Staff Signature

Privacy Policy

Last updated October 2, 2026

This policy explains what Staff Signature ("we") collects when you use staffsignature.com, why, and what we do with it. We collect as little as the product needs and we do not sell any of it.

What we collect

Signature details you type: name, title, department, phone numbers, email, organization, website, address, links, and the logo you upload. These are the content of your signature and are stored so your signature page keeps working.

Purchase details: the email you give at checkout, what you bought, and the amount. Card numbers never reach us; Stripe processes payment and we receive only a confirmation.

Organization codes: when a staff member redeems a team keyword we record their email, name, title, the time, the result, their IP address, and their browser type. The organization's administrator can see this log. It exists so the organization can verify who used its seats.

Verification codes: a six-digit code sent to your email before a seat is used. Codes expire in 15 minutes.

Link clicks: if the organization keeps click tracking on, links in installed signatures pass through staffsignature.com before reaching their destination. We record the signature, which link, the time, and the browser type. We do not record the IP address of the person who clicked and we do not identify them.

Emails we send: we log the address, the type of email, the time, and whether it was delivered, so we can fix delivery problems.

Google Workspace: if an organization authorizes central install, we read the names, titles, departments, phone numbers, and email addresses of its users from its Google directory and set each user's Gmail signature. We do not read, send, or store any email content. Access is limited to the two Google scopes listed in the Admin Console and can be revoked by the organization at any time in its Google Admin console.

Cookies and browser storage

Private pages (your signature page, the Admin Console, the Agency Console) set a single strictly necessary cookie holding your access key so the key does not sit in the address bar. We set no advertising or analytics cookies. The signature builder saves your unfinished draft in your browser's local storage until you finish.

Stripe sets its own cookies on checkout.stripe.com during payment; Stripe's privacy policy covers those.

How we use it

To build, host, and display your signature; to process payment; to run organization keywords and their logs; to send the transactional emails the product needs (your links, verification codes, invites requested by your organization, reminders, alerts); and to prevent abuse.

We do not use your data for advertising and we do not sell or rent it. We share it only with the services that run the product: Stripe (payment), Supabase (database and file storage), Vercel (hosting), Resend (email delivery), and Anthropic (the optional signature import, which processes the screenshot or file you upload and returns a layout; it is not used to train models).

Emails sent on behalf of organizations

When an organization invites its staff, we send the invitation and up to a few reminders on its behalf. Every one of those emails names the organization and carries a one-click stop link. Reminders stop the moment you install or opt out.

Retention and deletion

Signature pages are kept until you delete them, because installed signatures load their images from us. You can delete your signature and its data from the edit link on your page, or by emailing us. Organization administrators can remove their organization's data by emailing us. Click records are summarized for 90 days. Email logs are kept for 90 days.

Your rights

You can ask for a copy of your data, a correction, or deletion at any time by emailing hello@staffsignature.com. We answer within 30 days. Residents of California and the European Economic Area have additional rights under their laws, and we honor them.

Security

Private pages are reached by long random links, not passwords. Keep those links private and use the "new private link" button if one is shared too widely. Data is encrypted in transit and at rest by our providers. No system is perfectly secure; if we learn of a breach affecting you we will tell you.

Children

The product is for working professionals and is not directed at children under 16.

Changes

We will post changes here with a new date. Material changes to how we use data will be emailed to purchasers.

Staff Signature · 10931 S Santa Columbia Dr, Goodyear, AZ 85338 · hello@staffsignature.com