Business Privacy Policy
Effective Date: May 30, 2026
This policy describes how Doro handles business account data, campaign data, billing information, and linked social platform credentials. By using Doro as a business, you agree to the practices described here. If you do not agree, please discontinue use of the service.
1. Scope and Definitions
This policy applies to personal and business information we process when you use Doro business accounts, dashboards, and related services.
- Personal Information: information that relates to or could reasonably be linked with an identifiable individual or business contact.
- Platform Data: data from linked social platforms, including account IDs, usernames, and OAuth token metadata.
- Campaign Data: campaign setup, member submissions, analytics, moderation, reward verification, and related records.
- Service Providers: third parties that process information on our behalf to operate the platform.
2. Business Data We Collect
- Business profile information, contact details, address, and map location coordinates you provide
- Campaign configuration, prompts, rewards, and moderation actions
- Member submission and redemption records tied to your campaigns
- Campaign performance metrics and analytics dashboards
- Billing and payment metadata, including Stripe customer and payment method identifiers and campaign credit purchase history
- Device, usage, and security logs related to your business account
- Website cookie preferences where you use the business web portal
We do not collect member OAuth tokens, member passwords, or private social messages through your business account.
3. How We Use Business Information
- Create and manage business accounts and campaigns
- Process campaign credit purchases and billing records
- Display submission review, analytics, and reward verification tools
- Support fraud prevention, security, and platform enforcement
- Provide customer support and service communications
- Improve features and comply with legal obligations
Where applicable under GDPR and similar laws, we rely on contractual necessity, consent (for example social account linking), and legitimate interests in securing and improving the platform.
4. Social Media Data and Tokens
When a business links social accounts, we may store:
- Platform username and platform account/user ID
- OAuth access tokens and refresh tokens (if provided)
- Token expiration and linked-account metadata
- Approved analytics and insights metrics authorized by granted scopes
How this data is used:
- Enable linked-account features and relinking workflows
- Fetch approved analytics and insights metrics for your dashboards
- Support campaign verification and moderation operations
If you remove Doro from your Facebook or Instagram account in Meta settings, we receive a deauthorize notice, clear stored tokens, and mark the link disconnected. We may retain your username and platform user ID until you re-link or delete your business account, as described in Retention.
Token handling and security:
- Encrypted at rest using application encryption controls
- Transmitted over HTTPS/TLS
- Limited internal access with role-based controls
- Deleted from active records when accounts are unlinked
5. How We Share Information
- Members: campaign details, reward terms, and business profile information you publish may be visible to members participating in your campaigns
- Service Providers: cloud hosting, authentication, payments (Stripe), email, analytics, and security vendors under confidentiality and data-processing obligations
- Corporate transactions: in connection with a merger, acquisition, or asset sale, subject to this policy
- Law enforcement and regulators: when required by law (see Section 11)
We do not sell business personal data to data brokers.
6. Cookies and Website Technologies
On the business web portal, we use essential cookies and similar technologies needed for sign-in, session management, and account security. Our cookie banner lets you accept or decline non-essential uses where applicable; declining may limit sign-in and account features that depend on session cookies.
We do not use advertising cookies on the business portal for third-party ad targeting based on this policy as currently described.
7. Retention
- Linked social token credentials are retained while account linking is active and deleted from active records on unlink. If you revoke Doro in Meta (Facebook/Instagram) settings, we clear tokens and mark the link disconnected but may keep username and platform IDs until you re-link
- Campaign and analytics records are retained while needed for service operation, reporting, support, security, and legal compliance
- Billing and payment records may be retained for up to six years for tax, audit, and legal compliance purposes
- Account records are generally retained while your account is active and for a reasonable period afterward as required for legal, security, or operational purposes
8. Security
We use administrative, technical, and organizational safeguards designed to protect business information, including encrypted transport (HTTPS/TLS), encryption at rest for sensitive credentials, role-based internal access controls, and monitoring for abuse.
9. International Transfers
Doro is based in the United States. If you access the service from outside the U.S., your information may be transferred to, stored in, and processed in the U.S. or other countries where we or our service providers operate. We use appropriate safeguards where required by applicable law.
10. Your Choices and Rights
- Unlink social accounts from business settings
- Update business profile and contact information in your account
- Request access to, correction of, or deletion of your data
- Delete your account through account settings or our Data Deletion page
To exercise privacy rights, contact info@getdoro.co. We may need to verify your identity or authority before fulfilling a request.
Depending on where you live, you may have additional rights under laws such as GDPR, CCPA/CPRA, or VCDPA. We do not sell personal information.
11. Processors and Integrations
We use service providers and APIs, including:
- Cloud hosting and storage infrastructure (including AWS services)
- Identity/authentication providers (including Amazon Cognito)
- Social platform APIs (including Instagram/Meta)
- Payments infrastructure (Stripe) for campaign credit purchases
- Email and communications infrastructure
12. Requests from Public Authorities
- We review each request for legal validity and scope
- We challenge or narrow overbroad requests where legally permitted
- We disclose only data required by law (data minimization)
- We document requests, responses, and legal reasoning
13. Changes to This Policy
We may update this policy from time to time. If we make material changes, we will update the effective date at the top of this page and may provide additional notice by email or in-app message. Continued use after the effective date means you accept the updated policy.
14. Contact
Privacy questions can be sent to info@getdoro.co.