Privacy Policy

Last updated: July 17, 2026

Overview

Doorline LLC (“Doorline,” “we,” “us”) provides door-to-door canvassing software to organizations that run field campaigns — including political campaigns, advocacy and issue organizations, and the firms that run canvassing on their behalf. This Privacy Policy describes how we collect, use, disclose, and protect personal information in connection with our web console, our mobile applications, and the report pages available at doorline.app (together, the “Services”). We encourage you to read it in full.

Our customers use the Services to manage their campaigns and to record the work of their canvassers. In doing so, our customers upload and control voter and constituent information. Where we process that information on a customer’s behalf and under its instructions, the customer — not Doorline — is responsible for it and for its lawful collection and use. We process our customers’ uploaded information only to provide the Services, and each customer represents that it has the right to use that information for canvassing. We do not sell personal information, and we do not use it for advertising.

Personal information we collect and how we use it

We collect the following categories of personal information and use each of them to provide, secure, and support the Services:

Account information. When an administrator creates an account for you, we collect your name, email address, phone number, and a password. We use this information to authenticate you, administer your account, and keep it secure.

Canvassing activity. When a canvasser records activity at a door — such as a survey response, a door status, or a note — we collect that activity, the record it relates to, and the time it occurred. Authorized administrators within the same organization may review this activity. We use it to operate the canvass and to provide reporting to that organization. This can include contact preferences: when a person asks not to be contacted again, the organization’s administrators can record a do-not-contact request (with the reason given), and we use it to exclude that person from the organization’s future canvassing lists and exports.

Voter and constituent information. Our customers upload records that may include names, residential addresses, party affiliation, date of birth, gender, telephone numbers, electoral districts, voter identification numbers, and voting-participation records. Voters do not interact with the Services directly. We use this information only to provide the Services to the customer that uploaded it. Access is limited to that customer’s authorized users, and to Doorline personnel only under the support-access controls described in “How Doorline personnel access customer data” below.

Location information

When a canvasser records an action in our mobile app, we collect the device’s location and reported accuracy at that moment, together with the approximate distance between the device and the door. We collect location only at the time an action is recorded; we do not track location continuously or in the background. The app may display a canvasser’s live position on their own device to aid navigation, but that live position is not transmitted to us unless an action is recorded. To let canvassing continue where there is no signal, the app stores a copy of your assigned walk list (voter names, addresses, map locations, party, gender, and age) on your device. This copy is kept in the app’s cache storage, which iOS and Android exclude from device backups, and it is deleted when you sign out. Door results and survey responses you record while offline — including the GPS reading taken at the door — are saved on your device until a connection is available, and each is removed once it has been delivered to our servers.

Information collected automatically

When you use the Services, we automatically collect limited technical information, such as your IP address, the pages or resources you request, and the date and time of your request. We use this information to operate, secure, and troubleshoot the Services. We use local storage on your device to keep you signed in.

Maps. Our web console, our report pages, and our mobile apps display maps provided by Mapbox. When a map loads, your device connects to Mapbox to retrieve map imagery, and Mapbox receives technical information from your device, including your IP address and the map area being displayed. Mapbox’s handling of that information is described in its own privacy policy. We do not use advertising cookies or third-party advertising trackers on our sites or in our apps.

Published reports

A customer may choose to publish a report for its own clients at a unique link. A published report presents campaign progress on a map: door statuses and, where the customer chooses, responses to selected survey questions, shown at the address level. Responses appear only as the survey’s predefined answer choices — a write-in answer appears only as the word “Other,” never the typed text. Published reports exclude voter names, canvasser identities, and action timestamps. Report links created on or after July 15, 2026 are protected by a password and expire automatically — after 90 days by default, or a period of up to one year chosen by an administrator. A link’s password can be changed, or the link rotated, but a password can never be removed from a link. The customer controls who receives a link and its password and may revoke a link at any time. Links created before that date remain accessible until the customer revokes them, and we provide customers a tool to revoke them.

With whom we share information

We may share personal information as follows:

Within your organization. Information is available to authorized users of the customer organization you belong to, according to their role. Customer data is not shared with, or visible to, other customer organizations.

Service providers. We share information with service providers that perform functions on our behalf. These currently include: Heroku, which hosts our servers and databases and runs the systems that power Doorline; MongoDB Atlas, which stores our database on servers in the United States; Mapbox, which draws the maps you see on our website, in our mobile apps, and on report pages (when a map loads, Mapbox receives your device’s IP address and the area of the map being shown); Geocodio, which converts street addresses into map coordinates so each home appears in the right place on the map (we send only the street address — never anyone’s name); Resend, which sends account and security emails on our behalf — such as password-reset links and notices about your account or organization — and for that purpose receives the recipient’s name and email address; Expo, which delivers updates to our mobile app; and Apple and Google, which distribute our mobile app through their app stores and provide the location services built into their devices. These providers are authorized to use the information only as necessary to perform services for us. A current list of our service providers is available on request.

