What CARMAgree™ collects, where it goes, and how long it is kept.
DealDoctor® PLLC (“DealDoctor”, “we”, “us”) operates CARMAgree™, an electronic-signature service delivered through the web application at carmagree.com and through the CARMAgree™ applications for iOS and Android. This policy describes how information is collected, used, disclosed and protected in connection with those services (the “Services”).
DealDoctor® PLLC also publishes CARMAI™, a separate software platform with a separate privacy policy. This policy addresses CARMAgree™. CARMAgree™ accounts are created and managed separately from CARMAI™ subscriptions, under this policy and the CARMAgree™ EULA, and no CARMAgree™ data is used by or made available to another DealDoctor® product.
By using the Services you consent to the practices described here. If you do not agree with this policy, please do not use the Services.
Before an envelope is sent, CARMAgree™ can run an integrity screen over the document with CARMAscan™. The screen reports what it found; it does not rewrite the document. The sender decides whether to acknowledge a finding on the record or to pull the document back and revise it.
Where the work happens. Three stages of the screen read the file on DealDoctor®-operated servers and send nothing outward:
Where information leaves. The counterparty-screening stages of the screen send party names to public-record sources operated by third parties. Section 5 sets out what is sent, to whom, and what is done with the answer.
What the screen is not. The stages CARMAgree™ runs are rule-based and deterministic. In the Services as they are built today, CARMAgree™ does not route your document text to an AI provider, and the analysis surfaces of DealDoctor®’s other products are not reachable from a CARMAgree™ account. The screening report itself states the limit of what it can tell you: it reports counts and verdicts, and party screening is not a substitute for confirming the counterparty is a registered legal entity in good standing.
The screen report is the sender’s own record. As the report states on its own face, it is not part of the signed document, it is not attached to the certificate of execution, and it is not shown or sent to any signer.
When an account is created at carmagree.com we collect the account holder’s name, email address, organisation name and role designation, together with the account, organisation and user identifiers the Services assign. The sender name and reply-to address you set in Settings are stored on the account as well. Accounts are created on the web; the mobile applications sign in to an account that already exists.
We collect error reports, performance metrics and session data so that the Services can be operated and kept working. The CARMAgree™ mobile applications carry no third-party analytics SDK, no advertising SDK and no advertising identifier, and they do not present an App Tracking Transparency prompt. Envelope events are collected as well, but they are collected as part of the evidence record described in 3.5 rather than as analytics. We also record the IP address from which you accept the terms, request or confirm account deletion, and make requests to the Services.
We collect and store the document a sender uploads to send for signature, the sealed executed copy produced when signing completes, the typed signature a signer applies (recorded as /s/ followed by the name), and any note a sender writes when acknowledging a screening finding or recording a reason for proceeding.
A sender may also compose a standing covering note — one held in the account’s settings, and one held against each template. That note is stored on the account. In the Services as they are built today it is shown to the sender in the send flow as a preview of what a template or the account default carries, and it is not placed in the message a signer receives. If that changes, this paragraph and the app-store disclosures in 3.10 change with it.
We collect the names and email addresses of the people a sender addresses an envelope to, together with any title and company the sender supplies, and the entries a sender keeps in the in-app Contacts list. Those entries are typed by the sender. Where the sender requires one, we also hold a per-recipient access code, stored in hashed form and never emailed. The CARMAgree™ applications do not read the device address book: the iOS application declares no contacts usage description and imports no contacts framework, and the Android application has no such permission.
Each envelope carries an evidence record, and the certificate of execution reproduces it. For each signatory the record can include:
The certificate also carries a SHA-256 hash of the executed PDF. As the certificate states, that hash proves the integrity of the signed document content: a later modification would change the hash and be detectable. The hash is computed on every executed document.
In addition, and where it can be applied, the executed PDF is sealed with a platform certificate using the PAdES mechanism, and a timestamp is obtained from an RFC 3161 timestamp authority (see section 5.2). Both are best-effort: if the seal cannot be applied the document is stored unsealed, and if the timestamp authority cannot be reached the seal is applied without a timestamp. The platform certificate is a self-signed certificate held by us for this purpose; it identifies the seal as ours and is not issued by a public certificate authority. The SHA-256 hash on the certificate of execution is the integrity record that does not depend on either.
