Legal
Privacy Policy
Effective August 15, 2026. This describes the live Stampside product at stampside.com — not a generic template.
Who we are
Stampside is launching a public notary directory at stampside.com (https://stampside.com). We list commissioned notaries and let the public request service. Title companies can still schedule through the related Notary Score workspace. We do not hold funds. Payment for a signing is between the notary and the person who hired them.
Placeholder — fill before production
Legal entity name: [TO BE COMPLETED]
Mailing address: [TO BE COMPLETED]
Until that is filled in, treat the operator as “Stampside (operator of stampside.com).” Contact: [email protected]. We have not invented an LLC, street address, or data protection officer.
What we collect
We collect information you give us, information created when you use the service, and a few things from other services you choose to connect.
- Account. Name, email, optional phone, password (hashed — we never store it in plaintext), account type (notary, title company, or platform staff), and optional photo.
- Notary profile. Business name, biography, home base address and coordinates, travel radius, counties served, languages, hours, fees, RON settings, and credentials (Indiana commission number, E&O coverage, other certifications).
- Title-company interest. If you join the waitlist, we store company name, contact name, email, phone, operating states, typical monthly closings, platforms you use, notary services you need, and optional notes. That is a request to stay in touch — not a live title workspace.
- Title company workspace. When a company workspace exists: company name, locations, staff memberships and roles, and a private preferred-notary list (including internal notes that stay inside that company).
- Appointments. Parties, borrower display name, service address, schedule, fee, instructions, status history, mileage estimates, and in-file messages. We do not collect Social Security numbers or loan numbers.
- Messages and reviews. Direct threads between a title user and a notary, and reviews on completed appointments (scores plus optional comment).
- Invoices. Line items, amounts, and paid/sent status. We record that an invoice exists; we do not process card payments or hold escrow.
- Technical. Session cookie, IP address and browser user-agent on the session record, and product event logs described below.
Accounts and sign-in
Title companies
Title-company ranked dispatch is in development. Companies register interest (company, contact, email, phone, states, volume, platforms, services) so we can email them when the workspace is ready. Google and Facebook are not used for company accounts. Joining the list is not a live workspace signup.
Notaries
Notaries can register with email and password, or continue with Google or Facebook when those providers are configured. A social sign-in creates a notary listing — never a title-company workspace.
Social providers (Google, Facebook)
Sign-in is brokered through our sign-in provider. The provider authenticates you; we do not receive your Google or Facebook password. From the identity token we typically receive email, name, and sometimes a profile photo URL. We store those on your Notary Score user record and link the sign-in account so you can sign in again.
Session cookie
After a successful sign-in (password or social), our API sets an HttpOnly cookie named ns_session (SameSite=Lax; Secure when the site is served over HTTPS). The cookie holds a random session token. We store a hash of that token, expiry (12 hours), IP, and user agent. Signing out deletes the cookie and the session row. This is how we keep you logged in — not an advertising cookie.
Password reset
Email/password accounts can request a one-hour reset link sent by email. Social-only notaries are told to use the provider button instead; we do not invent a password for those accounts.
Platform staff
Operations staff sign in at stampside.com/login with Google or email. They must be platform administrators in our database. The operations console is not a second public sign-in.
What we store
The product database holds the records the service actually uses:
- Users, sessions, and password-reset tokens (hashed).
- Notary profiles, credentials, availability, and uploaded headshots (JPEG, PNG, or WebP, stored on our servers; max 5 MB).
- Organizations, locations, memberships, and preferred notaries.
- Appointments, status events, messages, reviews, invoices, and disputes.
- In-app notifications.
- Product analytics events (see below).
- Admin audit logs of staff actions.
- Optional calendar OAuth tokens, encrypted at rest.
- Official commission-check results when you run a registry lookup.
Photos from Google/Facebook may be stored as a URL to the provider’s image, until you upload your own headshot. Credential file uploads and cloud object storage are reserved in the data model; live photo uploads today go to local application storage.
Calendars
Your Notary Score weekly hours, time-off blocks, and booked appointments are the calendar of record for offers. Connecting Google Calendar is optional.
- We do not create a Google account or provision a Google Calendar for you. You connect a calendar you already have.
- If you connect Google, we request busy-time and calendar-event access. We import busy intervals from your primary calendar so those times are not offered as open slots.
- If connected, we may also create, update, or delete events on that same calendar for Notary Score appointments (summary includes the borrower display name and signing address). You can disconnect; we then stop using those tokens.
- Microsoft / Outlook calendar is modeled in the product but is not enabled yet. We do not sync Outlook until that connection actually ships.
