Cookie Policy
Sign For Free uses necessary browser storage to run the service. Optional analytics and advertising technologies are blocked unless you actively allow the relevant purpose. Refusing them does not affect the signing service.
What we store, and why
| Name | Type | Purpose | Retention |
|---|---|---|---|
preferredLocale | Cookie | Remembers the language you selected, so we don’t have to guess it again on your next visit. | 1 year, or until you change your language. |
sff.optionalCookiePreferences.v1 | Local storage | Remembers your analytics and advertising choices and their policy version. | 6 months, until the policy changes, or until you clear site data. |
| Firebase Authentication session | Browser storage (managed by the Firebase SDK) | Keeps you signed in across visits, so you don’t have to log in again on every page load. | Persistent, until you sign out. |
The preference record is used only to remember your choice. It contains no account, document, recipient, advertising, or device identifier. The legacy sff.cookieNoticeAcknowledged value is not treated as optional technology consent.
Optional providers
This deployment currently has no advertising or analytics providers enabled. An enabled provider is still blocked until you consent, and is restricted to the public landing page and blog.
- Analytics: Google Analytics 4, when configured and allowed.
- Advertising measurement: Google Ads, when configured and allowed.
- Personalized advertising: Google, Meta, X, and Reddit technologies, only when each is configured and you allow personalized advertising.
For attribution, an enabled provider may receive an allowlisted UTM or advertising-click identifier. A direct browser request also exposes ordinary request metadata such as IP address, browser or device information, and time to that provider. Our curated campaign report does not copy those identifiers or request metadata.
Your consent record
When you agree to our Terms of Service, Privacy Policy, and the other items on the consent screen, that record is stored on our servers against your account — not in a separate cookie. It is only reachable once you are signed in, so it relies on the authentication session above rather than storing anything extra in your browser.
What we never send to advertising providers
- Document contents, filenames, titles, PDFs, or audit trails.
- Signer or recipient details, email addresses, names, or signatures.
- Envelope, document, recipient, or account identifiers.
- Signing links, authentication tokens, form contents, or URL parameters other than allowlisted campaign and advertising-click identifiers.
How optional technologies are controlled
Optional provider scripts are loaded dynamically only after an affirmative choice. No choice, a refusal, an expired choice, a storage error, and a policy-version change all keep them blocked. Google uses Basic Consent Mode; we do not send cookieless pings after a refusal. Server-side conversion APIs are not used to bypass your choice.
Managing cookies
Open Privacy choices at any time to change or withdraw optional consent. Withdrawal stops future events and removes first-party advertising cookies we can control. It does not automatically erase data already lawfully received by a provider; privacy requests can be made through the process in our Privacy Policy.
See the consent screen for the full list of items you agree to when using Sign For Free.