The findings of the integrity screen, the acknowledgment a sender records against them and the sender’s note are stored with the envelope in the sender’s audit trail. They are not placed on the certificate of execution and are not disclosed to signers.
Signing in sets one session cookie. It is named carmai_sid, it carries the HttpOnly, Secure and SameSite=None attributes, and it expires 24 hours after it is set. The name is a legacy string from the shared platform layer that both DealDoctor® products are built on; it identifies a session and nothing more, and it carries no information about you.
The mobile applications authenticate with a bearer token rather than a cookie. The Android application discards the session cookie that the sign-in response carries. On iOS, Apple’s networking layer stores that cookie for its 24-hour life and returns it to carmagree.com with requests, as it does for any application that uses the system default session. The cookie carries the same session token; the copy the application itself uses is held in the Keychain as described in 3.8.
We do not set advertising cookies, tracking cookies or third-party cookies. Transactional email sent by the Services carries no open-tracking pixel and no click-tracking redirect.
The CARMAgree™ applications for iOS and Android are native applications that talk to carmagree.com over HTTPS; they do not embed a web browser. The properties below are read from the applications’ own source and build configuration:
The Services do not request precise or coarse location, and no geolocation lookup is performed on the IP addresses recorded in the evidence record. We do not collect health or fitness data, audio recordings, calendar data, browsing history or search history. A typed signature is stored as user content, not as a photograph. On the web, payment card details are entered on a payment page operated by our payment processor and do not reach the Services. In the mobile applications, envelope credits and seats are bought through the App Store or Google Play: the store takes the payment, and the application sends us the store’s purchase record so that the purchase can be credited to your account. Card details are not collected by the Services or by the mobile applications.
| What it is | Apple App Privacy | Play Data safety | Shared |
|---|---|---|---|
| Party names read from the document for screening | Contact Info → Name | Personal info → Name | Yes — to the public-record sources in 5.1 |
| Account holder’s name; each signer’s name | Contact Info → Name | Personal info → Name | No |
| Sign-in address; each signer’s address | Contact Info → Email Address | Personal info → Email address | No |
| Counterparty details entered in Contacts | Contact Info → Other User Contact Info; Contacts | Contacts (optional) | No |
| Account, organisation, envelope and signer identifiers | Identifiers → User ID | Personal info → User IDs | No |
| Optional per-recipient access code set by the sender | Other Data → Other Data Types | Personal info → Other info (optional) | No |
| The uploaded agreement and the sealed executed copy | User Content → Other User Content | Files and docs | No — the email provider in section 6 is a service provider |
| Typed signatures; sender’s notes | User Content → Other User Content | App activity → Other user-generated content | No |
| Envelope events written into the evidence record | Usage Data → Product Interaction | App activity → App interactions | No |
| IP address and user agent in the evidence record | Other Data → Other Data Types | Not a Play data type on its own; disclosed in 3.5 above | No |
| Data used to track you across apps or websites | None | None | — |
| Advertising identifier | Not collected | Not used | — |
| Device identifier, including a push token | Not collected | Not collected | — |
| Location | Not collected | Not collected | — |
| Messages to a signer | Not collected | Not collected | — |
| Payment card details | Not collected | Not collected | — |
| In-app purchase record (the store’s transaction or purchase token), sent to us to credit the purchase — see 3.9 | Purchases → Purchase History | Financial info → Purchase history | No |
| Crash logs and diagnostics | Not collected | Not collected | — |
We use the information described above to:
We do not use it to:
This section describes the points at which information leaves DealDoctor®-operated systems in the course of using CARMAgree™, other than the service providers listed in section 6.
Where party screening is configured on the server, the integrity screen reads the party names from the document (or uses the names the sender supplies) and sends each name to public-record sources operated by third parties, of the following kinds:
| Source | What it is | What is sent |
|---|---|---|
| A United States government sanctions list | Sanctions screening | The party name |
| A United States government federal-exclusions list | Federal exclusions screening | The party name |
| A public archive of United States federal court records | Litigation search | The party name |
| A United States government securities-filings registry | Entity identity lookup | The party name |
What is transmitted is the name string. The document itself is not sent to these sources. The answers returned are recorded in the sender’s screening report and audit trail, and are summarised as counts and verdicts rather than as a docket list.
