Doorman
Privacy notice
Last updated 10 August 2026
The short version
Doorman helps a shop check that a shopper is old enough to buy age-restricted products. When a shopper takes a photo for an age check, that photo is analysed in memory and discarded within the same request. It is never written to disk, never stored, never sent anywhere else, and never seen by a person. We do not keep the photo, and we do not create or keep a face template or any other biometric identifier.
Who is responsible for what
The merchant running the shop decides that an age check is required and is the controller of that decision. Doorman acts as a processor on their behalf. If you are a shopper with a question about a specific shop, contact that shop first.
What we process, and why
| Data | Why | How long |
|---|---|---|
| A single photo frame (only if the shopper chooses the photo check) | To estimate an apparent age | Held in memory for the length of one request, then discarded. Never stored. |
| A date of birth (only if the shopper uses that route) | To compare against the required age | Used during the request only. Never stored. |
| IP address | To determine the country and region, so that photo checks are not offered where local law restricts them | Used during the request only. Never stored. |
| A record that a check happened | So the merchant can show an inspector that checks are being carried out | Stored. Contains the time, the method used, the outcome, the age required, a five-year apparent-age band, the country/region, and a reference code. It contains no name, no photo, no date of birth and no IP address. |
| Shop settings, rules and Shopify session credentials | To run the app for the merchant | Stored while the app is installed. |
Automated decisions
An age estimate is produced by software, not by a person. It is deliberately not treated as a final answer: a shopper whose estimated age is close to the threshold is asked to verify another way rather than being refused. A shopper who believes a decision was wrong can ask the shop to verify them by another route.
Where photo checks are not offered
Photo-based age estimation is switched off for shoppers located in Illinois and Texas. Those shoppers are offered a non-biometric route instead. Merchants can add further regions.
Retention and destruction
Photo frames and dates of birth are destroyed at the end of the request that used them — in practice within about a second, and always before the response is returned. No copy is retained in any backup, log or cache. Records that a check happened are kept for as long as the merchant needs them for compliance purposes and are deleted within 30 days of the app being uninstalled, along with the shop's settings and credentials.
Sub-processors
Hosting is provided by Oracle Cloud. If a merchant enables optional identity-document checks, that check is carried out by the document verification provider they have chosen, under that provider's own terms; we receive only a pass or fail and a reference code.
Your rights
Depending on where you live you may have the right to access, correct, delete or object to the processing of your personal data. Because we do not store photos, dates of birth, names or IP addresses, there is generally nothing held about an individual shopper to retrieve. Requests can be sent to the address below and are answered within 30 days.
Contact
Questions or requests: privacy@doorman.app