Privacy Policy
Last updated: July 17, 2026
Data controller
Nate Alexeev
Israel
Contact: nate@doormatch.io
What we collect
When you use doormatch, we collect:
- Account information — name, email, phone, profile picture
- Authentication — password (hashed), OAuth tokens (if using Google/Apple login)
- Usage data — search queries, listing views, saved listings, application history
- Communication — chat messages between seekers and agents
- Documents — files you upload (ID, Schufa, payslips) for applications
- Device information — IP address, browser, device type, platform
- Calendar data — if you connect Google Calendar, we read your events and free/busy times to manage viewing appointments
Why we collect it
- To provide the platform — listing search, applications, scheduling, contracts
- To authenticate you and secure your account
- To enable communication between seekers and agents
- To generate analytics for agents (listing performance, conversion rates)
- To improve search results using AI-powered recommendations
- To send transactional emails (verification, reset, contract invitations)
Legal basis
We process your personal data under Article 6(1) of the GDPR:
- Performance of a contract — you signed up to use the service
- Legitimate interest — improving the service, preventing fraud
- Consent — marketing emails, optional calendar integration
- Legal obligation — retaining contracts per German commercial law
Who we share with
- Between platform users — seekers and agents share contact info and application docs necessary for renting
- Viewing participants — when a viewing is scheduled, the appointment details (including participant email addresses) are added to the Google Calendar events of the people invited to that viewing
- Infrastructure providers — hosting (EU only), email delivery, analytics — bound by DPAs
- AI processing — application content may be processed by Claude (Anthropic) to generate summaries and drafts. No training, EU residency preferred
- Not sold, not advertised — we don't sell your data or use it for advertising. We share it only with viewing participants, service providers under data-processing agreements, or as legally required.
Google user data
If you connect Google Calendar, doormatch uses Google APIs to manage property-viewing appointments. This section describes exactly how we handle data received from Google.
- What we access — events on your primary Google Calendar (we read, create, update, and delete viewing appointments) and your free/busy times
- Why — to schedule and sync property viewings and to prevent double-booking
- Token storage — the OAuth tokens that let us reach your calendar are stored server-side in our database under strict access controls
- Your calendar events — fetched on demand to display your calendar; they are not copied into our database. Viewing appointments that doormatch creates exist both as records in doormatch and as events in your Google Calendar
- Sharing — Google data is never sold and never used for advertising; it is shared only with viewing participants (event attendees), service providers under data-processing agreements, or as legally required
- Disconnect — disconnecting Google Calendar revokes doormatch's access to your Google account entirely (this includes Google Sign-In, so you may need to sign in with Google again) and deletes the stored tokens
- Retention — calendar tokens are kept until you disconnect or your account is permanently deleted, whichever comes first; fetched event and free/busy data is transient and is not retained
- Account deletion — deactivating your account in Settings is a soft deactivation; for permanent deletion of all data, including Google tokens, email nate@doormatch.io
doormatch's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Your rights
- Access your data — download a full export from Settings
- Correct inaccurate data — edit profile any time
- Deactivate your account — from Settings → Privacy; for permanent deletion of all data, email nate@doormatch.io
- Object to processing — contact us
- Complain to a supervisory authority — the Austrian Data Protection Authority (DSB) in the EU, or the Israeli Privacy Protection Authority
Retention
We keep active-account data for as long as your account is active. Deactivating your account in Settings is a soft deactivation; permanent deletion of all personal data happens on request to nate@doormatch.io. Google Calendar credentials are kept until you disconnect or your account is permanently deleted, whichever comes first; fetched event and free/busy data is transient (read on demand, never persisted). doormatch viewing records are kept until permanent account deletion completes. Contract-related data may be retained up to 10 years per German commercial law. Anonymized analytics may be kept indefinitely.
Contact
Questions, deletion requests, or concerns? nate@doormatch.io.