SealGuard ("we," "us," "our") operates the SealGuard digital seal management platform at instaseal.co and app.instaseal.co. This Privacy Policy describes how we collect, use, and share personal information when you use our Service.
When you register, we collect your name, email address, firm name, and professional license details (license number, state, and discipline). This information is necessary to verify your professional credentials and operate the Service.
For professional verification, we use Stripe Identity to confirm your identity via government-issued ID and selfie matching. We store only the verification result and the verified name returned by Stripe — not your ID images or biometric data. Stripe's handling of your identity data is governed by Stripe's Privacy Policy.
When you seal a document, we record metadata about the seal (professional name, license, verification ID, timestamps, document hash) but we do not store the document itself. The document passes through the Service transiently and is not retained.
When someone scans a sealed document's QR code or visits a verification page, we log the timestamp, IP address, and user agent of the visit. This data is used to provide verification traffic analytics and evidence trails. IP geolocation is resolved offline (no third-party lookup is performed on the viewer's IP).
We collect standard server logs and usage metrics to operate and improve the Service.
By design, verification pages are public. When you seal a document, the following information is visible to anyone who scans the QR code: your professional name, license number and state, discipline, firm name, project name, seal status, and sealed date. This public disclosure is the core function of the Service and is necessary for the verification to work.
We use third-party service providers including Stripe (identity verification and future payment processing), Render (hosting), and Vercel (website hosting). These providers process data only as necessary to provide their services to us.
We may disclose information if required by law, regulation, or legal process.
Seal records, verification events, and status history are retained indefinitely as part of the immutable compliance record — this permanence is a core feature of the Service. Account information is retained as long as your account is active. You may request account deletion by contacting us; note that sealed document records and their public verification pages will persist (they are part of the evidentiary record relied on by third parties).
We use industry-standard security measures including encrypted connections (TLS), hashed passwords (bcrypt), two-factor authentication (TOTP), and access controls. Seal approval requires a fresh TOTP code for every document.
Depending on your jurisdiction, you may have rights regarding your personal data including access, correction, deletion, and data portability. To exercise these rights, contact us at info@instaarch.com. Note that certain data (sealed document records, verification history) cannot be deleted as it forms part of the immutable compliance record.
The Service is not directed to individuals under 18. We do not knowingly collect personal information from children.
We may update this Privacy Policy from time to time. Material changes will be communicated via the email associated with your account. The current version is always available at instaseal.co/privacy.
For privacy-related questions or requests, contact us at:
info@instaarch.com
SealGuard by Insta
Operated by InstaArch, Inc.