Privacy Policy
Last updated July 11, 2026
DoorDroppr is built on honest, first-party, offline attribution. We measure that a flyer worked — not who you are across the web. This policy explains what we collect, why, how long we keep it, and the rights you have. It applies to workers who walk routes, organizations that run campaigns, and recipients who scan a DoorDroppr QR code.
01Controller and processor — who is responsible
DoorDroppr operates in two distinct roles depending on the data:
- DoorDroppr as controller. For account creation, authentication, billing, security, and our own product operation, we determine the purposes and means of processing.
- DoorDroppr as processor. For the campaign, coverage, scan, and conversion data an organization generates by using DoorDroppr, the organization is the controller and we process that data on its behalf, under its instructions, per our Data Processing Agreement. The organization is responsible for having a lawful basis to collect worker location data and recipient attribution data, and for its own notices to workers and customers.
If you are a worker or recipient with questions about an organization's use of your data, contact that organization first; we support lawful requests routed through them.
02What we collect (and what we don't)
We practice data minimization — we collect only what the service needs to function, and we process on-device wherever we can so raw signals never have to leave the phone.
Information you provide
- Account data: name/display name, email, and a password (stored only as a salted hash by our auth provider — never plaintext).
- Organization data: organization name, your role, and invite codes you create or redeem.
- Support communications you send us.
Location and motion data (workers) — sensitive
We do not track your location when you are not on an active shift. Background collection stops when you end or pause a shift. While a shift runs, a persistent notification makes tracking visible, and you can revoke the OS location permission at any time.
Shift, attribution, and conversion data
- Shift and coverage data: start/end time, distance walked, doors/segments covered, assigned route, and computed coverage stats.
- Attribution data (recipients): when someone scans a QR or follows a short link, we log — server-side — a timestamp, a coarse IP-derived approximate location (city/region, not a precise address), a user-agent, a session identifier, the landing URL, and a first-party attribution token so a later booking can be tied back to the flyer.
- Conversion data: when a scan leads to a booking, lead, purchase, or call, we may record the event type, value, currency, and an external reference. We do not collect full payment-card numbers.
- Device and technical data: app version, device model, OS, language, IP address, crash logs, and diagnostics needed to run and secure the service.
What we deliberately do not collect
- No biometric identifiers (face/fingerprint) — device unlock is handled by your OS, not us.
- No contacts, photos, microphone, or camera content beyond a QR scan you initiate.
- No cross-site advertising profiles, and no personal data purchased from brokers.
03Why we use your data
| Purpose | Data used |
|---|---|
| Create and secure your account | Account, device |
| Map coverage while you walk a shift (consent-based) | Location, motion/gait, shift |
| Show the live team map to your organization | Location, shift |
| Measure flyer → scan → booking performance | Attribution, conversion |
| Billing and subscription management | Account, plan |
| Reliability, fraud prevention, and security | Device, technical, shift |
Where we rely on consent — most importantly for background location — you may withdraw it at any time by ending shifts and revoking the OS permission. Withdrawal does not affect processing already carried out lawfully.
04Worker monitoring — our commitments
- Shift-scoped only. Location and motion collection happens only during an active shift the worker started — no off-shift, 24/7, or covert tracking.
- Transparent. An on-device notification makes active tracking visible.
- Purpose-limited. Used for coverage mapping, the live team map, effort stats, and delivery verification — not unrelated surveillance.
- Organization responsibility. Employers using DoorDroppr must comply with applicable worker-notice and consent laws and inform workers before requiring the app.
05Automated decision-making and verification scores
DoorDroppr may compute a delivery-verification confidence score from shift, location, and motion/gait signals to estimate whether a route was genuinely walked. Where such a score could have a legal or similarly significant effect on a worker (for example, in a marketplace payout context):
- We provide meaningful information about the logic involved;
- A person — not software alone — makes the final decision (human review);
- You can contest the outcome and ask for it to be re-examined.
We do not currently make solely-automated decisions that produce legal effects without a human in the loop.
06How we share data
We do not sell your personal data and do not share it for cross-context behavioral advertising. We share only with: your own organization's admins; vetted subprocessors under contract (hosting/database/auth, map basemap and routing providers, app-store and OS location/motion services, a payment processor when paid plans are enabled, and error/diagnostics tooling); as required by law or to protect safety; and in a business transfer subject to this policy.
07Cookies and the attribution token
Attribution uses first-party cookies and local storage on the landing pages reached through a scan — not third-party ad-tech. Where required by law, the organization's landing page must obtain consent before non-essential cookies are set, and must honor Global Privacy Control and consent-mode signals. The mobile app uses no third-party advertising SDKs.
08How long we keep data
| Data | Retention target |
|---|---|
| Account data | Life of the account + 30–90 days after a deletion request |
| Precise location breadcrumb trails | About 12 months, then deleted or aggregated to coverage-only |
| Motion / gait-derived measures | About 12 months, alongside the shift they belong to |
| Scan / attribution events | Up to 24 months |
| Diagnostics / logs | About 90 days |
| Billing records | As required by tax/accounting law |
In-product history on free plans may be visible for a shorter window than our backend retention; the table above governs deletion, not in-app visibility.
09Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, or port your data; to restrict or object to certain processing; to withdraw consent (e.g. revoke location permission); to opt out of any sale/sharing for ads (we do neither, but we honor GPC); to non-discrimination for exercising your rights; to appeal our decision on a request; and to lodge a complaint with your data-protection authority or attorney general.
To exercise these rights, email hello@turf.example or use in-app account controls. If your data was generated within an organization that is the controller, we will route or support your request with that organization.
10Security, transfers, children, and changes
- Security: encryption in transit and at rest, tenant isolation enforced by row-level security, least-privilege access, and server-side-only handling of sensitive operations. We notify affected users and regulators of a qualifying breach as required by law.
- International transfers: where we move data across borders we rely on appropriate safeguards such as the EU Standard Contractual Clauses and the UK IDTA/Addendum.
- Children: the service is for adults in a work context and is not directed to children.
- Changes: we may update this policy and will note the new date; material changes will be signalled in-app or by email.
Questions, requests, or complaints? Email hello@turf.example.