Skip to content
Doramo
Legal

Privacy
Policy

What we collect, why we collect it, who we share it with, and the rights you can exercise over your information.

This Privacy Policy is incorporated into the Doramo Terms of Service. It is not legal advice.

Effective date
August 24, 2026
Company / controller
Doramo, Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, US
Privacy contact / Privacy Officer
privacy@doramoapp.com
On this page

1Overview and our two roles

This Privacy Policy explains how Doramo collects, uses, shares, and protects personal information when you use the Doramo application, website, and services (the "Platform"). Doramo is a technology platform and marketplace that connects Clients with independent cleaning and property-care Providers and gives Providers tools to run their business. Doramo is not a cleaning company and does not perform services. It applies to Clients, Providers, and Provider Personnel.

Property-care services may include cleaning, residential cleaning, commercial cleaning, move-in/move-out cleaning, Airbnb or short-term-rental cleaning, mobile car wash/detailing, lawn care, landscaping maintenance, and related services offered by Providers through the Platform.

Doramo plays two different roles depending on the data:

  • Doramo as controller. For information about our own users — account, device, usage, location, communications, and the data needed to operate the Platform — Doramo decides how and why it is processed.
  • Doramo as service provider / processor. When a Provider uses the Platform to manage its own business and inputs information about its customers, properties, and personnel, that Provider is the controller of that information and Doramo processes it on the Provider's behalf under our agreement with the Provider and the Data Processing Addendum. Providers are responsible for providing any notices and obtaining any consents required before entering personal information about their own customers, properties, personnel, contractors, or subcontractors into the Platform.

(Under California law, this means Doramo acts as a "business" for its own users' personal information and as a "service provider" for Provider-entered customer, personnel, and property data.)

2Information we collect

2.1 Information you provide.

  • Account and identity: name, email, phone, password, role (Client/Provider), and business details for Providers.
  • Provider business data: team member, contractor, customer, and property address records that Providers enter to run their business.
  • Bookings and communications: requests, messages, and details exchanged through the Platform.
  • Support requests and feedback; reviews and ratings you submit.

2.2 Payment and billing information. Payments are processed by Stripe, our payment processor. Stripe is used for two purposes: (a) to bill Providers for their subscription, per-lead fees, and the in-app platform fee; and (b) where a Provider accepts in-app payment, to process the Client's payment and route funds to the Provider through Stripe Connect. Doramo does not collect or store full payment card numbers; Stripe collects and processes payment and payout information directly under its own terms and privacy policy. We receive limited transaction metadata (e.g., amount, status, last four digits) needed to operate the Platform and reconcile our fees. When a Client pays a Provider directly off the Platform, Doramo does not process or receive that payment and does not collect payment information for it.

2.3 Location information. With your permission, we collect precise device location (GPS) to power features such as routing, estimated arrival times, real-time travel/traffic information for a Provider's next job, and job check-in/out. With your separate "Always" permission, we also collect job-site arrival and departure in the background, including while the app is closed, for a job you are scheduled to work that day; we receive those crossings, not a continuous trail of your movements. Precise location is sensitive and is collected only with your consent, and you can disable it in your device settings (some features may not work without it). Section 6 describes both uses and the limits that apply to the background one.

2.4 Communications and live message translation. We process the content of messages you send and receive through the Platform to deliver them and to operate features such as live message translation (available on certain subscription plans). If live translation is enabled, message text may be processed by Doramo or by a third-party translation provider solely to provide the translated message and related safety/security functions. Any such provider acts as our service provider / processor and is identified in Section 5.

2.5 Device and usage information. Device identifiers, app version, IP address, log data, and how you interact with the Platform, collected automatically and through similar technologies (see Section 7).

2.6 Screening information. If identity or background screening is facilitated, related information is collected and processed by a third-party screening vendor (a consumer reporting agency) under its own terms, with the consents required by law. This is governed by the separate Doramo Background Check / FCRA documents (see Section 8).

