Privacy Policy
The short version, up front: we collect your account basics (name, email), your listings and photos, bookings, messages, and payment/verification data handled by Stripe — including, only with your separate express consent, a biometric selfie match for ID verification. It's shared with the other party to your rental (what they need for the handoff) and the providers that run doop — Clerk, Stripe, Neon, Vercel, Resend — which store data in the United States. We never sell your personal information.
1. Who is responsible
doop (legal entity being incorporated) is responsible for personal information under its control. Our privacy officer can be reached at privacy@doop.to — questions, requests, and complaints all start there.
2. What we collect, and why
We collect only what these purposes need, and new purposes get new consent.
- Account: name and email (via Clerk, our sign-in provider) — to create and secure your account.
- Profile: display name, bio, avatar — your public presence on doop.
- Listings: titles, descriptions, photos, replacement value, city — to run the marketplace.
- Bookings and payments: dates, amounts, booking references. Card details are handled by Stripe — we never see or store card numbers. Owners' payout details live with Stripe Connect.
- Identity verification: a government-ID check and biometric selfie match performed by Stripe Identity, only with your express consent — we store only the pass/fail outcome and date, never your ID images or biometric data.
- Messages: booking-thread messages — to coordinate handoffs and as evidence if something is disputed.
- Usage and logs: IP address, device/browser, timestamps — for security and debugging.
- Consent records: which Terms version you accepted and when, and any marketing opt-in.
3. Biometric ID verification — express consent and an alternative
- Verification is performed by Stripe Identity as our service provider. The selfie's facial geometry is matched to your ID; Stripe retains this data only per its own notice (deletion within about a year).
- This is sensitive information, so we ask for your express, opt-in consent inside the verification flow — separate from this policy.
- You can decline biometric verification and request a manual alternative (slower document review) at privacy@doop.to.
4. Who we share with — and who we don't
- The other party to a booking: your display name, profile, city-level location, and verification status; at confirmation, what's needed to coordinate pickup. Never your payment details.
- Service providers under contract: Clerk (authentication), Stripe (payments, payouts, identity), Neon (database), Vercel (hosting and photo storage), Resend (email). Each may use the data only to provide its service to us.
- Legal: when required by law or court order, or to protect users or doop from fraud and abuse; and professional advisors under confidentiality.
- We do not sell personal information, and we do not share it for third-party advertising.
5. Where your data is stored
Our providers store and process data primarily in the United States. While there, it is subject to US law and may be accessible to US authorities under lawful-access regimes. We use contractual and technical safeguards, but we can't make foreign law inapplicable — using doop means your information will be transferred to these providers.
6. How long we keep things
When a retention period ends, we delete or irreversibly de-identify the data.
- Account and profile: while your account is active, plus 2 years after closure.
- Transactions, receipts, payouts: 7 years (tax and financial-record requirements).
- Booking messages and handoff evidence: 2 years after the booking closes (dispute window).
- ID verification outcome: while your account is active. (Stripe deletes the underlying biometric data per section 3.)
- Consent records: life of the account plus 2 years.
- Server logs: about 90 days.
- Our internal breach log: at least 24 months (legal requirement).
7. How we protect it
Encryption in transit and at rest, access limited to those who need it, payment data never touching our servers (Stripe-hosted checkout), and managed secrets. No system is perfectly secure — which is why the next section exists.
8. If something goes wrong
We keep a record of every breach of security safeguards for at least 24 months. If a breach creates a real risk of significant harm, we will report it to the Privacy Commissioner of Canada as soon as feasible and notify affected people directly — what happened, what information was involved, and what we're doing about it.
9. Your rights
You may access the personal information we hold about you and how it's used, correct it, withdraw consent (some features — like booking — may stop working, and this doesn't undo processing already done or data we must legally keep), and close your account. Write to privacy@doop.to; we respond within 30 days. If you're not satisfied, you can complain to our privacy officer and to the Office of the Privacy Commissioner of Canada (priv.gc.ca).
10. Email
- Transactional email (booking requests and confirmations, messages, receipts, security notices) is part of the service.
- Marketing email is sent only with your express opt-in — never a pre-checked box — and always includes a working unsubscribe, honoured within 10 business days.
11. Cookies
We use only cookies necessary to run doop (sign-in sessions, security). No advertising or cross-site tracking cookies.
12. Age and scope
doop is for adults (18+) in Ontario, Canada. We don't knowingly collect information from minors, and we delete it if we discover it. This policy doesn't yet address Quebec or US privacy laws — the service isn't offered there.
13. Changes
We'll post changes here and notify you of material ones. For genuinely new purposes, we'll ask for consent. Contact: privacy@doop.to.