor. Expires after 12 hours.pacts_consent— records your analytics and advertising cookie preferences (accepted or declined). Expires after 1 year.ph_*— optional product analytics cookies set by PostHog only after you provide consent via our cookie banner, used to understand how visitors and customers use the platform._gcl_*— advertising measurement: set by Google Ads when you arrive from one of our advertisements, so that a later sign-up can be attributed to it. Not set if you press Decline in our cookie banner, or if your browser sends the Global Privacy Control signal, which we honour as a decline. Expire after 90 days.
Our advertising measurement sends Google the fact that a visit from one of our advertisements led to a sign-up, and later to a first set of terms sent; it never sends the content of your terms, your recipients, or anything about them. Under some US state privacy laws this may count as “sharing” for advertising purposes: Decline in the cookie banner, or the Global Privacy Control signal, is how you opt out, and we honour both. Advertising measurement is not used to build a profile of you or to show you advertisements elsewhere.
Authentication cookies are HTTP-only and sent only over HTTPS in production. Pages where a recipient reads and accepts terms (under /a/ and /c/) set no tracking cookies and load zero third-party analytics scripts. Fonts are served from our own domain, so viewing a page does not call out to a third party.
8.Security
No client application can read or write our database directly; every access goes through our servers. File uploads use short-lived, server-authorised addresses, and imported agreements are sealed after upload and checked against their fingerprint every time they are served. Our servers record the acceptance time and the network and browser information available to them; these details support the evidence record but do not on their own prove a person’s identity or authority. Verification codes are stored hashed and never in plain text. Pages carrying a personal link are excluded from search engines, cannot be embedded in a frame, and do not leak their address to sites they link to.
No system is perfectly secure. If you believe you have found a vulnerability, please write to support@pacts.io and we will respond.
Authorised Vorcu Labs, LLC staff may access workspace data to provide support and operate the service. They sign in to the internal console with a second authentication factor, privileged actions require that factor to have been confirmed within the previous ten minutes, and opening a workspace or a record and every change made there is written to a tamper-evident, hash-chained log.
9.Your rights
Depending on where you live, you may have the right to access, correct, delete, export, or restrict the processing of your personal data, and to object to it. To exercise any of these, write to privacy@pacts.io. We will respond within one month, or tell you within that time if the law allows us longer and why.
If you are unhappy with our response you may complain to your local data protection authority. If you are in California, we do not sell or share personal information as those terms are defined by the CCPA, and we do not discriminate against anyone for exercising their rights.
10.Children
Pacts is a business tool and is not directed at anyone under 16. We do not knowingly open accounts for them; if we learn that we have, we will close the account and delete its data. People named in a customer’s records or imported agreements are handled under that customer’s instructions, as described in section 2.
11.Changes
If we make a material change we will update the version and date at the top of this page and notify account holders by email before it takes effect. Account holders are asked to accept the new version the next time they use the app, and we keep a record of that acceptance.
Pacts is not a law firm and does not provide legal advice. These documents describe how the service operates; they are not advice about your own obligations.