2.7 Biometric information. To verify identity, Doramo's identity verification vendor captures a photograph of your face and generates from it a scan of face geometry. This occurs at onboarding, together with your government-issued identity document, and again before each dispatch, to confirm that the person arriving is the person previously verified. A scan of face geometry is a biometric identifier and is treated as sensitive personal information. It is collected only with your separate written consent, obtained before any capture, and is used only to verify identity, to confirm identity before dispatch, and to investigate a specific reported incident of suspected identity fraud or account sharing. It is never sold, leased, traded, or otherwise profited from, and is never used to train any model or to infer any characteristic about you. Collection, retention, destruction, and your right to withdraw consent are governed by the separate Doramo Biometric Data Policy & Consent.

2.8 Sources. We collect personal information directly from you, automatically from your device and use of the Platform, from other users to enable a connection (e.g., a Client's request shared with a Provider), and from our service providers (e.g., Stripe, screening vendor).

3California "Notice at Collection"

The following summarizes the categories of personal information we collect, the purposes, and retention. We do not sell personal information and do not "share" it for cross-context behavioral advertising as those terms are defined under California law.

Category (Cal. Civ. Code)ExamplesPurposeRetainedSold / Shared
IdentifiersName, email, phone, account ID, IP addressCreate and operate accounts; securityLife of account + 24 monthsNo
Customer records / commercial infoBookings, transactions, billing, Provider business recordsProvide and reconcile the serviceLife of account + 24 monthsNo
Internet / network activityApp usage, device, log dataOperate, secure, and improve the Platform24 monthsNo
Precise geolocation (sensitive)GPS while app in use; job-site arrival/departure crossings in the background, with "Always" permissionRouting, ETA, traffic, check-in/out; job-site arrival and departure recordsUntil job completion + 30 days, then deleted or de-identifiedNo
Communications contentMessages, support requests, reviewsDeliver messages; live translation; supportLife of account + 24 monthsNo
Professional / employment infoProvider business, team, contractor recordsProvider business-management toolsPer Provider instruction / agreementNo
Billing / legal / dispute recordsInvoices, payment metadata, dispute and fraud recordsTax, accounting, disputes, fraud prevention, legal defenseUp to 7 years where requiredNo
Account credentials (sensitive)Login/passwordAuthentication and securityLife of accountNo
Biometric information (sensitive)Scan of face geometry from a selfie; ID document imageIdentity verification; pre-dispatch identity confirmation; investigation of reported identity fraudReference scan: account life, destroyed within 90 days of closure and within 12 months of last use. Pre-dispatch scans: 30 days. ID image and onboarding selfie: 12 monthsNo

Sensitive personal information. We treat precise geolocation, account login credentials, and biometric information as Sensitive PI. We use Sensitive PI only for the purposes above (to provide the service and maintain security), not to infer characteristics. Under California law you may request to limit the use of your Sensitive PI.

In the preceding 12 months, we have not sold or shared personal information. The categories of recipients to whom we disclose personal information for business purposes are described in Section 5.

4How we use information

We use personal information to: operate and provide the Platform and marketplace; create and manage accounts; connect Clients and Providers; enable bookings, messaging, live translation, leads, and payments (via Stripe); provide Provider business-management tools; provide location-based features (routing, ETA, traffic, and job-site arrival and departure); bill subscriptions, leads, and the in-app fee; maintain safety, security, and integrity; prevent fraud and abuse; provide support; comply with law; and improve the Platform.

Bases, as applicable: contract performance; your consent (e.g., precise location); our legitimate interests (operating and securing the Platform); and legal obligations. For Provider-customer data, the Provider sets the purposes and lawful basis.

