Legal
Privacy policy
Last updated 23 September 2026
Who this covers
Door-Let is property management software for landlords, provided by Doorlet Private Limited, a company registered in India. Two groups of people appear in it: landlords, who hold an account and use the app, and renters, whose details a landlord records in order to manage a tenancy. Renters do not hold accounts. This policy describes how we handle both.
If you are a renter and your landlord uses Door-Let, your landlord decides what is recorded about you. Requests to see or correct that information should go to your landlord first. You can also contact us at support@doorlet.in.
What we collect
From landlords
- Your email address, used to sign you in. You can sign in with Google, in which case we do not receive your Google password, or with a one time code we send to that address. Those codes, and a record that they were sent, are kept.
- Your name and phone number, which you enter yourself when you set up your account.
- Your properties, buildings and units, and the rent terms you set.
- Payment records, whether imported from a statement or entered by hand.
- Settings such as your preferred language and reminder preferences.
About renters, entered by the landlord
- Name, phone number and unit.
- Lease dates, rent, deposit and any charges or loans recorded against them.
- Payment history.
- Documents the landlord uploads, which may include Aadhaar cards, PAN cards and lease agreements. Identity numbers are handled as set out below.
Where it is stored
Application data is held in a managed Postgres database in Mumbai, India, and the application server is also in Mumbai. Access is restricted to the account that owns the data and to the small number of people who operate the service.
Who else receives it
Door-Let is built on services run by other companies, and each of them sees the part of your data it needs to do its job. We share nothing with anyone else.
- Supabase, our database and file storage provider, which holds the application data and the documents you upload in its Mumbai region.
- Google, if you choose to sign in with a Google account, and Google Play once paid plans open, which takes the subscription payment itself.
- Razorpay and Setu, our payment providers, when you send a renter a payment link or give them a virtual account number to pay into. They receive the amount and the details needed to collect it, and they hold the card or bank details, which never reach us.
- Meta, through the WhatsApp Business Platform, when Door-Let sends or receives a tenancy message over WhatsApp. Depending on the feature, this can include an invitation and its answer, a rent notice, a payment receipt, a language choice, a join request or a bill photo sent for assistance. Meta receives the phone number and the message, template or media content, and returns information such as button answers and delivery or read status. Meta may process this outside India. If SMS reminders are switched on for the service, MSG91 receives the phone number and SMS text.
- Anthropic, Google and OpenRouter, the AI providers described in the next section, which is the most limited case and the one we restrict most tightly.
WhatsApp choices and automatic messages
Before a landlord sends each Door-Let invitation, the app asks them to confirm that the renter gave them the number and agreed to be contacted about their tenancy. The invitation lets the holder say that it is their number or choose Not me. A person can also reply STOP to withdraw the WhatsApp consents Door-Let can identify for that number at that time. Door-Let records those choices so the relevant landlord cannot simply invite the number again. A later connection must start through the holder's own join request and the landlord's approval where that route is available.
Some WhatsApp messages are automatic transactional messages rather than drafts a landlord reads one by one. For example, Door-Let may acknowledge a reply, welcome a renter after they connect, report the result of a join request, or send a payment receipt after the landlord records a payment. These features are controlled separately and may not be available on every account.
Not me and STOP stop the messages tied to the consents Door-Let identifies; they do not delete tenancy or payment history. They also do not promise that an unrelated landlord can never enter the same number in a different account. Contact support@doorlet.in if messages continue after either choice or if you believe the number is being used incorrectly.
Camera and photos
The app asks for camera access so you can photograph a document, and for access to your photo library so you can pick one you have already taken. It uses them for nothing else. Images you choose are uploaded to Door-Let and handled as set out below. The app does not read, index or upload the rest of your photo library.
What is sent to AI providers
Door-Let uses third party AI services to read documents, draft reminders and summarise your position. Those providers are outside India. What reaches them is deliberately limited.
Identity-card photos and text prompts
- Aadhaar and PAN card photos. Detected identity numbers are masked on our server before AI processing, with a partial suffix left visible. If no number is detected or masking fails, the card scan stops for manual entry. Text detection is not infallible: it may miss a number when an image contains several. Lease documents have different limits, described below.
