Privacy Policy
Last updated August 10, 2026
Dr. Signing is a directory and business workspace for notary signing agents in the United States, operated by Victor Stodieck, a Florida-commissioned notary. This policy explains what the service collects, what it publishes, who else handles it, and how to get rid of it. The service is intended for use in the United States only.
What we collect
Everything below is information you type in yourself, or that the software derives from it. The one thing we collect that you do not type is a count of page views on the public pages, described under Cookies and analytics.
Your account
Your email address, your name, and your account role (notary, company user, or administrator). There is no password, because Dr. Signing does not use passwords — see “Signing in” below.
Your notary profile
Your full name, business name, headline, biography, phone number, website, and profile photo. Your street address, city, state and ZIP code. The map coordinates derived from that address. Your service radius, the states you serve, the languages you speak, and the signing types you accept.
Your credentials: commission number, commissioning state and commission expiration date; your E&O carrier, coverage amount and policy expiration date; whether you hold an NNA certification; the date of your most recent background check; and any other certifications you list.
Practical details: years of experience, whether you accept remote online notarization, and whether you have a dual-tray printer and a scanner. Optionally, the fees you charge per signing type.
Sign-in and security records
A record of each sign-in link requested for an email address, with a timestamp. This exists for one reason: to stop someone from using the sign-in form to flood a stranger's inbox. It is deleted automatically one hour after it is written.
Payment records
If you subscribe to Pro, we store the Stripe customer ID and subscription ID Stripe gives us, the status of the subscription, its renewal date, and whether it is set to cancel. We do not store your card number, expiration date or security code, and we never see them.
We do not ask for and do not store your Social Security number, your date of birth, your driver's license, or your bank account details.
That is about your own account, and it stays true. It is separate from the closing documents a company may upload for a signing order, which do contain a consumer's Social Security and bank account numbers — theirs, not yours. Those are not part of your account, they are deleted on a short timer, and they are described in full under Closing documents.
What is public, and what is never shown
A public profile is genuinely public. It is served to anyone on the internet without an account, it is listed in our sitemap, and search engines are invited to index it. A public profile shows your name and business name, your city and state, your headline and bio, your photo, your service radius and the states you serve, your languages and signing types, your years of experience, and — when you provide it — your website.
Your phone number is the one field you choose about. By default it is published with the rest of the profile. In your dashboard you can switch it to be shown only to people signed in as a title company or as a Pro notary; when you do, the number is not sent to the page at all — not in the visible text and not in the structured data search engines read. The page says a number exists and how to reach it, and the number itself is fetched only after we check who is asking.
Most of your credentials are part of what is published. That includes your commissioning state and the month your commission expires, your E&O carrier and coverage amount, your NNA status, your background-check date and your other certifications. Publishing them is the point of a directory a title company can trust, but you should know it before you type them in. Leave a field blank and nothing appears.
Your commission number is never published. We collect it for one purpose — checking your commission against the state register, as described below — and it stays private. It is not on the list of fields a public page may show, so it does not reach the page, the structured data search engines read, or anything else served to a visitor. The reason is the same one that keeps us from trusting a New York commission automatically: states publish names and commission numbers together, so republishing that pair would only make it easier to collect, and would not prove anything about anyone.
Your street address is never displayed publicly. Neither is your ZIP code. We store the street address for one purpose: to turn it into coordinates so distance search works and so a pin can be drawn on the map. The list of fields that may appear on a public page is written out explicitly in the code, and the address is not on it.
Map pins are deliberately imprecise. Most signing agents work from home, so an exact coordinate is a home address. Before any coordinate leaves our servers — on the directory map and in the structured data search engines read — it is rounded to two decimal places, a grid of roughly 1.1 km, about seven tenths of a mile. That is precise enough to choose a notary in your area and not precise enough to find a front door.
You can turn it off at any time. Setting your profile to Private in your dashboard removes it from the directory, from the city and state pages, from the sitemap and from the public profile URL immediately. It does not delete your account. Note that search engines and archiving services keep their own copies on their own schedule, and we have no control over how quickly those disappear.
Credential verification
When you enter a commission number, Dr. Signing checks it against the state's own published register where that register exists. Today two states publish one: Texas and New York. We send the commission number to the state's open data endpoint and read back the record, then compare the name on it to the name on your profile.
Only Texas can produce a Verified badge automatically, and here is exactly why. Matching a name to a number proves nothing, because both are published together in a file anyone can download. Texas also publishes a contact email for each commission. We compare that email to the email on your account — the same inbox that receives your sign-in link. If they match, the badge is granted. If they do not, or if the state publishes no email at all, no badge is issued and the case goes to a manual review queue instead. New York publishes no contact detail, so a New York commission is never verified automatically.