5How we share information

  • Between users, to enable a connection and booking (e.g., name, property/location, and contact as needed).
  • Stripe — to bill Providers and, on the in-app rail, to process Client payments and Provider payouts via Stripe Connect.
  • Google Maps Platform — to provide mapping, routing, ETA, and traffic features.
  • OpenAI — where live message translation is used, to translate message text solely to return the translation and to support related safety and security functions.
  • Identity verification vendor — to authenticate government-issued identity documents and perform the face-geometry comparison described in Section 2.7, acting solely on our instructions.
  • Screening vendor — to facilitate background checks (Section 8).
  • Service providers that host and support the Platform (cloud hosting/database, error monitoring, communications).
  • Legal and safety, when required by law or to protect rights, safety, and Platform integrity; and business transfers, subject to this Policy.

Service providers and subprocessors. Third parties that process personal information on our behalf (such as Stripe, Google Maps Platform, and our translation, screening, hosting, communications, and error-monitoring providers) act as our service providers / processors under contracts that limit them to processing the information only to provide services to us and prohibit using it for their own purposes, including training their own models. A current list of subprocessors is published at doramoapp.com/subprocessors.

We do not disclose Provider-customer data except to provide the Platform to that Provider, through our service providers/processors, as the Provider directs, or as required by law.

6Precise location (GPS)

We collect precise location only with your consent, and for exactly two purposes.

While you are using the app (foreground). Routing, ETA, real-time travel and traffic for the next job, weather for the area you are working in, and job check-in/out.

Job-site arrival, including while the app is closed (background). With your separate "Always" permission, your device watches for you crossing a circle of approximately 150 metres around the address of a job you are scheduled to work that day, and tells your company when you arrive and when you leave. This is how a timesheet records an arrival that happens before anyone opens an app.

What this means in practice, and what we commit to:

  • We receive crossings, not a trail. We do not receive your position between crossings, and we do not build a route, a history of your movements, or any picture of where you are when you are not at a job site.
  • No job, no monitoring. A circle is watched only on the day of a scheduled job — a job later in the week does not mean you are monitored today. On a day with no job scheduled, the monitoring is switched off, not merely ignored.
  • Only your customer's job addresses. We never watch any other place.

You can withdraw consent at any time in your device settings, and you may choose "While Using the App" instead of "Always" — the app keeps working, and arrivals are then recorded only when you open it. We treat precise location as Sensitive PI and retain it only as needed for the related feature (until job completion + 30 days), then delete or de-identify it. These practices match the disclosures in the Apple and Google app stores (Section 15), which declare background location.

This section was corrected on 2026-08-24, together with Sections 2.3, 3, 4, and 10.7. The Policy previously stated that we did not collect location in the background, which stopped being accurate when job-site arrival monitoring was added.

7Cookies, analytics, and advertising

We use limited cookies and similar technologies to operate and secure the Platform and to understand usage through analytics. We do not use third-party advertising SDKs, we do not sell personal information, and we do not "share" or process personal information for cross-context behavioral advertising or for profiling that produces legal or similarly significant effects. If we ever introduce advertising, tracking, or such profiling, we will update this Policy and the applicable app-store and cookie disclosures before doing so. We honor recognized opt-out signals, including the Global Privacy Control (GPC), where required (Section 9).

8Background checks and screening

If identity or background screening of Providers or Provider Personnel is offered, it is performed by a third-party screening vendor — a consumer reporting agency identified on our Subprocessors Page — and is governed by separate documents: the standalone Background Check Disclosure and Authorization, plus the adverse-action process, set out in the Doramo Background Check / FCRA Pack, not in this Policy. In the U.S., a clear standalone disclosure and separate written authorization are obtained before screening, and the FCRA pre-adverse / adverse-action steps are followed before any decision based on a report; state/local rules may also apply. In Canada, screening requires consent and is governed by PIPEDA and provincial law. Any screening is limited and point-in-time and is not a guarantee of any person's fitness, character, or conduct.

9Your privacy rights

9.1United States — California (CCPA/CPRA)

You may have the rights to know, access, delete, and correct your personal information; to opt out of sale or sharing; and to limit the use of Sensitive PI. We do not discriminate against you for exercising these rights, and you may use an authorized agent to submit a request, subject to verification. We honor the Global Privacy Control (GPC) where applicable. To exercise rights, contact privacy@doramoapp.com or use the privacy request form in the Doramo app.

