Privacy policy
Doorman looks at the network a visitor arrives on and decides whether your rules let them in. That is a small amount of data about a large number of people, so this page states exactly what is collected, who else sees it, and when it is deleted.
Last updated 2 August 2026.
Who we are
Doorman is operated by Style Beauty LLC, Cheyenne, Wyoming, United States, trading as NovaStack. Write to support@novastack.co about anything on this page.
Two different relationships
For the data Doorman handles on behalf of a store, the merchant decides and we execute. The merchant writes the rules; we apply them and keep the record. Under the GDPR the merchant is the controller and we are the processor.
For the merchant's own account, the shop domain, the chosen plan, and the correspondence we exchange, we decide, and we are the controller.
What is collected about a storefront visitor
On each request to a protected storefront, the edge sees and records:
- the IP address the request arrives from;
- the country and the network operator Cloudflare derives from that address;
- the browser's user agent string, the referring page, and the path requested;
- the time, and what the rules decided.
That is the whole list. Doorman does not see, and does not ask for, a visitor's name, email address, postal address, password or payment details. It sets no advertising cookie and builds no profile that follows anyone between stores.
What is collected about an order
On the Pro plan, when an order is created, Shopify sends us the order's identifier and number, the country it ships to, the type of payment used, and the browser IP address Shopify itself recorded for that order. We check that address, write a verdict and a reason back onto the order, and keep the verdict.
Card numbers never reach us. Shopify does not send them and we have no field to hold them. Where an order carries no browser IP, the assessment records that it could not be checked rather than inventing a score.
Why any of it is processed
To carry out the merchant's own access rules, and to give the merchant an honest record of what those rules did. The lawful basis is the merchant's legitimate interest in protecting their store from fraud and abuse, exercised through instructions they write themselves. Simulation mode exists precisely so a merchant can see the effect of a rule on real people before it affects anyone.
How long it is kept
Retention follows the store's plan, and a scheduled job enforces it rather than a promise doing so:
| Plan | Visitor and detection records |
|---|---|
| Free | 7 days |
| Standard | 90 days |
| Pro | 365 days |
Past that deadline, visitor records and detection records are deleted outright.
Order risk assessments are treated differently, and it is worth stating plainly. The row survives, because a merchant needs to know later why an order was held or cancelled, and because the order itself outlives any log. The IP address inside it is erased on the same deadline, so what remains is the verdict and the reason with nothing identifying the person who placed it.
What happens when the app is uninstalled
Shopify tells us, and everything belonging to that store is deleted: rules, settings, block pages, bypass links, visitor records, detection records, order assessments, sessions and subscriptions. The operational trail we keep of the deletion itself is stripped of order numbers and order identifiers in the same pass, so nothing that points at a person or a purchase survives it.
We answer Shopify's customers/data_request, customers/redact
and shop/redact notifications automatically.
Who else sees the data
Only the services below, each for the purpose stated. There is no other recipient, and we do not sell, rent or share any of it for advertising.
| Who | Where | What they receive |
|---|---|---|
| Shopify | Canada and worldwide | The platform itself. Order and shop data reaches us through Shopify's APIs and webhooks under the permissions the merchant granted at install. |
| Cloudflare | Worldwide, at the point of presence nearest the visitor | Runs the edge decision. Sees the visitor's IP address, and the country and network operator Cloudflare derives from it, on every storefront request. |
| Infomaniak | Switzerland | Hosts the application and its database. Holds the rules, the settings and the logs described below. |
| IPQualityScore | United States | Receives one IP address per lookup and returns a network reputation. It is sent no order, no customer and no shop identifier. |
| AbuseIPDB | United States | Same arrangement, used as a second opinion. One IP address per lookup, nothing else. |
Where it is processed
Three answers, because there are three places and it would be misleading to give one:
- The company is in the United States.
- The application and its database are hosted in Switzerland.
- The edge decision runs on Cloudflare at the point of presence nearest the visitor, which is wherever in the world that visitor is.
Transfers out of the EEA and the UK rest on the European Commission's standard contractual clauses where the recipient does not have another adequacy route.
Rights
A shopper's rights of access, correction, deletion, restriction, portability and objection are exercised against the store, which is the controller. Ask the store, and the store can ask us; we answer them and we answer Shopify's automated requests. If a merchant wants a copy or a deletion of their own account data, write to us directly.
A complaint can be brought to a supervisory authority in the country of residence.
Children
Doorman is a tool for merchants and is not directed at children. We do not knowingly process a child's data, and there is no field in which one could be entered.
Changes
Material changes are announced in the app before they take effect. The date at the top of this page always reflects the current version.