Privacy Policy
This explains what [YOUR LEGAL ENTITY NAME] collects when you use Doorderly, why, and what we do not do with it.
Two different kinds of information are involved here, and they are governed differently.
Information about you, our customer — your name, email and how you use the product. We decide what to collect, and this policy governs it.
Information about your tenants, which you enter. You decide what is collected and why; we only store and process it on your instructions. Your own privacy obligations to your tenants are yours, not ours, and this policy does not replace them.
1. What we collect about you
- Account information
- Your name, email address, and a hash of your password. We never store the password itself and cannot recover it.
- Content you enter
- Properties, units, occupancy, rent figures, notes, and — as those features arrive — tenants, leases and payment records.
- Technical logs
- Standard web server logs: IP address, timestamp, the page requested, and browser user-agent. Used for security and diagnosing faults.
- API token usage
- The name you gave each token and when it was last used, so you can spot a device that should no longer have access. Tokens themselves are stored only as hashes.
We do not collect location data, contacts, or anything from your device beyond what your browser sends with an ordinary request.
2. Cookies
Doorderly sets one cookie: a session
cookie, when you sign in to the management panel. It keeps you signed in
and nothing else. It is marked HttpOnly so scripts cannot
read it, SameSite=Lax to limit cross-site use, and
Secure over HTTPS.
There are no analytics cookies, no advertising trackers, and no third-party scripts on these pages. Nothing here reports your visit to anyone else. That is a design choice, and it is why you were not shown a cookie banner.
3. How we use information
- To run the service and show you your own data.
- To authenticate you and keep accounts separate.
- To diagnose faults and investigate security incidents.
- To contact you about your account, outages, or changes to these terms.
We do not use your data for advertising, do not sell or rent it, and do not use your content to train machine learning models.
4. Who else sees it
Very few parties, and none of them for their own purposes:
- Our hosting provider, which operates the servers your data sits on.
- Backup storage under our control, to which encrypted transfers are made.
- Law enforcement or a court, where we are legally compelled. Where we are permitted to tell you, we will.
If the business is ever sold or merged, your data may transfer with it. You would be told before that happened, and given the chance to export and close your account first.
5. How it is protected
- All traffic runs over HTTPS.
- Passwords are stored as bcrypt hashes, never as text.
- API tokens are stored only as SHA-256 hashes. A copy of our database contains nothing that could be used to sign in as you.
- Accounts are isolated at the database level using foreign key constraints, so one customer's records cannot be returned to another even if application code were wrong.
- The application's database account can read and write rows but cannot alter the database structure.
- Backups are taken regularly, transferred over encrypted connections, and restricted to administrator access.
No system is perfectly secure, and we will not pretend otherwise. If a breach affects your data we will tell you promptly, describe what happened, and say what we are doing about it.
6. How long it is kept
Your data is kept while your account is open. When you ask us to delete it, live data is removed within 30 days.
Backups are a separate matter and it is worth being precise: deleted data persists in existing backups until those backups age out on their normal retention schedule, which does not currently exceed 12 months. We do not restore deleted data from a backup except to recover from a failure.
Server logs are kept for a limited period for security and diagnostics.
7. Your rights
You can ask us to:
- Show you what we hold about you.
- Correct anything inaccurate.
- Delete your account and its data.
- Export your data in a portable format.
Write to privacy@doorderly.com. We will respond within 30 days. We do not charge for these requests and will not treat you differently for making one.
Depending on where you live you may have additional statutory rights — several US states and the UK and EU grant them. We apply the rights above to everyone regardless, because operating two standards is how the weaker one becomes the default.
If your request concerns data a landlord entered about you as a tenant, contact that landlord: they decide what is held and why. We will pass a request on where we can identify the account.
8. Children
Doorderly is a business tool and is not directed at children. We do not knowingly collect information from anyone under 13. If you believe we have, write to us and we will delete it.
9. Where data is held
Data is stored on servers in the United States. If you access the service from elsewhere, you are sending your data to the United States, where privacy law differs from your own.
10. Changes
If we change this policy materially, we will update the date at the top and notify account holders by email before it takes effect. We will not make a material change quietly.
11. Contact
[YOUR LEGAL ENTITY NAME]
[STREET ADDRESS]
[CITY, STATE ZIP]
privacy@doorderly.com