The email the state publishes is never shown back to you or to anyone else in the application. We store the outcome of the check, a short note explaining it, and the date it ran.
Signing in
There are no passwords anywhere in Dr. Signing. To sign in you enter your email address and we send you a one-time link. The link works once and expires after 24 hours. Because there is no password, there is no password for us to leak.
Sign-in and sign-up forms are protected by Cloudflare Turnstile, which decides whether a submission came from a person or a script.
Who else handles your information
We use the following services to run Dr. Signing. Each one is bound by its own privacy policy, linked below. We do not sell your personal information, and we do not share it with anyone for advertising.
- Vercel
Hosting and content delivery for the website itself. Because every request to this site passes through Vercel's servers, its runtime logs record the path and query string requested, your browser's user agent, the response status and the edge region that served you; Vercel matches IP address and user agent to let us filter those logs. This has always been true of running the site here, with or without analytics.
- Vercel Web Analytics
Counts page views on the public pages so we know which ones people actually find. It is cookieless and stores nothing on your device. See the section on cookies and analytics below for exactly what it records.
- Neon
The PostgreSQL database where your account and profile are stored, hosted in the United States (US East).
- Resend
Sends transactional email: the sign-in link, account and team invitations, and the notices that carry a signing order — the invitation to a notary, and the assignment, decline and cancellation notices to the company that placed it.
- Stripe
Processes Pro subscription payments. Checkout and the billing portal are hosted by Stripe; card numbers are entered on Stripe pages and never reach Dr. Signing servers.
- Cloudflare
DNS for drsigning.com; the Turnstile challenge that tells a person from a bot on the sign-in and sign-up forms; and Cloudflare R2, the private storage that holds signing packets and scanbacks. Those files go from the uploader's browser straight to R2 and back the same way — they do not pass through Dr. Signing's own servers.
- OpenStreetMap / Nominatim
Converts the address you enter into map coordinates. Your address text is sent to Nominatim when you save it, and only then — never on every search.
- OpenFreeMap
Serves the map tiles drawn behind the directory map. Your browser requests tiles directly, so OpenFreeMap sees your IP address like any website you visit.
Beyond these, we will disclose information if we are legally required to — a subpoena, a court order, a valid request from law enforcement — or where we need to in order to establish or defend a legal claim.
How long we keep things
- Your account and profile are kept until you ask us to delete them. A profile set to Private stays in the database; it just stops being published.
- Sign-in links expire after 24 hours and are purged after they expire.
- Sign-in attempt records are purged one hour after they are written.
- Signing orders and their event log are kept for as long as the account exists. They are the record of work performed, so they are not on a timer; deleting the company account deletes them.
- Closing documents — signing packets and scanbacks — are the exception, and they are on a short timer. Seven days after the closing for a Free notary, thirty days for Pro. A daily job deletes the file from storage and then records that it is gone. Deleting the account that owns the order removes them too, whichever comes first. See Closing documents for what they contain and who could open them while they existed.
- Invoices and the payment details recorded against them are kept for as long as the notary's account exists. They are that notary's business and tax records, so they are not on a timer; deleting the account deletes them. Deleting a company account leaves the invoices standing with the company name already printed on them, because the work was done and may not have been paid for — but they stop counting towards any payment figures, since there is no longer a company for them to describe. See Invoices and payment records.
- Mileage logs and expense records are kept for as long as the notary's account exists, for the same reason as invoices: they are tax records, and they are not on a timer. They also outlast a lapsed subscription — losing Pro does not delete a year you still have to file. Deleting the account deletes them. See Mileage, expenses and your Schedule C summary.
- Payment and subscription records held by Stripe are kept under Stripe's own retention rules, which we do not control and which are generally driven by tax and accounting law.
Deleting your account
Email support@drsigning.com from the address on your account and ask us to delete it. There is no self-service delete button in the dashboard yet; until there is, email is the way, and we will confirm when it is done.
Deleting your account removes your user record and, with it, your notary profile, your street address and coordinates, your credentials, your fee schedule, your sessions, your connections to companies, the invitations you sent and received, your invoices and the payments recorded against them, and your subscription record in our database. If you have a paid Pro subscription, it is cancelled at Stripe as part of the deletion, before anything is removed here — we will not delete your account while a card is still being charged.
Three things survive, and it is better to say so plainly. Signing orders you accepted stay with the company that placed them — they are the record of work performed, and they lose your name but keep the closing. The append-only order timeline described above keeps the internal identifier of whoever took each step, including you; it is an audit trail and it cannot be edited or deleted. And anything Stripe keeps about past payments stays under Stripe's own retention rules, as does any copy a search engine or archive made while your profile was public.
