Skip to main content

Trust center

This page consolidates what we can show about security, data location, evidence records, retention and continuity. It states what exists today. Where something does not exist yet, it says so. It is not a certification: WaiverKit holds no SOC 2, ISO 27001 or HIPAA attestation.

Security measures

  • All traffic is served over TLS through Cloudflare's edge in front of our own servers.
  • The application and its PostgreSQL 17 database run on a server we operate at Hetzner in Nuremberg, Germany; the database listens on the loopback interface only.
  • Signature images and generated PDFs are stored on Cloudflare R2; database dumps are copied to a separate R2 bucket over TLS. R2 encrypts objects at rest; the dumps are not additionally encrypted before upload.
  • Authentication and sessions are handled by Clerk. Team roles (owner, member) exist on the Business plan; every other plan has one owner account.
  • Every signing writes an audit row with the template version, template hash, consent version, IP address and user agent, in addition to the signed record itself.
  • Every deploy is gated by the CI run of the exact commit (type check, lint, the test suite, a production build and a 5xx smoke test), and /api/health reports the commit that reached production, so a green pipeline and a live change are checked separately.

Where your data is processed

Sub-processors match section 5 of our Data Processing Agreement.

ProviderPurposeRegion
Hetzner Online GmbHApplication hosting and PostgreSQL databaseNuremberg, Germany (EU)
Cloudflare, Inc.Edge network, DDoS protection, R2 object storage for signatures, PDFs and database backups (encrypted at rest by R2)Global edge; R2 bucket in Cloudflare's automatic region
ClerkAuthentication, sessions, user directoryUnited States
StripePayments and subscription billingUnited States and EU entities
Resend (via Amazon SES)Transactional emailEU (eu-west-1) for the sending domain
OpenAIAI drafting and translation of waiver template text from the prompt and business description you submit. Signer answers, signatures and signed records are never sent.United States

What a signed record contains, and what the activity log is

On every plan, including Free, each signed waiver stores:

  • The signer's name and the answers they typed, exactly as submitted.
  • The signature (drawn or typed) as an image, and whether it was drawn or typed.
  • The server timestamp of the signing, the signer's IP address, user agent and device type.
  • The template version number, a SHA-256 hash of the template, and a snapshot of the legal text and field definitions shown at that moment. Editing the template later does not change the signed record.
  • The consent-to-electronic-signature checkbox and the version of the consent text the signer saw.
  • A generated PDF containing the document and this evidence block.

Example, synthetic values: signed 2026-09-14T09:12:41Z · IP 203.0.113.42 · Safari on iPhone · template v3 · sha256 9f1c…5f7e · consent esig-v1-2026-04 · signature: drawn.

Separately, the administrative activity log records who did what in your account: template created, updated or deleted, plan changes, business deletion, and every signing. Each row carries the actor, the action, the changed fields, the IP address and the time.

Example, synthetic values: 2026-09-13T16:04:10Z · [email protected] · template.update · fields changed: clauses, expiryDays · IP 198.51.100.7.

The activity log is kept for every business on every plan. It is viewable from the dashboard (Activity log) on the Business plan; on other plans, WaiverKit support extracts it on request from the account owner.

What the record does not establish: the identity of the signer beyond the details collected (an optional ID photo can be required per template), the signer's legal capacity, or whether the waiver's terms will be enforced. Enforceability is decided by a court under the law of your state.

What happens to records when your plan changes

Measured from the code on 2026-09-14. Rows are account states; columns are what you can still do.

