General information, not legal advice. This text explains how the service works and what we do; it does not promise any legal outcome.
Privacy Policy
Version 2026-10-01
Who runs Docustay
Docustay is a product of GLRS LLC. In this document, “we”, “us” and “our” mean GLRS LLC. To reach us, use the Contact page.
1. Docustay’s role
Docustay provides software organisations use to prepare, send, sign and keep documents. This policy covers two different roles, and which one applies depends on whose data it is.
- Your clients' and leads' data (organisation data). The organisation is the data controller. Docustay is a data processor, acting only on the organisation's instructions, under the Data Processing Addendum (see our DPA). If you are a client or lead of an organisation using Docustay and have a question about your information, contact that organisation directly — their own privacy policy, linked from their client portal, explains their collection and use of it. Docustay does not decide what an organisation collects or how long it keeps it; the organisation does.
- An organisation owner's or staff member's own Docustay account. For this — your login, your account settings, your use of the software itself — Docustay is the data controller, and the rest of this policy describes that relationship.
2. What we collect
- Account information: name, email, and sign-in details (we use Firebase for authentication; we never see or store your password ourselves).
- Organisation information: your organisation's name, address, timezone and the settings you configure.
- Usage information: how you use the product, to fix problems and improve it — error logs, performance data, and which features you use.
- Billing information: processed by Stripe; we store what plan you're on and your billing history, not your full card number.
- Organisation data, as a processor: whatever your organisation and its clients enter into Docustay — client records, documents, messages, session notes, payments. We process this on the organisation's behalf and do not use it for our own purposes.
- Payment records:If you collect payments through a payment field, Docustay keeps the amount, currency, payment status, Stripe session and payment references and a receipt link, and the fee charged. Card details stay with Stripe.
- Translation suggestions: if you use "Suggest a better translation", Docustay keeps the language, the sentence, the text you suggest, your note, and your email address only if you add one. We do not keep your IP address: a one-way code made from it and the date limits how many suggestions one address can send in a day, and the code is not used for anything else. Only the people Docustay names to review suggestions can read them. A suggestion that is approved can become part of the translation: only the text is used, never your email. You can ask us to delete a suggestion by writing to privacy@docustay.app.
3. Sub-processors
We use the following companies to help provide Docustay. Each is bound by a contract to protect data at least as strictly as we do, and to use it only to provide their service to us.
- Railway — application and database hosting.
- Google Cloud / Firebase — authentication and supporting infrastructure.
- Stripe — payment processing.
- Resend — transactional email delivery.
- Twilio — SMS and phone-number verification.
- SeaweedFS (self-hosted) — document and file storage, run on our own infrastructure rather than a third-party storage vendor.
We'll update this list if it changes, and material changes are covered by section 8.
4. Security
We use encryption in transit and at rest where supported by our providers, role-based access controls, two-step sign-in for staff accounts, tenant isolation enforced at the database level (Postgres row-level security, applied to every table that holds organisation data — not an application-level check that could be bypassed by a bug elsewhere), automated backups, and a dedicated signing certificate for documents clients sign through the platform. No system is perfectly secure.
5. Retention and deletion
We keep personal information only as long as we need it to provide our services and meet legal obligations, and we delete it when you ask us to. An organisation can request export or deletion of its data at any time by contacting us; we'll complete a deletion request within 30 days unless we're required to keep something by law (for example, financial records).
6. Breach notice
If we become aware of a security incident affecting organisation data, we will notify the affected organisation without undue delay so they can meet their own notification obligations to their clients, consistent with our Data Processing Addendum.
7. Your rights
If you are a client or lead of an organisation using Docustay, direct requests about your personal information to that organisation — they control it, and we help them fulfil requests when asked. If you are an organisation owner or staff member with your own Docustay account, you can ask us to see, correct, delete or export your account information, or to stop processing it for purposes you haven't agreed to, by emailing privacy@docustay.app. California residents have rights under the CCPA/CPRA; we honour equivalent requests for everyone, not only California residents.
8. Children
Docustay itself is not directed to children; organisation owners and staff using it must be adults. An organisation may use Docustay to hold records about minors (as clients of that organisation) — that data is the organisation's, governed by their own policy and our DPA with them, not by this policy directly.
9. Changes
We'll update the effective date above when this policy changes, and ask current organisation owners to re-accept it on their next sign-in when a change is material (see our Terms of Service, section on changes).
Self-hosted installs: usage ping and licence check
If you run Docustay on your own server, the worker sends one anonymous usage ping a day to docustay.app: a random install identifier the install made for itself, the software version, and five whole numbers (documents sent this month, documents signed, workspaces, users, days running). It never includes document content, names, email addresses or your server's address, and we do not log the request address for that route. Turn it off with DOCUSTAY_TELEMETRY=off, or send the same report by hand from Settings. If you use a Pro licence, the install also presents its licence key and install identifier to renew a signed note that lets it keep working for up to 30 days offline.
10. Contact
Docustay · privacy@docustay.app