1. What TapSign is
TapSign lets a person approve a sign-in, payment, email or other action with a key held in their own phone's secure hardware. The phone signs; TapSign checks the signature. TapSign does not hold that key and cannot approve anything on a person's behalf.
These terms cover the TapSign website, the enterprise portal, the TapSign mobile apps and the TapSign Mail browser extension (together, the "Service"), provided by PG Digital Global. If your organisation has a signed agreement with us, that agreement takes precedence where the two differ.
2. What TapSign protects — and what it does not
It protects: an approval cannot be made without your enrolled phone. The key is created inside the phone's secure hardware, can never be copied out, and each use needs your own fingerprint or face. TapSign's servers never hold it, so neither TapSign, nor anyone who breaks into TapSign, can approve for you or forge your signature.
It protects: a signed email shows whether its subject, body or recipients were changed after you approved it. Changes in the enterprise portal (issuing server keys, removing phones, adding administrators) also need a phone approval. A server that connects to TapSign must sign every request with a key only that server holds, and a captured request cannot be replayed.
It does not protect: a request you approve yourself. If you approve something you did not start, TapSign cannot tell — read the card on your phone before you approve.
It does not protect: the privacy of your email. TapSign signs email; it does not encrypt it, and your mail provider handles your messages as it always does. Recipients without TapSign receive your email normally but cannot check the signature.
It does not protect: a computer that is already controlled by someone else. For email, your phone confirms the number of recipients, not the text, so malware on your computer could change the text before it is signed. Keep your computer clean.
It does not protect: a server key that its owner loses. Whoever controls a server holding a TapSign connector key can use it until the key is revoked in the portal. And a lost phone can only be replaced through the recovery your workspace has set up.
3. Accounts, phones and browsers
A workspace belongs to the organisation that created it. Its administrators decide who may join, which phones are enrolled and which browsers are linked, and they can revoke any of them at any time.
You are responsible for the phones and browsers you enrol: keep the phone locked with your own biometric or passcode, do not approve a request you did not start, and revoke a lost device promptly from the app or the portal.
4. Acceptable use
Use the Service only for accounts, mailboxes and systems you are authorised to protect. Do not use it to impersonate anyone, to send unsolicited or deceptive email, to probe, overload or bypass the Service's security checks, or to reverse engineer it except where the law allows.
We may suspend access that puts other customers or the Service at risk, and will tell the workspace administrator why unless the law or an active investigation prevents it.
5. The TapSign Mail browser extension
The extension runs only in Gmail and Outlook on the web. Its single purpose is to let you approve an email you are sending with your phone, and to show that a signed email you receive is genuine. It needs the TapSign mobile app on an enrolled phone to sign.
A signed email carries a short signature record that recipients can check. The extension never sends the text, subject, attachments or recipient addresses of your email to TapSign — see the privacy policy for exactly what it does send.
6. Your data
Your content remains yours. We process only what the Service needs to check approvals and signatures, as described in the privacy policy, and we do not sell it or use it for advertising.
Deployments hosted on your own servers (on-premises) keep their data on those servers; TapSign's cloud relays only a content-free notification to wake the phone, unless you switch relaying off.
7. Availability and changes
We work to keep the Service available and secure, but it is provided on an "as is" and "as available" basis unless your agreement sets a service level. We may change or improve features; if a change removes something you rely on, we will give workspace administrators reasonable notice.
8. Plans and fees
Paid plans are billed as shown at checkout or in your order, and refunds follow the terms shown there. Enterprise, dedicated and on-premises deployments follow the commercial terms agreed for them.
9. Liability
To the extent the law allows, PG Digital Global is not liable for indirect or consequential loss, and our total liability for any claim is limited to the fees you paid for the Service in the twelve months before the claim. Nothing in these terms limits liability that cannot be limited by law.
10. Ending the Service
You can stop using the Service at any time: uninstall the app or extension and revoke your devices. A workspace administrator can close the workspace. We may end access for serious or repeated breach of these terms.
11. Changes to these terms
We may update these terms. The date below shows the current version; material changes are announced to workspace administrators before they take effect. Questions go to the contact form on this site.