This policy describes how Waiver.com LLC, at 363 North Sam Houston Pkwy E, Suite 125, Houston, TX 77060, handles personal information across waiver.com, app.waiver.com, the signing pages we host for our customers, and our API. It works alongside the Terms of Service; where a customer has a signed business associate agreement with us, that agreement governs protected health information.
1. Who we are, and the two roles we play
Waiver.com LLC runs Waiver.com, a digital waiver and consent platform used by gyms, guides, studios, clinics, event organizers, and other activity businesses. Our address is 363 North Sam Houston Pkwy E, Suite 125, Houston, TX 77060.
We handle personal information in two very different capacities, and almost every question about this policy turns on which one applies:
- For our customers, we are the controller. When you open an account, pay us, email us, or read this website, we decide what we collect and why. Sections 2, 4, and 5 describe that.
- For our customers’ signers, we are the processor. When one of your participants fills in your waiver, you decided what to ask and why. We hold and process that information on your instructions, as your service provider. Under HIPAA the same split makes you the covered entity (or a business associate) and us your business associate. Section 3 describes that.
If you signed a waiver at a business and want your information corrected or removed, contact that business — they hold the relationship and the record. If you cannot reach them, write to us and we will help you find the right contact.
2. The information we collect about our customers
When you run a Waiver.com account, we hold:
- Account and profile information — your name, work email address, phone number, password (stored only as a salted hash), two-factor settings, role, and the organization and locations you belong to.
- Organization information — your business name, addresses, logo, branding, waiver templates, event and session settings, and staff list.
- Billing information — your plan today, and, once billing launches, your billing contact and address, your invoices, and the last four digits and brand of your card. Full card numbers go directly to our payment processor and never reach our servers.
- Support and correspondence — the emails you send us and our replies, so the next person who helps you knows what happened last time.
3. Signer information we process for our customers
When someone signs a document through Waiver.com, the fields on that document were chosen by the business that asked them to sign. Depending on that business, a record can include a name, date of birth, address, email, phone number, emergency contact, the names and ages of minors covered by the signature, answers to health or eligibility questions, the signature image itself, and the identifiers we capture to make the record hold up later: the timestamp, the IP address, the device and browser, and the exact version of the document that was displayed.
We use that information only to provide the service to the business that collected it: to render and store the record, to deliver a copy, to send the reminders that business has configured, to power its dashboard and check-in, and to support and secure the platform. We do not use it for our own purposes, we do not sell it, we do not advertise with it, and we do not use one customer’s signer data to train models for anyone else.
Answers to sensitive questions — health conditions, medications, allergies, and anything else a customer marks as sensitive — are encrypted at the field level in addition to the encryption that covers the whole database.
Signed records are immutable. Each one is written once into a hash-chained log, so a record cannot be quietly edited after the fact — not by the business, not by a signer, and not by us. A correction is made by signing a fresh record; the original is kept exactly as it was, and can be voided with a reason but never altered.
4. Information collected automatically, and cookies
Like any web service, our servers record technical details of the requests they receive: IP address, browser and operating system, the pages or API endpoints requested, timestamps, and referring page. We use these to keep the service running, to diagnose faults, to enforce rate limits, and to detect abuse. We also keep an access log of the reads and writes staff members make inside a dashboard, which is a security feature as much as a privacy one.
Cookies and browser storage. The dashboard sets a session cookiethat keeps you signed in and protects forms against cross-site request forgery; without it the product cannot work. Small preferences — the location you last worked in, whether a panel is open, an unfinished signing draft — are kept in your browser’s own storage rather than sent to us.
Analytics, on the marketing site only. Our public website at waiver.com uses Google Analytics to measure visits — which pages people read, where they arrived from, and whether something is broken. It sets its own cookies to do that, and Google processes that data for us as a sub-processor. The app and the signing pages carry no analytics at all: no Google Analytics, no third-party trackers, and no advertising cookies. A signing page is somebody’s medical history on a tablet, and nothing third-party belongs on it.
How to opt out of the analytics.Block or clear cookies for waiver.com in your browser settings, or install Google’s own opt-out browser add-on from tools.google.com/dlpage/gaoptout — either one stops the measurement without affecting anything else on the site.
We set no advertising cookies, we do not enable Google’s advertising features, and we build no cross-site profiles, so there is nothing to track you with across other companies’ sites.
5. How we use information
We use the information described above to:
- provide, operate, and maintain the service, and store the records our customers create;
- authenticate users, prevent fraud and abuse, and investigate security incidents;
- send transactional messages — signing invitations, reminders, receipts, password resets, and service notices;
- bill for subscriptions and text message usage;
- answer support requests;
- understand which features are used, in aggregate, so we know what to build and what to fix;
- comply with law, respond to lawful requests, and enforce our terms.
