Privacy Policy

Last updated: July 17, 2026

Data controller

Nate Alexeev
Israel
Contact: nate@doormatch.io

What we collect

When you use doormatch, we collect:

  • Account information — name, email, phone, profile picture
  • Authentication — password (hashed), OAuth tokens (if using Google/Apple login)
  • Usage data — search queries, listing views, saved listings, application history
  • Communication — chat messages between seekers and agents
  • Documents — files you upload (ID, Schufa, payslips) for applications
  • Device information — IP address, browser, device type, platform
  • Calendar data — if you connect Google Calendar, we read your events and free/busy times to manage viewing appointments

Why we collect it

  • To provide the platform — listing search, applications, scheduling, contracts
  • To authenticate you and secure your account
  • To enable communication between seekers and agents
  • To generate analytics for agents (listing performance, conversion rates)
  • To improve search results using AI-powered recommendations
  • To send transactional emails (verification, reset, contract invitations)

Legal basis

We process your personal data under Article 6(1) of the GDPR:

  • Performance of a contract — you signed up to use the service
  • Legitimate interest — improving the service, preventing fraud
  • Consent — marketing emails, optional calendar integration
  • Legal obligation — retaining contracts per German commercial law

Who we share with

  • Between platform users — seekers and agents share contact info and application docs necessary for renting
  • Viewing participants — when a viewing is scheduled, the appointment details (including participant email addresses) are added to the Google Calendar events of the people invited to that viewing
  • Infrastructure providers — hosting (EU only), email delivery, analytics — bound by DPAs
  • AI processing — application content may be processed by Claude (Anthropic) to generate summaries and drafts. No training, EU residency preferred
  • Not sold, not advertised — we don't sell your data or use it for advertising. We share it only with viewing participants, service providers under data-processing agreements, or as legally required.

Google user data

If you connect Google Calendar, doormatch uses Google APIs to manage property-viewing appointments. This section describes exactly how we handle data received from Google.

  • What we access — events on your primary Google Calendar (we read, create, update, and delete viewing appointments) and your free/busy times
  • Why — to schedule and sync property viewings and to prevent double-booking
  • Token storage — the OAuth tokens that let us reach your calendar are stored server-side in our database under strict access controls
  • Your calendar events — fetched on demand to display your calendar; they are not copied into our database. Viewing appointments that doormatch creates exist both as records in doormatch and as events in your Google Calendar
  • Sharing — Google data is never sold and never used for advertising; it is shared only with viewing participants (event attendees), service providers under data-processing agreements, or as legally required
  • Disconnect — disconnecting Google Calendar revokes doormatch's access to your Google account entirely (this includes Google Sign-In, so you may need to sign in with Google again) and deletes the stored tokens
  • Retention — calendar tokens are kept until you disconnect or your account is permanently deleted, whichever comes first; fetched event and free/busy data is transient and is not retained
  • Account deletion — deactivating your account in Settings is a soft deactivation; for permanent deletion of all data, including Google tokens, email nate@doormatch.io

doormatch's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Your rights

Retention

We keep active-account data for as long as your account is active. Deactivating your account in Settings is a soft deactivation; permanent deletion of all personal data happens on request to nate@doormatch.io. Google Calendar credentials are kept until you disconnect or your account is permanently deleted, whichever comes first; fetched event and free/busy data is transient (read on demand, never persisted). doormatch viewing records are kept until permanent account deletion completes. Contract-related data may be retained up to 10 years per German commercial law. Anonymized analytics may be kept indefinitely.

Contact

Questions, deletion requests, or concerns? nate@doormatch.io.