Privacy Policy

Privacy built for trust.

Last updated: June 2026

About this policy

This policy explains how DoorLetter collects, uses, shares, and protects personal information when you use our website and services in the United States. It also describes the privacy rights available to U.S. residents, including residents of California under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the “CCPA/CPRA”), and similar state laws.

Who we are

DoorLetter is operated from the United States. We act as the business responsible for the personal information described in this policy.

For privacy matters, contact us through our contact form or at privacy@doorletter.com.

Information we collect

We collect the following categories of personal information:

  • Account & contact data — name, email, and any phone number you provide.
  • Content you create — the letters and messages you write and the recipient addresses you select.
  • Recipient addresses — mailing addresses you target, derived from public and open data sources (see “Homeowners & direct mail”).
  • Payment data — processed by Stripe; we receive confirmation and limited billing details, not full card numbers.
  • Usage & device data — IP address, browser, pages viewed, and similar analytics, collected with consent where required.

How we use your information

  • To provide the service: printing and mailing your letters, delivering replies, and managing your account.
  • To process payments and prevent fraud.
  • To send transactional and, where permitted, marketing email — consistent with the CAN-SPAM Act (see below).
  • To measure and improve the site, with your consent for non-essential analytics and advertising tools.
  • To comply with law and enforce our terms.

Cookies, analytics & advertising

We use cookies and similar technologies for essential functionality, analytics (Google Analytics), and advertising/retargeting (the Meta Pixel). The Meta Pixel may constitute “sharing” of personal information for cross-context behavioral advertising under the CPRA. You can control these through our Cookie Policyand the “Do Not Sell or Share” choice described below, and we honor Global Privacy Control (GPC) signals where required.

Service providers we share data with

We share personal information with vendors who process it on our behalf:

  • Lob — physical letter printing and mailing via the U.S. Postal Service (USPS).
  • Stripe — payment processing.
  • Resend — transactional and notification email.
  • Supabase — database and authentication.
  • Vercel — website hosting.
  • Anthropic — AI assistance for drafting letters (your text is processed to generate suggestions).
  • Google Analytics and Meta — analytics and advertising, with consent where required.

Homeowners & direct mail

DoorLetter helps people send personal letters to residential addresses. Mailing addresses are derived from public and open data sources (such as OpenStreetMap and open building data) together with reverse geocoding. We do not need or collect a homeowner’s name to deliver a letter, and letters are addressed generically.

If you are a homeowner and do not wish to receive DoorLetter mail, you can opt out at doorletter.com/unsubscribe and we will add your address to our suppression list. For email, we comply with the CAN-SPAM Act: commercial messages identify the sender, include a valid postal address, and honor opt-out requests promptly.

Your privacy rights (CCPA/CPRA and other states)

Depending on where you live, you may have the right to:

  • Know and access the personal information we hold about you.
  • Delete your personal information.
  • Correct inaccurate personal information.
  • Opt out of the “sale” or “sharing” of your personal information.
  • Limit the use of sensitive personal information.
  • Not be discriminated against for exercising these rights.

To exercise any of these rights, contact us at privacy@doorletter.com. You may use an authorized agent to submit a request on your behalf. We will verify your request before responding.

Do Not Sell or Share My Personal Information

We do not sell your personal information for money. We may “share” limited information with advertising partners (e.g., via the Meta Pixel) for cross-context behavioral advertising. To opt out, decline advertising cookies in our cookie settings, enable a Global Privacy Control (GPC) signal in your browser, or email privacy@doorletter.com.

Data retention

We keep personal information only as long as needed for the purposes above. Financial and transaction records are retained for approximately seven (7) years to meet U.S. tax and accounting requirements (e.g., IRS guidance). Other data is deleted or anonymized when no longer needed.

Where we process data

We are based in, and primarily process data in, the United States. Some of our service providers may process data in other countries; where they do, they are contractually required to protect it.

Children’s privacy

DoorLetter is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child has provided us information, contact us and we will delete it.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above, and where appropriate we will provide additional notice.

Contact

Questions about your privacy or this policy? Reach us through our contact form or at privacy@doorletter.com.