Legal

Privacy Policy

Last updated: August 24, 2026

This Privacy Policy describes how Rize Technologies, LLC, a Wyoming limited liability company doing business as Rize Ink (“Rize Ink,” “we,” “us,” or “our”), collects, uses, discloses, and retains personal information in connection with the Rize Ink websites, applications, and services (the “Service”).

This Policy applies to visitors to our websites, to agents and brokerages that hold accounts, to the clients and signers those accounts invite, and to anyone who contacts us. It does not apply to a brokerage’s own privacy practices, or to a third-party site reached from a link in a document.

1. Our role, and when this Policy applies

Rize Ink handles personal information in two distinct capacities, and which one applies changes who is accountable for it.

1.1 Information we handle for our own purposes

For account registration, billing, support, security, our own websites, and our own communications, Rize Ink decides why and how the information is processed. This Policy governs that processing, and Rize Ink is the controller or business for it.

1.2 Information we handle on a customer’s behalf

The documents, transactions, property records, client records, and signer records inside a customer’s account are processed on that customer’s instructions. The customer — ordinarily the agent’s brokerage — is the controller or business for that information, and Rize Ink is the processor or service provider. The Data Processing Addendum governs that processing, and it controls over this Policy where the two address the same subject.

This Policy still describes what the Service records in that capacity, because a signer or client is entitled to know what happens when they use it. But a request to access, correct, or delete information held inside a customer’s account is ordinarily directed to that customer. See section 13.

2. Information you provide to us

  • Account and profile information. Name, email address, password, and the role assigned to the account. A profile may also carry a telephone number, job title, company, brokerage, a short biography, a profile photograph, and a brokerage logo.
  • Billing information. Subscription plan and status, and a customer reference, card brand, and last four digits returned to us by our payment processor. Full payment card numbers are entered on the processor’s own hosted checkout page and are never received or stored by Rize Ink.
  • Client and transaction records. Property addresses, transaction type and status, closing and other critical dates, and the names and email addresses of buyers, sellers, and additional parties an agent records. A client invited to the client portal also has a portal password and activation record.
  • Documents and their contents. Files uploaded to or generated by the Service, the fields placed on them, and every version retained. A real-estate document may contain any information the parties put in it. Rize Ink does not inspect document contents for its own purposes.
  • Signer information. The name and email address of each recipient invited to sign, their signing order and role, an access code where one is set, the signature or initials they adopt, and their recorded consent to do business electronically.
  • Support and correspondence. What you send us when you contact support or legal, including the contents of the message.
  • Marketing captures. An email address submitted on a public page — for example, to request the closing checklist — together with the page it came from.

3. Information the Service records automatically

The Service records the following in the ordinary course of operating and of producing a defensible signing record:

  • Signing audit trail. When a signer opens a signature request, consents to do business electronically, or completes a signature, we record the time, the IP address, and the browser and device string reported by their browser. These appear on the certificate of completion, which is what makes an electronic signature evidentiary.
  • Document history. Each material action taken on a document — sent, viewed, field completed, revised, sealed, completed — with the actor and the time.
  • Sessions. Active sessions carry the IP address and browser and device string of the request that created them, and the time of last activity.
  • Marketing captures. The IP address a public-page submission came from, so that we can limit abuse of the form.
  • Support access. If an account administrator grants Rize Ink support staff time-limited access to their account, every request, approval, entry, and expiry in that grant is logged with the actor, the reason given, and the IP address involved.

4. Information we receive from others

  • Delivery and open events. Our email provider reports whether a signature-request email was delivered and, subject to section 5.4, whether it was opened.
  • Billing events. Our payment processor reports subscription, payment, and card-status events. It does not send us full card numbers.

5. Analytics, tracking technologies, and cookies

5.1 No advertising or analytics trackers

Rize Ink does not use third-party analytics, advertising, retargeting, session-replay, or behavioral-profiling services on our websites or in the Service. We load no advertising pixels and no tag-manager containers. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, as those terms are defined under applicable United States state privacy laws. Because we do not sell or share personal information for those purposes, a Global Privacy Control or Do Not Track signal has no such disclosure to disable; we do not currently respond to those signals separately.

5.2 Cookies

The only cookies Rize Ink sets are strictly necessary ones: a first-party session cookie, and a cross-site request forgery token that protects forms you submit. Both are set on our public pages as well as inside the Service, because the same form protection applies to both. Neither is used for advertising or to track you across other websites. We set no advertising cookies, no analytics cookies, and no third-party cookies.

5.3 Interaction events on our marketing pages

Our public marketing pages include lightweight instrumentation that notes interactions such as which buttons are clicked, which frequently asked questions are opened, how far down a page you scroll, and which steps of the interactive demo are completed. These events are held in your browser’s memory for the life of the page and are not transmitted to Rize Ink or to any third party. They record event names and counts only: they never include text you type, an email address you submit, document contents, or signer information. If we later connect an analytics provider, we will name that provider here and update the date above before any collection begins.

