Doorman

Privacy notice

Last updated 10 August 2026

The short version

Doorman helps a shop check that a shopper is old enough to buy age-restricted products. When a shopper takes a photo for an age check, that photo is analysed in memory and discarded within the same request. It is never written to disk, never stored, never sent anywhere else, and never seen by a person. We do not keep the photo, and we do not create or keep a face template or any other biometric identifier.

Who is responsible for what

The merchant running the shop decides that an age check is required and is the controller of that decision. Doorman acts as a processor on their behalf. If you are a shopper with a question about a specific shop, contact that shop first.

What we process, and why

DataWhyHow long
A single photo frame (only if the shopper chooses the photo check)To estimate an apparent ageHeld in memory for the length of one request, then discarded. Never stored.
A date of birth (only if the shopper uses that route)To compare against the required ageUsed during the request only. Never stored.
IP addressTo determine the country and region, so that photo checks are not offered where local law restricts themUsed during the request only. Never stored.
A record that a check happenedSo the merchant can show an inspector that checks are being carried outStored. Contains the time, the method used, the outcome, the age required, a five-year apparent-age band, the country/region, and a reference code. It contains no name, no photo, no date of birth and no IP address.
Shop settings, rules and Shopify session credentialsTo run the app for the merchantStored while the app is installed.

Automated decisions

An age estimate is produced by software, not by a person. It is deliberately not treated as a final answer: a shopper whose estimated age is close to the threshold is asked to verify another way rather than being refused. A shopper who believes a decision was wrong can ask the shop to verify them by another route.

Where photo checks are not offered

Photo-based age estimation is switched off for shoppers located in Illinois and Texas. Those shoppers are offered a non-biometric route instead. Merchants can add further regions.

Retention and destruction

Photo frames and dates of birth are destroyed at the end of the request that used them — in practice within about a second, and always before the response is returned. No copy is retained in any backup, log or cache. Records that a check happened are kept for as long as the merchant needs them for compliance purposes and are deleted within 30 days of the app being uninstalled, along with the shop's settings and credentials.

Sub-processors

Hosting is provided by Oracle Cloud. If a merchant enables optional identity-document checks, that check is carried out by the document verification provider they have chosen, under that provider's own terms; we receive only a pass or fail and a reference code.

Your rights

Depending on where you live you may have the right to access, correct, delete or object to the processing of your personal data. Because we do not store photos, dates of birth, names or IP addresses, there is generally nothing held about an individual shopper to retrieve. Requests can be sent to the address below and are answered within 30 days.

Contact

Questions or requests: privacy@doorman.app

Back to Doorman