Effective September 11, 2026

Privacy Policy

YesPage is proposal and e-signature software for contractors and consultants. This policy explains what we collect, why, who handles it for us, and what you can ask us to do with it. It covers two kinds of people: senders, the businesses with a YesPage account, and signers, the clients those businesses send proposals to. If something here is unclear, email hello@yespage.co.

What we collect

From senders. Your email address and name when you create an account, your business name, logo, colors, team, reviews, license numbers, and stored signature when you add them, the proposals you write, the contacts you add or import (name, email, company, phone, and any notes you keep), and your mobile number if you turn on text notifications. We do not ask for a password; sign-in is by an emailed link or code.

From signers. Your name and email address as entered by the business that sent you the proposal, your mobile number if the business asked us to text you the link, which optional items you selected, your typed or drawn signature, and, for every signature, the date and time, your IP address, and your browser and device type. We record these because an electronic signature is only useful if it can be shown later who signed, when, and from where.

From everyone who opens a proposal page. When a page is opened we record the time, the IP address, the browser, and how long each section of the proposal stays on screen, so the business can see that its proposal was read. This is not advertising tracking and it is not shared with anyone but the business that sent the proposal.

Payments. Card and bank payments are processed by Stripe. Card numbers go directly to Stripe and never touch our servers. We keep the amount, the date, the last four digits and card brand, and Stripe's receipt link so both sides can see that a payment was made. When a business records a cash or check payment, we keep what they typed.

How we use it

  • To run the product: build, send, track, sign, and pay for proposals, and produce the signed PDF and certificate of completion.
  • To send the emails and text messages the product is built around: the proposal link, reminders, signing and payment confirmations, sign-in links, and notifications to the business.
  • To keep signatures verifiable. Every event on a proposal is written to a hash-chained audit trail that cannot be edited afterward.
  • To prevent abuse: rate limits, the report link on every proposal page, and blocking accounts that send fraud or spam.
  • To bill paid plans and to collect the platform fee on card payments made on the Free plan.

We do not sell personal information. We do not use signer or contact data for advertising, and we do not contact a business's clients for our own purposes.

Text messages

YesPage can send SMS text messages in two situations. A business can ask us to text its client the link to a proposal, up to two reminders if it goes unsigned, and a confirmation when it is signed or paid. A business can also turn on texts to its own mobile number when a client opens, signs, or pays.

Consent is collected before the first message: the business confirms its client agreed to receive texts about the proposal, and a business user opts in on their own Settings page. Message frequency depends on how many proposals are sent. Message and data rates may apply. Reply STOP to any message to stop receiving texts from YesPage, and HELP for help. Opting out is honored immediately for all YesPage messages to that number.

Mobile numbers and SMS consent are never sold, rented, or shared with third parties or affiliates for marketing or promotional purposes. Numbers are shared only with the messaging provider that delivers the texts, and only to deliver them.

Who processes data for us

We run on a small number of providers, each bound by its own data processing terms. They receive only what they need to do their job.

  • Neon (database hosting) and Fly.io (application hosting), United States.
  • Cloudflare (file storage for uploaded images, signed PDFs, and certificates).
  • Resend (email delivery).
  • Twilio (text message delivery, when enabled).
  • Stripe (payments, payouts to businesses, and subscription billing).
  • Sentry (error reports, which can include the account and proposal involved but not proposal content).

Cookies

We use two cookies and no third-party trackers. A session cookie keeps a business signed in for up to 30 days. A per-proposal cookie on the client page tells one visit from the next, so a business sees “opened twice” rather than a dozen page loads. Neither is used for advertising.

How long we keep it

Signed proposals, their signatures, audit trails, PDFs, and certificates are kept for seven years from signing, because a signed agreement has to stay verifiable for as long as either party might need it. Drafts, unsent proposals, and contacts are kept while the account exists and deleted with it. Sign-in links and codes expire after 15 minutes. Page view records are summarized after 30 days.

If a business deletes its account, everything except signed proposals and their records is removed. Signed records are kept for the retention period above and remain available to signers through the verification page, because a signer's copy of a signed agreement is theirs too.

Your choices

  • Businesses can edit or delete contacts, proposals that were never sent, library content, and their own details at any time in the app.
  • Signers can ask the business that sent a proposal, or us, for a copy of what they signed. The certificate of completion is emailed at signing and can be verified at any time on our verification page.
  • Anyone can email hello@yespage.co to ask what we hold about them, to correct it, or to have it deleted, subject to the retention rules above for signed agreements. We answer within 30 days.
  • To stop text messages, reply STOP. To stop emails about a proposal, reply to the email and the business will hear from you; sign-in and receipt emails are transactional and stop when the account closes.

Security

Data moves over HTTPS only. Sign-in and signer links are random, single-use where they can be, and stored hashed. Signature images and signed PDFs are hashed with SHA-256 and the hashes are written into the audit trail, so a copy can be checked against the original years later without trusting us. Access to production systems is limited to the people who run YesPage.

Children, changes, and contact

YesPage is a business tool and is not directed at children under 16. We do not knowingly collect their information.

When this policy changes, the date at the top changes and businesses with an account get an email if the change affects them. Older versions are available on request.

Questions and requests: hello@yespage.co. See also the Terms of Service.