SignSheet · Privacy

Privacy Policy

Last updated: May 1, 2026 · Operator: NG Company · BN 71138 4412 · Coquitlam, BC, Canada

1. What this document is for

SignSheet is a tool for processing handwritten timesheets. This page tells you what data we collect, why, where it lives, who can see it, and how to get it deleted.

We've tried to write it in plain English. If anything is unclear, write to us at privacy@ngcompany.ca and we'll explain — and update the page if we should have been clearer.

2. What data SignSheet handles

CategoryExamplesWhy we hold it
AccountYour email address, your company name, your roleTo sign you in, to scope your data to your company
Uploaded photosPhotos of paper sign-in sheetsThis is the core feature — we OCR the photo into structured data
Extracted dataNames, FOS codes, sign-in / sign-out times, dates, sheet metadataOutput of OCR; this is what you ultimately export to payroll
Activity logWho signed in when, who exported what, settings changesTamper-proof audit trail required by §6
Operational telemetryAnonymised request counts, error stack tracesTo detect and fix problems

We do not collect: marketing analytics, behavioural ad data, third-party tracking pixels, or anything we can't justify against the table above.

3. Where the data lives

DataProviderRegion
Auth + tenant data + uploaded photosSupabase (Postgres + Storage)Canada (ca-central-1)
Internal lookup tables (employees, settings)Neon (Postgres)United States (us-east-1)
Application code + edge functionsVercelGlobal edge, mostly US
OCR processing (transient)Anthropic (Claude API)United States
Email deliveryResendUnited States
Rate-limit and short-lived flagsUpstash RedisCanada

Cross-border data transfer: Some processing happens in the US (OCR, some lookup tables). Photos themselves are stored in Canada. Anthropic's data-handling policy: anthropic.com/legal/privacy.

4. Who can see your data

5. How long we keep things

DataRetention
Account + audit logLifetime of the account, plus 12 months after deletion
Uploaded photos90 days from upload, then auto-deleted (cron job; you can request earlier deletion)
Extracted timesheet dataLifetime of the account, plus 12 months for legal/accounting holds
Operational telemetry90 days
Database backups14 days rolling

6. Your rights (PIPEDA / PIPA-BC)

You may, at any time:

If you have a privacy complaint we haven't resolved to your satisfaction, you can contact:

7. Security

How we protect your data is summarised in our Customer Security Brief. Key facts: encryption in transit and at rest, tamper-proof audit log, independent pre-launch audit (April 2026), independent penetration test scheduled for the second month after launch.

We will notify affected users within 72 hours of detecting any breach that involves your data.

8. Cookies and similar

SignSheet uses cookies only for what's necessary to keep you signed in. We don't use marketing or analytics cookies. We don't use third-party trackers.

9. Children

SignSheet is a B2B tool for adult employees. We do not knowingly collect data from anyone under 18.

10. Changes to this policy

We'll update the Last updated date at the top whenever this policy changes. Material changes (something that meaningfully affects your data) trigger an in-app notification and an email.

11. Contact