Draft for Attorney Review — September 2026

Privacy Policy

This Privacy Policy explains how Stacks Cloud LLC (“SignBreezy,” “we,” “us,” or “our”) collects, uses, discloses, and retains personal information through SignBreezy. It applies to Hosts and other account users as well as guests whose information is processed through SignBreezy.

1. Information We Collect

Account Information When a Host creates or uses an account, we may collect: • name; • email address; • company or business information; • account credentials; • property information; • billing and subscription information; and • account preferences.

Reservation Information SignBreezy may receive reservation information from Hosts, booking-platform communications, forwarded emails, integrations, or other sources authorized by the Host. This may include: • guest name; • reservation dates; • reservation number; • property; • number of guests; • booking platform; • rates, taxes, fees, and totals; and • other reservation information.

Guest-Provided Information Hosts may configure SignBreezy to collect information directly from guests, including: • legal name; • home or mailing address; • email address; • telephone number; • additional guest names; • vehicle information; • responses to Host questions; • acknowledgments; • signatures; and • other information requested in connection with an agreement.

Identification Documents When required by a Host, SignBreezy may collect and store government-issued identification, such as a driver's license or passport, including images and information appearing on or extracted from the document. Merely uploading an ID does not necessarily involve identity verification.

Identity-Verification Information If identity verification is enabled, additional information may be collected and processed to authenticate an identification document and determine whether the individual presenting it matches the document. Depending on the verification method, this may include: • identification-document images and data; • selfies and facial images; • video or liveness captures; • facial or biometric information derived from those materials; • device and network information; • fraud and risk signals; and • verification status and results.

We use Didit to provide identity-verification technology. Didit's current verification notice confirms these categories can be processed during a verification flow.

[ATTORNEY REVIEW: This section needs a biometric-information review covering BIPA and other state biometric statutes, California sensitive personal information, retention/destruction requirements, and the exact consent shown before verification.]

Documents and Agreements We process templates, agreements, PDFs, Google documents, signatures, fields, tokens, formulas, and other content used to create and complete agreements.

Payment Information Payments are processed through Stripe. Stripe may receive payment information and related identifiers necessary to process transactions, prevent fraud, and operate its services. Stripe's current DPA describes circumstances in which Stripe operates as a processor and circumstances in which it acts as a controller.

Technical Information We may automatically collect: • IP address; • browser and device information; • timestamps; • login and activity information; • diagnostic information; • security events; and • cookies or similar technologies.

2. How We Use Information

We use personal information to: • provide SignBreezy; • create and populate rental agreements; • obtain electronic signatures; • collect guest information requested by Hosts; • collect identification when requested; • perform identity verification when enabled; • calculate values used in agreements; • store completed agreements and records; • process payments; • communicate about accounts, agreements, and transactions; • provide customer support; • maintain security and prevent abuse or fraud; • troubleshoot and improve SignBreezy; • comply with legal obligations; and • establish, exercise, or defend legal rights.

3. Hosts and SignBreezy

Hosts determine many aspects of the guest information processed through SignBreezy, including what information they request, whether they require identification or identity verification, and how certain records should be retained.

Where SignBreezy processes guest information solely on behalf of a Host, the Host may be the business or controller responsible for determining the purpose of that processing, and SignBreezy may act as its service provider or processor.

For certain processing undertaken for SignBreezy's own purposes—such as account administration, security, fraud prevention, billing, or legal compliance—Stacks Cloud LLC may independently determine the purposes and means of processing.

[ATTORNEY REVIEW: This controller/processor allocation needs to be reflected in your DPA with Hosts. I strongly recommend that SignBreezy eventually have a separate Data Processing Addendum.]

4. How We Disclose Information

We may disclose personal information to service providers that help us operate SignBreezy, including providers of: • identity verification; • payment processing; • hosting and infrastructure; • document and cloud services; • email and communications; • security and fraud prevention; • customer support; and • analytics.

We may also disclose information: • at a Host's direction; • where necessary to complete a transaction requested by a user; • to comply with law, legal process, or valid governmental requests; • to protect rights, safety, security, or property; • in connection with a merger, acquisition, financing, restructuring, or sale of all or part of our business; or • with consent or as otherwise disclosed when information is collected.

We do not disclose government IDs or identity-verification information publicly.

