Privacy & Policy
This Privacy Policy explains how DOORO collects, uses, stores, processes and protects your personal information when you use our platform and services.
Last updated: July 21, 2026
Information We Collect
Welcome to DOORO's privacy policy ("Privacy Policy" or "Policy").
This Privacy Policy explains how Blum Cab Mobility Solutions Private Limited CIN U62099GJ2025PTC166132, registered at A-1142 to A-1148, Money Plant High Street, Near BSNL Office, Jagatpur, Dascroi, Ahmedabad, Gujarat 382470, India, operating the DOORO brand ('DOORO', 'we', 'us' or 'our'), collects, uses, shares, stores and protects personal data when individuals use https://www.withdooro.com/ the DOORO mobile application, customer-support channels, recruitment and employment channels, and related services (collectively, the "Platform").
This Policy applies to Customers, prospective Customers, website visitors, DOORO employees and Service Personnel, job applicants, authorised representatives of business Customers, and other individuals who interact with us. It should be read with the Terms and Conditions, Cookie Policy, Cancellation and Refund Policy, employee notices where applicable, and any just-in-time notice displayed when data is requested.
DOORO acts as a data fiduciary for personal data where it determines the purpose and means of processing. Service Personnel process Customer data only as authorised for assigned work and under DOORO’s employment, confidentiality, security and operational instructions. A separate vendor or business partner may act as an independent data fiduciary where it determines its own purposes and means of processing, in which case its privacy notice may also apply.
Privacy Principles
We seek to process personal data for lawful, specified and necessary purposes; provide clear notice; collect only data reasonably needed; keep data accurate where relevant; protect it with reasonable security safeguards; retain it only as long as necessary or legally required; and provide accessible channels for rights and grievances.
Consent is requested where required and may be withdrawn with comparable ease. Withdrawal does not affect processing already lawfully completed and may prevent us from providing a feature that genuinely requires the relevant data.
Personal Data We Collect
Account and identity data: name, mobile number, email, username, password or authentication token, profile photo, age confirmation, preferred language and account identifiers.
Contact and service-location data: home or service address, landmark, pin code, saved addresses, live or approximate location where enabled, access instructions, building details, household preferences and emergency or alternate contact information you choose to provide.
Booking and service data: selected services, schedule, service notes, property or appliance details, requested tasks, Service Personnel assignment, arrival and completion events, before-and-after images where relevant and permitted, support history, service history, ratings, complaints and resolution records.
Payment and transaction data: payment method type, UPI ID or masked payment details received from payment processors, payment status, invoices, refunds, Credits, chargebacks, taxes and transaction identifiers. We generally do not receive or store complete card numbers or card security codes when a regulated payment processor handles them.
Communications data: in-app chat, emails, support tickets, SMS or WhatsApp interactions, call metadata, call recordings where notice and consent requirements are met, and communications with Service Personnel through Platform tools.
Device and technical data: IP address, device identifiers, app instance ID, operating system, browser, network, language, time zone, app version, crash logs, diagnostic information, security events, referring URL and cookie or SDK identifiers.
Usage and analytics data: pages or screens viewed, clicks, search and booking flow, feature use, session duration, response to notifications, campaign attribution and interaction patterns.
Safety, fraud and trust data: reports of misconduct, suspected fraud signals, blocked accounts, identity verification results, device or payment risk indicators, incident evidence, and records required to protect Customers, Service Personnel, other employees and the Platform.
Employee, Service Personnel and applicant data: identity and contact details, photograph, address, government identification where lawfully required, bank and tax details, skills, training, work history, assigned service areas, shift availability, customer ratings, background or police-verification results where applicable, driving or technical credentials where relevant, attendance, leave, salary, incentives, payroll, statutory benefits, performance, disciplinary, safety and employment records.
Marketing and preference data: consent choices, notification settings, preferred services, survey responses, promotion use and communication preferences.
