Trust & security

Your records deserve real protection.

JustSignOff uses layered safeguards to protect business accounts, customer approvals, photos, and signed documents—without selling the information entrusted to us.

Last updated: July 26, 2026

Encrypted connections

JustSignOff is served over HTTPS, and data sent between the app and its service providers uses encrypted connections.

Private document storage

Photos and signed PDFs are stored in private buckets and are not published as open, permanent files.

Role-based access

Owners, supervisors, and workers receive different access based on their role and company membership.

No sale of customer data

We do not sell personal information or use customer information for third-party advertising.

Infrastructure

Encryption and hosting

JustSignOff runs on managed infrastructure from Vercel and Supabase. The site enforces HTTPS and HSTS, which direct supported browsers to use encrypted connections. Our primary infrastructure providers state that they encrypt data in transit and at rest; their current controls are described in the provider links below.

Payment details are entered into Stripe's hosted checkout. JustSignOff does not receive or store complete card numbers.

Authorization

Who can see what

Each team member receives a separate account. Owners can access company records and manage the team. Supervisors can be given company-wide operational visibility. Workers are limited to work approvals they create or that are assigned to them. Database row-level security and protected server endpoints enforce these boundaries.

Owners can deactivate a former worker's access and replace team members without sharing the owner's credentials.

Accounts

Login and session security

Authentication is managed by Supabase and supports one-time email codes or approved Google and Microsoft sign-in. JustSignOff does not store a separate account password. After login, an encrypted browser session can keep the user signed in until it expires, is cleared, or the user signs out.

Users should keep their email account and device protected, avoid shared logins, sign out of shared devices, and promptly remove access for anyone who leaves the company.

Files

Photos and signed PDFs

Uploaded photos and generated PDFs are kept in private Supabase storage. Authorized downloads use short-lived signed URLs or a valid customer approval token; files are not intended to be publicly indexed. Private and token-based pages also instruct search engines not to index them.

Lifecycle

Retention and deletion

Work approvals, PDFs, photos, audit events, and delivery records remain available while an account is active. After cancellation, documents remain downloadable for 90 days and are then scheduled for permanent deletion. Some limited account, billing, fraud-prevention, or legal records may remain with JustSignOff or its processors when required for legitimate business or legal obligations.

Before the retention period ends, account owners should download signed PDFs and export their work-approval history.

Resilience

Backups and recovery

Our hosting and data providers maintain infrastructure resilience according to their services and the plans we use. JustSignOff does not currently promise a specific recovery-point objective, recovery-time objective, or individual-file restoration service. Provider backup coverage can vary by plan, and database backups may not include stored photos or PDFs.

For durable business records, customers should use the built-in signed-PDF downloads and CSV export in addition to the online copy.

Operations

Monitoring and incident response

JustSignOff monitors system runs, delivery failures, PDF status, sending limits, and operational incidents in its owner command center. Restricted platform administrators may access account and work-approval information when reasonably necessary to provide support, investigate fraud or security concerns, recover a document, or operate the service.

We investigate suspected security incidents and will notify affected users when required by applicable law. Security concerns can be reported to support@justsignoff.com.

Subprocessors

Specialized service providers

We use established providers only where needed to operate JustSignOff. Their own certifications and security programs apply to their services; they do not make JustSignOff itself independently certified.

Privacy

No sale or advertising use

JustSignOff does not sell personal information, use customer information for third-party advertising, or allow advertising networks to follow users across unrelated websites. Operational data is shared only with service providers needed to run the product, as explained in our Privacy Policy.