Legal
Cookie Notice
Applies to cecursign.io, formerly sign.cecur.io, which permanently redirects here.
Version 1.1Last updated 21 August 2026
This notice is grounded in what the site actually sets. CecurSign uses no analytics, advertising or tracking cookies of any kind. Every cookie below is strictly necessary to sign in and stay signed in.
Contents
Cookies we set
| Cookie | Set by | Purpose | Duration |
|---|---|---|---|
cecur_session | CecurSign API | Keeps you signed in to your account. HttpOnly | Session-based; expires when the session expires |
__session | CecurSign web app (Auth0 SDK) | Encrypted login session for Auth0-based sign-in. HttpOnly | Session-based |
__txn_* | CecurSign web app (Auth0 SDK) | Short-lived transaction state while a login is in progress; removed when login completes | Minutes |
Third party cookies during sign-in
When you sign in, you are briefly redirected to our identity provider, Auth0 (Okta, Inc.), which sets its own cookies on its own domain to operate the login (for example to remember an active login session and to protect against cross-site request forgery). Those cookies are set on the Auth0 domain, not on cecursign.io, and are covered by Auth0's own notices.
Browser storage that is not a cookie
The application stores some preferences in your browser's local storage (for example in-app notification preferences and interface state). This data stays in your browser, is not a cookie, and is not sent to us with every request. The ePrivacy rules on storing and accessing information on your device apply to local storage in the same way as to cookies; we use it only for interface state you have chosen, which is strictly necessary to provide the interface you asked for.
Public signing pages
Recipients signing a document do not need an account. Signing links carry their access token in the link itself, not in a cookie, so visiting a signing page does not set authentication cookies unless you also log in to an account.
No consent banner
Because every cookie and item of browser storage in use is strictly necessary for a service you have requested (signing in, or holding interface state you chose), no cookie consent banner is shown. This is the strictly-necessary exemption in Regulation 5(5) of the Irish ePrivacy Regulations 2011 (S.I. No. 336 of 2011) and regulation 6(4) of the UK PECR.
Changes
If we add cookies or third party scripts, this notice will be updated first, and a consent mechanism will be added if any non-essential cookie is introduced.
The rest of our legal documents
- Privacy NoticeWhat CecurSign records about account holders, signers and visitors, why, who it is shared with, and how to exercise your rights.
- Terms of ServiceThe terms that govern business use of CecurSign, including what the signatures are, what we warrant, and what we do not.
- Data Processing AgreementThe Article 28 processing terms between Cecur Limited and customers of CecurSign, with the sub-processor list and the security measures actually in place.
- Sub-processor ListThe maintained list of third parties that process personal data on behalf of CecurSign customers, and how we notify changes to it.