Encrypted connections
JustSignOff is served over HTTPS, and data sent between the app and its service providers uses encrypted connections.
Trust & security
JustSignOff uses layered safeguards to protect business accounts, customer approvals, photos, and signed documents—without selling the information entrusted to us.
Last updated: July 26, 2026
JustSignOff is served over HTTPS, and data sent between the app and its service providers uses encrypted connections.
Photos and signed PDFs are stored in private buckets and are not published as open, permanent files.
Owners, supervisors, and workers receive different access based on their role and company membership.
We do not sell personal information or use customer information for third-party advertising.
Infrastructure
JustSignOff runs on managed infrastructure from Vercel and Supabase. The site enforces HTTPS and HSTS, which direct supported browsers to use encrypted connections. Our primary infrastructure providers state that they encrypt data in transit and at rest; their current controls are described in the provider links below.
Payment details are entered into Stripe's hosted checkout. JustSignOff does not receive or store complete card numbers.
Authorization
Each team member receives a separate account. Owners can access company records and manage the team. Supervisors can be given company-wide operational visibility. Workers are limited to work approvals they create or that are assigned to them. Database row-level security and protected server endpoints enforce these boundaries.
Owners can deactivate a former worker's access and replace team members without sharing the owner's credentials.
Accounts
Authentication is managed by Supabase and supports one-time email codes or approved Google and Microsoft sign-in. JustSignOff does not store a separate account password. After login, an encrypted browser session can keep the user signed in until it expires, is cleared, or the user signs out.
Users should keep their email account and device protected, avoid shared logins, sign out of shared devices, and promptly remove access for anyone who leaves the company.
Customer access
Every customer approval page uses a long, cryptographically random token. A customer does not need an account, but anyone who receives that unique link may be able to open it. Treat approval links like private documents and send them only to the intended customer.
Approval activity records the typed signer name, time, IP address, and device information for the document audit trail. Once a work approval is completed, conflicting actions are blocked.
Files
Uploaded photos and generated PDFs are kept in private Supabase storage. Authorized downloads use short-lived signed URLs or a valid customer approval token; files are not intended to be publicly indexed. Private and token-based pages also instruct search engines not to index them.
Lifecycle
Work approvals, PDFs, photos, audit events, and delivery records remain available while an account is active. After cancellation, documents remain downloadable for 90 days and are then scheduled for permanent deletion. Some limited account, billing, fraud-prevention, or legal records may remain with JustSignOff or its processors when required for legitimate business or legal obligations.
Before the retention period ends, account owners should download signed PDFs and export their work-approval history.
Resilience
Our hosting and data providers maintain infrastructure resilience according to their services and the plans we use. JustSignOff does not currently promise a specific recovery-point objective, recovery-time objective, or individual-file restoration service. Provider backup coverage can vary by plan, and database backups may not include stored photos or PDFs.
For durable business records, customers should use the built-in signed-PDF downloads and CSV export in addition to the online copy.
Operations
JustSignOff monitors system runs, delivery failures, PDF status, sending limits, and operational incidents in its owner command center. Restricted platform administrators may access account and work-approval information when reasonably necessary to provide support, investigate fraud or security concerns, recover a document, or operate the service.
We investigate suspected security incidents and will notify affected users when required by applicable law. Security concerns can be reported to support@justsignoff.com.
Subprocessors
We use established providers only where needed to operate JustSignOff. Their own certifications and security programs apply to their services; they do not make JustSignOff itself independently certified.
Privacy
JustSignOff does not sell personal information, use customer information for third-party advertising, or allow advertising networks to follow users across unrelated websites. Operational data is shared only with service providers needed to run the product, as explained in our Privacy Policy.