User content: reviews, comments, photos, videos, service instructions and other material voluntarily uploaded or submitted.
Sensitive or High-Risk Information
Please do not provide information that is not needed for a booking. Service notes should not contain passwords, full bank details, unnecessary government identifiers, health records or confidential documents.
Some services may incidentally reveal health, disability, religious, household or lifestyle information. We process such information only where reasonably necessary for the requested service, safety, accessibility, legal compliance or another clearly disclosed purpose.
Precise location, identity documents, background checks, call recordings and incident evidence receive access controls and retention limits appropriate to their sensitivity.
How We Collect Data
Directly from you when you register, book, pay, contact support, complete a survey, apply for employment, join DOORO as Service Personnel, submit a complaint, upload content or otherwise interact with us.
Automatically through cookies, mobile SDKs, logs, device permissions, analytics and security technologies when you use the Platform.
From Service Personnel and other employees when they receive or perform an assignment, update booking status, submit service evidence, record attendance, report an incident or provide feedback.
From payment processors, identity-verification providers, background-check providers, app stores, communications providers, referral partners, advertising partners and other vendors, subject to their lawful authority and privacy terms.
From publicly available sources, government or professional registers, and lawful authorities where needed for verification, fraud prevention, safety or compliance.
Purposes of Processing
We process personal data to: create and secure accounts; verify identity and eligibility; show available services; estimate prices; assign and dispatch Service Personnel; provide directions and access information; send booking and safety updates; process payments, invoices, Credits and refunds; provide support; investigate complaints, incidents and fraud; monitor service quality; personalise language and relevant features; maintain records; administer recruitment, employment, shifts, attendance, payroll, incentives, benefits, training, supervision and performance; comply with tax, company, consumer, payment, labour, safety and other legal obligations; protect legal rights; improve the Platform; analyse demand and operations; prevent misuse; and communicate policy or service changes.
With appropriate consent or another lawful basis, we may send offers, measure campaigns, personalise marketing, request surveys, use non-essential analytics, and show relevant advertisements.
We may create aggregated or anonymised information that does not reasonably identify an individual for analytics, service planning, research, safety trends and business reporting.
Grounds for Processing and Consent
Depending on the activity and applicable law, processing may be based on your consent, steps requested before entering a contract, performance of the service contract, compliance with legal obligations, responding to a medical or safety emergency, voluntary provision for a specified purpose, employment, payroll, benefits, workplace-safety and personnel-management purposes, or another legitimate use permitted by law.
Where consent is the basis, the notice will describe the personal data and purpose in clear language. You may withdraw consent through account settings, the cookie preference tool, unsubscribe controls or by contacting us. A service may become unavailable where the withdrawn data is essential to provide it.
We do not treat silence, inactivity or a pre-ticked box as consent where affirmative consent is required.
Location and Device Permissions
The app may request location permission to verify service availability, suggest addresses, assign nearby Service Personnel, support employee navigation and attendance verification, estimate arrival, prevent fraud and improve safety. You may choose approximate or precise location where your device supports that choice.
Camera or photo permission may be used for profile images, service-condition images, invoices, identity verification or complaint evidence. Microphone permission may be used only for a clearly identified feature such as a support call or voice input. Notification permission is used for booking updates, reminders and optional marketing.
You can manage permissions in device settings. Disabling a permission may limit the related feature but should not prevent unrelated functions.
Cookies, SDKs and Similar Technologies
We use cookies, pixels, local storage, mobile SDKs and similar technologies for essential operation, authentication, security, preferences, analytics, performance, attribution and advertising. Details, providers, duration and choices are described in the Cookie Policy.
Non-essential cookies or SDKs will be used based on consent where required. You can change choices through the cookie preference centre and device or browser settings.
