Effective October 8, 2026
Updated October 8, 2026: drafts you never sent are deleted with your account (section 5).
Undersign is an electronic signature service, available at undersign.cc and in the Undersign mobile apps. It is operated by Suntree Inc. ((주)선트리, “we”). This policy explains what personal information we collect, why, who processes it, how long we keep it, and the rights you have.
We do not collect your location, contacts, photo library, payment information or advertising ID.
We don’t use your information for advertising or profiling.
Other parties to a document. A completed document comes with a certificate of completion. It lists each signer’s name, email address, title and role, the business they signed for (if any), how they were verified, and when they signed.
Service providers that process data for us under contract, only to provide Undersign:
| Provider | What they do | Location |
|---|---|---|
| Hostinger International Ltd. | Hosts our servers and database, including uploaded documents | India |
| Danal Co., Ltd. | Identity verification | Republic of Korea |
| Twilio Inc. | Sends text messages (verification codes, signing links) | United States |
| Google LLC | Sends email (Gmail) and Android push notifications (Firebase Cloud Messaging) | United States |
We disclose information to authorities only when the law requires it. We never sell or rent personal information.
Our servers are located in India, and Twilio and Google process data in the United States. Your information is transferred to them over encrypted connections when you use the service. Each provider receives only the information its task needs, as listed above: the hosting provider stores everything you keep in Undersign; Twilio receives phone numbers and message text; Google receives email addresses, message text and device tokens. They keep it only as long as needed to provide their service to us. If you don’t want your information transferred, you can choose not to use Undersign or delete your account. That may mean you can’t use the service.
We use one essential cookie to keep you signed in. We don’t use analytics or advertising cookies.
All traffic is encrypted with HTTPS. Passwords are stored only as Argon2 hashes, and identity connecting information only as a keyed hash. Each document’s audit trail is hash-chained, so any change to it can be detected. Access to production systems is restricted to authorized staff.
You can ask to see, correct or delete your personal information, or to stop its processing. You can view and edit most of it in Settings → Profile. To delete your account, go to Settings → Profile → Delete account (설정 → 프로필 → 회원 탈퇴). Step-by-step instructions are at undersign.cc/ko/legal/account-deletion. If you can’t sign in, or for anything else, email allsign523@gmail.com. We will respond within 10 days.
Undersign is a service for adults. We don’t knowingly collect personal information from children under 14.
When we update this policy, we will post the new version here with a new effective date. If the changes are significant, we will also tell you in the app or by email.
You can also contact the Personal Information Infringement Report Center (privacy.kisa.or.kr, phone 118).