Last updated: May 1, 2025
We collect the minimum needed to run Dataroom, and we never sell your data. Here's what we collect, why, and what you can do about it.
Account data: name, email, workspace name, billing details (via Stripe, we never see your card).
Content: documents, links, envelopes, proposals, updates, and metadata about how they're used.
Usage: visits, page views, geolocation (country-level), device/browser, performance telemetry.
Recipient data: when someone opens a link, signs a doc, or fills a form, we capture the email and engagement data the sender configured.
We share data only with subprocessors required to run the service. See the full list at /legal/subprocessors. We don't sell data, and we don't use it for advertising.
You can access, correct, export, or delete your data at any time from settings. For requests, email privacy@sendmint.com. We respond within 30 days.
We keep your data as long as your account is active. After cancellation, your data is read-only for 30 days, then permanently deleted (with backups expired within 35 days).
Dataroom is not directed at children under 13 (or under 16 in the EU). We don't knowingly collect their data.
Dataroom operates in the US and EU. Transfers outside your region are governed by Standard Contractual Clauses (SCCs) and additional safeguards as required.
Data Protection Officer: dpo@sendmint.com.