SpiffySign

Privacy Policy

Effective Date: April 27, 2026

Operated by: Iowa Automations LLC, Cedar Falls, Iowa

What This Policy Covers

This Privacy Policy describes how SpiffySign (“we,” “us,” “our”), operated by Iowa Automations LLC, collects, uses, stores, and protects information when you use our web application at spiffysign.com. This policy applies to all users of SpiffySign, including real estate agents (“Agents”) and the buyers or other parties who sign agreements through the platform (“Signers”).

Information We Collect

From Agents (account holders)

When you create a SpiffySign account, we collect:

  • Full name and optional display name
  • Email address
  • Phone number
  • Brokerage name
  • Iowa real estate license number
  • Payment information (processed and stored by Stripe; we do not store credit card numbers)
  • Your drawn signature image (if you choose to save one in Settings)

We also store your agreement preferences, including default fee percentage, retainer period, geographic area, and jurisdiction.

From Signers (people who sign agreements)

When you sign an agreement through SpiffySign, we collect:

  • Full name (entered by the Signer during signing)
  • Email address (entered by the Signer during signing)
  • Phone number (provided by the Agent who sent the agreement)
  • Drawn signature image
  • Initials (for buyer representation agreements, if required by the Agent)
  • IP address at the time of signing
  • Browser user agent string at the time of signing
  • Timestamp of when the agreement was viewed and signed

Automatically collected information

When you visit spiffysign.com, our hosting provider (Vercel) may collect standard web server logs, including IP addresses, browser type, and pages visited. We do not use tracking cookies or third-party analytics tools.

How We Use Your Information

We use the information we collect to:

  • Create and manage Agent accounts
  • Generate, deliver, and store signed agreements
  • Produce signed PDF documents that include signatures, names, and an electronic signature audit trail
  • Send signed agreement PDFs to Agents and Signers via email
  • Process subscription payments through Stripe
  • Communicate with Agents about their accounts or our service

We do not sell, rent, or share your personal information with third parties for marketing purposes.

Electronic Signatures and Audit Trail

Each signed agreement PDF includes an electronic signature audit trail containing: the Signer's name, email, phone number, IP address, browser user agent, and the date and time of signing. This audit trail is included to establish the legal validity of the electronic signature under the Iowa Uniform Electronic Transactions Act (Iowa Code Chapter 554D) and the federal Electronic Signatures in Global and National Commerce Act (E-SIGN Act).

Where Your Data Is Stored

  • Account data and agreement records: Stored in a PostgreSQL database hosted by Supabase (cloud infrastructure provided by Amazon Web Services). Data is encrypted at rest.
  • Signature images and signed PDFs: Stored in private cloud storage buckets hosted by Supabase. Access is restricted by row-level security policies.
  • Payment data: Processed and stored by Stripe. We store only your Stripe customer ID and subscription status.
  • Email delivery: Transactional emails are sent through Resend. Email content is not stored by us after delivery.

Who Can Access Your Data

  • Agents can access only their own account information and the agreements they have created, including Signer information for those agreements.
  • Signers can view agreement details only through their unique, private signing link.
  • Iowa Automations LLC (the platform operator) has administrative access to all data for the purposes of operating, maintaining, and supporting the platform.
  • We do not provide data to third parties except as required by law (such as a valid court order or subpoena) or as necessary to operate the service (Supabase for data storage, Stripe for payments, Resend for email delivery, Vercel for web hosting).

Data Retention

We retain account data and signed agreement records for as long as your account is active and for a reasonable period afterward to comply with legal obligations and resolve disputes. Signed agreement PDFs and their associated audit trails are retained indefinitely as legal records, consistent with real estate industry practice.

If you wish to delete your account and associated data, contact us at anton@iowaautomations.com. We will delete your account data within 30 days, subject to any legal retention requirements. Note that signed agreement PDFs may be retained as legal records even after account deletion.

Data Security

We implement reasonable technical and organizational measures to protect your data, including:

  • Encryption in transit (HTTPS/TLS on all connections)
  • Encryption at rest (provided by our infrastructure providers)
  • Row-level security policies restricting database access to authorized users
  • Private storage buckets with scoped access policies for signature images and signed PDFs
  • Unique, randomly generated tokens for Signer access (signing links are not guessable)
  • Signing links that are deactivated after use (signed or expired agreements cannot be accessed)

No method of electronic storage or transmission is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

Third-Party Services

SpiffySign uses the following third-party services to operate:

Each of these services has its own privacy policy governing how they handle data.

Children's Privacy

SpiffySign is not intended for use by anyone under the age of 18. We do not knowingly collect information from children.

Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify Agents by email or by posting a notice on our website. Your continued use of SpiffySign after any changes constitutes acceptance of the updated policy.

Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:

Iowa Automations LLC
Cedar Falls, Iowa
anton@iowaautomations.com