Member Privacy Policy
Effective Date: July 16, 2026
This Member Privacy Policy describes how Doro collects, uses, stores, and protects personal data for member accounts. By using Doro, you agree to the practices described here. If you do not agree, please discontinue use of the service.
1. Scope and Definitions
This policy applies to personal information we process when you use Doro as a member, including our website, mobile app, and related support interactions.
- Personal Information: information that relates to or could reasonably be linked with an identifiable individual.
- Platform Data: data we receive from linked social platforms (for example username, platform user ID, follower count, and OAuth token metadata).
- Campaign submission data: campaign submission content and related metadata (for example post URL, caption, tags, likes/views, and thumbnails).
- Service Providers: third parties that process personal information on our behalf to operate the platform.
2. Information We Collect
- Account data: name, email, profile details, and account preferences
- Age verification data: date of birth, and (if you are 13 to 17) a record that you acknowledged parent or legal guardian permission
- Campaign data: seat claims, reward redemption events, submissions, and campaign participation records
- Linked social account data: username, platform user ID, follower count, OAuth tokens, and token expiration metadata when you connect an account
- Performance insights: approved post and account metrics used for campaign verification, rewards, and analytics features you access
- Device and usage data: IP address, device type, app actions, and logs used for security, reliability, and support
- Location data (optional): when you grant permission, approximate location used for map and local discovery features
We do not collect your private direct messages, full follower or following lists, ad account credentials, or other social platform data you have not authorized through the linking flow.
3. How We Use Your Information
- Operate, secure, and maintain member accounts
- Verify age eligibility and enforce our minimum-age and guardian-permission requirements
- Verify campaign submissions and reward eligibility
- Display campaign participation status and strike information
- Support local discovery and map features
- Prevent fraud, enforce our terms, and respond to support requests
- Improve features and platform reliability
- Comply with legal obligations
Where applicable under GDPR and similar laws, we rely on consent (for example social account linking and optional location), contractual necessity to provide the service, and legitimate interests in securing and improving the platform.
4. Social Media Account Linking
You may voluntarily link social media accounts. Linking may be required for certain Doro campaign workflows.
When linked, we may use Platform Data to:
- Verify ownership and authenticity of campaign submissions
- Check required mentions, tags, or hashtags for campaign rules
- Fetch approved post metadata needed for campaign review and rewards
- Support account linking, relinking, and token-expiry handling
If you remove Doro from your Facebook or Instagram account in Meta settings, we receive a deauthorize notice, clear stored tokens, and mark the link disconnected. We may retain your username and platform user ID until you re-link or delete your Doro account, as described in Retention.
Token storage and security:
- OAuth tokens are encrypted at rest using application encryption controls
- All token traffic uses encrypted transport (HTTPS/TLS)
- Token access is restricted to server-side workflows that need it
- Tokens are not displayed to other users
5. How We Share Information
- Participating businesses: for campaigns you join, the sponsoring business may view your campaign submissions, redemption status, and related performance metrics for that campaign. Businesses do not receive your OAuth tokens, passwords, or unrelated private account data.
- Service Providers: cloud hosting, authentication, email, analytics, and security vendors under confidentiality and data-processing obligations
- Corporate transactions: in connection with a merger, acquisition, or asset sale, subject to this policy
- Law enforcement and regulators: when required by law or to protect rights and safety (see Section 10)
We do not sell or rent your personal information to data brokers.
6. Retention
- Linked social OAuth tokens are retained while your account linking is active. When you unlink in Doro, token credentials are removed from active records. When you revoke Doro in Meta (Facebook/Instagram) settings, we clear tokens and mark the link disconnected but may keep username and platform IDs until you re-link
- Date of birth and related age-verification records are retained while your account is active and for a reasonable period afterward as needed for eligibility enforcement, security, and legal compliance. We do not store date of birth when age verification indicates the user is under 13
- Campaign records are retained while needed for rewards, reporting, support, fraud prevention, and legal compliance
- Account records are generally retained while your account is active and for a reasonable period afterward as required for legal, security, or operational purposes
7. Security
We use administrative, technical, and organizational safeguards designed to protect personal information, including encrypted transport (HTTPS/TLS), encryption at rest for sensitive credentials, role-based internal access controls, and monitoring for abuse.
8. International Transfers
Doro is based in the United States. If you access the service from outside the U.S., your information may be transferred to, stored in, and processed in the U.S. or other countries where we or our service providers operate. We use appropriate safeguards where required by applicable law.
9. Your Choices and Rights
- Unlink social accounts from Doro settings when permitted (not allowed after you have started redeeming a reward on an active campaign seat)
- Revoke Doro in Facebook or Instagram account settings (Apps and websites / Connected experiences). This disconnects Instagram in Doro and may apply campaign strike rules if you already redeemed a reward
- Request access to, correction of, or deletion of your data
- Withdraw consent where processing is consent-based (see our Data Deletion page for account removal)
To exercise privacy rights, contact info@getdoro.co. We may need to verify your identity before fulfilling a request.
Depending on where you live, you may have additional rights under laws such as GDPR, CCPA/CPRA, or VCDPA, including the right to object to certain processing or opt out of sale/sharing where applicable. We do not sell personal information.
10. Requests from Public Authorities
- We review each request for legal validity and scope
- We challenge or narrow overbroad requests where legally permitted
- We disclose only the minimum data required by law
- We document requests, responses, and legal reasoning
11. Children's Privacy
Doro is not intended for children under 13. We require members to provide a date of birth to help enforce this rule. We do not knowingly collect or retain personal information from children under 13. If age verification indicates a user is under 13, we do not store the date of birth and the member cannot continue until they provide an eligible date of birth. If you believe we have collected information from a child under 13, contact us for prompt deletion. Users under 18 should use the service only with parent or guardian permission, as described in the Member Terms.
12. Changes to This Policy
We may update this policy from time to time. If we make material changes, we will update the effective date at the top of this page and may provide additional notice by email or in-app message. Continued use after the effective date means you accept the updated policy.
13. Contact
Privacy questions can be sent to info@getdoro.co.