Privacy Policy
Last updated: 26 August 2026
Doris - bookwithdoris.com
Last updated: 26 August 2026
This Privacy Policy explains how ItsMeFil Ltd ("we", "us", "our") collects, uses, and protects personal data when you use Doris at bookwithdoris.com.
We are registered in England and Wales. We are committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who We Are
Data controller: ItsMeFil Ltd (Company No. 17218858), registered in England and Wales.
Contact: hello@bookwithdoris.com
For the personal data of members invited by an organisation administrator, and for the details of guests entered by an administrator when booking a room on their behalf, the organisation acts as data controller and we act as data processor on their behalf. In both cases the organisation decides what is collected, why, and how long it is kept; we store and process it on their instructions.
2. What Data We Collect
Organisation administrators
- Name and email address (used for account creation via Clerk)
- Organisation name and settings
- Subscription and billing information (held by Paddle - we do not store payment card data)
Organisation members (invited users)
- Name and email address
- Booking records - which rooms were booked, when, and by whom
- Custom field responses on bookings (as configured by the organisation administrator)
- Push notification subscription data (if opted in)
Guests (people who hire a room without becoming members)
Some organisations hire rooms to people who are not members and never will be - a birthday party, a community meeting, a wake. An administrator enters the guest's details on their behalf; the guest never uses Doris, never creates an account, and never visits our website.
- Name (required) and phone number (required)
- Email address (optional - used only to send booking confirmations and payment links)
- Any additional fields the organisation chooses to capture (for example an address for invoicing, or access requirements)
- The booking record itself - which room, when, and any payment recorded against it
The organisation chooses which of these fields to collect and how long to keep them (see Section 6). We hold them on that organisation's behalf as its data processor.
Referrals (if a Doris user refers your organisation to us)
Any Doris user can refer another organisation to Doris. When they do, they give us:
- The email address they are referring (required)
- The organisation's name, if they choose to give it (optional)
- A short personal note to include in the invitation, if they write one (optional)
We use that email address once, to send a single invitation on the referrer's behalf, and we keep the record so the referrer can see what became of it and so we can pay their reward if the organisation subscribes. We do not add referred addresses to any mailing list, and we do not send follow-ups or reminders. If you receive an invitation and do nothing, you will not hear from us again.
The invitation identifies the person who sent it: it gives their name, and it carries their email address as the reply address, so that a reply reaches them rather than us. The referrer is told this before they send. If you were referred and want to reply, you are replying to that person directly.
Here, ItsMeFil Ltd is the data controller (not the referrer's organisation) - the referral is a personal act by an individual, and the reward is paid to them personally. Our legal basis is legitimate interest: telling an organisation about a service a peer recommends, balanced against the single, low-volume, clearly-attributed nature of the message. You can object at any time using the contact details in Section 12, and we will delete the record.
What we do NOT collect
- Passwords - authentication is handled entirely by Clerk (clerk.com)
- Payment card data - we never see or store card details, in either of the two money flows Doris touches. An organisation's subscription is billed by Paddle (paddle.com), who take the card details themselves. Card payments made to an organisation by its members or guests are taken by Stripe (stripe.com) on that organisation's own Stripe account, and the card details are entered with Stripe. Both are described in Section 5.
- Client, patient, or service-user data of any kind - see the note below on the difference between a guest who hires a room and the people an organisation serves
- Special category data (health, clinical, religious, political data etc.)
- Anything sent to an AI service by us. Doris has no built-in AI assistant. Your data reaches an AI service only if your own organisation deliberately connects one, which is described under "Organisation-directed integrations" in Section 5.
Doris is a room booking tool. The personal data it holds is the data of the people who book and use rooms - staff, volunteers, members, and guests who hire a room from the organisation.
A guest is the person hiring the room, not the people an organisation serves. If you are a counsellor or therapist, your clients' details should never enter Doris. The same applies to a charity's beneficiaries, a school's pupils, or any other service user. Booking a room for a client is fine; recording who that client is, is not.
3. How We Use Your Data
We use your data to:
- Operate the room booking service
- Manage your account and subscription
- Send push notifications you have opted into
- Send service-related communications (trial status, account notifications)
- Record what members and guests owe an organisation, and, where that organisation has connected its own Stripe account, send them a link to pay it
- Send a single referral invitation when an existing user refers an organisation, and pay that user's reward if it subscribes
- Comply with our legal obligations
We never use your account or booking data for advertising, and we do not sell your data to third parties. The only advertising-related measurement we do happens on our public marketing pages, uses no Doris account data, and only runs if you consent to it (see Sections 5 and 9). We do not share your data with any third party except as described in Section 5.
