Trust & data protection
Privacy Policy
A clear account of the information Signature Studio processes, why it is needed, and the controls available to administrators and employees.
1. Scope and who we are
This Privacy Policy explains how MA Signature Studio, operated by Muhammad Makhdoom Alam (“MA Signature Studio,” “we,” “us,” or “our”), handles information when administrators, employees, authorized customer representatives, and website visitors use the Signature Studio platform and its related services.
Organizations using a dedicated customer workspace generally decide which employee information is submitted and how signatures are governed. In those circumstances, the organization is responsible for its instructions and MA Signature Studio processes the information to provide the service.
2. Information we collect
Account and administrative information
We may process names, business email addresses, authentication identifiers, approved-administrator status, profile preferences, and security or audit events needed to operate and protect an administrator account.
Employee signature information
The platform may process information entered by an employee or administrator, including name, title, department, pronouns, business contact details, address, website, meeting link, social links, headshot, company logo, signature layout, styling choices, approval state, and installation status.
Workspace content and files
We process brand settings, field rules, signature templates, disclaimers, campaign content, uploaded images, integration settings, and audit records created through a workspace.
Demo request information
When someone requests a demonstration, we collect the name, work email address, phone number, company name, company size, email platform, optional message, privacy acknowledgement, and limited referral or campaign information submitted with the request.
Technical and support information
We may receive ordinary request, device, browser, timestamp, diagnostic, and security information generated when the service is accessed, together with information a user includes in a support request.
Website analytics
We use Vercel Web Analytics to understand overall website usage, such as page views, referring pages, approximate location, and device or browser type. The service uses anonymized data and does not use cookies to recognize visitors. We do not use website analytics to identify visitors by name or email. Our analytics configuration excludes secure employee request pages and removes query parameters before analytics data is sent.
3. Google and Gmail data
When a user chooses a Google-powered feature, Signature Studio requests the minimum Google permission needed to manage that user’s Gmail signature settings: https://www.googleapis.com/auth/gmail.settings.basic.
- We use the permission to identify the account’s primary Gmail “send as” address and install or update the approved email signature selected by the user.
- We do not request, read, download, analyze, or store Gmail message content, attachments, contacts, or mailbox history, and we do not send email messages on the user’s behalf.
- For employee one-click installation, the access granted for that installation is used to apply the signature and the Google token is revoked after the installation attempt completes. We may retain the Gmail address, installation timestamp, result, and related audit record.
- For an administrator-enabled Gmail integration, encrypted authorization tokens may be stored for the period needed to provide the connected feature. The administrator can disconnect the integration to stop future access.
MA Signature Studio’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
4. How we use information
We use information to provide, secure, support, and improve the service, including to:
- authenticate approved administrators and maintain secure sessions;
- generate, preview, approve, copy, export, and install email signatures;
- apply an organization’s brand, field, disclaimer, campaign, and layout rules;
- operate requested Google, Microsoft, directory, storage, and email-delivery integrations;
- maintain private request links, status records, audit history, and operational integrity;
- respond to demo enquiries, understand prospective customer needs, and arrange requested follow-up;
- prevent abuse, investigate failures, provide support, and comply with applicable obligations.
Where applicable, processing is based on the user’s consent, performance of requested services, legitimate interests in operating a secure service, and compliance with legal obligations.
5. How information is shared
We do not sell personal information or Google user data. Information may be disclosed only as reasonably necessary:
- to the customer organization and its authorized administrators;
- to infrastructure and service providers supporting hosting, authentication, databases, storage, email delivery, security, and requested integrations, including Vercel, Supabase, Google, Microsoft, and configured email providers;
- to professional advisers, authorities, or other parties when required by law or necessary to protect rights, safety, and service integrity;
- in connection with a legitimate business reorganization, subject to appropriate confidentiality and data-protection safeguards.
Service providers are permitted to process information only for the services they provide to us or as otherwise allowed by applicable law.
6. Retention and deletion
We retain information only for as long as it is reasonably needed to provide the workspace, honor an organization’s instructions, maintain security and audit history, resolve disputes, and satisfy applicable obligations. Retention periods vary by record type, workspace configuration, and customer agreement.
Authorized administrators may update or remove workspace and employee information through available controls. A user or organization may also request access, correction, export, disconnection, or deletion by contacting us. We may need to verify identity and authority before completing a request, and limited records may be retained where required for security, legal, or legitimate operational purposes.
Users can revoke Google access from their Google Account permissions at any time. Disconnecting an integration stops future API access but does not automatically erase records that must be retained for the purposes described above.
7. Security and international processing
We use reasonable technical and organizational safeguards designed to protect information, including HTTPS in transit, restricted administrative access, server-side credentials, encryption for stored integration tokens, private status tokens, access controls, and audit logging. No internet service can guarantee absolute security.
MA Signature Studio and its service providers may process information in countries other than the user’s own. Where required, we use contractual or other appropriate safeguards for international processing.
8. Choices and rights
Depending on location and applicable law, users may have rights to request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. Users may also contact the relevant data-protection authority. We will respond to valid requests in accordance with applicable requirements.
The service is intended for professional and business use and is not directed to children under 18. We do not knowingly collect personal information from children through the service.
9. Changes to this policy
We may update this policy to reflect changes in the service, law, security practices, or integrations. We will publish the revised version here and update the effective date. Where a material change affects how previously authorized Google user data is used, we will provide appropriate notice and request renewed consent when required.
10. Contact us
MA Signature Studio
Operated by Muhammad Makhdoom Alam
Faisalabad, Punjab, Pakistan
Email: hello@masignaturestudio.com
Website: www.masignaturestudio.com
Use the subject “Privacy Request” for privacy, access, deletion, or Google-data questions.
