State of M&A Data Rooms — Q2 2026 Read the report →
Collect Documents

Collect documents from clients — without the email attachment chase.

Every professional-services engagement starts by collecting documents from clients — and the default tool, email attachments, fails structurally: size caps bounce files, PII sits in inboxes forever, versions fork, nothing is organized, there is no audit trail, and follow-up is manual nagging. Replace it with one standing permissioned upload link per client. Clients upload without creating an account — they are never billed — the documents land organized in a room you control, and that same room then carries the downstream workflow: review, NDA-gated sharing onward, e-signatures, and analytics. Free tier to start; Business $30/admin/month; Data Room $52/admin/month. Trusted by 6,800+ customers.

The uploader's side is account-free: they open your link, verify their email, and drop files straight into your folders — nothing to install, nothing to pay.

What does it mean to collect documents from clients on Peony?

Collecting documents from clients on Peony means sending each client a standing, permissioned upload link into a folder you built in advance, so they upload their files directly into a room you control — with no account, no password, and no charge to them. It is the inbound half of a data room: instead of pushing a file out to a recipient, you set up a doorway that named clients drop files through, and every upload is attributed, organized, and logged as it lands. The direction of trust reverses from sending, and almost every tool people reach for by default — email most of all — was built for the wrong direction.

The reason to do this in a data room rather than a collection-only tool is continuity: on Peony a data room and an upload link are the same object, so the set of files you collect is already the working room. There is a free tier to start. The Business plan ($30/admin/month) adds Simple NDA gating, screenshot protection, AI document Q&A, and unlimited e-signatures; the Data Room plan ($52/admin/month) adds dynamic watermarks, Advanced NDA with countersigning, granular permissions, and auto-indexing. Pricing is flat per admin seat — only admins are billed, and the clients uploading to you are always free and never need an account.

The whole workflow is: create a room per client and pre-build the folders, grant access to the client's email, send one link, watch files arrive organized and attributable, and then run the rest of the engagement in the same place — review the documents, share them onward under watermark and behind an NDA-gated link, and send agreements back for e-signature with no export and no re-upload. Peony serves 6,800+ customers across accounting, legal, M&A advisory, lending, insurance, and fund administration — every one of which starts by collecting documents from a client.

Why do email attachments break document collection?

Because email was built to push attachments outward, and collection needs the opposite — and every weakness shows up at exactly the moment the data is most sensitive. When you ask a client to "just email it over," you inherit six structural failures at once:

  • Size caps bounce files. A large loss-run PDF, a scanned deed, or a folder of statements hits the attachment limit and the send fails — so the client zips it, splits it, or gives up.
  • PII sits in the inbox forever. A passport scan or a bank statement now lives in your mailbox permanently, syncs to every device, and is one careless forward from exposure. You cannot revoke an email.
  • Versions fork. The client sends the wrong 1099, then the right one, then a corrected one — and you are left guessing which of three attachments is current at 11pm.
  • Nothing is organized. Files arrive scattered across threads with names like "scan_final_v2," and you spend real time downloading and refiling before you can even start the work.
  • There is no audit trail. Six months later, when a regulator, examiner, or opposing counsel asks who supplied a document and when, an inbox is not a chain-of-custody record.
  • Follow-up is manual nagging. You have no view of what is outstanding, so chasing the missing K-1 is another email, and another, and another.

A standing permissioned upload link flips the direction: email carries the request link, never the payload, and the client uploads into a space you control. You own the structure, the audit trail, the retention clock, and the ability to shut access off. The full horizontal playbook — across prop firms, accountants, lawyers, lenders, and agencies — is in how to collect documents from clients securely.

How does a client upload portal work on Peony?

