Privacy policy
Last updated: July 3, 2026
Doorman is a Shopify app that helps merchants detect and block automated traffic on their storefront. This policy explains what data we process, why, who we share it with, and how long we keep it. It applies to the Doorman app, the diagnostic tools on this website (including the store audit), and this website itself. We've kept the language plain on purpose — if anything is unclear, write to us at [email protected].
The data controller for this policy is Edge Traversal LLC, a California limited liability company ("Doorman," "we," "us"), reachable by mail at 307 S. Pixley St, Orange, CA 92868, USA and by email at [email protected].
For the merchant's customers (storefront visitors), the merchant is the data controller and Doorman is a data processor under their direction. For the merchant themselves, and for visitors to this website, Doorman is the data controller.
Data we process from storefront visitors
When the Doorman script runs on a merchant's storefront, we record the following for each request that warrants a bot-detection check:
- IP address — used live for rate limiting, datacenter detection, and country lookup. Before a detection event is stored, the IP is anonymized by removing the host portion (IPv4 is reduced to its /24 network, IPv6 to its /48 prefix), so the stored event does not contain a full, identifying address. The full IP is also held transiently (under 60 seconds) in our rate-limit store.
- User-agent string — to detect headless and automated clients.
- Behavioral signals — timing, scroll, mouse movement, touch, WebGL fingerprint, browser features. These are scored client-side; only the score and the contributing signal names (e.g. headless_detected, no_interaction) are sent to our servers.
- Country code — derived from IP via MaxMind GeoLite2.
- Cart and checkout tokens — Shopify-issued opaque identifiers that let us correlate a flagged session with the resulting order.
- Page URL — the storefront URL where the event occurred.
We do not record names, emails, addresses, payment data, or browsing history outside the merchant's storefront. The Doorman script does not set cookies and does not track visitors across stores or sessions.
If the merchant enables our optional Klaviyo integration and a checkout is flagged as suspicious, we send the buyer's email address to the merchant's own Klaviyo account with the properties doorman_suspicious=true and a doorman_flagged_at timestamp. The email is not stored on Doorman's servers; it passes through from Shopify's webhook payload and is forwarded to Klaviyo in a single fire-and-forget request.
Data we process from merchants
- Shop domain (e.g. yourstore.myshopify.com) and Shopify plan name.
- Shopify session — OAuth access tokens, plus the staff member's name and email as supplied by Shopify during install. Used only to authenticate the merchant in the embedded admin UI.
- Subscription billing data — the Shopify-issued subscription ID and status. We do not see your card details; Shopify processes payments.
- Settings you configure — sensitivity level, feature toggles, and (if you enable Klaviyo) your Klaviyo API key. The Klaviyo API key is encrypted at rest with AES-256-GCM.
- Aggregated counts — daily request counts and average latency, used to render the dashboard. No per-visitor PII.
Data we process from this website
Separately from the app, this marketing website collects the following:
- Store audit inputs — when you run our free store audit, you submit a storefront URL. We fetch only publicly available data from that URL (its HTML,
robots.txt, and a handful of public Shopify endpoints — the same data a search engine sees). We do not access your admin, orders, or customer data. The URL is not stored unless you also give us your email to receive the report. - Email address — if you ask us to email you the audit report, we collect the email address you provide, the audit score, and the URL you audited. We use this to send you the report and a short educational email series about closing the gaps it found. Every email includes a one-click unsubscribe; you can opt out at any time. We do not sell this address or share it for others' marketing.
- Analytics — we use Plausible Analytics, a privacy-focused, cookieless analytics service that collects aggregate usage statistics and does not track you across sites or build an individual profile.
The legal basis for the audit and analytics is our legitimate interest (Art. 6(1)(f)) in operating and improving the site; the legal basis for the email series is your consent (Art. 6(1)(a)), which you may withdraw at any time by unsubscribing. We handle these emails consistent with the US CAN-SPAM Act.
Why we process this data (legal bases under GDPR)
- Contract (Art. 6(1)(b)) — to provide the bot detection service the merchant subscribed to.