If you only want to disappear from the directory, you do not need us: set your profile to Private in the dashboard and it is out of the directory, the sitemap and the public URL straight away.
Signing orders
A title company, escrow office, signing service or closing attorney can place a signing order through Dr. Signing. The order carries the signer's name and, when the company provides them, their phone number and email address, plus the signing address, the property address, the loan and escrow numbers and any notes. That information belongs to the company that entered it; we hold it to run the closing and for no other purpose, and we never sell it or use it to market anything to the signer.
An invited notary does not see the signer. An open order is offered to up to fifteen agents, of whom fourteen will never work on it. Before accepting, an agent sees the city, the date, the type of signing and the fee, and nothing else — not the signer's name, not their phone number, not the street address, not the loan number. Those appear only to the one agent who accepts.
Every step of an order is written to an append-only log with the actor, the time and the IP address it came from. The log cannot be edited or deleted; correcting it means adding to it. It is what lets the company see the closing as it happens, and it is the audit trail an examiner would ask for. Uploading and downloading a document are steps like any other, and they are logged the same way.
An order can also carry the closing documents themselves. Those are far more sensitive than anything described above and are covered separately under Closing documents.
Order email goes to the people the order concerns and to nobody else: the invitation to the invited agents, and the assignment, decline and cancellation notices to the company that placed the order.
Closing documents and nonpublic personal information
A company can upload the signing packet for an order, and the assigned notary can upload the scanbacks afterwards. These are PDFs, and they contain the most sensitive information anywhere in this service: a closing package routinely carries the borrower's Social Security number, bank account numbers and income. That is nonpublic personal information about a consumer, and it brings the Gramm-Leach-Bliley Act and its Safeguards Rule into scope.
In this arrangement Dr. Signing acts as a service provider to the title company, escrow office, signing service or closing attorney that sends the documents, and to the notary who receives them. That information belongs to them, not to us. We handle it only to move it between the two parties to a signing, and for nothing else: we do not read it, we do not mine it, we never market anything to the consumer named in it, and we never sell it.
Where the files actually go
They are stored in a private Cloudflare R2 bucket that has no public access and no listing. The file travels from the uploader's browser directly to that storage using a one-time link that expires, and comes back the same way — it does not pass through Dr. Signing's own servers in either direction. The address of each stored file is 256 bits of randomness with nothing in it derived from the order, so knowing one tells you nothing about any other.
Who can open them
Exactly two parties: users of the company that placed the order, and the one notary the order is assigned to. Nobody else, at any point.
This is deliberately stricter than the rest of an order. An open order is offered to up to fifteen agents; being invited lets an agent see the city, date, type and fee so they can decide, and it does not let them open a single document. Only accepting does. And if an order stops being assigned to a notary, their access ends with it — the check is made against the current assignment every time a file is requested, not against a list kept somewhere.
Every download is recorded, and the record cannot be edited
Each time anyone requests one of these files, we write a line to the order's append-only log with who asked, when, and the IP address it came from — before the file is handed over. That log is the audit trail an examiner would ask for, and the same one that lets the company watch the closing happen. It cannot be edited or deleted; the database refuses.
Because the download link works for a short time without a further sign-in, anyone the link is forwarded to could open the file while it is still valid. That is why the link is issued only at the moment of the click, is never embedded in a page, expires in fifteen minutes, and is recorded against the person who asked for it.
They are deleted on a timer
This is the part that matters most, so it is stated plainly: these documents are not kept. Each one is given a deletion date when it is uploaded, counted from the closing — seven days for a Free notary and thirty days for Pro. A job runs daily that deletes the file from storage and then marks it gone here. After that the document is not recoverable by you, by the company, or by us. The date is shown next to every file, before it disappears.
An upload that was started and never finished is swept the same way within a day, so a file that was sent but never completed does not sit in storage unnoticed.
We are not SOC 2 certified, and we will not imply otherwise. The design above — least privilege, an audit log that cannot be rewritten, short-lived access, encryption at rest, and keeping as little as possible for as short as possible — is what such an audit examines, and we built to it. It is not the same thing as having passed one. Large title companies do ask; when we can answer yes, we will say so here and not before.
Invoices and payment records
Closing an order raises an invoice for the notary who did the work, if they are on Pro. The invoice carries a number, the amount agreed on the order, the payment terms, the signing date, the signer's name and the billing details of the company that placed it. A notary can also enter an invoice by hand for work that never came through Dr. Signing — a job from another platform, a signing service, or a walk-in — and that one carries whatever they typed, including the name of the company they are billing.