A link in, an account-free upload, an organized landing — and a free tier to start. The flow is the same whether you collect once or every quarter:

  1. 1. Stage the folder tree first. Create a room per client relationship — "2025 Tax Packet — Smith Family," "Discovery — Acme v. Beta," "Q3 Reporting — Borrower X" — and pre-build the folders you want files to land in.
  2. 2. Grant access to the client's email. This is the identity gate. The link works for that named submitter, not for "anyone who has it," so an unexpected uploader is immediately visible.
  3. 3. Send one standing link. The client opens it, verifies their email, and uploads directly into your folders — no signup, no password, no app, and no charge to them.
  4. 4. Files land organized. Because a room and an upload link are the same object, documents arrive in structure and attributable — with a per-submitter log of who uploaded what, when, and which version.
  5. 5. Run the rest in the same room. Review as files land, share onward under watermark and behind an NDA gate, and send agreements back for e-signature — no export, no re-upload.
  6. 6. Close it out. Set link expiry so access lapses on a schedule, or revoke instantly when the engagement ends — collected files don't linger past their purpose.

What does it cost — and what do clients pay?

Clients pay nothing, ever, and never create an account — only admin seats on your side are billed, and pricing is flat. File collection uses permissioned upload links, which are part of Peony's core sharing, so you can start on the free tier. Above that, two flat per-admin plans add the controls most collection workflows want:

  • Business — $30/admin/month. Adds Simple NDA gating, screenshot protection, AI document Q&A, and unlimited e-signatures — the plan for organized intake plus a confidentiality gate and a year of analytics retention.
  • Data Room — $52/admin/month. Adds dynamic watermarks, Advanced NDA with countersigning, granular permissions, and auto-indexing — for intake that carries real regulatory or reputational risk and gets shared onward.

The pricing is flat per admin seat, not metered: there are no per-room, per-client, or per-upload fees, so separating every client into their own room costs nothing extra. The people uploading to you — clients, borrowers, LPs, counterparties — are always free and never need an account, so your bill is bounded by the one, two, or ten admins on your team who run collection, not by how many people send you files. Full plan detail is on the pricing page.

How do you keep one client from seeing another client's documents?

Two layers: a separate room and link per engagement, and granular permissions on the Data Room plan ($52/admin/month). Structurally, each client's documents live in a different container — a link into one engagement physically cannot reach another — so the classic inbox failure of forwarding the wrong attachment or over-sharing a folder simply has no path. On top of that, granular permissions bind access to named email addresses, so even inside a shared workspace a person sees only what you granted them, and an uploader who verifies an unexpected email shows up as an outsider rather than a silent leak.

Because pricing is flat per admin seat with no per-room fee, giving every client its own room is the default rather than an upgrade — one flat $52/admin/month whether you run three engagements or thirty. That is the structural answer to confidentiality: not a policy you hope people follow, but a boundary the tool enforces.

What can client document collection on Peony do?

One standing upload link per client

Send each client or engagement a permissioned link into a folder tree you pre-build. They upload directly — no signup, no password, no app — and the friction that stalls collection disappears. Part of Peony's core sharing, on the free tier and up.

Files land organized in the room

A data room and an upload link are the same object, so documents arrive already in your folder structure — no download-and-refile, no reconstructing which email thread has the current version.

Per-submitter audit trail

Every upload is logged with email, timestamp, and version, so months later you can prove exactly who supplied which file — the record an auditor, examiner, or opposing counsel expects.

Uploaders are always free

Only admin seats are billed. Clients, borrowers, LPs, and counterparties uploading to you never create an account and never pay — your bill is bounded by your team, not by how many people send you files.

Separate rooms per engagement

Give each client its own room and link so one client's documents can't reach another's. Combined with granular permissions on Data Room, access is identity-bound to named emails.

The same room runs the downstream workflow

Once files are in, share them onward under watermark and NDA, and send agreements back for e-signature — no export, no re-upload. Collection, sharing, and signing in one SOC 2 Type II room.

Granular permissions (Data Room)

On the Data Room plan ($52/admin/month), each person sees only the folders you grant them, and an uploader who verifies an unexpected email is immediately visible rather than a silent leak.

Retention and instant revoke

Access is identity-bound, ends on a set expiry date, and can be revoked per person or per room the moment an engagement closes — so collected files don't linger past their purpose.

Recurring cycles on a standing link

For quarterly or seasonal collection, the link stays the same and you update the folder tree in place — the borrower or client reuses one doorway every cycle instead of getting a fresh checklist.

