Legal Pact
CatalogDocumentsFAQ
Sign in
CatalogDocumentsFAQSign in

Legal

Privacy policy

Your documents contain your life — leases, jobs, family matters. This policy explains exactly what we collect, why, and the control you keep. No ad trackers, no selling data. Ever.

Effective date: July 25, 2026

On this page

1Who we are and what this policy covers2What we collect3Why we use it (and the legal bases)4Cookies5Who we share data with6International transfers7How long we keep data8Your rights9Data about other people in your documents10How we protect your data11Children12Changes to this policy13Contact
On this page
1. Who we are and what this policy covers2. What we collect3. Why we use it (and the legal bases)4. Cookies5. Who we share data with6. International transfers7. How long we keep data8. Your rights9. Data about other people in your documents10. How we protect your data11. Children12. Changes to this policy13. Contact

1. Who we are and what this policy covers

This policy describes how Legal Pact, Inc. (“Legal Pact”, “we”) handles personal data when you use legal-pact.com and our document builder (the “Service”). For data protection law — including the EU General Data Protection Regulation (GDPR) — Legal Pact is the data controller of the data described here.

Contact for anything privacy-related: support@legal-pact.com.

The short version: we collect only what the Service needs to work — your email, your answers, your purchases. We use no advertising trackers and no third-party analytics, we never sell personal data, and you can have everything deleted whenever you like.

2. What we collect

Account data. Your email address, and your name and profile picture if you sign in with Google. Sign-in is passwordless, so we never hold a password for you.

Document answers. What you enter into a questionnaire and the documents generated from it. Answers can include personal data — names, addresses, dates, financial figures — about you and about other people you choose to include (for example, the other party to a contract).

Purchase data. Which documents you bought, when, for how much, and the receipt we email you. We never see or store your card number — payment details go directly to our payment processors; we receive only a confirmation of payment and a payment reference.

Support conversations. Messages you send us by email or through the live chat, so we can help you and keep context.

Technical data. Standard server logs (IP address, browser type, pages requested, timestamps) used for security and to keep the Service running.

3. Why we use it (and the legal bases)

GDPR requires a legal basis for each use of personal data. Ours are:

  • To provide the Service — generating your documents, live preview, saving them to your account, sign-in links, receipts, customer support. Basis: performance of our contract with you.
  • To process payments and keep required records — transactions, invoices, tax and accounting. Basis: contract and legal obligation.
  • To keep the Service secure — server logs, abuse and fraud prevention, protecting sign-in (magic-link tokens expire after 15 minutes). Basis: legitimate interest in running a safe service.
  • To send product news — only if you opted in. Every email has an unsubscribe link, and marketing preferences are off by default. Basis: consent, withdrawable at any time.

We do not use your data for advertising, we do not profile you, and we make no automated decisions with legal or similarly significant effects.

You are never obliged to give us data — but some of it is what the Service runs on: without an email address we cannot sign you in or deliver files, and without your answers there is nothing to build a document from.

4. Cookies

We use only cookies the Service cannot work without — which is why you do not see a cookie-consent banner:

  • Session cookie — keeps you signed in.
  • Security (CSRF) cookie — protects forms against cross-site request forgery.
  • Country cookie — remembers which country edition of the site you chose.
  • Live-chat cookies — set by the chat widget so a conversation survives a page reload; they appear only if you open the chat.

There are no advertising, tracking or third-party analytics cookies.

5. Who we share data with

We never sell personal data and never share it for advertising. Data leaves our systems only to the service providers (processors) we need to run Legal Pact, each bound by a data-processing agreement:

  • Hosting and infrastructure — running the Service and storing your account and documents.
  • Email delivery (Resend) — sending sign-in links, receipts and (if opted in) product news to your address.
  • Payment processors — handling card and express-checkout payments (they process your payment data as independent controllers under their own policies).
  • Sign-in with Google (Google LLC) — only if you choose it; Google tells us your email, name and profile picture, nothing more.
  • Live chat (Chatwoot) — powering the support chat if you use it.