We send our own customers occasional product and account emails. You can opt out of the non-essential ones at any time; we will still send the ones you need to run your account, like a failed payment or a security notice.
7. Sub-processors
A sub-processor is a vendor that processes data on our behalf so that we can run the service for you. Each is bound by a written agreement and may use the data only to do the job we hired it for. Only our hosting provider can hold protected health information, and no vendor receives any until it has signed a business associate agreement with us.
- DigitalOcean — Hosting: droplets, our PostgreSQL and Redis, and encrypted file storage. United States (San Francisco region). Active.
- Cloudflare — DNS for our domains. United States. Active.
- Resend — Transactional email — invitations, receipts, and account notices. United States. Active.
- Stripe — Subscription billing and payments. United States. Not yet active.
- An SMS provider — SMS delivery for signing links and reminders. United States. Not yet active.
- Google Analytics — Visitor measurement on the waiver.com marketing site. United States. Active — marketing site only, never the app or signing pages.
The sub-processor page carries the current list with more detail, including what each vendor receives. We give account owners at least 30days’ notice by email before a new sub-processor starts handling customer data.
8. How long we keep information
Signed records are kept for 7 years by default, measured from the date of signing. That default exists because a waiver is worth having exactly when someone questions it years later, and because the limitation periods that matter to our customers commonly run that long. The period is adjustable on request.
You can ask us to delete a specific record, a signer, or an entire account at any time by writing to help@waiver.com. We complete a deletion request within 30 days, unless you or we are legally obliged to keep the data — because it is the subject of a claim, a legal hold, or a regulatory duty of yours.
Account and billing records are kept while the account is open and then for as long as tax and accounting law requires. Support email is kept while it is useful and then deleted.
9. How we protect information
Everything is encrypted in transit with TLS and at rest on encrypted volumes, with field-level encryption over sensitive answers on top of that. Access is role-based and least-privilege. Two-factor authentication is available to your staff and we recommend it; our own administrative accounts require it. Every human read of a signer’s record is written to an access log, and records are hash-chained so tampering is detectable.
The security page describes all of this in more depth, including how to report a vulnerability to help@waiver.com. No system is perfectly secure; if a breach affects your data we will tell you promptly, as described there and in the business associate agreement.
10. Your rights and choices
Depending on where you live, you may have the right to know what personal information is held about you, to get a copy of it, to have it corrected, to have it deleted, to receive it in a portable format, and not to be discriminated against for asking. Residents of Texas have these rights under the Texas Data Privacy and Security Act, and residents of California, Colorado, Connecticut, Virginia, and a growing list of other states have comparable rights under their own laws.
If you are one of our customers, email help@waiver.com and we will verify your identity through your account and respond within the time the applicable law allows.
If you signed a waiver at a business that uses us, that business decides what happens to your record. Ask them first. If you contact us, we will pass the request to them and support them in carrying it out; we will not delete or change their record on our own initiative.
You may appeal a refusal by replying to our decision; we will review it and explain the outcome in writing. Texas and several other states also let you complain to your state attorney general.
11. We do not sell personal data
We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are used in United States state privacy laws. We never have. There is no opt-out to offer you, because there is nothing to opt out of.
12. Children
The Waiver.com dashboard is for businesses. It is not directed at children, and no one under 13 should create an account or use it. If we learn that a child under 13 has opened an account, we delete it.
Information about a minor can still reach the platform, because a parent or legal guardian signing a waiver may name the children in their party and answer questions about them. That information is collected by the business running the activity, under its own authority and its own policy, and we process it only as that business’s service provider. Requests about a minor’s record go to that business.
13. Health information and HIPAA
Many waivers ask health questions, and some of our customers are covered entities under HIPAA. When a customer is a covered entity or a business associate and its records contain protected health information, we act as its business associate under a signed business associate agreement, and that agreement — not this policy — governs how we may use and disclose that information.
The agreement is free and available on request from help@waiver.com. Read the terms of it at /baa and what it means in practice at /hipaa.
14. Where your data lives
Waiver.com is operated from the United States, and all account and record data is stored on servers in the United States. Our sub-processors are United States companies operating United States infrastructure.
If you or your signers are outside the United States, using the service means information is transferred to and processed in the United States, where privacy law differs from the law where you live. We do not currently offer data residency in another country. If your obligations require a specific transfer mechanism or a data processing addendum, write to help@waiver.com and we will work through it with you.
15. Changes to this policy
We will update this policy as the product and the law change. The date at the top always reflects the current version. When a change materially affects how we handle personal information, we email account owners at least 30 days before it takes effect. Older versions are available on request.
16. Contact
For any privacy question, request, or complaint — including a request to exercise the rights in section 10 — write to us. A person answers.
Waiver.com LLC363 North Sam Houston Pkwy E, Suite 125
Houston, TX 77060
help@waiver.com