Where a party is identified as an individual rather than an organisation, the court-records and securities-registry lookups are not run and no request for that party is submitted to them — the request is not made at all, rather than made and discarded — because a docket search against an individual’s name matches any person who shares it, and a securities registry registers entities rather than people. The sanctions and exclusions lookups are run for individuals, because those lists name people.
That identification is made from the party name, taking into account the designation the sender applies to each party in the send flow. Where it cannot be made confidently the party is treated as an organisation, so a misidentification results in a lookup being run rather than skipped.
A screening result is held in memory for six hours so that repeating a screen on the same name within that window does not repeat the outbound request. A lookup that fails, times out or is rate limited is not cached, and it is never reported as a clear result.
When an executed PDF is sealed, a cryptographic hash of that PDF is sent to a third-party RFC 3161 timestamp authority so that the seal carries a trusted time. The timestamp authority we use is DigiCert. A hash is sent; the document is not, and a hash cannot be turned back into the document it was computed from. No name, address or other detail from the envelope is sent with it. If the timestamp authority cannot be reached, the seal is applied without a timestamp.
A document can point outward — at a URL, or at terms said to be incorporated by reference. The integrity screen CARMAgree™ runs before an envelope is sent does not follow those pointers. Where a link or an external data connection is present in the file it is read out of the file itself, on our own servers, and reported to the sender as a finding. No request is made to the linked server, and nothing about your document is disclosed to it.
This matters because the servers a document points at are chosen by whoever drafted it, not by you and not by us. Should a future release retrieve linked material on the envelope path, this section will say so before that release ships.
We may disclose information where we are required to do so by law, or where disclosure is necessary to respond to a security incident, to protect the rights or safety of a person, or to enforce our agreements.
We engage a small number of service providers to operate the Services. Each processes information on our instructions for the purpose shown.
| Provider | Purpose | What it receives |
|---|---|---|
| Amazon Web Services | Hosting and storage | The data described in section 3, held on infrastructure in the United States (Northern Virginia region) |
| Postmark AC PM LLC | Transactional email delivery | Account email (the email-verification, password-reset and account-deletion links, carrying the account holder’s address) and envelope email (the signing invitation, the reminders, the partial-signature notices and the execution notice, carrying the recipient’s name and email address, the sender’s name, the document name and the signing link, and, on the execution notice, the sealed executed PDF as an attachment) |
| Stripe | Payment processing for seats and envelope purchases on the web | The billing details entered on the payment page. Payment pages are not rendered inside the mobile applications |
| DigiCert | RFC 3161 timestamping of the platform seal | A cryptographic hash of the executed PDF, and nothing else |
The public-record sources in section 5.1 are independent third parties rather than service providers acting on our instructions, and their handling of a query is governed by their own terms.
The Data Processing Addendum for CARMAgree™ is published at carmagree.com/dpa, and the table above is the sub-processor list it carries. Where we engage a new sub-processor, notice is given by updating that page.
The Services run on commercial cloud infrastructure located in the United States. Traffic is encrypted in transit over HTTPS with HTTP Strict Transport Security. Data is encrypted at rest. The hosting provider takes a daily automatic snapshot of the server for disaster recovery and keeps the seven most recent, so data deleted from the Services can remain in a snapshot until that snapshot is deleted in the ordinary course — currently seven days for the daily snapshots. Envelope data is held in a database provisioned for your organisation alone, separate from the database of every other customer; one customer’s envelopes are not exposed to another.
Access within an organisation is governed by the roles its administrator assigns, and administrative actions are written to an audit log. Unless required by law, DealDoctor® does not access your account or your data without your prior written consent, and does so solely as necessary to provide, maintain, support and secure the Services, as the EULA provides.
While your subscription is active, your workspace holds your envelopes, your executed documents, their certificates of execution, the audit trail and the SHA-256 hash of each signed document.
If you cancel, or your subscription is terminated, your access runs to the end of the current billing cycle and then for a further sixty (60) days. That window is for export — you can download everything in it. Once it closes, CARMAgree™ deletes the envelopes and executed documents held for your workspace.