- Bill photos sent over WhatsApp. When bill help is switched on, a bill photo sent to Door-Let over WhatsApp is read by Google's or Anthropic's AI to fill in the bill. Before that, Door-Let's own software blacks out any Aadhaar or PAN number it finds on the image. It can miss a number it cannot read clearly. If a photo cannot be checked this way at all, it is not sent to an AI provider.
- Phone numbers in text prompts are reduced to the last four digits.
- Detected email addresses are removed from text prompts. Text filtering does not remove details printed in a document image.
Sent in a reduced form
- Renter names are reduced to a first name in prompts. A scanned identity document is the exception: the provider receives the masked image, and the name, address and photograph printed on the document remain legible on it. Only the identity number is blacked out.
- Amounts, dates and unit identifiers.
- Bank transaction references are the exception to the first-name rule. To match a payment to the right rent, the reference is sent as it appears on the statement, and it can include the payer's full name. Aadhaar, PAN, phone numbers and email addresses are still removed from it first.
Lease documents are treated on a best-effort basis: identity numbers found on them are masked, but a lease whose masking fails is still processed, where an identity document would have been stopped. The security page explains this and the other limits in detail.
Retention
A record of every AI call is kept for 30 days by default and then deleted automatically. Identity numbers are never written to those records.
Your account data is kept for as long as your account is open. When you ask us to delete your account, your login is closed at once and the private documents you uploaded are removed from storage. Both happen while the request is being handled, not later.
After that we work to two periods. Your contact details, and the renter phone numbers and email addresses in your portfolio, are erased within 30 days of the request. The rent charges you raised, the payments recorded against them and the audit trail behind them are kept for seven financial years after the year they belong to, with the renter name and the unit needed to keep each record readable, and no more.
For WhatsApp, the contact information removed within that 30 day period includes phone-number fields and message-body contact content linked to your account. Door-Let may keep the remaining consent, withdrawal, delivery and operational audit metadata with the account history, after the contact content is removed. A payment receipt can also remain represented in the financial and audit history described above.
If someone whose number is not linked to any Door-Let account sends us a WhatsApp message, the message text and any attachment reference are removed after 30 days.
We hold that financial history for your sake rather than ours. Indian tax law requires the person earning the income to keep records of it for seven years, and rental income is income. Keeping the charges and payments for the same period means the record is still there if you are ever asked for it. The duty is yours; we are making sure you can meet it.
Three things about those periods that most policies would leave out. Some of it runs automatically today: AI call records are deleted after 30 days, expired sign-in code records are cleared, and messages from numbers not linked to any account are cleaned after 30 days. The rest is a commitment we carry out ourselves. Backups are held by our database host for 7 days and roll forward on its schedule, so a record can survive in one after we have erased it from the live database, though we do not restore a deleted account from a backup. And the record that a sign in code was sent to you is held apart from your account for security reasons, outside the two periods above.
If you want to know exactly what is still held about you after a deletion, ask us and we will tell you. Our account deletion page sets out what goes at once and what is held.
Selling data
We do not sell your data, and we do not rent it out. Renter records, payment histories and uploaded documents are never given to advertisers, data brokers or other landlords.
This website
This site runs no advertising trackers and sets no advertising cookies. When you submit the contact form, Door-Let uses the details you enter only to respond to your enquiry. The form sends them through Door-Let's first-party website API, not an advertising service.
Your choices
- You can ask for a copy of the data held about you.
- You can ask us to correct anything inaccurate.
- You can ask us to delete your account. The account deletion page explains how, what is removed and what may remain.
- You can use Door-Let without the AI features, entering details by hand instead.
- You can choose Not me to refuse a landlord's WhatsApp invitation, or reply STOP to withdraw every WhatsApp consent Door-Let can identify for your number.
Contact
Write to support@doorlet.in with any question about this policy, including anything you want corrected, copied or deleted, and we will answer it. If you want to raise a grievance about how your data has been handled, write to our Grievance Officer, Hari Babu Manne, at support@doorlet.in with "Grievance" in the subject line. We acknowledge a grievance within two working days and answer it within thirty days. If you are not satisfied with our answer, you may also complain to the Data Protection Board of India.