Legal · Privacy
Privacy Policy
How Safeclose collects, uses, shares, and protects personal information when you visit our websites, use our electronic chattel infrastructure, or interact with our demos, support, and sales channels.
1. Overview
Safeclose provides electronic chattel infrastructure for secured lending—systems that help institutions originate, create, execute, vault, control, transfer, and evidence electronic chattel paper and related packaging across the collateral lifecycle. This Privacy Policy explains how we handle personal information in connection with Safeclose websites (including marketing and documentation surfaces), product applications, APIs, demos, support, and related communications (collectively, the “Services”).
We designed this Policy for banks, lenders, originators, servicers, enterprise customers, workforce users, and consumers who may appear in transactions as signers, borrowers, co-owners, or other counterparties. Roles matter: the enterprise customer that invites you often decides how transaction data is used; Safeclose processes that data to provide the Services.
If you do not agree with this Policy, please do not use the Services. If you have questions, contact us at the email below before continuing.
2. Who we are and how to contact us
In this Policy, “Safeclose,” “we,” “us,” and “our” refer to the Safeclose organization operating the Services under the Safeclose brand, including affiliates that help deliver the product (which may historically appear under related SecureClose product lines for e-sign, vault, and recording). Our marketing and product experiences may be reached at safeclose.com and related application hostnames.
Privacy requests, questions, and notices should be sent to support@safeclose.co with the subject line “Privacy request.” We may ask you to verify your identity before acting on a request.
If we appoint a data protection officer or EU/UK representative, we will update this Policy with those details.
3. Scope and relationship to customers
This Policy covers personal information Safeclose processes as:
Where an enterprise customer (for example a bank, captive finance company, dealer group, or lender) configures the Services for its lending network, that customer typically determines the purposes of processing transaction packages, borrower and signer data, and collateral records. In those cases, the customer is the controller (or equivalent) and Safeclose acts as a processor or service provider. Customers’ own privacy notices and agreements with their borrowers and counterparties also apply.
This Policy does not cover third-party websites, LOS/DMS/core systems, DMS dealers, titling partners, or other services that customer environments may link to, even if those systems exchange data with Safeclose.
- A business operating our own websites, demos, sales, support, and account administration; and
- A provider processing customer content and end-user data to operate vault, signing, automation, and network features for enterprise customers.
4. Information we collect
We collect information in three main ways: you provide it; your organization or counterparties provide it; and we collect it automatically when Services are used.
4.1 Account, workforce, and customer profile information
When an organization onboards or a user is invited, we may process:
- Name, work email, phone number, job title, and role or permissions;
- Organization, company, location, brand, and relationship-graph details (for example bank, lender, originator, servicer associations);
- Authentication identifiers managed through our identity provider (including single sign-on where configured);
- Billing contacts, invoice metadata, and subscription plan details;
- Support tickets, training activity, and correspondence with us.
4.2 Transaction, collateral, and package content (customer content)
Enterprise customers and their users may upload, generate, or cause the Services to store content required to run digital collateral workflows. Depending on configuration, this may include:
- Identity and contact details of borrowers, co-owners, guarantors, signers, dealers, and other counterparties;
- Addresses, employment or business details provided for underwriting or closing packages;
- Government identifiers or identity-document metadata where a customer enables identity verification features;
- Vehicle or asset attributes (for example VIN, serial numbers, stock numbers, equipment schedules);
- Contract, chattel paper, disclosure, lien, release, assignment, and related PDF or structured document packages;
- Signature, initials, acknowledgments, checkboxes, typed fields, uploads, and timestamps associated with execution;
- Vault identifiers, custody events, transfer packages, webhook payloads, and audit or activity logs needed to prove control and lineage;
- Any other materials a customer chooses to place in templates, flows, data rooms, or API submissions.
4.3 Electronic signatures and identity confirmation
Where enabled, the Services capture electronic signature artifacts (including drawn or typed signatures and initials), device and session context for the signing ceremony, and confirmation status from identity or verification tools configured by the customer. We process this information to complete packages, create evidence, and support dispute, compliance, and audit use cases initiated by the customer or required by law.
4.4 Audio-visual and screen evidence of execution
Certain deployments capture screen activity and/or webcam and microphone streams during in-person or remote closing sessions to create an evidence package associated with the transaction. Where those features run:
- Users may be prompted for consent consistent with the customer’s workflow and applicable law;
- Temporary recording segments may be processed by rendering systems (including cloud workers) to produce a final evidence file;
- Intermediate chunks may be discarded after a successful render while the customer-retained final package and related metadata remain stored under the customer’s retention choices and our operational backups;
- Audio-visual evidence can contain biometric-like imagery (for example a face on camera) but is collected as transaction evidence rather than for generalized biometric identification product features.
4.5 Device, log, and usage information
We automatically collect technical information such as IP address, approximate location derived from IP, browser and device type, operating system, language, referring URLs, pages or product screens viewed, feature usage, timestamps, crash diagnostics, performance metrics, and security logs. For remote signing links, we may store token identifiers, link expiration, and access attempts (including failed PIN attempts where that feature is used).
4.6 Cookies and similar technologies
We and our service providers use cookies, local storage, and similar technologies to authenticate sessions, remember preferences (for example theme), maintain security, load chat or support widgets if enabled for a portal, and understand product reliability. Strictly necessary cookies are required for the Services to function. Where analytics or support chat tools are loaded for customer portals, those vendors may set their own cookies subject to their policies. Our public marketing site currently emphasizes content and demos over advertising pixels; if we introduce advertising or additional analytics, we will update this Policy and, where required, consent mechanisms.
