Doors
PrivacyTerms

Doors

Privacy Policy

Effective 6 August 2026. Version 1.0.

Summary. This Privacy Policy explains what personal information Doors collects, why it is collected, the legal bases relied upon, to whom it is disclosed, how long it is retained, and the rights available to you. Doors does not sell personal information, does not display advertising, does not use third-party analytics or advertising trackers, and does not use your content to train artificial intelligence models. You may delete your account and its associated data at any time from Settings. This summary is provided for convenience only; the sections below govern.

1. Who we are

Doors (the “Service”) is operated by Carter Hunnisett, an individual established in Toronto, Ontario, Canada (“Doors”, “we”, “us” or “our”). For the purposes of the United Kingdom and European Union General Data Protection Regulation (the “GDPR”), we are the controller of the personal data described in this Policy. For the purposes of the Personal Information Protection and Electronic Documents Act (Canada), we are the organisation responsible for the personal information under our control.

In this Policy, “personal information” and “personal data” are used interchangeably and mean information about an identifiable individual. “You” means the individual using the Service.

This Policy applies to the Service and to communications we send in connection with it. It does not apply to third-party services reachable from the Service, which are governed by their own policies.

2. Summary of processing

The table below summarises each category of personal information we process. Sections 3 to 8 set out the detail.

Categories of personal information processed by Doors
CategoryInformationPurposeLawful basisIdentifiabilityDisclosure
AccountEmail address; password, stored only as a cryptographic hashAuthentication and account administration; service communicationsPerformance of a contractIdentifiableOur authentication provider only. Not visible to other users.
ProfileUsername, display name, biography, profile imageIdentification of your account to other usersPerformance of a contractIdentifiableVisible to all authenticated users of the Service.
LocationHome city, region and country; geographic coordinates where you elect to provide themOrdering shows and suggested accounts by proximityConsentIdentifiableYour city, region and country are visible to authenticated users. Coordinates are disclosed to no other user and are transmitted to no browser other than your own.
ActivityShows logged, ratings, written descriptions, photographs, companions recorded, attendance intentionsProvision of the core functionality of the ServicePerformance of a contractIdentifiableVaries by entry. See section 5.
Social graphAccounts followed, followers, blocks, likesGeneration of your feed; enforcement of blockingPerformance of a contractIdentifiableFollower and following lists are visible to authenticated users. Blocks are not disclosed to the blocked account.
SpotifySpotify display name, most-played artists, and access and refresh tokens, where you connect the integrationRecommending artists you may wish to see performConsentIdentifiableNot disclosed. Tokens are accessible only to our server processes.
SupportFeedback messages and abuse reports you submitMaintaining and improving the Service; acting on reports of abuseLegitimate interestsIdentifiableAdministrators of the Service, and our email provider for notification purposes.
TechnicalServer logs; a cryptographic hash of your IP address on authentication eventsSecurity, abuse prevention and rate limitingLegitimate interestsNot identifiableNot disclosed. IP addresses are hashed before storage and cannot be recovered.

We do not collect: advertising identifiers; browsing activity on other websites; contact lists; microphone or camera access (photographs are selected by you from your device); payment card or financial information, the Service being provided free of charge and processing no payments; or continuous or background location.

3. Information we collect

3.1 Information you provide. Information entered when registering, completing your profile, recording attendance at a show, rating a show, writing notes, uploading photographs, tagging companions, submitting feedback, and reporting content.

3.2 Information generated by your use of the Service. The accounts you follow, accounts you block, entries you like, and the records necessary to operate security controls such as rate limiting.

3.3 Information received from third parties. Where you connect your Spotify account, we receive your Spotify display name and most-played artists from Spotify. We also obtain information about artists, venues and events from Ticketmaster and Setlist.fm; that information does not relate to you.

4. Purposes and lawful bases

Where the GDPR applies, we rely on the lawful bases identified in the table at section 2, namely:

  • Performance of a contract (Article 6(1)(b)), to provide the account and functionality you have requested;
  • Legitimate interests (Article 6(1)(f)), to keep the Service secure, to prevent abuse, and to maintain and improve the Service. We have assessed that these interests are not overridden by your rights and freedoms, in part because the information used for these purposes is minimised and, in the case of IP addresses, is hashed before storage;
  • Consent (Article 6(1)(a)), for geographic coordinates and for the Spotify integration. Consent may be withdrawn at any time in Settings, without affecting the lawfulness of processing carried out before withdrawal; and
  • Compliance with a legal obligation (Article 6(1)(c)), where we are required to retain or disclose information by law.

We do not process special categories of personal data within the meaning of Article 9 of the GDPR, and you should not submit such data through the Service.

