Effective 31 August 2026 · Version 2026-08-31
Privacy Policy
This policy explains how Doorwise handles personal information across our website, demo, prospecting platform, billing, support and communications.
1. About Doorwise
Doorwise is an Australian sole trader business (ABN 93 607 312 279) operating in New South Wales, Australia. We are committed to handling personal information openly and in accordance with applicable Australian privacy law, including the Privacy Act 1988 (Cth) and Australian Privacy Principles where they apply.
For privacy enquiries or to request this policy in another accessible format, email support@doorwise.com.au.
2. Personal information we collect
Account and organisation information
Names, email addresses, phone numbers, passwords in protected form, agency details, roles, invitations, permissions, account status, authentication factors and login or session information.
Billing and transaction information
Plan, billing interval, subscription status, Stripe customer and transaction references, billing contact and invoice information. Payment card details are entered directly with Stripe; Doorwise does not receive or store full card numbers.
Customer workspace data
Property addresses, contact names and details, notes, prospecting activities, follow-up dates, appointments, call or door-knock outcomes, consent or contact-permission records, assignments, imports, exports and team activity entered by customers and their users.
Demo, enquiry and marketing information
Demo registration details, agency interest, usage dates, usage limits, enquiries, support correspondence and your separate marketing consent or unsubscribe choice.
Technical and usage information
IP-derived security identifiers, browser and device information, timestamps, pages or features used, performance measurements, diagnostic events, security events, session identifiers and audit records. We seek to minimise diagnostic information and do not intentionally place passwords, authentication tokens or full payment details in logs.
3. How we collect information
We collect information directly from you, from your organisation and authorised users, when you import data, when you use the service, from payment and service providers, and from property, mapping or market-data sources used to provide requested features. An agency may add information about property owners, prospects, team members or other contacts. In that situation, the agency is responsible for notifying those individuals where required.
You may deal with us anonymously for general website browsing where practical, but we need identifying details to provide accounts, paid services, support and privacy rights.
4. Why we collect and use information
- to create, authenticate and administer accounts and organisations;
- to supply maps, records, follow-ups, collaboration, imports, exports and other requested features;
- to process subscriptions, payments, renewals, cancellations and account entitlements;
- to provide customer service and communicate essential service, billing and security messages;
- to detect abuse, protect accounts, investigate incidents and maintain audit records;
- to measure performance, diagnose faults and improve the product;
- to comply with law, enforce agreements and establish or defend legal claims; and
- to send marketing only where we have consent or another lawful basis, with an unsubscribe option.
We do not sell personal information. We do not use Customer Data for unrelated advertising.
5. Disclosure and service providers
We may disclose relevant information to:
- Supabase for database, authentication and related platform services;
- Stripe for checkout, subscriptions, billing, fraud prevention and tax features;
- Cloudflare for security checks and network services;
- hosting, backup, email delivery, mapping and property-data providers;
- authorised users and administrators within your organisation;
- professional advisers, insurers, auditors and contractors bound by appropriate duties;
- regulators, courts, law enforcement or other parties where required or authorised by law; and
- a genuine purchaser or successor in a business transaction, subject to confidentiality and applicable law.
Our Data Processing Terms describe how we handle personal information in Customer Data on an organisation’s instructions.
6. Overseas processing
Some service providers may store or process information outside Australia, including in the United States and other countries where they or their subprocessors operate. The countries can change as provider infrastructure changes. Where Australian privacy law applies, we take reasonable steps appropriate to the circumstances to require suitable privacy and security protections. Overseas recipients may be subject to different privacy laws and lawful government access regimes.
7. Cookies, local storage and similar technology
Doorwise uses essential cookies and browser storage for authentication, security, preferences, demo workspace state, performance and progressive web app functions. We do not currently use third-party advertising cookies. See our Cookie Notice for details and browser controls.
8. Security
We use administrative, technical and organisational safeguards appropriate to the information and service, including access controls, tenant isolation, encryption in transit, protected credentials, audit and security records, rate limits, multi-factor controls for privileged access, backups and service monitoring. No internet service can guarantee absolute security.
If we suspect an eligible data breach, we will investigate and take containment and notification steps required under applicable law, including the Notifiable Data Breaches scheme where it applies.
9. Retention and deletion
We retain information only for as long as reasonably needed for the purposes described above, legal obligations, dispute resolution and security. Retention depends on the record:
- temporary paid-signup records generally expire after two hours if checkout is not completed;
- workspace personal details are subject to the organisation’s configured retention period, which defaults to 730 days for inactive details unless a documented retention hold applies;
- demo data may be reset or removed when the demo expires or is inactive;
- billing, tax, consent, security and audit records may be kept for longer where reasonably required by law or to establish compliance; and
- deleted information may remain in protected backups until the relevant backup cycle expires.
Organisation administrators can export data and run available retention controls. You may also contact us about account deletion. We may retain a minimal record where legally required or necessary to prevent fraud and document an opt-out.
10. Direct marketing
Marketing consent is optional and separate from access to the demo or paid service. We record when and how consent was given. Marketing messages identify Doorwise and include a functional way to unsubscribe. You can opt out at any time using that method or by emailing us. We aim to action requests promptly and within the period required by law. Essential account, billing, support and security messages are not marketing and may continue while relevant.
11. Access and correction
You may request access to personal information we hold about you or ask us to correct it by emailing support@doorwise.com.au. We may need to verify your identity and authority. We will respond within a reasonable period and explain any lawful reason for refusing access or correction. An organisation’s administrator may also control information held in its workspace, so we may refer a Customer Data request to that organisation.
12. Privacy complaints
Send a written complaint to support@doorwise.com.au with enough detail for us to investigate. We will acknowledge it, investigate fairly and aim to provide a substantive response within 30 days. If you are not satisfied, you may contact the Office of the Australian Information Commissioner at oaic.gov.au.
13. Changes to this policy
We may update this policy when our practices, providers or legal obligations change. The current version and effective date will be published here. We will provide additional notice where a material change requires it.