BACK TO HOME
DocuSign

DocuSign

General Servicedocusign.com

Privacy Conclusion

"DocuSign presents a moderate-to-high privacy risk profile (62/100) comparable to Google/Microsoft due to extensive collection of sensitive financial and biometric data, broad sharing with advertising networks and marketing partners characterized as potential 'sales' under CCPA, and deployment of cross-context behavioral tracking via cookies and pixels. While the platform does not deploy advertising tracking in core products (eSignature, CLM, Identity), it collects data from third-party sources, retains data indefinitely, and limits user control over strictly necessary tracking. The fragmented opt-out mechanism and lack of Do Not Track signal recognition compound these concerns."

Risk Score
62
ELEVATED

DocuSign Privacy Concerns & Scorecard

Privacy Risk Analysis
Data CollectionCRITICAL

DocuSign collects extensive sensitive data including financial information (credit card numbers, financial account numbers), biometric data (electronic signatures), location data (GPS, geolocation), device identifiers, and authentication credentials. Additionally, data is collected from third-party sources about users without direct consent.

Third-Party SharingCRITICAL

DocuSign shares personal data with advertising networks, marketing partners, and data providers (including Clay for marketing contact data). Data is characterized as potentially being 'sold' or 'shared for targeted advertising purposes' under CCPA. Data about non-customers is collected through refer-a-friend programs and shared with third parties.

Tracking & AdsHIGH

DocuSign uses cookies, web beacons, tracking pixels, and similar technologies for cross-context behavioral advertising. Third-party advertising technologies track users to deliver targeted content and advertising. The company does not honor browser Do Not Track signals.

Transparency & RightsHIGH

While opt-out mechanisms exist, they are fragmented and limited. Users cannot opt out of strictly necessary cookies, declining cookies may limit service functionality, and organization account holders can find and access employee accounts. Policy changes can occur without clear notice.

Retention & ControlMEDIUM

Data retention periods are vaguely defined as 'no longer than necessary for purposes collected or as required by law' without specific timeframes. Chat transcripts and transaction data are retained by the company. Technical limitations may prevent deletion of certain data.

Recommended Actions

No recommended actions at this time.

Automate your privacy

Connect your accounts to TrueTerms to automate these privacy actions and monitor policy changes.

Data Collection & Tracking

Personal Information Collected

Identity Data

Account creation, service delivery, customer support, identity verification, and authentication

Financial Information

Payment processing, fraud detection, transaction management, and compliance

Biometric Data

Document signing, identity verification, and authentication

Location Data

Service delivery, compliance with regional requirements, analytics, and marketing targeting

Device Information

Service functionality, analytics, fraud detection, and advertising tracking

Usage and Behavior Data

Analytics, service improvement, advertising targeting, and user experience optimization

Communication Data

Customer support, service quality assurance, and marketing

Marketing and Inferred Data

Targeted advertising, marketing campaign delivery, and user segmentation

Cross-Platform Tracking

DocuSign deploys third-party advertising and marketing technologies that use cookies and similar tracking methods to deliver targeted content and advertising on DocuSign marketing websites and other websites across the internet. Data is shared with ad networks, ad measurement services, and remarketing providers to enable cross-context behavioral advertising, though this tracking is limited to marketing websites and not deployed in core customer products like eSignature.

Tracking Methods:

Cookies

First-party and third-party cookies used for analytics, authentication, remembering preferences, and targeted advertising on marketing websites and other sites

Web Beacons

Tracking pixels and web beacons deployed to collect information about user interaction and deliver targeted advertising

Local Shared Objects

Flash cookies and similar technologies used to store tracking information and persist user data across sessions

Device Fingerprinting

Device identifiers and attributes collected to identify and track devices for fraud detection and analytics

Google API Integration

Google APIs receive customer data for non-AI purposes; specific data flows and limitations not detailed in policy

AI & Data Training

DocuSign uses your content to train AI

Below is what's used and how (if at all) you can object.

What Content Is Used

  • Customer Data and Content

    Customer data, user information, and content may be used to train AI and machine learning models

How to Object

You can submit an objection using the steps below.

  1. 1

    Withdraw consent for AI/ML model training by submitting a request via the DocuSign Privacy Request Portal at https://privacy.docusign.com or by emailing privacy@docusign.com. The policy indicates consent is required and can be withdrawn, though specific mechanics and timeliness are not detailed.

Why We Analyzed DocuSign

TrueTerms automatically audits privacy policies and data practices using advanced machine learning to keep you informed and protected. This scorecard is based on the latest available public terms of service and privacy policies as of 2026.