5. Visibility of your information to other users

The Service is a social platform, and certain information is intended to be seen by others. The following statements describe the position accurately.

5.1 Visible to all authenticated users. Your profile; the shows you have logged, the ratings you have given them, and the written description you attach to an entry; and your follower and following lists.

5.2 Visible only to you. Your geographic coordinates; your email address; entries you have marked private; photographs you have uploaded; and the accounts you have blocked.

5.3 Descriptions are not private notes. The text you write about a show forms part of your review and is visible to other users alongside your rating. If you do not wish something to be readable by others, do not record it there; mark the entry private instead, which withholds the entry in its entirety.

5.4 Not accessible without an account. Application data is not accessible to a person who is not authenticated, and profiles are not published to search engines. Two exceptions apply: profile images and venue map images are held in public storage and are retrievable by any person holding the direct file address, although they are neither listed nor indexed.

5.5 Blocked accounts. An account you have blocked cannot view your activity, follow you, like your entries, tag you, or cause notifications to be delivered to you.

6. Cookies and similar technologies

The Service uses a small number of cookies, each of which is strictly necessary for the Service to function. We do not use cookies for advertising, profiling or third-party analytics, and accordingly we do not present a cookie consent banner.

  • Authentication cookies, set by our authentication provider, which maintain your signed-in session and persist until you sign out or they expire;
  • A password-reset marker, set only when you follow a password-reset link, which expires after fifteen minutes; and
  • A referral cookie, set only where you arrive by an invitation link, which records the inviting username so that the invitation may be honoured after registration, and which expires after thirty days.

The Service also uses your browser’s local storage to record which prompts you have dismissed, so that they are not presented repeatedly. That storage contains no personal information and no authentication tokens.

As each of these is strictly necessary, refusing them in your browser will prevent the Service from operating. No other consequence follows from refusing them.

7. Automated processing and artificial intelligence

7.1 Recommendations are algorithmic. Shows and accounts suggested to you are produced by deterministic program logic: overlap between the genres of artists you have logged, distance from your stated home location, and the number of accounts you follow who have indicated attendance. No machine learning model and no large language model is used to rank or to generate anything presented to you.

7.2 Your content is not used to train models. We do not transmit your content to any provider of artificial intelligence services, and we do not use it to train, fine-tune or evaluate any model, whether our own or that of a third party.

7.3 Development of the software. Parts of the software comprising the Service were written with the assistance of artificial intelligence tools. This concerns the authorship of source code only; no user content was involved.

7.4 No solely automated decision-making. We do not carry out decision-making based solely on automated processing which produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 of the GDPR. Decisions to remove content or to suspend an account are taken by a person.

7.5 Future changes. If we introduce a feature that submits your content to an artificial intelligence system, we will amend this Policy and give notice before that feature becomes available, and will obtain your consent where consent is required.

8. Disclosure of your information

We do not sell personal information, and we do not disclose it for advertising or marketing purposes. We disclose personal information only as set out below.

8.1 Service providers. We engage the following processors, each of which acts on our documented instructions and is bound by contractual confidentiality and security obligations:

  • Supabase— database, authentication and file storage. All information you submit is stored with this provider.
  • Vercel— application hosting. Processes requests and retains short-lived server logs.
  • Resend— transactional email delivery, comprising account emails sent to you and internal notifications when feedback is submitted.
  • Spotify— only where you connect the integration, and only to retrieve your most-played artists.
  • Mapbox— retrieval of a static map image for a venue. The request is made by our server, once per venue, and contains the coordinates of the venue only. No information relating to you is transmitted, and the resulting image is thereafter served from our own storage.

8.2 Third-party sources. We retrieve artist, venue and event information from Ticketmaster and Setlist.fm. We transmit search terms and entity identifiers to those services from our servers. We do not transmit information that identifies you.

8.3 Images retrieved directly by your browser. Artist images are served from content delivery networks operated by Ticketmaster and Spotify rather than copied to our own storage. Accordingly, when a page displaying such an image is rendered, your browser requests that image directly from the network concerned, which necessarily receives your IP address and browser user-agent string. We restrict the referrer transmitted with those requests to our own origin, so the particular page you are viewing is not disclosed.

8.4 Legal and safety disclosures. We may disclose personal information where required by applicable law, court order or binding request from a public authority; where necessary to establish, exercise or defend legal claims; or where necessary to protect the vital interests of any person. Where we are compelled to disclose your information, we will notify you unless prohibited from doing so by law or by the terms of the request.

