Privacy Policy

Last updated: September 2026 · Version v2026-09-09

FlowSign is a New Zealand e-signature and document platform operated by Studio Phoenix Limited (NZ company number 7857036, NZBN 9429047886629), trading as FlowSign. This policy explains what personal information we collect, why we collect it, who we share it with, and the rights you have under the Privacy Act 2020.

If you sign a document that another organisation sent through FlowSign, that organisation is the agency responsible for your information - this policy still applies to how we handle the information on their behalf.

1. Who we are

"FlowSign", "we", "us" and "our" means Studio Phoenix Limited, a company registered in New Zealand and trading as FlowSign. Search NZBN 9429047886629 on the NZ Companies Register (opens in a new tab) for our registered office and current filing details. Contact details are at the end of this policy.

2. Scope of this policy

We handle personal information in two capacities under the Privacy Act 2020, and this policy covers both:

  • As an agency, for our own customers - the people and organisations who sign up to send documents through FlowSign. We decide what information we collect from them and why.
  • As a service provider, for signers and recipients - where a customer uses FlowSign to send a document to you for signing, we handle your information on that customer's behalf and under their instructions. You should also read that organisation's own privacy statement.

3. What we collect

Information you give us

  • Your name, email address and (optionally) phone number.
  • Account credentials - a hashed password, or an identifier from a linked sign-in provider (Google, Microsoft).
  • Profile details you choose to add, including a display name, avatar image, and signing identity (drawn or typed signature and initials).
  • Business details for the organisation you administer - company name, billing address, NZBN or equivalent.
  • Documents you upload, and any personal information contained in those documents or their metadata.
  • Payment details you provide when subscribing to a paid plan - collected and processed by Stripe on our behalf; we do not store full card numbers.
  • Anything you tell us when you contact support.

Information about signers and recipients

When a FlowSign customer sends a document to you for signing, we collect and record:

  • Your name and email address (supplied by the sender).
  • The signature, initials, dates, text and other field values you enter to complete the document.
  • An audit trail - the IP address you signed from, the user agent (browser and device) of the device you used, timestamps for viewing, consenting and signing, and any authentication step you completed.

Information we collect automatically

  • Log data when you interact with the service - request URLs, response codes, timestamps, IP address and user agent.
  • Security events - sign-in attempts, session activity, and actions taken on documents and packages, kept as an audit trail.

FlowSign does not currently load third-party analytics, advertising or tracking scripts on its website or in the product.

4. How we collect it

We collect personal information:

  • Directly from you when you sign up, sign a document, contact us, or use the product.
  • Indirectly, from the FlowSign customer who added you as a signer. Where we collect your information indirectly, we will - at the point we first contact you, or as soon as practicable afterwards - make sure you know that FlowSign holds the information, who sent it to us, why we hold it, who we share it with, and your rights of access and correction under the Privacy Act 2020 (Information Privacy Principle 3A). This notification appears on the signing landing page and in the invitation email you receive.
  • Automatically as your device interacts with our servers, as described above.

5. Why we collect and use it

We use personal information to:

  • Provide the FlowSign service - create your account, send and receive documents, capture signatures, and store completed packages.
  • Verify identity and prevent fraud, unauthorised access, spam and abuse.
  • Produce the audit trail and signed certificates of completion that give an electronic signature its legal weight.
  • Bill for the service and manage subscriptions.
  • Respond to support requests, security notices, and legal enquiries.
  • Improve the product - diagnose bugs, measure reliability, and understand which features are used. Where we use information about how the product is used for improvement, we do so on an aggregated or de-identified basis.
  • Send transactional email you would expect from a service like FlowSign (signing invitations, reminders, receipts, account and security notices).
  • Send occasional service updates and, where you have opted in, marketing communications. You can opt out of marketing at any time; transactional emails you cannot opt out of while you hold an account.
  • Meet our legal obligations under New Zealand law.

We do not use personal information for automated decisions that produce a legal or similarly significant effect on you.

6. Who we share it with

We share personal information only where necessary:

  • Sub-processors - the infrastructure, email, payments and monitoring providers we use to run FlowSign. See our Sub-processors list for a current list of who they are, what they do, where they are based, and the lawful basis for each overseas transfer.
  • The organisation that sent you a document - the sender receives the signed document, the field values you entered, and the associated audit trail.
  • Other signers on the same document - where a document has multiple signers, each may see the completed signatures of the others, as designed by the sender.
  • Regulators, courts and law enforcement - where we are legally required, or where disclosure is necessary to protect our rights or the safety of others.
  • An acquirer - if FlowSign is sold, merged or reorganised, personal information may transfer as part of that transaction. Any acquirer will be bound to protect your information consistent with this policy.