5.4 Open tracking in signature-request emails

Emails that invite someone to review or sign a document include a single-pixel image that reports when the message is opened. If the recipient’s mail client loads that image, our email provider reports the time of the open, together with the IP address and mail-client information that the request carried, and we record it on the document’s audit trail. This is how an agent can see that a signature request was opened. A mail client that blocks remote images reports nothing, so the absence of a recorded open does not mean the message went unread.

6. Third-party hosts that deliver page assets

Some of our pages load typefaces and code libraries from third-party content delivery networks, currently Google Fonts, Fontshare, the Tailwind CSS content delivery network, Cloudflare cdnjs, and jsDelivr. To deliver a file, the network serving it receives your IP address and browser and device information, and the fact that the request was made. This is inherent to any content loaded from another domain and happens even though we run no analytics. These networks receive no documents, no form entries, and no signature data.

This includes the page on which a signer reviews and signs a document, which loads its PDF viewer library from Cloudflare cdnjs. The document itself is delivered only by Rize Ink and is never sent to that network. We are working to serve these assets from our own domain so that no third-party request is made.

7. How we use information

Rize Ink uses personal information to:

  1. Provide the Service, including preparing, sending, signing, sealing, storing, and returning documents.
  2. Create and preserve the signing record, including audit trails, certificates of completion, and seals.
  3. Create, authenticate, and administer accounts, and let account administrators manage their own users.
  4. Take payment, manage subscriptions, and keep billing records.
  5. Send transactional messages, such as signature requests, reminders, completion notices, and account and security notices.
  6. Respond to support, legal, and privacy inquiries.
  7. Secure the Service, including detecting, investigating, and preventing fraud, abuse, and unauthorized access, and enforcing rate limits.
  8. Maintain, troubleshoot, and improve the Service.
  9. Send the specific material a person asked us for on a public page, and — where permitted, and subject to an unsubscribe link in every message — other marketing about Rize Ink.
  10. Comply with law, respond to lawful requests, and establish, exercise, or defend legal claims.

Where information sits inside a customer’s account, we use it only to provide the Service to that customer, to comply with law, and for the limited security and operational purposes described above. We do not use document contents to train models, to build profiles, or for advertising.

8. How we disclose information

8.1 Within a customer’s account

Information in an account is visible to the users that customer authorizes, which may include the agent, their brokerage, team members, and transaction coordinators, according to the roles and permissions the account sets.

8.2 To the participants in a transaction

Sending a document discloses it, and what the sender puts in it, to the recipients chosen. A completed document and its certificate of completion — which names each signer and records the time, IP address, and browser and device string associated with their consent and signature — are available to the parties to that transaction, because that is the evidence an electronic signature rests on.

8.3 To service providers

We disclose information to the vendors listed in section 9, each of which receives only what its function requires and is bound to use it only to provide its service to us.

8.4 For legal, safety, and compliance reasons

We may disclose information where we believe in good faith that doing so is required by law or legal process, or is reasonably necessary to enforce our terms, to protect the rights, property, or safety of Rize Ink, our customers, or the public, or to investigate fraud, abuse, or a security incident.

8.5 Business transfers

If Rize Ink is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction. We will continue to protect it in accordance with this Policy, and will give notice before it becomes subject to a materially different policy.

8.6 With direction or consent

We disclose information as a customer instructs, and otherwise with the consent of the person concerned.

8.7 What we do not do

We do not sell personal information. We do not share it for cross-context behavioral advertising or targeted advertising. We do not disclose document contents to advertisers, data brokers, or list vendors, and we do not use them for our own commercial purposes.

9. Service providers

We use a small number of vendors to run the Service, each of which processes only what its function requires:

  • Stripe — subscription billing and payment processing. Card details are entered on Stripe’s own hosted checkout page; what we keep is a customer reference, the card brand, and the last four digits, so that a billing screen can show which card is on file.
  • SMTP2GO — transactional and signature-request email, including the delivery and open reporting described in section 5.4.
  • Amazon Web Services — document storage and hosting, and the key-management service that holds the non-extractable private key used to sign document seals.
  • A timestamp authority — an independent third party that countersigns the time of a seal. It receives only the seal’s cryptographic hash, never the document, and cannot reconstruct the document from it. Using an outside authority is the point: it is what lets a counterparty verify when a document was sealed without having to take our word for it.

None of these vendors is engaged for advertising or analytics purposes. The list of material subprocessors for customer personal data is maintained under the Data Processing Addendum.

10. Retention and deletion

We keep personal information for as long as needed for the purpose it was collected for, and then for any period required by law, by a legal hold, or by the integrity of an executed document.

