Stickylink Workspace, Terms of Service
Last updated: September 7, 2026
1. What Workspace is
Stickylink Workspace is a multi-tenant SaaS workspace that pairs a one-time purchase of physical QR or barcode stickers (the "Workspace Roll", 200 stickers per roll) with a cloud workspace for labs, R&D groups, and manufacturing engineering teams. Assets are created from templates, attached to a scannable code, organized in nested folders, and, on the Document Suite plan, authored as controlled manufacturing documents.
2. Plans, seats, and pricing
- Free Workspace, $0. No purchase or payment method required. Includes unlimited scans, up to 25 active records, the standard template library (fields may be removed but new custom fields may not be added), Excel/CSV export, and one year of audit history. Controlled documents and document releases are not included.
- Workspace Roll, $45 USD one-time per 200-sticker roll, plus shipping and applicable tax. Rolls ship in 3–5 business days. Rolls work with the free workspace; no subscription is required to use them.
- Secure Workspace, $99 USD per month per organization, up to 5 editing members. Adds multi-QR asset mapping, stock and inventory counters, maintenance logs, scan-side quantity edits, and shared folders.
- Document Suite, $249 USD per month per organization with 5 included seats; additional seats are $40 USD per month each. Adds custom templates, the in-app document editor, revision control and releases, travelers, setup sheets, manufacturing instructions with sign-offs, AI autofill and AI document review, and print/PDF/email output.
- Optional implementation and custom template packages, $500–$3,000 USD per engagement, depending on scope, with a 72-hour turnaround and two included revisions. All subscriptions are fully self-serve; implementation is never required.
- Custom sticker backings are quoted and ordered inside the dashboard; proofs must be approved by an organization admin before production.
Subscriptions are billed monthly or annually through our payment processor and are cancellable at any time. Plan changes are applied to your existing subscription: upgrades take effect immediately and are invoiced prorated for the remainder of the period, while downgrades and cancellations take effect at the end of the current billing period. After a cancellation the workspace reverts to the Free Workspace tier: gated features (document editing, releases, AI, unlimited records) are disabled, and existing documents and audit history remain viewable.
Membership rules by plan. On Free Workspace, email invitations are disabled; additional people join by signing up with an email address on your organization's verified domain and being approved by an admin. Secure Workspace adds email invitations and allows up to 5 editing members. Document Suite includes 5 seats with additional seats available at $40 USD per month each. Scanning a code and viewing a public record never consumes a seat.
3. Beta status
Workspace is offered as a beta product. It is provided "as is" and "as available" and may have bugs, downtime, and evolving features. We are actively working toward SOC 2 Type II and other attestations, see the Compliance Roadmap, but no such attestations exist today.
4. Security, how your data is protected
Workspace is built on managed cloud infrastructure with the following controls. These are descriptions of current product behavior, not certifications or guarantees.
- Encryption. All traffic is served over HTTPS/TLS. Database and file storage are encrypted at rest by our infrastructure provider.
- Tenant isolation. Every asset, template, document, folder, and audit entry is scoped to an organization ID and enforced with row-level security in the database, not just in the app. A member of one organization cannot query another organization's rows.
- Domain-locked organizations. A workspace can only be created for the email domain the creating user has verified, which prevents someone from claiming a domain they do not control. Later signups on the same domain require admin approval, and invites expire after 14 days.
- Role gating. Roles are stored separately from user profiles and checked server-side. Only organization admins can restructure or delete folders, approve members, transfer admin rights, release document versions, or download backing artwork.
- Sticker claim codes. Editing a scanned sticker requires the printed claim code, so scanning alone never grants write access. Claim tokens are rotated when a sticker is claimed.
- Private file storage. Uploaded PDFs, images, and videos are stored in private buckets and served through short-lived signed URLs issued only to authorized members. Files are not publicly listable.
- Shared snapshots. Read-only document links at
/v/:tokenexpose a frozen snapshot through an unguessable token and no edit surface. Treat those links as sensitive and share them deliberately. - Immutable audit log. Reads, edits, quantity changes, releases, and approvals are recorded append-only with actor, timestamp, and action.
- Multi-factor authentication. Members can enable TOTP MFA on their account; admins are strongly encouraged to do so.
- Payments. Card data is handled entirely by our PCI-compliant payment processor. We never see or store card numbers.
