Legal
Cookie policy
What the Signed website, portal and Outlook add-in store on your device, why, and how to change your choice.
Last updated
1.What cookies are
Cookies are small text files that a website stores in your browser. Browsers can also keep information in local storage and session storage, which work in much the same way. This policy covers all of them.
The Privacy and Electronic Communications Regulations (PECR) say a website has to ask before it stores anything on your device, unless it's strictly necessary for a service you've asked for. So Signed asks before it uses analytics, and doesn't ask for the things it needs to work.
2.The Signed portal
When you sign in to the Signed portal, it stores the following. None of it is used for analytics or advertising, and none of it is shared with anyone else.
| Name | Type and purpose | How long it lasts |
|---|---|---|
signed_session | Cookie, strictly necessary. Keeps you signed in. It only holds a random session token, and we only keep a hash of that token. It's httpOnly, so scripts on the page can't read it, it's only sent over HTTPS and it uses the SameSite=Lax setting, which helps stop other websites from using it. | 14 days, renewed while you use Signed. Removed when you sign out. |
signed_staff_session | Cookie, strictly necessary. Keeps Signed staff signed in to our internal console, with the same protections. You won't get this cookie unless you work for Signed. | Up to 12 hours. Removed when the staff member signs out. |
signed_designer_level | Local storage. Remembers whether you last used the simple or advanced signature designer. | Until you clear your browser's storage. |
signed:designer:open | Local storage. Remembers which panels you had open in the signature designer. | Until you clear your browser's storage. |
The session cookies are strictly necessary for the service you signed in for, so PECR doesn't require consent for them. The two designer settings are only written when you make those choices, stay on your device and are never sent to us.
The Signed website also asks the Signed service whether you're signed in, so its header can take you straight to the portal. That request uses the same signed_session cookie. The website doesn't set a sign-in cookie of its own.
3.The Outlook add-in
The add-in keeps its last copy of each signature it has fetched, in the storage Outlook gives add-ins on your device. The names start with signed_, and each copy holds the signature, its version and when it was fetched.
The add-in asks Signed for a fresh signature every time you write an email. It only uses the saved copy if Signed can't be reached within four seconds, so your email still gets a signature. Each copy stays on your device and is replaced whenever a newer one is fetched.
4.This website
usesigned.co.uk only sets cookies if you allow Google Analytics. It has no advertising, retargeting or social media tags and no session recording.
When analytics is in use, a banner asks on your first visit whether you allow it. Essential only keeps Google Analytics switched off. Allow analytics lets it set the _ga and _ga_<container-id> cookies. This is everything the website can store in your browser:
| Name | Type and purpose | How long it lasts |
|---|---|---|
cookie_consent | Local storage. Records whether you chose Allow analytics or Essential only, so the banner doesn't ask again on every page. Only written when you choose. | Until you clear your browser's storage. |
visit_journey | Session storage. Notes the page you arrived on and when, the site that sent you, any campaign tags and ad click IDs in that first link, the previous page and how many pages you've viewed. It stays in this tab and only reaches us if you send the contact form. | Until you close the tab. |
signed_api_key | Session storage. Only used if you paste an API key into the API reference, so the Try it tester can send requests with it. It's only sent to the Signed API, with the requests you make. | Until you close the tab or clear the key. |
_ga | Cookie, analytics, only if you allow it. Set by Google Analytics to tell one visitor from another, so visits are counted rather than page loads. | Two years. |
_ga_<container-id> | Cookie, analytics, only if you allow it. Set by Google Analytics to keep the state of your visit, such as when it started and how many pages you've viewed. | Two years. |
cookie_consent, visit_journey and signed_api_key are kept in your browser's storage rather than set as cookies, so they aren't sent to us as you browse. The notes in visit_journey are only sent if you submit the contact form, when they're included with your message as our privacy policy explains, and they're cleared when you close the tab.
Our servers also keep a standard log of requests. That isn't a cookie and is covered by the privacy policy too.
5.Google Analytics
We use Google Analytics 4 to see which pages are useful and how people find the site. It's provided by Google Ireland Limited, with Google LLC, and it only runs if you allow it.
- The Google Analytics script doesn't load at all until you allow analytics. If you choose Essential only, or don't choose, nothing is sent to Google.
_gatells one visitor from another and_ga_<container-id>keeps the state of your visit. Both last two years unless you delete them.- Google Analytics 4 doesn't log or store IP addresses.
- Advertising features are off. The site tells Google not to use advertising storage, not to use your data for advertising and not to personalise ads.
- Google may process the data in the United States, under the UK Extension to the EU-US Data Privacy Framework.
- We keep analytics data for up to 14 months.
- If you withdraw your consent, the
_gacookies are removed.
Google explains how it uses information from sites that use its services at policies.google.com/technologies/partner-sites (opens in a new tab).
6.Paying through Stripe
When you choose a plan, you're taken to Stripe Checkout on stripe.com to pay. Stripe sets its own cookies there, for things like fraud prevention and keeping your payment session working. Those cookies are covered by Stripe's own cookie and privacy policies, not this one.
7.Connecting Microsoft 365
When an admin connects Microsoft 365, they're sent to Microsoft to sign in and give consent. Microsoft sets its own cookies on its own sites, under its own privacy statement. We don't control them and can't see them.
8.Changing your choice
You can change your analytics choice at any time with the Cookie settings link in the footer of every page, which appears whenever analytics is in use. Choosing Essential only there withdraws your consent: it stops Google Analytics and removes the _ga cookies it has set.
You can also see, block and delete cookies in your browser's settings. Blocking them won't stop the website working, but blocking signed_session stops you signing in to Signed. Clearing this site's stored data means the banner asks you again on your next visit.
The Information Commissioner's Office (opens in a new tab) has general guidance on managing cookies.
9.Changes to this policy
We'll update this page, and the date at the top, before we change what the website, the portal or the Outlook add-in stores on your device.
10.Contact us
Questions about cookies? Email hello@usesigned.co.uk. Our privacy policy explains how we handle personal data more generally.