8.5 Takedown notices. Where you submit a notice under clause 8 of the Terms of Service alleging that content infringes your rights, we will ordinarily provide a copy of that notice, including your identity and contact details, to the user who submitted the content in order that they may respond. We will withhold it where doing so would place a person at risk.

8.6 Business transfers. If the Service is transferred to another operator, personal information may be transferred as part of that transaction. We will give notice before your information becomes subject to a materially different privacy policy.

9. International transfers

Our processors may store and process personal information in countries other than your own, including the United States. Where personal information is transferred out of the United Kingdom or the European Economic Area, that transfer is made under an adequacy decision where one applies, and otherwise under the European Commission’s Standard Contractual Clauses or the United Kingdom International Data Transfer Addendum, together with any supplementary measures required. Further information about these safeguards may be requested using the contact details at section 15.

10. Retention

We retain personal information only for as long as is necessary for the purposes set out in this Policy.

  • Account and content— retained until you delete them or delete your account.
  • Deleted accounts— removed from live systems promptly upon deletion, including uploaded photographs. Encrypted backups may retain a copy for up to thirty days, after which they are overwritten.
  • Security records, comprising hashed authentication throttling data — retained for no more than twenty-four hours.
  • Feedback messages— retained until you delete your account, at which point they are deleted with it.
  • Abuse reports— retained while the report is open, and thereafter as a record of the action taken. A report is deleted if the account which submitted it, the account to which it relates, or the entry to which it relates is deleted.
  • Server logs— retained by our hosting provider in accordance with its standard retention period.

11. Security

We implement technical and organisational measures appropriate to the risk. Access control is enforced at the database layer by row-level security policies rather than in application code alone, so that access control does not depend solely upon the correctness of any single part of the application. Passwords are hashed by our authentication provider and are not accessible to us. Photographs attached to a show are held in private storage and served through short-lived signed links; profile images are held in public storage, as they are displayed to other users. Authentication attempts and outbound account emails are rate limited, and IP addresses used for that purpose are hashed before storage.

No method of transmission or storage is entirely secure, and we cannot guarantee absolute security. In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within seventy-two hours where required to do so, and will notify you without undue delay where the breach is likely to result in a high risk to you.

If you believe you have identified a security vulnerability, please report it to the address at section 15 before disclosing it publicly.

12. Your rights

Subject to applicable law, you have the following rights in relation to your personal information. Several may be exercised directly within the Service without contacting us.

  • Access— to obtain confirmation of whether we process your personal information, and a copy of it.
  • Rectification— to have inaccurate information corrected. Your profile and location may be amended in Settings.
  • Erasure— to have your personal information deleted. Settings → Delete account removes your profile, logged shows, ratings, descriptions, photographs, social connections, feedback messages and any reports you have submitted. The operation takes effect immediately and cannot be reversed, subject only to the backup period stated at clause 10.
  • Restriction of processing— to require that we limit our processing in the circumstances provided by law.
  • Portability— to receive the information you have provided to us in a structured, commonly used and machine-readable format. Contact us and we will provide an export.
  • Objection— to object to processing carried out on the basis of our legitimate interests.
  • Withdrawal of consent— to withdraw consent to the Spotify integration or to the storage of geographic coordinates, in Settings, at any time.
  • Complaint— to lodge a complaint with a supervisory authority: in the United Kingdom, the Information Commissioner’s Office; in the European Union, the authority in your country of residence; and in Canada, the Office of the Privacy Commissioner of Canada.

12.1 Residents of California. We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined in the California Consumer Privacy Act as amended, and we have not done so in the preceding twelve months. Californian residents may exercise the rights to know, to delete, to correct, and to be free from discrimination for exercising those rights, using the contact details at section 15.

12.2 Exercising your rights. We will respond to a request within thirty days, and will inform you if a longer period is required together with the reason. We may need to verify your identity before acting on a request, and will do so using information already in our possession. No charge is made for exercising your rights unless a request is manifestly unfounded or excessive.

13. Children

The Service is not directed to children under the age of 13, and we do not knowingly collect personal information from them. If you believe a child has provided personal information to us, please contact us and we will delete the account and the associated data. Where a higher minimum age applies in your jurisdiction, that age applies instead.

14. Changes to this Policy

We may amend this Policy from time to time. The effective date at the head of this document will be updated accordingly. Where a change is material, we will give notice within the Service or by email before it takes effect. Your continued use of the Service after a change takes effect constitutes acceptance of the amended Policy.

15. Contact

Questions concerning this Policy, requests to exercise your rights, and requests for a copy of your data should be addressed to team@joindoors.com. A postal address will be provided on request.

© 2026 DoorsPrivacy PolicyTerms of ServiceBack to Doors