5. Identity Verification and Didit

SignBreezy uses Didit to perform certain identity-verification functions. Information necessary to conduct a verification may therefore be transmitted to Didit.

Didit currently describes itself as a processor when providing verification on behalf of its customer and states that its customer determines what information is collected and how long verification information is retained. Didit currently states that verification data is processed in the European Union by default and that retention can be configured by its customer. Didit's own privacy notices also apply to its processing.

Didit Verification Privacy Notice

[ATTORNEY REVIEW: Decide whether guests should receive a direct Didit privacy-notice link immediately before beginning verification. I would favor doing so regardless of whether legally required.]

6. Payment Processing

SignBreezy uses Stripe to process payments. Payment information submitted through Stripe is subject to Stripe's applicable terms and privacy practices. We receive transaction and account information necessary to administer subscriptions, usage charges, refunds, and our business relationship with customers.

Stripe Privacy and Legal Information

7. Data Retention

Hosts may establish retention periods for certain agreements, IDs, and related records. We retain information for the period selected by the Host where applicable, subject to legal requirements, security requirements, disputes, legal holds, backups, and other legitimate purposes.

After a SignBreezy account is closed, we generally retain account information for 30 days before deleting or de-identifying it, subject to exceptions required or permitted by law. Information stored in backups may remain for a limited additional period before being overwritten. Identity-verification information held by Didit may be subject to retention settings configured by SignBreezy and Didit's applicable systems.

[ATTORNEY REVIEW: Define exactly what the 30-day deletion covers. IDs and biometric information may require more specific retention/destruction treatment than ordinary account records.]

8. Security

We use administrative, technical, and organizational measures designed to protect personal information. No method of electronic transmission or storage is completely secure, however, and we cannot guarantee absolute security. Didit currently reports encryption in transit and at rest and states that it maintains independently audited security controls.

9. Adult Users

SignBreezy's signing and identity-verification features are intended for adults. We do not knowingly request minors to sign agreements or complete identity verification. A Host may provide information concerning minors as part of reservation or occupancy information where appropriate.

[ATTORNEY REVIEW: Children's-data language, particularly if Hosts can enter children's names/ages.]

10. Privacy Rights

Depending on where you live, you may have rights concerning your personal information, including rights to: • request access to personal information; • request correction; • request deletion; • obtain information about how personal information is used or disclosed; • obtain a portable copy where applicable; • limit certain uses of sensitive personal information; • opt out of certain sale or sharing practices where applicable; and • not receive discriminatory treatment for exercising applicable privacy rights.

California law provides qualifying consumers rights including rights to know, delete, correct, opt out of sale or sharing, limit certain uses of sensitive personal information, and receive nondiscriminatory treatment.

To submit a privacy request, contact: legal@signbreezy.com

We may need to verify your identity before fulfilling a request. If SignBreezy processes your information solely on behalf of a Host, we may direct the request to the applicable Host or assist that Host in responding.

11. Sale and Sharing of Personal Information

[ATTORNEY REVIEW REQUIRED]

SignBreezy should make an affirmative determination regarding whether any analytics, advertising, pixels, cookies, or other technologies constitute “sale” or “sharing” under California law or similar state laws.

I would not simply put “We never sell your data” here until counsel has reviewed your actual analytics/advertising stack.

If you do not run cross-context behavioral advertising and your vendor contracts qualify appropriately, the final policy could potentially say: We do not sell personal information for money and do not use guest IDs or identity-verification information for targeted advertising. But I'd have counsel confirm the broader “sale/share” representation.

12. Sensitive Personal Information

Government identification information, account credentials, precise information contained in identity documents, and biometric information may qualify as sensitive personal information under applicable laws. We use sensitive information only for the purposes described in this Policy and as otherwise permitted by law. We do not use guest government IDs or biometric verification information for advertising.

13. International Processing

Some service providers may process information outside the jurisdiction in which it was collected. Didit currently states that its default verification processing occurs in the European Union. Where required, we and our service providers use appropriate mechanisms for international transfers of personal information.

14. Changes to This Policy

We may update this Privacy Policy from time to time. When appropriate, we will notify users of material changes through SignBreezy, by email, or through another reasonable method. The effective date displayed at the top will indicate when the Policy was most recently updated.

15. Contact

Questions or requests concerning this Privacy Policy may be sent to: Stacks Cloud LLC California, United States legal@signbreezy.com