4. Legal Basis for Processing
We process personal data on the following legal bases under UK GDPR:
- Contract - to provide the service you have signed up for
- Legitimate interests - to operate, maintain, and improve the service
- Legal obligation - where required by law
- Consent - for optional processing such as push notifications and the optional marketing cookie on our public pages (either can be withdrawn at any time)
5. Third-Party Services
We use the following third-party services to operate Doris:
Clerk (clerk.com) - user authentication. Clerk processes email addresses and manages passwords. We never see your password.
Paddle (paddle.com) - subscription billing. Paddle acts as Merchant of Record and processes all payment data. We do not store card numbers or payment details.
Cloudflare (cloudflare.com) - hosting, database, and infrastructure. Data is stored in the EU/UK region. We also use Cloudflare Web Analytics to understand aggregate site usage (page views, approximate visitor counts, and country-level location). This is privacy-first and cookieless: it sets no cookies, does not store IP addresses, does not build a profile of you, and does not track you across other websites.
Sentry (sentry.io) - error monitoring. When Doris encounters a technical error, Sentry records diagnostic information (the error, the page or screen involved, and browser/device type) so we can find and fix bugs. We configure Sentry to minimise personal data: IP-address collection is disabled and identifying details are stripped before a report is sent. Error data is processed in Sentry's EU (Germany) region.
Stripe (stripe.com) - card payments made to an organisation by its members or guests, where that organisation has chosen to accept them. This is a separate flow from the Doris subscription above, and the difference matters. Paddle handles what an organisation pays us. Stripe handles what a member or guest pays that organisation: the organisation connects its own Stripe account, the money goes directly to that account, and we take no fee or share of it. When you follow a payment link, your card details are entered with Stripe on that organisation's account, never with us. Stripe receives the payer's name, email address, card details and the amount being paid, and is independently responsible for that data under its own privacy policy at stripe.com/privacy.
Meta (facebook.com) - optional advertising measurement on our public marketing pages only (the landing, pricing, and about pages). If - and only if - you accept the cookie banner shown on those pages, the Meta Pixel sets a cookie and tells Meta which of our public pages you visited, so we can measure whether our advertising works and reach people who showed interest in Doris. It never runs inside the Doris app itself, and no account, member, or booking data is ever shared with Meta. If you decline, nothing is loaded and no data is sent. Meta acts as an independent data controller for this data - see Meta's own privacy policy at facebook.com/privacy/policy.
PostHog (posthog.com) - website analytics on our public marketing pages only. If you accept the cookie banner, PostHog sets a first-party cookie to help us understand how visitors interact with our public pages (e.g., page views, button clicks, and signup flows). If you decline, PostHog still loads its scripts and sends anonymised event data calculated using a privacy-preserving server-side hash, but stores absolutely nothing on your device (no cookies, local storage, or personal identifiers). PostHog data is hosted entirely in the European Union (EU Cloud). No account, member, or booking data from the Doris application is ever sent to PostHog.
Resend (resend.com) - transactional email delivery. Resend sends the emails Doris generates: welcome and sign-in emails, billing statements, guest booking confirmations and payment links, and referral invitations. It receives the recipient's email address and the content of that message, and nothing else.
Tremendous (tremendous.com) - referral reward vouchers. If you earn a referral reward, we send your name and email address to Tremendous so it can deliver your voucher and let you choose which reward you want. Tremendous receives nothing else - no booking data, no organisation data, and no details of who you referred. It is used only for people who have earned a reward. Tremendous is based in the United States and transfers are made under the UK International Data Transfer Addendum.
Each of these providers has their own privacy policy and is independently responsible for their data handling.
Organisation-directed integrations (optional, off by default)
An organisation owner or admin can choose to connect outside services to their organisation's Doris data:
- Connected AI assistants - a read-only connection that lets an AI assistant the organisation already uses (for example Anthropic's Claude or OpenAI's ChatGPT) read that organisation's rooms, bookings, availability, analytics, and billing statements on the admin's behalf.
- Outbound webhooks - signed notifications about booking and billing events, sent to a URL the organisation controls.
These connections exist only if an admin deliberately sets them up, and any admin can revoke them at any time in Settings. When one is active, we send the organisation's data to the service the admin chose, acting on the organisation's instructions as data processor. Member email addresses are excluded unless the organisation explicitly switches them on. Guest contact details - name, phone number, email address and any additional fields the organisation captures - are never included in these connections. Once delivered, that data is handled by the receiving service under its own privacy policy, under the organisation's own arrangement with that service.
6. Data Retention
We retain your data for as long as your organisation's account is active.
If your trial expires or your subscription lapses, your organisation moves to read-only mode and your data is preserved.
