Security & Privacy
Your data security and privacy are a top priority for Ultimate eSign – Adobe Sign. Here's how we protect your information.
🔒 Encryption
- All OAuth tokens (monday and Adobe Sign) and email addresses are encrypted at rest using AES-256 before they're stored.
- They are decrypted only in memory, at the moment they're needed for an action — never stored in plain text.
- All data in transit is protected with HTTPS/TLS, and HSTS is enforced.
🔑 Secure authentication
- We connect to monday and Adobe Sign using secure OAuth — we never see or store your password.
- Every request is authenticated and authorized using monday's signed session token, so one account can never access another account's data.
- App secrets and encryption keys are never stored in client-side code or our code repository — they're loaded securely on our server.
📦 What data we store (and why)
- monday account/user IDs — to identify your account and authorize requests
- OAuth tokens — to perform the actions you request (read board data, send documents, update the board)
- Email addresses — your Adobe Sign account email and signer emails, to send documents
- Document metadata — board/item references, Agreement IDs, and status, to track documents
- Usage count — to enforce plan limits
We do not collect payment details (billing is handled by monday), and we never sell your data or use it for advertising.
🗑️ Data retention & deletion
- Your data is kept only while the app is installed and in use.
- When you uninstall, your personal data is removed and all End User Data is permanently deleted within 10 days — in line with GDPR and monday.com's marketplace requirements.
- You can request deletion of your data at any time by contacting support@inceptionsoftware.org.
✅ Compliance
- GDPR-compliant data handling
- Legally binding signatures powered by Adobe Sign (Adobe Acrobat Sign)
- Hosted over secure HTTPS with industry-standard encryption
Have a security or privacy question? Email support@inceptionsoftware.org and we'll be glad to help.