Sharing of Personal Data
Service Personnel: We make available only the Customer data reasonably necessary for an assigned employee or team to perform the booking, such as Customer name, contact relay, service address, task details, schedule, access notes and safety information. Service Personnel receive that data under DOORO’s confidentiality, security and employment instructions and are not authorised to use it for unrelated marketing, personal contact or off-platform solicitation.
Customers: We share limited Service Personnel details reasonably necessary for trust, booking and safety, such as first name, profile photo, skill or training indicators, vehicle or arrival details where relevant, and Platform contact options. Employment, payroll, personal-address and private contact information is not shared with Customers.
Service providers: We may use vendors for cloud hosting, customer support, communications, maps, analytics, fraud prevention, identity verification, background checks, cybersecurity, document storage, payment processing, tax, accounting and professional advice. They receive only data reasonably necessary for contracted functions and are subject to confidentiality and security obligations.
Affiliates and corporate transactions: Data may be shared with affiliates under common control or transferred in a merger, financing, restructuring, acquisition or sale, subject to continued legal protection and notice where required.
Legal and safety disclosures: We may disclose information to courts, regulators, law-enforcement agencies, emergency services, insurers, auditors or other persons where required by law, valid process, protection of rights and safety, investigation of fraud or an emergency.
Business partners and marketing: We may share limited data with referral, promotion or advertising partners only as disclosed and with consent where required. We do not sell personal data for money.
Payment Processing
Payments may be processed by Razorpay or other payment providers displayed at checkout. The provider independently processes payment credentials under its privacy policy and applicable payment-security standards. DOORO typically receives transaction status, token, masked instrument details and identifiers needed for reconciliation, refund and fraud prevention.
Do not send complete card numbers, CVV, UPI PIN, banking password or one-time password to DOORO, Service Personnel or a support representative.
International Data Transfers
Some vendors or cloud systems may process data outside the state or country where you are located. We will use contractual, technical and organisational measures required by applicable law and will comply with any government restriction on cross-border transfer.
Where a transfer requires consent or a specific notice, we will provide it. We assess service providers based on the nature of data, purpose, security and legal requirements.
Data Retention
We retain personal data only for as long as necessary for the stated purpose and legal requirements. Retention depends on account status, booking history, tax and accounting rules, limitation periods, safety and fraud risks, dispute status and legal hold obligations.
Indicative periods, subject to legal review and operational need: account and profile data while the account is active and for up to three years after closure; booking, invoice and payment records for up to eight years where tax or accounting law requires; support and routine communication records for up to three years; call recordings ordinarily up to 180 days unless needed for an open complaint, training sample or legal claim; precise location, attendance and raw operational logs for shorter periods appropriate to the feature; fraud and safety records for as long as reasonably necessary to prevent repeat harm; unsuccessful job-application data ordinarily up to two years; and employee, payroll, benefits and statutory employment records for the period required by labour, tax, social-security, limitation and other applicable laws.
When retention ends, data is deleted, securely destroyed or irreversibly anonymised. Backups may retain data for a limited rolling period and will not be restored for ordinary use after deletion.
Data Security
We use reasonable safeguards appropriate to the nature and risk of the data, which may include encryption in transit and at rest, access controls, authentication, network and application security, secure development, logging, vendor review, employee confidentiality, incident response, backups and periodic testing.
No system is completely secure. You must protect your device and credentials, avoid sharing one-time passwords, and notify us promptly of suspected compromise.
If a personal-data breach creates a legal notification obligation, we will notify the relevant authority and affected individuals in the manner and time required by applicable law, including information reasonably available about the incident, likely consequences and protective steps.
Children’s Privacy
The Platform is intended for adults. A person under eighteen may not independently create an account or consent to personal-data processing. A parent or lawful guardian must place and supervise any booking involving a child.
Where we knowingly process a child’s personal data, we will obtain verifiable parental consent where required, limit processing to the service and safety purpose, and avoid tracking, behavioural monitoring or targeted advertising directed at children unless lawfully permitted.
Contact us if you believe a child has created an account or submitted data without proper authorisation.