What we do not claim. Workspace is not HIPAA-, PCI-, ITAR-, FedRAMP-, or 21 CFR Part 11-certified, and we do not sign BAAs. We do not offer a contractual uptime SLA during beta. Do not treat anything on this page as a certification, audit result, or legal advice.
Report suspected vulnerabilities to hello@stickylink.io. We will acknowledge reports and ask that you avoid accessing other organizations' data while testing.
5. AI features
Document autofill and the AI review helper send the content you submit (uploaded PDFs, spreadsheets, documents, or images, and the document text being reviewed) to a third-party model provider through our AI gateway to produce suggested field values, spelling corrections, and improvement notes. AI output is suggestive only: it can be wrong, incomplete, or misread a drawing. You remain responsible for reviewing and approving every field before release. Do not submit content you are not permitted to process with a third-party service, and do not rely on AI output for safety, regulatory, or engineering sign-off.
6. Documents, revisions, and releases
Documents may be saved as revisions and promoted to releases. Releases are intended as controlled records: once released, a version snapshot is retained and cannot be edited in place. Sign-off fields and approval names are recorded as entered by your team. Stickylink provides the recordkeeping mechanism, it does not validate that your process meets any quality standard, and released documents are not a substitute for a validated QMS.
Printed and emailed copies. Documents you print, download as PDF, or send by email are stamped with a StickyLink QR code in the page header. Scanning that code opens the live record so a reader can confirm the current revision. A printed or emailed copy is a point-in-time snapshot and may become out of date after a later release; the record in Workspace is the controlling copy. You are responsible for how printed copies are distributed and withdrawn within your own document-control process.
7. Upload limits and acceptable files
Attachments include PDFs, spreadsheets, documents, images, and short videos. Video clips are limited to 3 per asset, 10 seconds, and 25 MB each. We may enforce additional storage or rate limits, and may remove files that violate these Terms.
8. Prohibited data (IMPORTANT)
You may not upload, transmit, or store the following categories of data in Stickylink Workspace:
- Protected Health Information (PHI) subject to HIPAA
- Payment card data subject to PCI DSS (cardholder numbers, CVV, etc.)
- Classified national security information, at any level
- ITAR- or EAR-controlled technical data
- Clinical trial records subject to 21 CFR Part 11 or FDA electronic-records rules
- Any data your organization is contractually or legally required to keep in a certified environment (ISO 27001, FedRAMP, HITRUST, etc.)
If you cause us to receive such data, we may suspend your account and delete the data without notice. You indemnify us against any resulting regulatory action.
9. Domain-based accounts
Workspace organizations are keyed to your corporate email domain. The first user on a given domain becomes the organization admin; subsequent signups on the same domain require admin approval. You represent that you are authorized to bind the entity that owns your email domain to these Terms.
10. Immutable audit log
The audit log is append-only by design and is not editable, exportable-with-deletions, or removable except through account termination. This is a feature, not a bug, intended to support your inspection cycles.
11. Data retention & archival
"Deleted" assets are archived rather than hard-deleted so historical records remain queryable. On account termination, we retain data for up to 90 days for restoration, after which it may be permanently removed. Excel export is available on every plan so you can take your records with you.
12. Governing law
These Terms are governed by the laws of the United States, without regard to conflict of law principles. Disputes will be resolved in the state and federal courts of your principal place of business unless the parties agree otherwise in writing.
13. Disclaimers
Workspace is provided "as is" and "as available" without warranties of any kind, express or implied, including merchantability, fitness for a particular purpose, and non-infringement. We do not warrant uninterrupted availability or that data will be preserved without loss.
14. Limitation of liability
To the maximum extent permitted by law, Stickylink and its team will not be liable for indirect, incidental, special, consequential, or punitive damages, or for lost profits, revenue, or data arising out of your use of Workspace. Our total liability for any claim relating to Workspace will not exceed the greater of $100 or the amount you paid us for Workspace in the 12 months preceding the claim.
15. Indemnification
You agree to defend and indemnify Stickylink from any claim arising out of the data you upload (including any prohibited data listed above), your use of Workspace, or your violation of these Terms or any law.
16. Changes
We may update these Terms. Material changes will be announced in-app or by email. Continued use after the update constitutes acceptance.
Questions? Contact us at hello@stickylink.io.
