I'm not great at this sort of stuff, but if Sign is meant to be a third party website that other websites authenticate your identity against, given by step 1:
Initial Step: Visit the ‘Sign’ website and input your email to start the process.
Could this also be likened to a less secure OAuth?