- Legitimate interests (Art. 6(1)(f)) — operating the bot detection itself, preventing fraud, and securing our own service. We've considered whether the visitor's interests override ours and concluded they do not, given the limited scope (anti-bot only) and absence of profiling for any other purpose.
- Consent (Art. 6(1)(a)) — applies where required (e.g. some jurisdictions for IP processing). The merchant is responsible for surfacing their own privacy notice and obtaining consent on their storefront.
Subprocessors
We use the following third-party services to operate Doorman:
- Fly.io — application hosting (United States).
- Neon (or equivalent managed Postgres) — primary database (United States).
- MaxMind — GeoIP lookups (United States; lookups are performed against a local database, not by sending IPs to MaxMind).
- Managed Redis (e.g. Upstash, or equivalent) — short-lived rate-limit counters keyed on IP, expiring within 60 seconds. No detection events or merchant data are stored here.
- Klaviyo — only when the merchant enables the integration. Receives the buyer email and a single boolean profile property.
- Cloudflare — hosting for the marketing website (this site only; not the app).
- Formspree — form delivery for the store-audit lead form on this website (United States). Receives the email address and audit details you submit through that form.
- Plausible Analytics — cookieless, aggregate website analytics for this site (EU-hosted). No cross-site tracking and no individual profiles.
Where personal data is transferred outside the EEA / UK, we rely on the European Commission's Standard Contractual Clauses or the equivalent UK transfer mechanism, depending on jurisdiction.
Retention
- Detection events (with anonymized IP and user-agent) — retained for up to 90 days, then automatically purged. They are also deleted within 48 hours of uninstall via Shopify's
shop/redactwebhook. - Aggregated daily counts — non-identifying request/latency totals; retained for the lifetime of the installation and deleted on
shop/redact. - Sessions — deleted on uninstall and again on
shop/redact. - Plan history (which Shopify subscription was active when) — retained for billing audit and to prevent trial-reset abuse on reinstall. Contains no customer PII.
Your rights
Depending on where you live (GDPR for the EEA / UK, CCPA / CPRA for California, similar laws elsewhere), you have the right to access, correct, delete, restrict, or port the personal data we hold about you, and to object to certain processing.
Storefront visitors: requests to access or delete your data should go to the merchant whose store you visited, since they are the controller. The merchant can forward the request to us. If a merchant uninstalls Doorman, all data tied to their store is deleted within 48 hours.
Merchants: email [email protected]. We respond within 30 days.
You can also lodge a complaint with your local data protection authority.
California residents (CCPA / CPRA)
We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act. We have not done so in the preceding 12 months.
The categories of personal information we collect are described above: identifiers (such as email address and truncated IP address), internet or network activity (such as user-agent and device signals), and geolocation inferred at the country level. We collect these for the business purposes stated in this policy — providing and securing the Service, operating this website, and (with your consent) sending the audit email series. We do not use or disclose sensitive personal information for purposes that would trigger a right to limit its use.
California residents have the right to know, access, correct, and delete their personal information, and the right not to receive discriminatory treatment for exercising these rights. To exercise a right, email [email protected]; we will verify your request against the information we hold. You may use an authorized agent to submit a request on your behalf, subject to reasonable proof of authorization.
Security
All traffic is over HTTPS. Database access is restricted to the application host. Merchant-supplied secrets (the Klaviyo API key) are envelope-encrypted with AES-256-GCM. Shopify session tokens are stored only as long as the merchant has Doorman installed.
Children
Doorman is not directed to children. The storefront data we observe is whatever traffic the merchant's store receives; we do not knowingly process data from children under 13 (or 16 in the EEA / UK).
Changes to this policy
Material changes will be communicated to installed merchants by email at least 30 days before they take effect. Non-material changes (clarifications, broken-link fixes) are published here without notice; the "Last updated" date at the top of this page reflects the most recent revision.
Contact
For any privacy-related question — access requests, processor information, complaints — email [email protected], or write to us at:
Edge Traversal LLC, a California limited liability company
307 S. Pixley St, Orange, CA 92868, USA