We do not touch the money. Dr. Signing does not collect, hold, transfer or process signing fees. The company pays the notary directly, exactly as the industry already works. Our only payment relationship with anyone is the $59 Pro subscription, described under Payment records. We never see or store bank account details for a signing fee, because none pass through here.
The notary records when payment arrived: the date, the method they were paid by, and a reference such as a check number if they enter one. That is a fact they assert about their own business, and nobody else can enter or change it.
What we calculate about a company, and what we refuse to
From those invoices we work out two numbers for each company that places orders here: how long it typically takes to pay, and what share of its invoices were paid within the terms it agreed to. Notaries see them before deciding whether to accept that company's work. This is the one place where Dr. Signing publishes something about a business rather than about its own users, so the limits are worth stating exactly:
- Only facts taken from invoices raised on this platform. There is no rating, no star, no score and no comment box anywhere in the product, and no way for anyone to leave one. Nothing a notary writes about a company reaches the figures, because there is nowhere to write it.
- Only invoices that came from an order the company itself created, assigned and closed. Hand-entered invoices naming a company never count towards that company's figures.
- Nothing is shown at all until at least five invoices from at least three different notaries have come due. Below that the answer is “not enough data”, not a number with a caveat.
- Only the last twelve months count, on a rolling basis, so an old bad stretch does not follow a company indefinitely.
- No single notary's experience sets the figure. Each notary counts once regardless of how many invoices they raised.
- A company can see its own figures and dispute any individual entry from its portal. A disputed entry stops counting while the dispute stands, and the notary who raised it can see the dispute.
Invoices are business records of the notary who raised them and are kept while the account exists; deleting the account deletes them, and with them their contribution to any company's figures.
Mileage, expenses and your Schedule C summary
A notary on Pro can keep a mileage log and a list of business expenses here, and ask for a year-end summary laid out on the lines of a Schedule C. The mileage log holds what the IRS expects a log to hold: the date of each trip, where you drove to, the business purpose, and the miles. Expenses hold a date, a category, an amount and your description. Either can be tied to one of your orders.
A mileage log is a record of your movements. Read across a year it shows where you were and when, which makes it the most sensitive thing we hold about you — more than your commission details, more than your invoices. So it is worth being exact about who reaches it: only you. No company sees your trips or your costs, not even the company on the order a trip is linked to. It is never used for the directory, never used for matching, never sold, never shared with a data broker, and never used to work out anything about anybody else. Every query for it carries your profile id in the database lookup itself, not as a check made afterwards.
If you offer to prefill a distance, we work it out from the coordinates already on your profile and on the order — a straight line, which we label an estimate because roads are longer than straight lines. We do not track your phone, we have no location permission, and we never follow a device. The miles that count are the ones you type.
The summary adds up the invoices you were actually paid, your mileage at the IRS rate that was in force on the day of each trip, and your expenses. You can download it as a PDF or a CSV. It is a summary for you and your tax preparer, not tax advice, and Dr. Signing is not a tax preparer. We do not file anything, we do not send it to any tax authority, and nobody here reviews it. Generating it sends your figures nowhere — the file is built on our server and handed straight to your browser.
These records are business records you have to keep, so they are kept while the account exists and they survive a lapsed subscription: if Pro ends, you keep what you entered, because you still have to file with it. Deleting your account deletes them along with everything else, described under Deleting your account. Export what you need first — once they are gone we cannot reconstruct them.
Your California rights
If you are a California resident, the California Consumer Privacy Act as amended by the CPRA gives you the right to know what personal information we have collected about you, to get a copy of it, to correct it, to delete it, and to limit the use of sensitive personal information.
We do not sell personal information and we do not share it for cross-context behavioral advertising. There is no opt-out to offer, because the thing you would be opting out of does not happen. We will not discriminate against you for exercising any of these rights — there is no version of Dr. Signing that costs more because you asked a privacy question.
To exercise any of these rights, email support@drsigning.com from the address on your account. We will verify that the request comes from you before acting on it, which for a passwordless service means confirming control of the account email.
Children
Dr. Signing is a professional tool for commissioned notaries and the companies that hire them. It is not directed at anyone under 18, and we do not knowingly collect information from anyone under 18. If you believe a minor has created an account, email us and we will remove it.
Changes to this policy
When this policy changes, the date at the top changes with it. If a change materially affects what we collect or who receives it, we will say so directly rather than quietly editing the page. The previous version of this policy said document exchange was planned and promised to update this page before it was switched on; the Closing documents section above was written in the same change that switched it on.
Contact
Questions about this policy, requests about your data, or a correction to something here that is wrong: support@drsigning.com.
See also our Terms of Service and what Dr. Signing is.