Beyond processors, we disclose data only if the law genuinely requires it (for example, a binding court order), or as part of a merger or acquisition — in which case this policy continues to apply to your data and we will notify you.

6. International transfers

Legal Pact serves users in the United States, the European Union and other countries, so data may be processed outside the country you live in — including in the United States.

Where data of EU/EEA, UK or Swiss users is transferred to a country without an adequacy decision, we rely on recognised safeguards — the European Commission’s Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework certifications of our providers.

7. How long we keep data

  • Account and documents — for as long as your account exists. Your saved documents stay re-downloadable indefinitely; that is a feature, not an accident.
  • Unfinished drafts — kept so you can resume where you left off; deleted with your account.
  • Purchase records — kept as long as tax and accounting law requires (typically up to 10 years), even after account deletion.
  • Support conversations — kept while relevant to helping you, then deleted.
  • Server logs — short-lived and rotated automatically.

When you delete your account (or ask us to), we erase your data except the minimum that mandatory law requires us to keep, and anything kept is locked to that purpose only.

8. Your rights

You control your data. Wherever you live, you can ask us at any time to:

  • access the data we hold about you and get a copy in a portable format;
  • correct anything inaccurate;
  • delete your account and data (“right to be forgotten”);
  • restrict or object to processing based on legitimate interests;
  • withdraw consent — for example, unsubscribe from product news — without affecting anything else.

Write to support@legal-pact.com from the email address on your account and we will action it — no forms, no fee, normally within a few days and always within the legal deadline. If you are in the EU/EEA or UK, you also have the right to lodge a complaint with your local data-protection authority.

California residents (CCPA/CPRA): you have the rights to know, correct and delete as described above, and the right not to be discriminated against for using them. We do not sell or “share” personal information as defined by the CCPA, so there is nothing for an opt-out (or the Global Privacy Control signal) to switch off. You can exercise any right by email or through the live chat on our site.

9. Data about other people in your documents

Documents often mention people other than you — a tenant, an employee, a business partner. For that data, you decide what goes into the document, and we process it only as your service provider: to assemble, preview, export and store the document for you. We never use it for anything else and never contact those people.

Please only include other people’s data that you are entitled to use for your document.

10. How we protect your data

  • All traffic is encrypted in transit (TLS), and data is encrypted at rest.
  • Passwordless sign-in: there is no password to steal or reuse. Sign-in links are single-use and expire after 15 minutes.
  • Card details never touch our servers — they go straight to PCI-DSS-certified payment processors.
  • Access to production data is restricted to the few people who operate the Service and is logged.

No system is perfectly secure, but if a breach ever affects your data we will notify you and the competent authority as the law requires.

11. Children

The Service is for adults entering into legal documents and is not directed at children under 16. We do not knowingly collect their data; if you believe a child has used the Service, contact us and we will delete the data.

12. Changes to this policy

If we change this policy in a way that matters — new data, new purpose, new recipient — we will notify you (by email or a notice in the Service) before the change takes effect. The “Effective date” above always shows the current version. We never weaken your rights retroactively.

13. Contact

Privacy questions, requests, complaints: support@legal-pact.com — Legal Pact, Inc. We answer every message, usually within one business day.

Questions about this policy?

We answer every message — usually within one business day. Write to support@legal-pact.com.

RelatedTerms of serviceRelatedRefund policy
Legal Pact

Attorney-reviewed legal documents, ready in minutes. Free for everyone while we are in beta — no card, no subscription, ever.

Documents

  • All templates

Company

  • How it works
  • FAQ
  • Contact

Legal

  • Terms of service
  • Privacy policy
  • Refund policy
© 2026 Legal Pact, Inc. All rights reserved.
United StatesLuxembourgFranceDeutschlandРоссияУкраїна
Legal Pact is not a law firm and does not provide legal advice. Our templates are for informational purposes only.