NDA gating and dynamic watermarks

Gate sensitive collected material behind an NDA and stamp every page with the viewer's identity when you share it onward. Simple NDA on Business ($30/admin/month); dynamic watermarks on Data Room ($52/admin/month).

What happens after the documents arrive?

The collected set becomes the working room — the same platform carries the rest of the engagement, with no export and no re-upload. This is the payoff of collecting inside a document platform rather than a collection-only tool that stops at intake. Three things happen in place:

  • You review as files land. Documents arrive organized and attributable, so you start work on the packet instead of assembling it from an inbox.
  • You share onward under control. The room the client uploaded into becomes the room a counterparty reads from — behind an NDA-gated link, stamped with the viewer's identity via dynamic watermarks, with a per-page access log (Data Room, $52/admin/month).
  • You send agreements back for signature. Engagement letters, subscription agreements, and consents go out for e-signature in the browser — no account required for the signer.

For the sell-side case this continuity is the whole point: the documents an M&A advisor collects from the seller are the data room bidders will read, so there is no collect-twice step. Collection, secure sharing, and signing live in one SOC 2 Type II room.

How do accountants and advisors run recurring collection cycles?

With standing links, update-in-place folders, and a repeatable structure you build once and reuse. For seasonal or quarterly collection — an accountant across a filing season, a lender pulling borrower reporting every quarter, a fund manager collecting subscription documents close after close — the link stays the same and you update the folder tree in place. The client or borrower reuses one doorway every cycle instead of getting a fresh checklist and a new upload link each round.

Because the folder structure is effectively a template you control, standing up the next cycle is copying the pattern, not designing it from scratch. Each submission is still logged per submitter with email, timestamp, and version, so the audit trail accrues cycle over cycle. For the private-credit version of this recurring workflow — financials and covenant certificates from a book of borrowers, every reporting period — see the borrower reporting data room guide.

Who uses Peony to collect documents from clients?

Accountants & bookkeepers

Collect tax-season PBC documents — W-2s, 1099s, K-1s, bank statements — one room per client, view-and-upload, link expiry after filing.

Attorneys

Collect KYC and matter documents from clients and opposing parties with identity-bound access and a clean per-file log for chain of custody.

Sell-side M&A advisors

Collect the seller's documents straight into the room that becomes the sell-side data room — no collect-twice, no export before diligence opens.

Lenders — borrower reporting

Collect quarterly reporting packages — financials, covenant certificates, compliance docs — on standing per-borrower links against a repeatable structure.

Insurance brokers

Collect policy and claims documents — declarations pages, loss runs, ACORD forms — organized in a room instead of buried in an inbox thread.

Fund managers

Collect LP subscription documents against a template structure you reuse close after close — per-LP upload links, every LP free.

Where does Peony stop — and what should sit alongside it?

Document collection is not identity verification. Peony holds, permissions, and logs the documents; it does not confirm that a passport is authentic or belongs to the person who uploaded it. When your workflow needs that — common for lenders, prop firms, and fund managers running KYC/AML — you run the check through a specialist like Sumsub, iDenfy, or Veriff and use the Peony room as the secure container that collects and audits the resulting files. The two sit side by side: the verification vendor proves who someone is; Peony proves what they submitted, when, and who touched it afterward.

Peony does not scan uploads for malware. If virus scanning is a hard requirement, run submitted files through a dedicated scanner in your own pipeline before processing. And a scope note on retention: expiry and revocation govern access to the room, not deletion from a client's own device if you allowed download — so for intake you don't want copied out, set downloads off and collect view-and-upload.

Don't over-tool a single low-stakes file. One signed form back from a trusted contact doesn't need watermarks and NDA gates — a plain upload link on the free tier is plenty. The data-room controls start earning their keep the moment you have multiple external submitters, sensitive personal or financial data, a retention obligation, or anyone who will later audit the chain of custody.

