Privacy Policy
DOQR is a digital doorbell service that requires no physical hardware. Door managers use the app; visitors scan the QR code and ring without installing an app. The manager can then choose a text, audio, or video response.
Data we collect
- Account information: email address, internal user ID, and account or plan status.
- Digital doorbell and communication data: doorbell names and settings, QR links, optional visitor name and type, messages, call type, timestamps, courier notes, and delivery information entered by a door manager.
- Device and security data: notification token, operating system and app version, browser user agent, language, time zone, and approximate device capabilities. Visitor IP addresses and device combinations are transformed into one-way keyed hashes for security and blocking.
- Purchase information: product ID, subscription status and expiry, and a one-way hash of the purchase token. DOQR does not see or store card or bank details; payments are processed by Google Play or the App Store.
- Camera and microphone: used with permission only when a user starts or accepts an audio or video call. Audio and video are not recorded. During a call they are transmitted through WebRTC directly between peers or, when required, through encrypted TURN relay.
Why we use data
We use data to operate accounts and digital doorbells, send visitor notifications, provide text, audio, and video communication, prevent misuse and repeated ring spam, block devices, verify subscriptions, maintain security, and provide support. DOQR does not display advertising, sell personal data, or create advertising profiles.
Service providers
To the extent needed to operate the service, data may be processed using Supabase for authentication, database, and realtime communication; Google Firebase/FCM for notifications; Cloudflare for WebRTC TURN relay when required; and Google Play or the App Store for purchases. These providers act under their own contracts and security obligations.
Retention and deletion
Visit history is limited by plan rules: Free accounts retain the three most recent records and Pro accounts retain up to 90 days. Security, subscription, and transaction records may be retained as needed for service security, fraud prevention, or legal obligations. When an account is deleted, directly related data is deleted or de-identified. Backup copies are removed through the normal backup cycle.
Security
We use HTTPS/TLS in transit, authorization checks, row-level access controls, short-lived call credentials, and one-way hashing for sensitive tokens. No online service can guarantee absolute security.
Your choices and rights
Delete your account from menu → Delete my account in the app, or submit a request through the account and data deletion page. Camera, microphone, and notification permissions can be changed in device settings.
Children’s privacy
DOQR is not designed for children and does not target people under 18.
Contact
For privacy or data requests, contact doqr@yummyorderapp.com.