4.7 Information from third parties
We may receive information from identity providers, payment processors, cloud infrastructure partners, customer systems (LOS, CRM, core, DMS, titling partners) connected via API or file exchange, optional identity-verification providers, public or commercial sources used for fraud prevention, and referrals from partners. Customers control which of their systems connect to Safeclose.
5. How we use personal information
We use personal information to:
- Provide, operate, maintain, and improve the Services, including custody, vaulting, transfer, validation, automation, and network features;
- Authenticate users, enforce permissions, and protect accounts, packages, and infrastructure;
- Execute customer-configured workflows: invitations, reminders, escalations, webhooks, exports, and integrations;
- Process payments, prevent fraud and abuse, and enforce our Terms;
- Communicate about product updates, security notices, administrative messages, and—where permitted—product education or marketing (you may opt out of marketing);
- Provide support, training, and professional services;
- Comply with law, regulate requirements, and respond to lawful requests;
- Establish, exercise, or defend legal claims;
- Create aggregated or de-identified insights that do not reasonably identify individuals, which we may use for analytics, benchmarking, and product development;
- Evaluate and improve models or validation logic that help detect incomplete packages—without using customer content for unrelated model training unless separately agreed in writing.
6. Legal bases (EEA / UK / similar regimes)
Where GDPR or similar laws apply and Safeclose is a controller, we rely on one or more of: performance of a contract; legitimate interests (for example securing services, improving reliability, B2B marketing to professional contacts, and preventing fraud)—balanced against individuals’ rights; consent where required (for example certain cookies, marketing, or optional recording prompts); and legal obligation. Where we act as a processor, our customers determine the applicable legal bases for their processing.
8. International transfers
Safeclose primarily operates infrastructure in the United States (including common cloud regions such as US East) and may process data in other locations where our providers or personnel operate. Where personal information is transferred from the EEA, UK, or Switzerland to countries without an adequacy decision, we rely on appropriate safeguards such as Standard Contractual Clauses (or successor mechanisms), transfer risk assessments where required, and contractual protections with subprocessors. Customers that require specific residency or private deployment should contract those controls with us in writing.
9. Retention
We retain personal information only as long as needed for the purposes described in this Policy, including to provide the Services, comply with legal, accounting, and dispute-resolution requirements, and maintain security backups.
Because electronic chattel paper, authoritative-copy custody, audit lineage, and secondary-market transferability can require long retention, customer content—including executed packages, custody events, and AV evidence files customers choose to keep—may be retained for the life of the contractual relationship and for additional periods customers configure or law requires. Workforce account data is typically retained while an account is active and for a reasonable wind-down period after deactivation. Temporary media used solely to render final evidence may be deleted sooner after successful processing.
When retention ends, we delete or de-identify personal information, subject to backup cycles and legal holds.
10. Security
We implement administrative, technical, and physical safeguards designed to protect personal information, including encrypted transport, access controls and role separation, authentication through enterprise identity providers, network and application monitoring, least-privilege operational practices, and vendor diligence. No method of transmission or storage is completely secure; we cannot guarantee absolute security. Customers are responsible for configuring user permissions, protecting API credentials, and securing their own environments.
11. Your privacy rights
Depending on your location, you may have rights to access, correct, update, delete, restrict, or object to certain processing; to portability; to withdraw consent; and to lodge a complaint with a supervisory authority. California residents may have additional rights under the CCPA/CPRA, including rights to know, delete, correct, and opt out of “sale” or “sharing” for cross-context behavioral advertising (if we engage in such activity—which we will describe clearly if applicable). We do not use or disclose sensitive personal information for purposes that require a right to limit beyond providing the Services.
If Safeclose processes your data solely as a processor for an enterprise customer, please contact that organization first. We will support customers in responding to requests according to our agreements and the law. You may also email support@safeclose.co and we will route the request appropriately.
We will not discriminate against you for exercising rights available under applicable law.
12. Children
The Services are directed to businesses and adult participants in commercial and consumer financing transactions. They are not directed to children under 16 (or under 13 where that is the legal threshold), and we do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us and we will take appropriate steps to delete it.
13. Automated processing
We use automated validation, scoring, and workflow logic to flag incomplete packages, route tasks, and assist fraud or security reviews. These tools support human decision-making by customers; Safeclose does not, as a general product rule, make legally significant lending underwriting decisions solely by automated processing for consumers. Where a customer configures automated decisions in its own workflows, that customer is responsible for providing any notices required by law.
14. Do Not Track and global privacy controls
Browsers may offer “Do Not Track” signals; industry standards for response remain inconsistent. We currently do not respond to DNT signals in a uniform way. Where required by law, we will honor browser-based opt-out preference signals for sale/sharing of personal information if we engage in those activities.
15. Third-party sites and services
The Services may link to third-party sites or embed third-party widgets. Their privacy practices are governed by their own policies. We encourage you to review them.
16. Changes to this Policy
We may update this Policy from time to time. We will post the updated version with a revised “Last updated” date and, for material changes, provide additional notice as required by law (for example email to account contacts or an in-product notice). Continued use of the Services after an update becomes effective constitutes acceptance of the updated Policy to the extent permitted by law.
17. Contact
Privacy questions and requests: support@safeclose.co
Please include enough detail for us to understand and verify your request. For enterprise customers under a data processing agreement, the notice procedures in that agreement control where they conflict with this Policy.
Contact
Questions about this document: support@safeclose.co