9.2United States — other state privacy rights

If you are a resident of a U.S. state with a comprehensive consumer privacy law, you may have the rights described below, to the extent that law applies to Doramo. As of the Effective date, these states include Arkansas, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia. California residents' rights are described in Section 9.1.

These laws are broadly similar. Where one applies to us, you may have the right to:

  • Confirm and access whether we process your personal data, and obtain a copy in a portable format;
  • Correct inaccuracies in your personal data;
  • Delete personal data we hold about you;
  • Opt out of (a) the sale of your personal data, (b) targeted advertising, and (c) certain profiling in furtherance of decisions that produce legal or similarly significant effects about you; and
  • Exercise these rights without being discriminated against.

Our current practices. We do not sell personal data, use it for targeted advertising, or use it for profiling that produces legal or similarly significant effects. As a result, the related opt-out rights may not apply to our current processing, and we will update this Policy before that changes.

Sensitive data. Most of these states require your opt-in consent before we process sensitive data. We treat precise geolocation (GPS) as sensitive and process it only with your consent, as described in this Policy.

Universal opt-out mechanisms. Where required by your state's law, we recognize universal opt-out mechanisms, including the Global Privacy Control (GPC), as a valid request to opt out of the sale of personal data and targeted advertising.

Appeals. If we decline to act on your request, you may appeal by contacting privacy@doramoapp.com. We will respond within the period required by your state's law and will explain our decision. Several states also allow you to submit a complaint to your state Attorney General.

State-specific notes.

  • Florida: Florida's law is narrower in scope and generally applies only to very large businesses; it may not apply to Doramo.
  • Texas: the Texas Data Privacy and Security Act applies regardless of business size; it has no minimum revenue or data-volume threshold.
  • Oregon: you may request a list of the specific third parties (not only the categories) to whom we have disclosed personal data.
  • Minnesota and Oregon: you may have additional rights regarding profiling, including to be informed about and, in certain cases, to review the basis of a profiling decision.

How to exercise your rights. Submit a request to privacy@doramoapp.com or through the privacy request form in the Doramo app. We will verify your identity and respond within the timeframe required by applicable law (generally 45 days, extendable where permitted). Where your state's law allows, you may use an authorized agent, subject to verification.

Applicability. Some of these laws apply only to businesses that meet specific thresholds. Where a law applies to Doramo, we honor the rights it grants.

9.3Canada (PIPEDA)

You may access and correct your personal information and withdraw consent, subject to legal or contractual limitations; we will explain the consequences of withdrawal. We collect, use, and disclose personal information for purposes a reasonable person would consider appropriate, and we limit collection to what is needed for those purposes. Users in Canada may challenge Doramo's compliance by contacting our Privacy Officer at privacy@doramoapp.com, and may contact the Office of the Privacy Commissioner of Canada or the applicable provincial regulator.

9.4Quebec (Law 25)

See Section 10.

We verify requests and respond within the timeframes required by applicable law.

10Quebec — Law 25

10.1 Privacy Officer. Doramo's Privacy Officer, reachable at privacy@doramoapp.com, is responsible for Doramo's compliance with Quebec privacy law.

10.2 Consent and withdrawal. We obtain consent appropriate to the sensitivity of the data and let you withdraw it, subject to legal/contractual limits.

10.3 Confidentiality incidents. We maintain a process and a register for confidentiality incidents, and where an incident presents a risk of serious injury, we will notify the Commission d'accès à l'information and affected persons as required.

10.4 Privacy impact assessment (PIA). We conduct a PIA proportionate to the sensitivity, purpose, quantity, and means of storage of the data for projects involving sensitive data (such as precise geolocation) and before transferring personal information outside Quebec, applying appropriate safeguards.

