Spize
Sign inSend a file

Privacy Policy

This policy covers senders, recipients, signers, sellers and buyers of Paid Shares, visitors to our site, and users of the desktop app and APIs. It does not cover third-party websites, applications or services that you use alongside Spize (for example the email service that delivers your messages, a sign-in provider you choose, or an AI assistant you connect) — those are governed by their own policies.

1. At a glance

2. What we can never read: your transferred files

Spize’s core is designed so that we do not have access to the contents of the files you transfer:

One deliberate exception: Spize Sign. To assemble, flatten and cryptographically seal signed documents, signature documents are processed on our infrastructure and are therefore not end-to-end encrypted in the way transfers are. They are encrypted in transit and at rest, access-controlled, and processed only to provide the signature service. Section 3(c) describes the associated data.

3. Personal data we process

a. Account and profile data

b. Transfer and share metadata

c. Spize Sign data

d. Billing data

e. Technical logs and diagnostics

f. Analytics (only with your consent)

g. Communications and waitlist

h. What we do not collect

4. Purposes and legal bases

Where we rely on legitimate interests, we have assessed that the processing is limited to what is necessary and does not override your rights, given the minimal data involved and the protective design of the Service; you can object as described in Section 10. We do not carry out automated decision-making that produces legal or similarly significant effects on you. Anti-abuse systems may flag activity automatically, but decisions with significant effect (such as account termination) involve human review.

5. Cookies and similar technologies

We use strictly necessary storage (sign-in session, local encryption keys, your consent choice) and, only with your consent, first-party analytics cookies. No advertising cookies. The full inventory, durations and the way to change your choices at any time are in the Cookie Policy.

6. Who receives personal data

We do not sell personal data and we do not share it with third parties for their own marketing. Data is disclosed only to:

7. International transfers

We are established in Italy, and some of our service providers process data in the United States or other countries outside the European Economic Area. Where personal data leaves the EEA, we rely on the safeguards of GDPR Chapter V: European Commission adequacy decisions (including, for certified U.S. providers, the EU-U.S. Data Privacy Framework) and/or Standard Contractual Clauses with supplementary measures as needed. Note that end-to-end encrypted content is ciphertext wherever it is stored — the keys never leave your side. You can request a copy of the relevant safeguards via info@spize.io.

8. Retention

9. Security

Beyond end-to-end encryption of transferred content, we apply technical and organizational measures appropriate to the risk (Art. 32 GDPR): TLS for all connections, encryption at rest on our storage, hashed passwords and one-time-code authentication, scoped API keys, access controls and least-privilege administration, logging and monitoring, and separation between content ciphertext and account systems. No system is perfectly secure: protect your share links and passwords — anyone with a complete link (including its key fragment) can download and decrypt that Share until it expires. If a personal-data breach occurs that is likely to result in a risk to you, we will notify the competent authority and, where required, you, in accordance with Articles 33–34 GDPR.

10. Your rights (GDPR)

Under the GDPR you have the right to:

To exercise any right, email info@spize.io. We may need to verify your identity (normally by confirming control of the account email). We respond within one month, extendable by two further months for complex requests, as the GDPR allows. Exercising rights is free of charge except in the cases of manifestly unfounded or excessive requests provided by law. Note that we cannot “retrieve” the contents of end-to-end encrypted Shares for an access request — we do not have the keys.

11. U.S. state privacy rights

We are an Italian company and may not meet the applicability thresholds of U.S. state privacy statutes (such as the California Consumer Privacy Act as amended by the CPRA, or the Virginia, Colorado, Connecticut and similar acts). To the extent such a law applies to you, we honor it:

12. Children

The Service is not directed to children. Accounts require you to be at least 18. We do not knowingly collect personal data from children under 16 (or under 13 for U.S. COPPA purposes); if you believe a child has provided us personal data, contact info@spize.io and we will delete it.

13. Data you provide about other people

When you give us someone else’s email address (to notify a share, request files or invite a signature), you are responsible for being entitled to do so. We process that address solely to deliver the requested interaction and related service messages, and this policy is available to those recipients from every message and page involved. Recipients can object to further messages at any time via info@spize.io.

14. Changes to this policy

We may update this policy from time to time. For material changes we will give notice through the Service or by email before they take effect; the “Last updated” date above reflects the latest revision. Earlier versions are available on request.

15. Contact

Privacy questions and rights requests: info@spize.io (BouncyLoop SRL). For the rules governing use of the Service, see the Terms of Service; for cookies, the Cookie Policy.