We do not sell personal information.

7. Overseas disclosure

Some of our sub-processors are based outside New Zealand. Under Information Privacy Principle 12, we only disclose personal information to a party outside New Zealand where an exception in IPP 12(1) applies. In most cases the exception we rely on is IPP 12(1)(f) - we have reasonable grounds to believe the recipient is required to protect the information in a way that, overall, provides comparable safeguards to the Privacy Act 2020, and we bind the recipient by written contract to those standards. Where a recipient is subject to a privacy law with comparable safeguards, IPP 12(1)(c) also applies.

A current list of overseas sub-processors, the jurisdictions in which they store data, and the IPP 12 basis for each transfer is published on our Sub-processors page.

8. How long we keep it

We keep personal information only for as long as we need it for the purposes above, or as required by law. Specifically:

  • Account information - for as long as you hold a FlowSign account, and up to 90 days after account closure to allow for reactivation and to complete billing.
  • Documents and signing sessions - kept indefinitely by default so signed records remain available. Organisations on paid plans can configure automatic deletion after a chosen number of days in their security settings; when that runs, documents and field values are permanently deleted and the audit trail is retained but anonymised (personal identifiers such as email addresses and IP addresses are removed).
  • Audit trail - kept for the life of the associated package, and retained indefinitely in anonymised form after retention purge for the integrity of historical records.
  • Billing records - retained for a minimum of seven years to meet tax and companies-law obligations.
  • Support correspondence - up to three years after the matter is closed.
  • Backups - encrypted operational backups are retained for up to 30 days on a rolling basis; information deleted from live systems is removed from backups when they age out.

9. How we protect it

We take reasonable technical and organisational steps to protect personal information from loss and unauthorised access, use, modification or disclosure, including:

  • Encryption in transit (TLS) and at rest for stored documents and databases, through our infrastructure providers.
  • Access controls, principle-of-least-privilege for staff, and Google Workspace single sign-on with mandatory two-factor authentication for administrative access.
  • Application-layer tenant isolation - every customer-scoped query is filtered by organisation identifier - with object storage protected by scoped signed URLs.
  • An audit log of security-relevant actions, kept for the life of the associated package and retained in anonymised form after retention purge.
  • Regular review of sub-processors and their security posture.

No online service can be guaranteed completely secure. If we become aware of a privacy breach that has caused, or is likely to cause, serious harm, we will notify the affected individuals and the Office of the Privacy Commissioner as soon as practicable, as required by Part 6 of the Privacy Act 2020.

10. Your rights

Under the Privacy Act 2020 you have the right to ask us for a copy of the personal information we hold about you (IPP 6) and to ask us to correct information that is wrong (IPP 7). You can also ask us to delete your account and associated personal information, subject to any records we are required to keep by law.

To exercise any of these rights, email us at privacy@flowsign.app with enough detail for us to identify the information (for example the sender's organisation, the document title and the approximate date). Account holders can also start a request from Account settings → Your data, which opens a prefilled email to us. We will respond within 20 working days.

11. Cookies and tracking

FlowSign uses strictly necessary cookies to keep you signed in and to protect the service (session cookies for authentication, CSRF tokens for form protection). We do not use advertising cookies. We do not currently load any third-party analytics or tracking scripts on the marketing website or in the product; if that changes, we will update this policy and, where required, ask for your consent before loading them. This section is reviewed whenever a script is added and no less than annually.

12. Children

FlowSign is a business product and is not intended for use by anyone under the age of 16. We do not knowingly collect personal information from children.

13. Changes to this policy

We may update this policy from time to time. When we do, we will update the "last updated" date at the top and, if the changes are material, notify account holders by email and post a notice in the product.

14. Contact us and our Privacy Officer

Our Privacy Officer is Anna Woodward. You can reach her at privacy@flowsign.app. For general legal enquiries, email legal@flowsign.app.

Studio Phoenix Limited trading as FlowSign · New Zealand · privacy@flowsign.app
NZBN 9429047886629 · NZ Company 7857036 · Companies Register

15. Complaints

If you are unhappy with how we have handled your personal information, please contact our Privacy Officer first so we can try to put it right. If you are not satisfied with our response, you can complain to the Office of the Privacy Commissioner:

privacy.org.nz (opens in a new tab) · enquiries@privacy.org.nz · 0800 803 909