10.5 Automated decisions. We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Where a screening result would lead us to deny, restrict, suspend, or remove your access to the Platform, that outcome receives individualized review by a person before it takes effect, and you may submit observations to that person. The automated award of a verification badge is not an adverse decision and is not subject to this review. Where Law 25 applies, you may request that we inform you of the personal information used to reach the decision, the principal reasons and the main factors and parameters that led to it, and of your right to have that personal information corrected.

10.6 Data portability. Where Law 25 applies, you may request that the computerized personal information you provided to us be communicated to you in a structured, commonly used technological format.

10.7 Location and identification technology. Where we use technology that allows you to be located (such as GPS), we inform you and you can activate or deactivate these functions; precise location is collected only with your consent, whether while the app is in use or, with your separate "Always" permission, for job-site arrival and departure while the app is closed (Section 6). You can deactivate the function at any time in your device settings, which stops the collection.

10.8 De-indexing / cessation of dissemination. Where Law 25 applies, you may request that we cease disseminating your personal information, or de-index a hyperlink that gives access to it, under the conditions provided by law (for example, where dissemination contravenes law or a court order or causes serious injury).

11Retention

We keep personal information only as long as needed for the purposes described, to comply with law, resolve disputes, and enforce agreements, then delete or de-identify it. Category-specific periods appear in Section 3, and biometric retention and destruction are governed by the Doramo Biometric Data Policy & Consent. We may retain certain records longer where needed to resolve a dispute or chargeback, prevent fraud, meet tax or accounting obligations, or establish or defend legal claims. Provider-customer data follows the Provider's instructions and our agreement.

12Security and confidentiality incident response

We use reasonable administrative, technical, and physical safeguards. No system is perfectly secure. We maintain an incident-response process and will notify affected users and regulators where required by applicable law (including Quebec — Section 10.3 — and U.S. state breach laws).

13International transfers

The Platform is operated in the United States. Information from Canada may be transferred to and processed in the United States with appropriate safeguards; transfers of Quebec data follow Section 10.4.

14Children / age

The Platform is intended only for users 18 and older. We require users to confirm they are at least 18 years old during signup. We do not knowingly collect information from anyone under 18. If you believe a minor provided information, contact privacy@doramoapp.com.

15App store disclosures

The data practices described in this Policy are reflected in Doramo's Apple App Privacy details on the App Store and in Doramo's Google Play Data Safety disclosures. If our data practices change, we will update this Policy and those disclosures together.

16SMS and text messaging

By providing your mobile number and creating an account, you agree to receive transactional text messages from Doramo about your account and bookings — booking confirmations and changes, provider dispatch and arrival notices, job completion, and cancellations. Message frequency varies with your booking activity. Message and data rates may apply.

If you separately opt in to marketing texts, you can expect recurring promotional messages. Consent to marketing texts is not a condition of using the Platform.

Doramo does not sell, rent, or share mobile phone numbers or SMS consent with third parties or affiliates for their own marketing purposes. Mobile information is disclosed only to service providers that support message delivery on Doramo's behalf, and those providers are contractually prohibited from using it for any other purpose. Mobile numbers and SMS consent are excluded from any category of personal information Doramo sells, shares, or discloses for cross-context behavioral advertising or targeted advertising under applicable state privacy laws.

  • Reply STOP to cancel at any time. Doramo also honors opt-out requests made by any other reasonable means, including QUIT, END, CANCEL, UNSUBSCRIBE, REVOKE, or a plain-language request. You will receive one final message confirming opt-out. Stopping marketing texts does not stop transactional messages needed to operate your account; to stop all texts, adjust notification settings or delete your account.
  • Reply HELP for help, or contact support@doramoapp.com.
  • Carriers are not liable for delayed or undelivered messages.

17Changes and contact

We may update this Policy; material changes will be notified in-app and/or by email and the Effective date updated.

Doramo, Inc. — 131 Continental Dr, Suite 305, Newark, DE 19713, US — Privacy contact / Privacy Officer: privacy@doramoapp.com