  1. During a subscription. Account and transaction records are kept while the account is active. A customer may access, export, and delete content through the Service’s own controls, subject to account permissions, brokerage record-retention requirements, legal holds, and the integrity of executed documents and audit trails.
  2. After termination. A customer ordinarily has 30 days to export available content. Rize Ink may remove content from active systems within 90 days after the export period ends. Residual backup copies may remain for up to an additional 180 days and are not ordinarily restored except for disaster recovery, security, or legal purposes. These are the timelines in section 17 of the Terms of Service.
  3. Audit events. The in-app event log for a document that is both completed and sealed is pruned about 18 months after the event. This does not shorten the signing record: by then the trail has been written into the sealed PDF’s certificate of completion and into the seal evidence package, which are the artifacts a counterparty relies on and which verify without our database. Events for documents still in flight are never pruned on this schedule.
  4. Marketing captures. An email address submitted on a public page is kept until it is withdrawn or is no longer needed for the purpose it was given for.
  5. Signed records and signer accounts. When a signing request is sent, we create an account for each signer’s email address — or use the one already held on that address — so the signer can reach what they sign. That account, and access to the records in the transaction, lasts five years from the transaction’s completion, or from the last signature on it where the transaction never completes. This is the period described in section 8.12 of the Terms of Service and disclosed to every signer before they sign.
  6. Archived records. At the end of that period we revoke access for everyone — the sender and each signer — and archive the records. Archiving is not deletion: the records are kept solely to meet legal obligations, and are not reachable through any account, signing link, or export. A record under legal hold is preserved and its period suspended until the hold is released.
  7. Legal holds. We may retain information where required by law, legal hold, fraud prevention, billing, security, or dispute resolution, for as long as that requirement lasts.

11. Security

Rize Ink maintains administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit and at rest, access controls and role separation, hashed credentials and access codes, cryptographic sealing of completed documents with an independently countersigned timestamp, logging, and time-limited, administrator-approved and fully logged support access to a customer’s account. The measures that apply to customer personal data are set out in Annex 2 of the Data Processing Addendum.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Keep your password confidential, and tell us promptly if you believe an account has been compromised.

12. Your privacy rights

12.1 The rights

Depending on where you live, you may have the right to:

  1. Know what personal information we hold about you, and how we collect, use, and disclose it.
  2. Access a copy of it, in a portable form where required.
  3. Correct information that is inaccurate.
  4. Delete it, subject to the exceptions the law allows.
  5. Opt out of sale, of sharing for cross-context behavioral advertising, and of profiling with legal or similarly significant effects. As stated in section 5.1, Rize Ink does none of these, so there is nothing to opt out of.
  6. Limit the use of sensitive personal information. Rize Ink does not request sensitive personal information for its own purposes, and does not use what may appear inside a customer’s documents for any purpose other than providing the Service.
  7. Not be discriminated against for exercising any of these rights.

12.2 How to make a request

Send a request to the privacy address in section 17, describing what you are asking for. If the information is held inside a customer’s account, see section 13 first — it will usually reach you faster.

12.3 Verification and authorized agents

We will take reasonable steps to verify that a request comes from the person it concerns, or from someone authorized to act for them, before we act on it. Verification is ordinarily done through the email address already associated with the information. An authorized agent may submit a request with written permission from the person concerned, and we may still contact that person to confirm it.

12.4 Timing and appeals

We will acknowledge a request promptly and respond within 45 days, or tell you why we need up to a further 45 days. If we decline a request, we will say why. Where the law gives you a right of appeal, you may appeal by replying to our response, and we will respond to the appeal within the period the law allows, and tell you how to contact your state’s attorney general if you remain dissatisfied.

13. Signers, clients, and others without an account

If you signed a document, were invited to sign one, or were given access to a client portal, the agent or brokerage that sent it decides what is collected and how long it is kept. Rize Ink processes that information on their instructions.

Direct a request about that information to the agent or brokerage that sent you the document. If you do not know who that is, or they do not respond, contact us at the address in section 17 and we will help identify the right party and pass the request on. We will act on it ourselves only where the law requires us to, or where the customer instructs us to.

One thing we cannot do is remove a completed document’s signing record at a signer’s request while the underlying transaction record must be preserved. The audit trail is what makes the signature enforceable, including for the signer.

14. Children’s privacy

The Service is a business tool intended for real-estate professionals and the parties to their transactions. It is not directed to children, and we do not knowingly collect personal information from a child under 13, or knowingly sell or share the personal information of anyone under 16. If you believe a child has provided us personal information, contact us and we will delete it.

15. Where information is held

Rize Ink is based in the United States and the Service is hosted in the United States. If you use the Service from another country, the information described in this Policy is transferred to and processed in the United States, where privacy laws may differ from those where you live. Transfers of customer personal data are addressed in the Data Processing Addendum.

16. Changes to this Policy

We may update this Policy. When we do, we will change the “last updated” date at the top. If a change materially affects how we handle personal information, we will give notice before it takes effect, through the Service, by email, or by another reasonable method. Continuing to use the Service after a change takes effect means the updated Policy applies.

17. Contact information

Questions about this Policy, or about personal information Rize Ink holds, can be sent to the address below. Privacy inquiries reach support@rizeink.com, which is the same address designated for privacy inquiries in the Data Processing Addendum.

Rize Technologies, LLC
Doing business as Rize Ink
169 Madison Ave STE 2322, New York, NY 10016
Privacy inquiries: support@rizeink.com
Legal inquiries: legal@rizeink.com
Telephone: 352-234-3389