"Peony is easily the best form factor for sharing client-facing material. It lets us stand out by embedding custom booking and website links into secure deck shares."
Y Combinator
RL

Robi Lin

Founder & CEO, Sepal AI (YC S24)

Frequently asked questions

I'm an accountant collecting tax-season PBC documents from a whole client book — how do I stop chasing W-2s, 1099s, and K-1s over email?

You give each client one standing upload link into a pre-built folder tree and stop pushing attachments through your inbox entirely. Create a room per client, pre-build the folders you want files to land in — W-2s, 1099s, K-1s, bank statements, prior-year returns — grant access to the client's email, and send one link. The client clicks, uploads directly into your structure with no account and no password, and you watch documents arrive in real time instead of reconstructing which of three email threads has the current 1099. Because a data room and an upload link are the same object on Peony, the collected packet is already organized the moment it lands — no download-and-refile step. There is a free tier to start, and pricing is flat per admin seat: Business at $30/admin/month adds Simple NDA gating, screenshot protection, AI document Q&A, and unlimited e-signatures; Data Room at $52/admin/month adds dynamic watermarks, Advanced NDA with countersigning, granular permissions, and auto-indexing. The client uploading to you is always free and never needs an account. After filing, link expiry ends access automatically, so a 2025 tax packet isn't still reachable in 2027.

I'm an attorney collecting KYC and matter documents from clients and sometimes opposing parties — can I do this without making non-technical people create accounts?

Yes — no-account upload is the core of it. You create a matter room, grant access to each person's email, and send a permissioned upload link that points into the folder you built. The client or opposing party clicks and uploads directly — engagement letters, IDs, discovery, privileged records — and never sees a signup screen, which is exactly the friction that stalls collection from people who don't have or won't use another login. Every upload is logged per submitter with email, timestamp, and version, so if chain of custody is ever questioned you can prove precisely who supplied which file and when. Access is identity-bound rather than "anyone with the link," so an unexpected uploader is immediately visible. One honest boundary: Peony holds, permissions, and logs the documents; it is not a KYC/AML identity-verification vendor. If your workflow needs to confirm a passport is genuine and belongs to the uploader, you run that check through a specialist like Sumsub, iDenfy, or Veriff and use the Peony room as the secure container that collects and audits the resulting files. On Data Room ($52/admin/month) you can also gate sensitive folders behind an NDA and set downloads off for privileged material you don't want copied out.

I'm a sell-side M&A advisor and the documents I collect from the seller become the data room — how do I avoid collecting them twice?

You collect straight into the room that will become the data room, so there is no second step. On Peony a data room and an upload link are the same object: you pre-build the diligence folder tree — corporate, financial, commercial, legal, HR — send the seller and their counsel permissioned upload links into it, and the documents they submit are already sitting where bidders will eventually see them. Nothing exports, nothing re-uploads, nothing gets re-filed. When collection is done and diligence opens, the same room flips to outbound sharing: you attach your NDA so no bidder sees a page before signing, run different NDAs for different buyer groups, stamp every page with the viewer's identity via dynamic watermarks, and read a per-page access log showing which bidder is deepest in which section — all on the Data Room plan at $52/admin/month. Because pricing is flat per admin seat, the seller and every person uploading to you is free; you pay only for the advisors on your side who run the process. That collect-then-share continuity in one room is the whole reason to collect here rather than in a collection-only tool you'd later have to migrate out of.

I'm a lender collecting borrower reporting packages every quarter — financials, covenant certificates, compliance docs — from a book of borrowers. Does this scale, and does it leave an audit trail?

Yes on both. Create one room per borrower with a pre-built reporting structure, send each borrower a standing upload link, and each cycle they drop that period's financials, covenant certificate, and compliance documents into the same folders — the structure is repeatable, so a quarter's package always lands in the same place. Because the link is standing, you don't reissue anything: the borrower reuses the same doorway every cycle and you update the folder tree in place. Every upload is logged per submitter with email, timestamp, and version, which is the chain-of-custody record examiners expect rather than a nicety — an inbox is not an audit trail. Access is identity-bound and ends on a set expiry or instant revoke when a facility closes. Pricing is flat per admin seat — Business $30/admin/month or Data Room $52/admin/month — and every borrower uploading to you is free and never creates an account, so onboarding a new borrower is sending a link, not provisioning a user. For the full private-credit version of this recurring-collection workflow, see our borrower reporting data room guide.

