Privacy

What we store, and why.

This page covers what's specific to Webway Sign, the document-signing product. Webway's company-wide privacy policy at webway.host/privacy applies as well — this page adds the detail that only makes sense for a signing tool.

Who we are

Webway Sign is a service of Webway. Documents, signatures and accounts described here belong to the Webway Sign product specifically; Webway's group-wide policy above covers Webway as a company. Questions about either one can go to support@webway.host.

What we store

  • Your account details: name, email address and role.
  • The PDFs you upload, and the fields and signatures placed on them.
  • The names and email addresses of the people you send documents to.
  • An activity log for each document — who opened, signed or downloaded it, when, from which IP address and browser.
  • If you turn on two-factor sign-in, the secret it's based on — encrypted, never stored as plain text.

Why we process it

To run the signing service you asked us for: storing your documents, sending links to the people you name, recording who did what and when, and producing the finished, signed copy.

You decide what goes into a document and who it's sent to — we don't check the contents or choose the recipients for you. For that reason, you're the one responsible for what's in a document and who it goes to; Webway processes it on your behalf, to provide the service.

Where it's kept

On servers in Johannesburg, South Africa.

How it's protected

  • Uploaded PDFs, page previews and signature images are encrypted (AES-256) before they're saved to disk.
  • Every connection to Webway Sign uses HTTPS.
  • Documents are walled off by organisation — another customer's account can't reach yours, even with a document's address.
  • Signing links expire (30 days by default, or a period you choose) and can carry a password and a limit on how many times they open.
  • Repeated wrong passwords lock a signing link or a sign-in for 15 minutes.
  • Two-factor sign-in (an authenticator app plus recovery codes) is available on every account and can be required by a team admin.
  • Every download is digitally sealed, so a change made to a downloaded copy afterwards can be detected.

Who can see it

People in your organisation, according to the view or edit permission you've given them, and the signers you send a document to. Webway's own admin screens show counts only — how many documents or people an account has — with no way to open a document from them. Emails Webway Sign sends (signing links, notifications) go out through our mail delivery provider.

How long we keep it

A document and its activity log are kept until you delete it, which removes the file, its previews, its signatures and its log immediately. Saved signatures are kept until the user who drew them is removed from your team.

If your Webway Sign service is cancelled or terminated, everything belonging to it — documents, signatures, activity logs and user accounts — is deleted immediately, not kept for a grace period.

Signers' rights

If you were sent a document to sign and want your information removed, ask the organisation that sent it to you — they control the document. You can also contact support@webway.host and we'll help direct the request.

Your rights

For requests about your personal information beyond what's described here — access, correction, objection — see Webway's company-wide policy at webway.host/privacy, or contact support@webway.host.

Cookies

Webway Sign itself sets one cookie: a session cookie used while you're signed in or signing a document. There's no analytics or advertising cookie in the app. Webway Sign's public pages — this one and the home page — load fonts from Google Fonts, so your browser makes a request to Google's servers to fetch them.

Last updated 14 September 2026