Signatories do not depend on that window. Every signer is emailed the fully executed document, with the certificate of execution appended to it, at the moment execution completes — so each party holds its own copy whether or not anyone keeps an account with us.
If you use CARMAgree™ with envelope credits and hold no subscription, your executed documents and their certificates of execution stay available for sixty (60) days from your most recent execution. Sending or buying another envelope restarts that period; if it lapses, the account is made dormant and its data may be deleted (EULA Section 6.a(iii)(C)). Before a dormant account’s data is deleted we email its administrators fourteen days ahead and again seven days ahead; restoring the account — write to support@carmagree.com before the date in that notice — takes it out of the deletion queue. Envelope credits themselves expire twelve (12) months after purchase — a separate clock.
A completed envelope can be downloaded as a single PDF in which the executed document, the signatures and the certificate of execution travel together. On a mobile device the same file can be saved or passed on through the system share sheet. The screening report exports separately, as the sender’s own record.
Export in CARMAgree™ works one envelope at a time and one report at a time, as described above. The Services do not offer a single organisation-wide export of all of an organisation’s data, and this policy does not promise one. Where you need records beyond what the envelope and report exports produce, write to privacy@dealdoctor.pro.
You can delete your account from inside CARMAgree™: sign in, open Settings, choose Delete my account, and confirm through the one-time link emailed to your account address. That link is valid for twenty-four hours. If you cannot sign in, write from your account email address to support@carmagree.com or to privacy@dealdoctor.pro.
Deleting the account closes your sign-in and overwrites your name and email address in the account record. Deleting your sign-in does not change an envelope. If you were the last active user of your workspace, the workspace closes with you, its organisation name is overwritten as well, and its outstanding signing links can no longer be opened or signed; if other people share the workspace, it stays open for them and every envelope in it — including yours still out for signature — continues exactly as before. This request does not itself delete executed documents or their evidence records: the executed document, its certificate of execution, the audit trail and the SHA-256 hash remain, together with the signer details that make the record provable, and stay subject to the retention terms for CARMAgree™ data in the EULA (Section 6.a(iii)), because the other parties to the envelope rely on them. If the workspace closed with you, everything in it — those records and the envelopes that were never executed — is kept for at least sixty (60) days after closure and is then deleted; that period is retention, not access, because you cannot sign in once the account is closed. Where a subscription, or envelopes you have paid for and not used, are still attached to the account, we keep the workspace rather than deleting it — write to us if you want it closed. If the workspace stays open for other people, all of it stays with the workspace. Each signer already holds the executed copy that was emailed to them at completion. Download anything you want to keep before you confirm, because you will not be able to sign in afterwards. The full table is at carmagree.com/support.
Billing records and email delivery logs sit with our payment and email providers under their own retention terms, and are not removed by this request.
Your sender name, reply-to address, default message and password can be changed in Settings. To correct the account email address or the organisation name, or for anything else, write to privacy@dealdoctor.pro.
You can opt out of non-essential communications. Transactional messages about an envelope you are a party to are not marketing and are part of the Services.
A signer receives a secure link and signs; there is nothing to install and no account to register. We hold what section 3.5 describes: the signer’s name and email address, any title and company the sender supplied, the typed signature the signer applied, the record of consent, and the timestamps, IP addresses and user-agent string that make the signature provable.
A person named as a counterparty in a document that was screened may also have had their name sent to the sources in section 5.1.
In each case the sender chose to send the document and determines what the record is used for. If you are a signer or a named counterparty and you want to know what is held about you, or you want it corrected, the sender is the right first contact. You may also write to privacy@dealdoctor.pro and we will route your request.
The Services are a business tool and are not directed to individuals under the age of 18. We do not knowingly collect personal information from children.
Our servers are located in the United States. If you use the Services from outside the United States, your information may be transferred to, stored in and processed in the United States. Email delivery and the screening lookups described in section 5.1 also involve providers and public-record sources in the United States.
We may update this policy. When we do, we will post the updated version here and revise the “Last updated” date, and we may also give notice in the application or by email. Continued use of the Services after an update takes effect constitutes acceptance of it.
| Subject | Contact |
|---|---|
| Privacy | privacy@dealdoctor.pro |
| Legal | legal@dealdoctor.pro |
| Support | support@carmagree.com · carmagree.com/support |