"DocuSign presents a moderate-to-high privacy risk profile (62/100) comparable to Google/Microsoft due to extensive collection of sensitive financial and biometric data, broad sharing with advertising networks and marketing partners characterized as potential 'sales' under CCPA, and deployment of cross-context behavioral tracking via cookies and pixels. While the platform does not deploy advertising tracking in core products (eSignature, CLM, Identity), it collects data from third-party sources, retains data indefinitely, and limits user control over strictly necessary tracking. The fragmented opt-out mechanism and lack of Do Not Track signal recognition compound these concerns."
DocuSign Privacy Concerns & Scorecard
DocuSign collects extensive sensitive data including financial information (credit card numbers, financial account numbers), biometric data (electronic signatures), location data (GPS, geolocation), device identifiers, and authentication credentials. Additionally, data is collected from third-party sources about users without direct consent.
DocuSign shares personal data with advertising networks, marketing partners, and data providers (including Clay for marketing contact data). Data is characterized as potentially being 'sold' or 'shared for targeted advertising purposes' under CCPA. Data about non-customers is collected through refer-a-friend programs and shared with third parties.
DocuSign uses cookies, web beacons, tracking pixels, and similar technologies for cross-context behavioral advertising. Third-party advertising technologies track users to deliver targeted content and advertising. The company does not honor browser Do Not Track signals.
While opt-out mechanisms exist, they are fragmented and limited. Users cannot opt out of strictly necessary cookies, declining cookies may limit service functionality, and organization account holders can find and access employee accounts. Policy changes can occur without clear notice.
Data retention periods are vaguely defined as 'no longer than necessary for purposes collected or as required by law' without specific timeframes. Chat transcripts and transaction data are retained by the company. Technical limitations may prevent deletion of certain data.
No recommended actions at this time.
Automate your privacy
Connect your accounts to TrueTerms to automate these privacy actions and monitor policy changes.
Data Collection & Tracking
Personal Information Collected
Account creation, service delivery, customer support, identity verification, and authentication
Payment processing, fraud detection, transaction management, and compliance
Document signing, identity verification, and authentication
Service delivery, compliance with regional requirements, analytics, and marketing targeting
Service functionality, analytics, fraud detection, and advertising tracking
Analytics, service improvement, advertising targeting, and user experience optimization
Customer support, service quality assurance, and marketing
Targeted advertising, marketing campaign delivery, and user segmentation
Cross-Platform Tracking
DocuSign deploys third-party advertising and marketing technologies that use cookies and similar tracking methods to deliver targeted content and advertising on DocuSign marketing websites and other websites across the internet. Data is shared with ad networks, ad measurement services, and remarketing providers to enable cross-context behavioral advertising, though this tracking is limited to marketing websites and not deployed in core customer products like eSignature.
Tracking Methods:
Cookies
First-party and third-party cookies used for analytics, authentication, remembering preferences, and targeted advertising on marketing websites and other sites
Web Beacons
Tracking pixels and web beacons deployed to collect information about user interaction and deliver targeted advertising
Local Shared Objects
Flash cookies and similar technologies used to store tracking information and persist user data across sessions
Device Fingerprinting
Device identifiers and attributes collected to identify and track devices for fraud detection and analytics
Google API Integration
Google APIs receive customer data for non-AI purposes; specific data flows and limitations not detailed in policy
AI & Data Training
DocuSign uses your content to train AI
Below is what's used and how (if at all) you can object.
What Content Is Used
Customer Data and Content
Customer data, user information, and content may be used to train AI and machine learning models
How to Object
You can submit an objection using the steps below.
- 1
Withdraw consent for AI/ML model training by submitting a request via the DocuSign Privacy Request Portal at https://privacy.docusign.com or by emailing privacy@docusign.com. The policy indicates consent is required and can be withdrawn, though specific mechanics and timeliness are not detailed.
Why We Analyzed DocuSign
TrueTerms automatically audits privacy policies and data practices using advanced machine learning to keep you informed and protected. This scorecard is based on the latest available public terms of service and privacy policies as of 2026.