SafeBind.ai
This Privacy Policy explains how SafeBind AI LLC ("SafeBind," "we," "us," or "our") collects, uses, discloses, and safeguards personal information. It applies to our marketing website, our applications and APIs, and our dealings with prospective and current customers. Please read it alongside our Terms of Service.
SafeBind acts in two different capacities. (1) As a business / controller for information about our website visitors, prospects, and customer account contacts. (2) As a service provider / processor for the end-consumer personal information and consent evidence that our customers capture using SafeBind and that we store and verify on their behalf and under their instructions. For that processed data, our customer is the business/controller; SafeBind does not sell it and does not use it for its own purposes. If you are a consumer whose data was captured on a customer's website, please direct privacy requests to that business (see Consumer evidence & your choices).
When a customer installs SafeBind on their web form, we capture and store consent evidence as a service provider. This can include the consumer's form interactions, a recording of the consent moment (the page’s structure and the consumer’s interactions, which can be replayed later), the disclosure and agreement text shown, device and browser signals, IP address, behavioral signals used for fraud detection, and the personal information the consumer submitted on the customer's form (such as name, contact details, and similar fields). For fraud detection we also compute a device fingerprint — a non-reversible hash derived from device characteristics such as the browser's canvas/WebGL rendering, graphics hardware, screen, platform, and time zone — and record automation indicators (for example, a headless or automated browser). We compare these characteristics with the browser the device reports itself to be, and across the parts of one visit, to detect a disguised or swapped device; and we time a few small requests from the browser to our servers (network round-trip timing), which can show traffic relayed through a hidden proxy. This fingerprinting is a similar technology used to detect fraudulent and automated submissions; it identifies a device, not an individual, and we do not use it for advertising. The SDK is designed to redact sensitive fields in the browser, before anything is sent to us — for example Social Security and driver's license numbers, payment-card and bank-account numbers, card security codes, passwords, and security answers, and any field the business has marked as sensitive — and a redacted field's value is not transmitted to us. The business that runs the form is responsible for marking sensitive fields the SDK might not recognize on its own. The Service is offered for United States traffic only. We process this data solely to provide the service to that customer, under our agreement and their instructions.
We may create aggregated or de-identified data (which cannot reasonably identify you) and use it for analytics and to improve our products. We do not use consumer evidence we process on a customer's behalf for any of our own purposes, including in aggregated or de-identified form.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We disclose personal information only as follows:
If you are a consumer, our Consumer Notice sets out in plain language what SafeBind records when you fill out a form on a business's website, what it never records, how long the record is kept, and who to contact about it. This section is the summary; that page is the detail.
If you are a consumer whose consent was captured on a business's website using SafeBind, that business is the controller of your information and determines how it is used. To exercise your privacy rights over that data — including access, correction, or deletion — please contact the business that operated the website. SafeBind will assist that business in responding to your request as required by law and our agreement with them. Because a consent record may be needed by that business to establish, exercise, or defend legal claims — for example, to respond to a claim under the Telephone Consumer Protection Act (TCPA) — or to comply with a legal obligation, the business may be entitled under applicable law to retain specific evidence for the applicable limitations period even after a deletion request; that decision rests with the business as the controller of the data.
Our marketing website and console use first-party cookies that are strictly necessary to operate the site and keep you signed in. To understand how the site is used we also run Google Analytics 4 on our marketing website, which sets first-party cookies to measure visits, where they came from, and which pages are viewed. We use these to improve the site, not to build advertising profiles. Our record page — the page a shared record link opens, whose address carries an access token — loads no analytics or advertising scripts at all, so no third party is present on the page where that token is handled. The token is also removed from the address bar, so it is not carried in referrer headers or browser history. If you are in the EEA, the UK or Switzerland, our tags are configured to store nothing on your device at all. You can control cookies through your browser settings; disabling strictly necessary cookies may affect functionality, and you can opt out of Google Analytics specifically with Google’s opt-out browser add-on.
Advertising measurement. Across our marketing website we use Google Ads conversion tracking (Google’s gtag.js). It sets cookies so we can tell whether a visit that arrived from one of our ads resulted in a demo request; it runs on every marketing page because the ad is usually clicked on one page and the demo requested on another. We use it for advertising measurement only — we do not run cross-site behavioral advertising, and we do not sell or share personal information as those terms are defined by state privacy laws. This is enforced in the tag itself, not merely as a policy: the site instructs Google to deny ad personalization and ad-user-data uses, so the tag can count conversions but cannot build advertising audiences from your visit. You can opt out of Google’s advertising cookies at adssettings.google.com, and Google’s handling of this data is described in its privacy policy.
Session capture on this website. Our demo page runs the same SafeBind tag a publisher installs, so that you can watch a record being made. What you enter on that page, together with a recording of your interaction with it, is transmitted to SafeBind and sealed into a real record, which we keep for the periods described under Data retention below. The page says so above the form and asks you to use made-up details; to have a demo record removed, email contact@safebind.ai. No other page on this website runs the tag. This website does not respond to Do Not Track or Global Privacy Control signals; we do not sell or share personal information, so there is nothing for such a signal to opt you out of.
Depending on where you live — including California (CCPA/CPRA) and states such as Colorado, Connecticut, Texas, Utah, and Virginia — you may have the right to:
To make a request about information for which SafeBind is the business/controller, email contact@safebind.ai with "Privacy Rights Request" in the subject line. We will verify your request and respond within the timeframes required by applicable law. You may also designate an authorized agent to act on your behalf.
Do Not Sell or Share: SafeBind does not sell or share your personal information. If our practices change, we will update this Policy and provide the required opt-out mechanism.
We retain account and billing information for as long as your account is active and as needed to provide the service, comply with legal obligations, resolve disputes, and enforce our agreements.
Consent evidence processed on a customer's behalf is retained on two bases, and both apply to the personal information contained in that evidence:
We retain consent evidence by default for the periods above and do not delete it in response to a mid-window consumer request; the customer, as controller, directs deletion. We delete sooner where the customer so instructs, and retain longer where a legal hold, an applicable legal-retention obligation, or the customer's need to establish, exercise, or defend legal claims requires it, to the extent permitted by applicable law. Where a customer's free self-serve save window has closed but the evidence is still within the period for which we retain it, that customer may request the evidence from us as a paid retrieval; a retrieval does not extend how long we hold it.
We use a combination of reasonable technical, administrative, and physical safeguards designed to protect personal information — including encryption in transit, encryption of stored evidence, cryptographic signing of records, access controls, and logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
SafeBind is operated from the United States and information we process is handled in the United States. If you access the service from outside the United States, you understand your information will be processed here. Our services are intended for businesses and are not directed to children under 16, and we do not knowingly collect personal information from children.
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, where appropriate, provide additional notice. Your continued use of the service after changes take effect constitutes acceptance of the updated Policy.
Questions or requests? Contact us at contact@safebind.ai, or by post at SafeBind AI LLC, 572 Blair Avenue, Piedmont, CA 94611, United States.