Fincore eSign

Fincore eSign - Privacy Policy

Version 2026-08-11 · Fincore eSign is a product of Chaturvedi Software House LLC, Dubai, United Arab Emirates.

1. Who we are

Fincore eSign, available at esign.fincoreerp.com, is an electronic signature service operated by Chaturvedi Software House LLC (“CSH”, “we”, “us”), a company established in Dubai, United Arab Emirates.

This policy explains what personal data we process when you use the Fincore eSign portal, sign a document you were invited to, or use the public verification tool, and it applies together with the Fincore eSign User Agreement.

2. Data we process

Portal users (staff of a licensed organisation): name, email address, hashed login credentials, role, notification preferences, and records of accepting the User Agreement.

Signers (people invited by email to sign): name, email address and optional title as entered by the sender; the one-time verification codes we email; the consent presented and accepted; the signature itself (a typed name or a drawn signature image); and audit metadata captured as evidence of the signing event, including IP address, browser user agent and timestamps. Where the sender requests a supporting attachment, the file the signer uploads.

Documents: the PDFs a licensed organisation uploads for signature, and the signed documents and Certificates of Completion the Service generates from them.

Technical data: server logs and rate-limiting counters needed to run the Service securely.

3. What we use it for

We process this data solely to operate the Service: transmitting documents for signature, verifying signer access by emailed one-time codes, producing signed artifacts and audit certificates, sending the emails the workflow requires, enforcing licences and quotas, preventing abuse, and providing support.

We do not sell personal data, we do not use it for advertising, and we do not use tracking for marketing purposes.

4. The public verification tool

The tool at esign.fincoreerp.com/verify checks whether a PDF matches a document processed by Fincore eSign. The file you select is fingerprinted (SHA-256) entirely inside your own browser; the file itself is never transmitted to, received by, or stored on CSH systems. Only the fingerprint is sent, and a successful match discloses only the envelope's completion time and the sending organisation's name.

5. Storage integrations you connect (Google Drive, OneDrive)

A licensed organisation's Owner can optionally connect the organisation's own Google Drive or Microsoft OneDrive so that completed signed documents and certificates are copied there automatically. These connections are made through Google's and Microsoft's own consent screens, with the narrowest available scopes: for Google Drive, drive.file (the Service can only access files it creates itself, never your other Drive content); for OneDrive, an app folder under Apps/Fincore eSign.

The access tokens these connections grant are stored encrypted and are used exclusively to copy the organisation's own completed documents into the organisation's chosen storage. Connections can be removed at any time from the Service's Settings page, and revoked from your Google or Microsoft account security settings.

Fincore eSign's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

6. Hosting and subprocessors

The Service runs on reputable cloud subprocessors: application hosting on Vercel, database hosting on Supabase (AWS ap-south-1, Mumbai, India), document storage on Cloudflare R2, and email delivery via Resend, or via the licensed organisation's own connected email provider where configured.

Stated honestly: primary data is not hosted inside the UAE today. CSH may update hosting locations and will reflect material changes in this policy.

Each organisation's data is isolated by tenant-scoped access controls enforced at the database layer.

7. Cookies

The portal uses only functional cookies: the authentication session cookies set at login, and two security markers used to sign you out after inactivity or when the browser is closed. Signers use one-time links and an emailed code; they do not need accounts. There are no advertising or cross-site tracking cookies anywhere in the Service.

8. Retention and deletion

Document content is retained according to the licensed organisation's retention choices and can be deleted by it; audit trails and Certificates of Completion of completed envelopes are retained as evidence records. Signed documents already delivered by email or synced to an organisation's own storage are outside CSH's systems and control.

9. Security

Data in transit is protected with TLS. Tenant isolation is enforced at the database layer on every query. Integration credentials are stored encrypted, API keys are stored only as hashes, portal sessions expire after inactivity, and access by CSH staff is limited to what operating the Service requires.

10. Your rights and choices

CSH handles personal data in accordance with applicable law, including UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. Portal users should direct requests about their account data to their organisation's administrator or to CSH. Signers may contact the organisation that sent them the document, or CSH, about the personal data captured with their signature; note that audit records of completed signatures are retained as evidence, as described above.

11. Changes and contact

Material changes to this policy are versioned and published on this page. Questions: Chaturvedi Software House LLC, Dubai, United Arab Emirates, via your CSH account representative or the support channel provided with your licence.

See also the Terms and Conditions · About Fincore eSign