Your Rights and Choices
Subject to applicable law, you may request: a summary of personal data being processed and processing activities; correction of inaccurate or misleading data; completion of incomplete data; deletion of data no longer necessary or processed based on withdrawn consent; withdrawal of consent; access to grievance redressal; nomination of another person to exercise rights in the event of death or incapacity where applicable; and information about major processors or recipients as required by law.
You may update many account details in the app, manage permissions in your device, change cookie choices, unsubscribe from marketing, or request account deletion through the Platform or by emailing help@withdooro.com.
We may verify identity before acting on a request. We may retain or refuse deletion of data where necessary for law, fraud prevention, safety, payment reconciliation, dispute resolution or legal claims. We will explain a refusal where required.
Rights requests should not be fraudulent, abusive or based on impersonation. You are responsible for providing authentic information and not suppressing material facts when making a complaint.
Account Deletion
You may request deletion in the app or by contacting support from the registered email or mobile number. We will confirm the request and explain any account impact, outstanding booking, balance or mandatory retention.
Deletion removes or de-identifies information that is no longer required. Transaction, tax, employment, fraud, safety, complaint and legal records may be retained for the applicable period. Public reviews may be anonymised rather than deleted where lawful and necessary to preserve service and review integrity.
Marketing and Advertising Choices
You may opt out of promotional email, SMS, WhatsApp or push notifications using the message control, app settings or support. Opting out does not stop essential booking, payment, safety, account or legal messages.
You can withdraw consent for advertising cookies through the cookie preference centre. Mobile operating systems may provide advertising-ID reset or tracking controls.
We do not guarantee that browser 'Do Not Track' signals are technically uniform. Where a legally recognised universal opt-out signal applies, we will respond as required.
Automated Systems
We may use automated or algorithmic systems to estimate prices, detect fraud, assign Service Personnel, prioritise support, personalise recommendations and analyse service quality. Assignment systems may use factors such as employee location, shift availability, training, service category, experience, ratings, completion history,
workload, risk signals and demand. These tools support DOORO’s operational decisions and do not create a direct contractual relationship between the Customer and Service Personnel.
Automated outputs support operations and do not remove human review where a decision has a significant adverse effect. You may contact support to contest an apparent error and provide relevant context.
Public Content and Social Features
Reviews or other content designated as public may be visible to other users and may be indexed by search engines. Do not publish personal contact details, home access codes, government identifiers or another person’s private information.
We may moderate or remove content under the Terms. Copies may remain in backups, legal records or third-party caches beyond our direct control for a limited period.
Third-Party Links and Services
Third-party sites, app stores, payment providers, social networks and embedded tools have independent privacy practices. This Policy applies only to DOORO’s processing. Review the third party’s privacy notice before providing data directly to it.
We may moderate or remove content under the Terms. Copies may remain in backups, legal records or third-party caches beyond our direct control for a limited period.
Changes to this Policy
We may update this Policy for legal, security, product or operational changes. The updated date will be posted. Material changes will be communicated through the Platform, email or another reasonable channel before taking effect where required.
A new purpose that is incompatible with the original notice will be supported by fresh notice and consent or another lawful basis.
Privacy Requests, Grievances and Support
Email for privacy, rights, account-deletion requests and grievances: help@withdooro.com
General and legal contact by email: info@withdooro.com
Chat support: Use the DOORO in-app or website support chat.
Registered office: A-1142 to A-1148, Money Plant High Street, Near BSNL Office, Jagatpur, Dascroi, Ahmedabad, Gujarat 382470, India
Support responses are ordinarily provided Monday to Friday, 9:00 a.m. to 6:00 p.m. Indian Standard Time, excluding public holidays.
Please state your registered mobile number, the nature of the request and sufficient details to identify the relevant account or booking. We aim to acknowledge grievances within forty-eight (48) hours and resolve them within one
(1) month or a shorter statutory period.