Email and SMS
We send account and signing messages when you use the product. Stay-in-touch, directory, and other promotional email is opt-in (unchecked by default). Examples of required or requested mail: password reset, email confirmation, a service request someone sent to a notary they asked to contact. Examples of opt-in mail: title waitlist “we’re ready” updates, product news, directory promotions.
- Email goes through an email delivery service, or SMTP if that service is not configured. Copies also land in your in-app notification list. Every message includes a one-click unsubscribe link at
/unsubscribe?token=…(RFC 8058 headers). Clicking it stops promotional and stay-in-touch mail immediately. It does not stop password reset or confirmation links you just requested. - SMS can go through an SMS delivery service when an operator enables it and a phone number is on your account. In the current product, those same events are sent by email and in-app; SMS stays off unless that flag is turned on.
Consent is stored as email_opt_in / email_opt_in_at / source, plus separate flags for appointment/request alerts and optional product updates. Title waitlist rows store the same stay-in-touch fields.
The email delivery service, any SMTP host, and the SMS provider (if enabled) see the recipient address and the message body we send.
Analytics
We log first-party product events in our own database (analytics_events) — for example page views, sign-up, sign-in, notary search, profile view, appointment request/accept/complete/cancel, review, and invoice generation. Events can include a user id, organization id, and a small JSON payload (such as a path, search query, or appointment id).
Pageviews are first-party only: the product site and operations console POST page_view to our API. An anonymous visitor id is stored in an httpOnly cookie named ns_vid (a UUID we set; not readable by JavaScript). We do not load a third-party advertising pixel, Google Analytics, Meta Pixel, Mixpanel, or similar tracker. When you arrive from an ad or tagged link, we may store first-touch utm_source,utm_medium, utm_campaign, utm_content, plussource / campaign query params, on your account at signup and on that pageview. Default retention for these events is 90 days (operators can change that).
Public pages load the IBM Plex Sans webfont from Google Fonts. That is a font request to Google, not an ad tag. Your browser’s IP address is visible to Google Fonts in the usual way.
Maps and location
We store coordinates for notary home bases, company locations, and appointment addresses so we can match distance and travel radius. Distance is calculated on our servers (haversine). A Google Maps API key may be configured for routing; live Google Routes is not turned on in this MVP, so we are not sending those coordinates to Google Maps for turn-by-turn estimates today.
Indiana commission checks
Notaries (and title staff looking at a listing) can check a commission against the official state registry when a public lookup is available — for Indiana, that is the same license search title companies already use. We send the name and optional license number, and we store the query plus the official result (name, license number, status, and source URL). We do not invent a private credential.
How long we keep data
- Account and operational records (profiles, appointments, messages, invoices, credentials) for as long as the account is active and as long as we need the file history.
- Users can be soft-deleted (
deleted_at). Ask us if you want an account closed. - Sessions expire after 12 hours; expired session rows are purged.
- Password-reset tokens expire in 60 minutes.
- Product analytics events: 90 days by default.
- Database backups: a rolling set (default 14 copies).
- Short-lived cache (search, verification, calendar busy) is not a permanent store of your profile.
Security
Passwords are hashed with bcrypt. Session tokens are random and stored hashed. Calendar OAuth tokens are encrypted. Production cookies are marked Secure when the site is HTTPS. We use same-site cookies and an Origin check against cross-site form posts. No method is perfect; email [email protected] if you believe there is a vulnerability that affects personal data.
Children
Notary Score is for working notaries and title-company staff — not for children. It is not directed at anyone under 13, and we do not knowingly collect personal information from anyone under 18. If you think we have, email [email protected] and we will delete it.
Your choices and rights
You can update profile, photo, credentials, hours, and calendar connection in the product. You can disconnect Google Calendar. You can sign out. You can ask us for a copy of your account data or to correct or delete what we can legally remove.
California. We do not sell or share personal information for cross-context behavioral advertising. California residents may request access or deletion at [email protected]. We do not use a “Do Not Sell” toggle because we do not sell PII.
Indiana. We serve Indiana title and notary operations. Commission verification uses Indiana’s public registry. Indiana residents may contact us at the same address for access or deletion questions.
Contact
Privacy questions: [email protected]. That address is not yet listed elsewhere on the site. It must be a monitored inbox before this policy is treated as live in production. There is no other public contact address in the product footer today.
Use of Notary Score is the use of this scheduling and listing service as described on stampside.com.
Last updated August 15, 2026. We will change this page if the product’s data practices change materially.