I'm an insurance broker collecting policy and claims documents from clients — declarations pages, loss runs, ACORD forms — how do I keep it organized instead of buried in email?

You replace the attachment thread with one upload link per client into a folder tree you control, so the documents arrive organized instead of scattered across your inbox. Pre-build the folders — declarations pages, loss runs, ACORD forms, prior policies — grant the client's email access, and send one link; they upload directly with no account, and you see each file land where it belongs. Email fails this structurally: size caps bounce large loss-run PDFs, versions fork when a client sends the wrong declarations page twice, sensitive policy data sits in the inbox forever, and there is no record of what arrived. A permissioned room fixes each of those — files land organized and attributable, with a per-submitter log of who supplied what and when. On the Data Room plan ($52/admin/month) you can gate anything sensitive behind an NDA, apply dynamic watermarks, and revoke access the moment a placement closes. Pricing is flat per admin seat, and every client uploading policy or claims documents to you is free and never needs an account.

I run several client engagements at once and cannot risk one client seeing another client's uploaded documents. How does Peony keep them separated?

Two layers keep them apart. First, structurally: you give each client or engagement its own room and its own upload link, so one client's documents physically live in a different container from another's — a link into the Smith engagement can't reach the Jones engagement. Second, with granular permissions on the Data Room plan ($52/admin/month), access is identity-bound to named email addresses, so even within a shared workspace a person only sees what you granted them, and an uploader who verifies a different email is immediately visible as an outsider rather than a silent leak. This is the failure that inboxes and shared drives invite — the wrong attachment forwarded, the over-broad folder share — and it's exactly what per-engagement rooms and named-email access are built to prevent. There are no per-room or per-client fees: one flat $52/admin/month whether you run three engagements or thirty, so separating clients into their own rooms costs nothing extra and is the default, not an upgrade.

Once the documents arrive, do I have to export them somewhere else to review them, share them onward, or get something signed?

No — that is the point of collecting inside a document platform rather than a collection-only tool. The set of files you collected is already the working room, so the downstream workflow runs in the same place with no export and no re-upload. You review the documents as they land; when you need to share them onward you do it under a dynamic watermark and behind an NDA gate on the Data Room plan ($52/admin/month) — the same room the client uploaded into becomes the room a counterparty reads from, with a per-page access log. When you need a signature back, you send agreements for e-signature in the browser with no account required for the signer. Collection, secure sharing, and signing live in one SOC 2 Type II room. Collection-only tools stop at intake and force you to move the files into whatever you use to share and sign; the whole advantage here is that the collected packet never has to leave the platform to do its next job.

I'm a fund manager collecting LP subscription documents for a close, and next fund I'll do it again — how do I run recurring collection cycles without rebuilding everything each time?

You build the subscription-document structure once, collect against it with per-LP upload links, and reuse the same repeatable structure on the next close. Create a room for the fund, pre-build the folders — subscription agreement, accredited-investor documentation, wire confirmations, KYC packet — and send each LP a permissioned upload link into their own folder; they upload with no account and never pay, and every submission is logged per LP with email, timestamp, and version. Because the structure is a template you control, standing up the next fund's collection is copying the pattern, not designing it from scratch, and you update folders in place as requirements change rather than emailing a fresh checklist each round. As with KYC generally, Peony collects and audits the subscription documents; the identity/accreditation verification itself, if you need it, runs through your verification vendor alongside the room. Pricing is flat per admin seat — Business $30/admin/month or Data Room $52/admin/month — so the cost is the fund's admins, not the number of LPs uploading, and every LP is free.

Get your first upload link in minutes.

Create a room, send one link, and watch the files arrive organized — off the email attachment treadmill for good. Free tier to start; Business $30/admin/month; Data Room $52/admin/month. Every client uploading to you is free and never needs an account.

No credit card required