Stage Autograph

Effective September 15, 2026

Privacy Policy

This policy explains how Stage Autograph handles information when organizations prepare, send, sign, and retain electronic contracts.

1. Who we are

Stage Autograph is an electronic contract workflow service operated by Stephen Bair (“Stage Autograph,” “we,” “us,” or “our”). Organizations use the service to manage source documents, assemble packets, send contracts, collect signatures and form responses, and maintain related audit histories.

2. Information we collect

Depending on how the service is used, we may collect:

  • Account and organization information: names, email addresses, optional telephone numbers, organization names and domains, roles, password hashes, and multi-factor authentication or passkey registration details.
  • Contract content: uploaded sources, packets, contracts, CSV import data, field values, signatures, initials, dates, attachments, and completed documents. This may include sensitive information such as Social Security or taxpayer identification numbers and bank account information when an organization chooses to collect it.
  • Workflow and audit information: sending, delivery, opening, reminder, signing, declining, completion, download, login, and administrative events, along with timestamps and available technical evidence such as IP address and browser information.
  • Communications: information contained in support requests and messages sent through the service.

3. How we use information

We use information to:

  • provide, operate, maintain, and improve Stage Autograph;
  • authenticate users and enforce organization access controls;
  • prepare, send, display, sign, and retain contracts;
  • create audit histories and deliver requested notifications;
  • prevent abuse, investigate security events, and protect the service;
  • respond to support requests and comply with applicable law.

We do not sell or rent personal information, and we do not use contract content for targeted advertising.

4. Organizations and recipients

The organization that creates and sends a contract decides what information is collected, who receives it, and why. That organization is responsible for providing required notices, obtaining necessary consent, limiting collection to appropriate information, and honoring recipient rights. Organization administrators may access and manage information in their workspace. Recipients should direct contract-specific questions and requests to the sending organization.

5. When we disclose information

We may disclose information only as reasonably necessary:

  • to the sending organization, its authorized users, and intended recipients to complete the requested workflow;
  • to vendors that provide hosting, email delivery, security, authentication, document processing, backup, or support services, subject to appropriate obligations;
  • to comply with law, legal process, or a lawful government request, or to protect rights, safety, and service integrity;
  • in connection with a merger, financing, reorganization, or transfer of the service, with appropriate notice and protections.

6. Security

We use administrative, technical, and organizational safeguards designed for the nature of the information we handle. These include encrypted connections, access controls, multi-factor authentication and passkeys, encryption of designated sensitive fields at rest, security logging, tamper-evident audit records, backups, and software patching. No system or transmission is completely secure, and we cannot guarantee that unauthorized access, loss, misuse, or alteration will never occur.

7. Retention and deletion

We retain information for as long as reasonably needed to provide the service, maintain contract and security records, satisfy legal obligations, resolve disputes, and enforce agreements. Organization administrators may delete eligible workspace content. Some information may remain for a limited period in protected backups or be retained in audit, fraud-prevention, or legal records when deletion would undermine their integrity or when retention is required by law. Organizations should maintain their own copies of important signed contracts.

8. Cookies and similar technology

Stage Autograph uses cookies and similar local technologies that are necessary for authentication, session security, preferences, and abuse prevention. We do not use advertising cookies.

9. Your choices and requests

Account users can review and update profile information in the service. Organization administrators can manage users and workspace content. To request access, correction, or deletion of other personal information, contact the sending organization first or email us at sbair@stephenbair.com. We may need to verify your identity and authority, and some requests may be limited by applicable law or legitimate recordkeeping needs.

10. Children and minors

Organization accounts are intended for adults authorized to act for an organization. A sending organization may use the service for a contract involving a minor only when it has appropriate authority and has obtained any required parent or guardian consent. Stage Autograph is not directed to children for independent use.

11. Changes to this policy

We may update this policy as the service, law, or our practices change. We will post the updated policy here and revise its effective date. If a change is material, we may provide additional notice through the service or by email.

12. Contact

Questions about this policy may be sent to sbair@stephenbair.com. Also review our Terms & Conditions.