Privacy policy

Effective September 29, 2026. Doorman (“we”, “us”).

The short version

1. Who is responsible for what

Account data. When you sign up, we decide how your account information is used, so we are the controller of it.

Form submissions. When a visitor submits a form on a customer's website that uses Doorman, the customer decides why that data is collected. The customer is the controller; we are their processor (service provider) and handle submissions only to provide the service. If you submitted a form on someone else's website, please contact that website's owner about your data; we will help them respond.

2. What we collect

From customers

From form submissions (on behalf of customers)

From visitors to this website

3. How we use it

Legal bases (where GDPR/UK GDPR applies): performance of our contract with you for account data; our legitimate interests in securing and improving the service; and, for submissions, the customer's instructions under our data processing terms.

No training, no selling. Submissions are sent to Jev only to be judged. We don't use them to train or fine-tune models, and we don't sell or rent personal data or use it for advertising.

Automated decisions. Doorman makes automated recommendations about whether a submission is genuine. Customers can review every held and dropped submission and deliver it with one click. These are recommendations to the customer, not decisions about you: the customer who runs the form decides what happens to each submission and can deliver any held or dropped one. If you think a message of yours was wrongly kept out, contact the website's owner.

4. Who we share it with

We use a small number of subprocessors to run Doorman. Each receives only what it needs.

SubprocessorPurposeData
TypeSafe (Jev)Judging each submissionSubmission text, signals and the form's business description
ResendSending emailRecipient address and email content, including forwarded submissions
StripeBillingAccount email, plan and payment details (entered directly with Stripe)
Fly.ioServers, database and networkAll service data, stored in the United States (San Jose, California)
MigaduOur own mailboxEmails you send to hello@withdoorman.com and our replies
Google FontsServing fonts on this websiteVisitors' IP address and browser details

Submissions also go wherever the customer points them (their email, Slack workspace or webhook). We may disclose data if required by law, or to protect the rights and safety of users and the service. If Doorman is acquired or merged, data may transfer to the new owner under this policy. We will give customers 30 days' notice of new subprocessors by email and on this page.

5. How long we keep it

DataKept for
Submissions, Free plan30 days
Submissions, Pro plan180 days
Submissions, Business plan365 days
Account, forms and keysUntil you delete the account
Login sessions30 days
Password reset links1 hour (7 days for the first “set a password” link)
Product event logsAbout 400 days
BackupsUp to 14 days
Billing recordsAs long as tax law requires, up to 7 years

Submissions older than the plan's period are deleted automatically. Moving to a plan with a shorter period deletes older submissions. Deleting your account removes its forms, keys and all submissions immediately (backups roll off within 14 days).

6. Cookies and local storage

We don't use advertising or third-party analytics cookies. The optional form script (d.js) sets no cookies; it adds a page-load timestamp and a hidden honeypot field to the form.

7. Security

Passwords are hashed with scrypt; API keys and session tokens are stored only as hashes. Traffic is encrypted in transit with HTTPS. Webhooks are signed so you can verify they came from us. Access to production data is limited to the people who run Doorman. No system is perfectly secure; if we learn of a breach affecting your data we will notify you without undue delay and within 72 hours where required.

8. International transfers

We and our subprocessors process data in the United States. Where data leaves the EEA or UK, we rely on the European Commission's Standard Contractual Clauses and, for the UK, the UK Addendum.

9. Your rights

Depending on where you live, you may have the right to access, correct, delete, export or restrict the use of your personal data, and to object to some uses. Customers can export everything we hold about their account as JSON, and delete the account, from Settings in the dashboard. For anything else, email hello@withdoorman.com. You can also complain to your local data protection authority.

If you submitted a form on a website that uses Doorman, contact that website's owner first: they control that data. We will forward requests we receive to them.

10. Children

Doorman is a business tool and isn't directed at children under 16. We don't knowingly collect their data as a controller.

11. Changes

We will post changes here and update the effective date. For material changes we will email account holders at least 30 days in advance.

12. Contact

Doorman. Email: hello@withdoorman.com.