If a trial is never converted to a paid subscription, the organisation stays in read-only mode, with its data preserved, for six months after the trial ends. During that time the organisation can reactivate itself or subscribe and carry on where it left off. After six months we archive the organisation. Archiving switches the organisation off: nobody can sign in to it and it is no longer used. The data is retained on our systems at that point, not erased.
We would rather be plain than reassuring here. There is no automatic job that permanently erases an organisation's data after a set period. Permanent deletion happens when someone asks us for it, or when we decide we no longer need to hold the data. If you want your data permanently deleted, ask us and we will do it and tell you when it is done. See Section 8.
Guest details are the exception, and they are deleted automatically. An organisation sets how long it keeps a guest's contact details after the date of the booking, between 1 and 24 months, and 12 months unless it changes that. Once the period passes, the name, phone number, email address and any additional fields are permanently deleted, automatically and without anyone having to ask. The booking record itself remains - the room was still booked - but it no longer identifies anyone.
This deletion is not optional and is not something the organisation has to remember to do. It also keeps running if the organisation stops subscribing or turns guest bookings off, because lapsing is not a reason to hold someone's details for longer than promised.
Referral records. We keep a referral record for as long as it may still result in a reward, and afterwards as part of our financial records where a reward was paid. If you were referred and did not sign up, you may ask us to delete the record at any time - see Section 8.
You may request deletion of your data at any time by contacting us. See Section 8 for your rights.
7. Data Security
We take appropriate technical and organisational measures to protect your data, including:
- Encryption in transit (HTTPS, enforced by Cloudflare)
- Database access restricted to the application layer
- Secrets and API keys never stored in code or version control
- Clerk, Paddle and Stripe handle the most sensitive data (credentials and card payments) under their own security programmes
No system is completely secure. In the event of a data breach affecting your rights and freedoms, we will notify the ICO within 72 hours and affected individuals without undue delay.
8. Your Rights
Under UK GDPR, you have the right to:
- Access - request a copy of the personal data we hold about you
- Rectification - ask us to correct inaccurate data
- Erasure - ask us to delete your data (subject to legal obligations)
- Restriction - ask us to restrict processing in certain circumstances
- Portability - receive your data in a machine-readable format
- Object - object to processing based on legitimate interests
- Withdraw consent - for consent-based processing (e.g. push notifications), withdraw at any time
If you were referred to Doris by someone: ItsMeFil Ltd is the data controller for that referral record. You can ask us to delete it, or object to the processing entirely, by emailing hello@bookwithdoris.com - we will act on it and you will receive nothing further. We will tell you who referred you if you ask.
If you are a guest who hired a room: the organisation you booked with is the data controller for your details, and we hold them only on its behalf. Please contact that organisation directly to ask about, correct, or delete your details - its name is on the confirmation email you received. If you cannot reach them, contact us at hello@bookwithdoris.com and we will help the organisation respond. Your details are in any case deleted automatically after the period that organisation has set.
To exercise any of these rights, contact us at: hello@bookwithdoris.com. We will respond within one month.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
9. Cookies
Inside the Doris app, we use only essential cookies and session tokens necessary to operate the service - no advertising or tracking cookies, ever. For usage analytics we use Cloudflare Web Analytics, which is cookieless - it sets no cookies and does not track you across other websites (see Section 5).
Our public marketing pages offer optional tracking cookies: the Meta Pixel, used to measure our advertising (see Section 5), and PostHog, used to understand visitor interactions. These are set only if you accept the cookie banner; declining prevents cookies from being set, and your choice is remembered (if you decline, PostHog operates in a cookieless mode using a server-side hash as described in Section 5). You can change your mind at any time using the "Cookie preferences" link in the page footer.
When you accept cookies on our marketing pages, the following tracking and analytics storage elements are set:
- Cookie:
ph_phc_n2mPKAXBiM5aejGcTo8N6M33jCyuPCPkMqm5qToxrPJg_posthog(PostHog) - stores a unique identifier, session metadata, and active feature flags to measure visitor behavior. Expires after 365 days. - LocalStorage Keys:
ph_phc_n2mPKAXBiM5aejGcTo8N6M33jCyuPCPkMqm5qToxrPJg_posthog- stores session metadata, distinct ID, and active feature flags.__ph_opt_in_out_phc_n2mPKAXBiM5aejGcTo8N6M33jCyuPCPkMqm5qToxrPJg- stores your opt-in/opt-out status for capturing.
10. Children
Doris is intended for use by adults within organisations. We do not knowingly collect data from anyone under the age of 16. If you believe a minor has registered without appropriate authority, please contact us immediately.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or via the Doris admin dashboard. Continued use of the service after changes take effect constitutes acceptance of the updated policy.
12. Contact
Privacy queries and data subject requests: hello@bookwithdoris.com
ItsMeFil Ltd (Company No. 17218858), registered in England and Wales.