Account stateView signed recordsExport PDF / CSVRecords retainedIn backups
Active paid planYesPDF on every plan; CSV on Pro and BusinessYesYes
Downgraded to Free (cancelled or expired)Yes, all historyPDF; CSV no longer availableYesYes
Payment failed, grace periodYesAs on your planYesYes
Payment failed, grace period overYesAs on your planYes; creating templates and accepting new signings is blocked until payment is fixedYes
Business deleted by youNoNo (export before deleting: PDF per waiver, CSV on eligible plans, or the full JSON export in Settings)The business and its templates are marked deleted and no longer served; signed records and their files stay in storage until the deletion request is processed under the retention rules in the privacy policy (a hard delete is a reviewed step, not automatic)Until the backup rotation removes them (daily, weekly and monthly copies)
Business closed by WaiverKit (service discontinuation)See continuity belowSee continuity belowSee continuity belowSee continuity below

Marketing copy says records stay accessible for as long as your account exists, on every plan including Free. Deletion follows the DPA and the retention rules in our privacy policy.

Health, minor and identity data: what may be collected and where it goes

A business chooses which fields its waiver asks. The form builder offers text, email, phone, date, checkbox, select, textarea, signature and initials fields, plus template-level options for an emergency contact, a photo of an ID document, and guardian signing for minors. Questions about allergies, injuries, pregnancy or medication are ordinary text or checkbox fields the business writes itself.

Data categoryWho decides to collect itStored whereSent to the AI provider
Signer identity (name, email, phone, date of birth, address)Business, per templatePostgreSQL (Germany)No
Health disclosures typed into custom fieldsBusiness, per templatePostgreSQL (Germany), inside the signed recordNo
Guardian name, email and relationship for a minorBusiness, if minor signing is enabled (Pro and Business)PostgreSQL (Germany)No
Photo of an ID documentBusiness, if the template requires itCloudflare R2, attached to the record; not verified automaticallyNo
Signature imageAlways collectedCloudflare R2No
Business description and drafting prompt for AI ComposerBusiness, when it uses AI drafting or translationSent to OpenAI to generate the template text; not used for training under our API termsYes (this category only)

Retention: records are kept while the account exists and as the retention rules in the privacy policy require. Access: the account owner and, on the Business plan, team members. WaiverKit staff read a business's account only for support; a staff read of an account page or of that account's waiver list is written to that business's activity log, while cross-tenant support lists are not attributed to a single business.

Languages are not jurisdictions

  • The interface, the signing page and the marketing site are available in 19 languages.
  • Waiver text you write can be translated into the same 19 languages; the translation is machine-assisted and you remain responsible for the wording.
  • Our English template library is written for United States law and marks the states where a clause is limited; the translated template pages adapt clauses and notes to the law of each language's main jurisdiction, machine-assisted and checked by our automated editorial pipeline, not by a human native speaker. No version carries a legal review for any jurisdiction; the templates page and every article say so.
  • A language count therefore says nothing about legal coverage.

/waiver-templates

Support and escalation

Email support on weekdays, Europe/Zurich time (CET, CEST in summer). Most replies within a few hours during Swiss business hours, always within one business day; this is our practice, not a contractual service level. No phone line, no 24/7 desk. An outage of the signing flow is handled first at any time it is read.

Contact page and coverage details

Business continuity

  • WaiverKit is operated by Clashware Sarl, Lausanne, Switzerland, a two-founder engineering company.
  • Backups: the production database is dumped four times a day (03:00, 09:00, 15:00 and 21:00 UTC), size-verified, and copied over TLS to a separate Cloudflare R2 bucket with daily, weekly and monthly retention (7, 28 and 365 days). R2 encrypts objects at rest; there is no additional client-side encryption of the dumps.
  • Recovery is rehearsed: an automated restore drill runs on the first day of every month and restores the newest dump into a scratch database, counting tables and rows. The last drill on 2026-09-01 restored the WaiverKit database successfully (18 tables).
  • You can leave at any time with your data: PDF per waiver on every plan, CSV on Pro and Business, and a full JSON export of your account from Settings.
  • If we ever discontinued the service, account owners would be notified by email with an export window before shutdown. Our terms do not yet state the length of that window; until they do, treat this as our stated intention rather than a contractual term.

Contracts and policies