Version 1.0 · Draft · Owner: Legal
Download .md →Touch2Sign Ltd
Version: 1.0
Effective date: 11 July 2026
Owner: [Legal / DPO]
Approved by: Robert — CEO / Managing Director
Next review: 11 July 2027
Describe how Touch2Sign Ltd uses cookies and similar technologies on the Touch2Sign website and application. Supports ePrivacy Directive requirements and GDPR transparency obligations. Complements the public Privacy Policy.
Applies to:
/sign/[token], /mobile-verify/[token]) Does not apply to native mobile apps if launched separately (update policy if applicable).
Cookies are small text files stored on your device when you visit a website. Similar technologies include local storage, session storage, and pixels. This policy uses "cookies" to refer to all such technologies unless stated otherwise.
| Category | Purpose | Consent required? | Strictly necessary / essential | Authentication, security, load balancing, signing session | No — required for service |
|---|---|---|
| Functional | Remember preferences (language, cookie choice) | No if essential to preference; otherwise yes |
| Analytics | Usage statistics, performance monitoring | Yes — opt-in |
| Marketing | Advertising, retargeting | Yes — opt-in (not used by default) |
Touch2Sign does not use marketing cookies by default.
| Cookie / storage | Provider | Purpose | Duration | Cognito session tokens | Amazon Cognito | User authentication | Session / configured expiry |
|---|---|---|---|
| Signing session state | Touch2Sign | Part 11 PIN session, signing flow | Up to 30 minutes |
| CSRF / security tokens | Touch2Sign | Request forgery protection | Session |
| Load balancer affinity | AWS | Route requests to healthy instance | Session |
cookie_consent |
Touch2Sign | Stores consent choice | 12 months |
These cookies are necessary to provide the eSignature and eWitness service. The service cannot function without them.
| Cookie | Provider | Purpose | Duration | Status | [e.g. _ga] | [Google Analytics / Plausible / etc.] | Page views, funnels | [duration] | Only if user consents |
|---|
Analytics cookies are loaded only after explicit consent via the cookie banner. Review and update this table when analytics tools are enabled.
Signing flows may redirect to identity providers:
| Provider | Purpose | Policy link | OneID | UK bank IDV | OneID privacy policy |
|---|---|---|
| eID Easy | QES / EU IDV | eID Easy privacy policy |
These are controlled by the identity provider during verification — not Touch2Sign first-party cookies.
Touch2Sign implements consent via the CookieConsent React component (components/ui/CookieConsent.tsx):
cookie_consent local storage / cookie Consent records:
Stored client-side; aggregate consent metrics reviewed quarterly for compliance audit.
| Method | Action | Cookie banner | Accept or reject non-essential cookies on first visit |
|---|---|
| Footer link | "Cookie settings" — reopen preferences |
| Browser settings | Block or delete cookies (may break signing/login) |
Blocking essential cookies will prevent login and document signing.
Touch2Sign does not respond to DNT browser signals. Consent is managed via the CookieConsent component per ePrivacy requirements.
When new non-essential cookies are added:
Questions about cookies: privacy@touch2sign.com
Reviewed annually and whenever cookie inventory or analytics tooling changes.
Approval
| Name | Role | Signature | Date | Robert | CEO | Electronic | 11 July 2026 |
|---|---|---|---|
| Legal / DPO |
Questions: security@touch2sign.com · privacy@touch2sign.com