Signtosee / FAQ

Product & compliance answers

SignToSee is built for document workflow automation and access control. Every relevant flow is engineered for auditability under EU-focused compliance standards.

How do I know which links I have sent and to whom?

link-management

Your dashboard acts as mission control. It gives a complete overview of active and inactive Gates, shows each Gate name, the whitelisted email addresses, and a real-time log of who signed and when.

Can anyone open the link?

link-management

That depends on your Gate configuration. If you leave a Gate open, anyone who verifies their email can sign and access it. If you enable whitelist mode, only the specific email addresses you entered can attempt access.

Does this work with any URL?

link-management

Yes. You can gate Notion, Figma, Canva, Google Docs, and personal website URLs. SignToSee protects access to the URL itself. If the destination has its own login or paywall, the recipient must still complete that external access flow.

What happens if my client signs multiple times for the same URL?

link-management

A signature for a specific Gate is recorded as a validated session. To preserve monthly signature capacity, instruct clients to bookmark the destination URL after unlock, rather than re-entering the SignToSee Gate every visit.

Is the link permanent?

link-management

No. By default, links have a maximum lifetime of 1 day to support urgency and security. You can adjust expiry windows, reactivate expired links, or permanently delete Gates from the dashboard.

What if I want to change an uploaded document later?

link-management

You cannot modify the original uploaded payload behind an existing Gate. SignToSee creates a SHA-256 fingerprint of the exact file to preserve tamper-evident record integrity. If you need a new version, create a new Gate.

What if my client shares the link with someone else?

security-best-practices

Two scenarios exist. 1. If they share the SignToSee Gate link and whitelist mode is enabled, unauthorized third parties are blocked during verification. 2. If they share the raw destination URL after unlocking, they bypass your intended access workflow. Your access log still documents who accessed and accepted the consent terms in SignToSee.

Does SignToSee prevent downloading, screenshotting, or copying?

security-best-practices

No. SignToSee is an access control layer, not DRM. No software can fully prevent out-of-band capture, such as a camera photo of a monitor. SignToSee documents access and acceptance of consent terms.

What extra steps should I take to secure my work?

security-best-practices

Use SignToSee as an access control layer, and combine it with strict operational hygiene: - Never share your master workspace. Create isolated client files. - Keep destination permissions view-only unless active collaboration is required.

What exactly is logged on your servers?

access-logs

We log access fields needed to establish a verifiable consent trail under eIDAS while minimizing GDPR risk: - Timestamp with timezone - Signer identity via verified email (reversibly encrypted at rest) - Network and device context (hashed IP representation plus user-agent) - Document metadata, including size and SHA-256 fingerprint for uploaded files - Cryptographic chain linkage so tampering breaks integrity checks

How long do you keep my access records?

access-logs

Access logs are retained while your account exists. Deleting a Gate does not remove associated access records because historical accepted terms must remain intact. Full account deletion follows GDPR right-to-erasure processes.

Is this service annoying for my clients?

access-logs

No. The recipient flow is intentionally lightweight: they verify their email and accept the terms once, then they can access the protected content. It should feel like a short security check, not a burden.

Should I let my lawyer review your terms templates first?

legal-regulatory

Yes. You are welcome to have counsel review your setup. SignToSee provides a standard consent notice with configurable variables and an eIDAS-compatible access log. SignToSee does not provide legal advice.

Do you use marketing cookies or trackers on Gate pages?

legal-regulatory

No marketing trackers are used on recipient Gate pages. No ad pixels and no invasive third-party marketing analytics are included. Only strictly necessary functional components are used for secure verification and session flow.

How do you handle abuse of the software?

legal-regulatory

Abuse monitoring is active. Accounts distributing malware, phishing, or illegal content are terminated, data access is locked, and escalation to relevant European authorities may occur as required.

What are the exact subscription limits?

account-subscription

- Scout: 1 active link, 3 creations per month, 5 signatures per month - Sentinel: up to 15 active links, 50 creations per month, 150 signatures per month - Sentinel +: everything in Sentinel + 5GB hosted storage for encrypted files.

How does the 5GB upload limit work for Guardian?

account-subscription

Guardian accounts have a total hosted storage cap of 5GB at any given time. You can delete older Gates and hosted files to free capacity for new uploads.

Can I cancel anytime?

account-subscription

Yes. You can cancel at any time. Premium features remain available through the current billing period, then the account downgrades to Scout. Unused-time prorated refunds are not provided.

What happens if your servers crash?

account-subscription

Infrastructure is deployed on EU-sovereign platforms with high-availability controls. No platform guarantees absolute uptime. During incidents, preserving access log integrity is prioritized and status communication is handled transparently.

Can I write my own custom consent form text?

consent-workflow

No. Bring-your-own legal text is not supported. SignToSee uses a locked standard consent notice and lets you configure only these variables: assessed value, penalty multiplier, duration, and jurisdiction country.

What can I include in the 'Personal Additions' section?

consent-workflow

Our base template is deliberately clean and simple. The 'Personal Additions' section is entirely optional, allowing you to attach specific legal mechanics if needed. For example, you can add a 'Liquidated Damages Penalty' clause to establish a predefined monetary compensation if your confidential information is misused. SignToSee provides these structural placeholders but does not offer legal advice on what to include. You are solely responsible for ensuring any personal clauses and penalty values are enforceable in your chosen jurisdiction.

Will click-to-accept hold up across EU countries?

consent-workflow

eIDAS states that electronic signatures cannot be denied legal effect solely because they are electronic. SignToSee provides technical records of access, identity linkage, and acceptance flow. It does not guarantee legal outcomes in any specific situation.

How does SignToSee link consent terms to the specific person?

consent-workflow

The system binds recipient identity signals, acceptance event timing, and the consent payload context into a tamper-evident access structure. This creates a cryptographic bond between accepted terms and the signer session record.

What happens if I update a template later?

consent-workflow

Historical access records remain intact. Signed events preserve the exact term state at acceptance time, so later template changes do not retroactively alter prior accepted records.