Legal and safety. We may disclose information where we believe in good faith that doing so is required by law or legal process, or is necessary to protect our rights, our users, or the public.

Business transfers. Information may be transferred in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.

We do not sell personal information, and we do not share it for advertising purposes.

How Doorline personnel access customer data

Doorline staff cannot open a customer organization’s voter or canvassing data in the product without an individual, time-limited support-access grant that names the reason for access. Each grant is limited to a single organization and expires automatically. Access under a grant is designed to be recorded in an audit log that identifies the staff member, the organization, what was accessed, when, and the stated reason, and those records are retained. Staff access is used to provide support, maintain security, and operate the Services.

How we protect information

We maintain reasonable administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, use, or disclosure. These include encryption of data in transit, storage on infrastructure that encrypts data at rest, access controls that limit each user to the information of their own organization, the staff-access controls described above, and the ability for administrators to disable access promptly. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

How long we keep information

While your organization’s account is active. We retain account and campaign information for as long as the related customer account is active, or as otherwise instructed by the customer organization that controls the information. An organization with an active subscription is never deleted for inactivity.

After termination. When a customer’s relationship with Doorline ends, the customer retains read-only access to the Services for 60 days and may export its data during that period. After that period, we aim to permanently delete the customer’s data.

Suspended accounts. If an organization’s subscription has been suspended and the organization has recorded no canvassing activity for approximately 30 months, we aim to permanently delete its data. Reactivating the subscription ends that period.

On request. A customer may request deletion of the information it controls at any time, and we aim to complete verified deletion requests within 30 days.

What deletion covers. Deletion removes the organization’s voter and constituent records, canvassing records, uploaded files, and identity records from our live systems. We retain records that document the deletion itself and our access logs, because they are the evidence that our controls operated; we also retain limited technical and billing records as needed to comply with our legal obligations or resolve disputes. We also retain aggregate, non-identifying usage statistics about the Services — for example, the total number of organizations served or doors knocked through the Services — which contain no personal information and do not identify any customer, user, or voter. Cached address-to-coordinate lookups, which contain no names, expire automatically after 18 months of disuse. Residual copies of deleted data may persist in our encrypted database backups for up to 12 months before being overwritten in the ordinary rotation of those backups; backups are used only for disaster recovery.

Deleting your account

You can delete your Doorline account yourself, at any time, from inside the mobile app: Profile → Delete account. Deletion takes effect immediately for your login and contact details: your email address, phone number, and password are removed, and your account can no longer be used to sign in.

The doors you knocked and the survey answers you recorded stay with the campaign. Those are the organization’s records of work performed, and the organization — not Doorline — controls them. Notwithstanding account deletion, your name remains attached to those field records for a limited period (180 days by default) so the organization can verify who performed which field work; canvassing records include the location at which each door was logged, and an organization must be able to attach that record to a person in order to check it. This is a fraud- and quality-prevention measure. After that period, we aim to remove your name so that the records no longer directly identify you; the records themselves, including door statuses, survey answers, timestamps, and recorded locations, remain part of the organization’s operational records. Administrative records reflecting actions you took in a supervisory role — such as work you assigned to others — are likewise retained as part of the organization’s records.

Account deletion is not available while you are the only administrator or the only billing administrator of an organization; you must first transfer that role. If you have already uninstalled the app, you can contact us at hello@doorline.app and we will process eligible deletion requests after verifying them.

Your privacy rights

Depending on where you live and subject to applicable law, you may have the right to request access to the personal information we hold about you, to correct or delete it, and to not be treated differently for exercising these rights. To make a request, contact us at hello@doorline.app. We may need to verify your identity before responding, and we will respond as required by applicable law.

If your information appears in a file uploaded by one of our customers, that customer controls the information. You may contact that organization directly, or contact us and we will refer your request to the controlling organization and assist as appropriate.

Your choices

You may decline the location permission on your device; you will still be able to browse the map and view records, but you will not be able to record canvass actions. You may request access to, correction of, or deletion of your personal information by contacting us, and you may ask your organization’s administrator to disable your account.

Children

The Services are not directed to, and are not intended for use by, anyone under 18 years of age, and we do not knowingly collect personal information from children through the Services. Voter files uploaded by our customers may lawfully include registered pre-registrants under 18; that information is controlled by the customer that uploaded it.

Changes to this policy

We may update this Privacy Policy from time to time. The “Last updated” date above reflects the most recent revision, and material changes will be communicated to affected customers and users.

How to contact us

If you have questions about this Privacy Policy or about your personal information, contact us at hello@doorline.app.