← Back to Doorly

Privacy Policy

Last updated: 4 August 2026

The short version. Doorly is read-only against your store — it never writes anything. It collects nothing that identifies a shopper: no name, no email, no IP address, no cookie identifier, and no date of birth. When a shopper enters a date of birth on the age gate, it is compared in their own browser and discarded before anything is sent anywhere. We do not sell data, and we never will.

Who we are

Doorly is an age-verification app for OpoShop stores, published by Found. This policy covers the Doorly app, the storefront age gate it renders, and the website at trydoorly.com. Contact: brandon@tryfound.io.

Merchant store data

When you install Doorly, OpoShop's OAuth flow grants us a store access token. We request the narrowest scopes the app can function with — users:read, products:read, collections:read — and no write scope of any kind. With them we read:

That is the complete list. Doorly does not read your orders, your customers, your revenue, or your inventory, because an age gate has no business knowing any of it.

Shopper data

This is the part that matters most for an age gate, so we will be exact.

There is no shopper profile in Doorly, because there is nothing to build one from.

Payment data

Doorly never sees, handles, or stores card or payment data. It is not part of your checkout and has no access to it.

Where data is stored, and for how long

Your configuration and the daily counters are stored in Doorly's own MongoDB database, scoped strictly per store — one store can never read another store's data, and this is enforced at the database index level as well as in the application. Data is hosted on Fly.io in the United States.

We keep your configuration for as long as the app is installed, plus a short period afterwards so that reinstalling restores your exact gate rather than starting you over. Daily counters are retained as your verification record. Request deletion at any time by emailing us and we will remove your store's data.

Uninstalling

Removing Doorly from your store immediately stops the age gate rendering — OpoShop calls our uninstall endpoint, and the storefront configuration flips off at once. Your access token is no longer usable.

Sub-processors

Cookies

On your storefront, Doorly sets exactly one first-party cookie (doorly_ok_<age>) holding a timestamp, so a shopper who has already confirmed is not asked again. It is not a tracking cookie and it is not used for advertising, profiling, or analytics. The Doorly admin uses browser storage to keep your session.

Your rights

Depending on where you are, you may have rights to access, correct, export, or delete data we hold about you as a merchant. Email brandon@tryfound.io and we will action it. For shoppers, there is generally nothing to action — we hold nothing that identifies them.

Changes

If this policy changes materially we will update the date at the top and, where the change affects how data is handled, notify merchants in the app.

Contact

brandon@tryfound.io