Privacy Policy
Last updated: September 10, 2026
Doors.events is operated by Battle Plan Mil LLC, doing business as Doors.events ("we", "us", or "our"). This Privacy Policy describes what information we collect when you use doors.events, how we use it, and your rights regarding that information.
1. What we collect
We collect the minimum information needed to run an RSVP service:
- Organizers: email address (used to sign in via magic link) and an optional display name.
- RSVP guests: the name, email, and any custom answers the organizer asks for on their event's RSVP form. Phone number is optional.
- Technical: a one-way hash of your IP address (for rate-limiting and abuse prevention) and a basic user-agent string. We do not store raw IP addresses.
2. How we use it
We use the information you provide to deliver the RSVP service:
- Render the public RSVP page for an event.
- Send transactional emails: sign-in links to organizers, RSVP confirmations to guests, and reminder emails before an event.
- Operate basic abuse protection (rate-limiting on the public RSVP form and on sign-in requests).
We do not sell your information. We do not show third-party advertising to your guests.
We do not sell guest lists, guest email addresses, or any other information you or your guests give us, and we never use your guest list to advertise to your guests. We share it only with the service providers listed in the next section, who deliver our email and host the site.
3. Who we share with
We share the minimum data necessary with four service providers: Resend, Cloudflare, Netlify and Stripe.
- Resend: for transactional email delivery. Privacy policy.
- Cloudflare: DNS, bot and abuse protection (Turnstile), and website analytics. Privacy policy.
- Netlify: for application hosting and storage. Privacy policy.
- Stripe: for payment processing. When you pay for an event or a subscription we send Stripe your email address, what you are paying for, and the random internal IDs we use to match the payment back to your account. We do not send your name, your event’s title, or anything about your guests. Your card details go straight to Stripe and never reach our servers, and if Stripe asks you for a billing name or address during checkout, that stays with Stripe. Privacy policy.
We also load our typefaces from Google Fonts, which means Google's servers see your IP address and browser type when a page loads.
We do not share your information with anyone else.
When you share an event link, the app you paste it into (Slack, iMessage, Facebook and others) fetches the page to build a preview card. That card shows the event name, date, time, venue and host name. If you would rather those details not appear, share the link somewhere that does not generate previews.
4. How long we keep it
Event data (including event details and all RSVPs submitted to it) is automatically and permanently purged one year after the event's end date. This applies to every event, every organizer, without exception. Thirty days before purge, the organizer receives an email with a one-click link to export their RSVP list as CSV. After the purge date, the event, its RSVPs, any uploaded flyer, and all associated guest data are permanently purged and cannot be recovered.
Organizer accounts are similarly purged after 18 months of no login activity, with a 30-day warning email sent at the 17-month mark. Sign-in tokens expire within 15 minutes and are purged on use. Hashed IP rate-limit counters expire within an hour.
5. Cookies
We set four first-party cookies, all of them necessary: one for your session, one to remember a device you have signed in from before, and two used during two-factor sign-in. None are advertising or tracking cookies, and we set no third-party cookies. All four are Secure and SameSite=Lax. The session cookie is HttpOnly, so scripts cannot read it.
We use Cloudflare Web Analytics to see which pages get visited and how quickly they load. It sets no cookies, does not fingerprint your device, and does not follow you to other sites. We do not use advertising trackers or tracking pixels, and we do not use Google Analytics.
6. Your rights
- RSVP guests: to delete your RSVP from an event, contact the organizer (the host of the event you replied to), or email us at legal@doors.events with the event link and the email you RSVP'd with.
- Organizers: you can delete individual events (which removes their RSVPs) from your dashboard. To delete your organizer account entirely, email legal@doors.events.
7. Children
Doors is not directed at children under 13. We do not knowingly collect personal information from children under 13. Many Doors events are for children (birthdays, school events, youth programs); in those cases the organizer is responsible for obtaining parental consent to share a child's information with us via an RSVP, and the parent or guardian, not the child, is the intended user of the RSVP form.
8. Changes to this Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. Material changes will also be announced via email to organizer accounts.
9. Contact
Privacy questions? Email legal@doors.events.