Last updated 15 September 2026
Privacy Policy
This policy explains what personal data Doorlyn uses, why, who we share it with, how long we keep it and the rights you have. We collect as little as we can: Doorlyn never needs to know who your guests are.
1. Who is responsible for your data
TAYLOR JACS LIMITED (“we”, “us”) is the controller of the personal data described in this policy. Our company details are on the Legal information page. For any privacy question or request, email support@taylorjacs.shop with “Privacy” in the subject.
Where you enter personal data about other people into a book (for example a contact’s name and phone number), you decide what is included and we process it on your behalf, as described in section 15 of our Terms of Service.
2. What we collect
| Data | Where it comes from |
|---|---|
| Book content — the home details you type in (names of the home and area, your first name if you add it, instructions, local places, contacts you add) | You, in the book maker |
| Account data — email address, hashed password, plan, subscription status and dates | You, when you create an account or subscribe |
| Billing data — name, billing country, last four card digits, payment status, invoices. Full card details are handled by our payment provider and never reach us | Our payment provider |
| Consent records — the plan, price and the boxes you ticked when subscribing, with the date, a hashed IP address and browser type | You, on the subscribe page |
| Support messages — your name, email and what you write to us | You, by email, phone or the contact form |
| Usage and technical data — a count of books made this month (in a cookie), server logs including IP address, browser type and pages requested | Your browser, automatically |
We do not collect information about your guests or tenants, and Doorlyn will not make a book that appears to contain it. We do not use advertising or analytics trackers. People who open a shared mobile link are not identified or tracked: the book is carried in the part of the link that browsers do not send to servers.
3. Why we use it and our legal basis
| Purpose | Legal basis (UK GDPR / EU GDPR) |
|---|---|
| Making, displaying and delivering your books; running your account and plan allowance | Performance of our contract with you |
| Taking payments, sending receipts, confirmations and renewal or price-change notices | Contract; legal obligation |
| Keeping proof of your consent to automatic renewal and immediate supply | Legal obligation; legitimate interests in being able to show we followed consumer law |
| Answering questions, complaints, refund and data requests | Contract; legitimate interests in helping customers |
| Keeping Doorlyn secure, preventing abuse of free allowances and fixing faults | Legitimate interests in running a safe, reliable service |
| Keeping accounting and tax records | Legal obligation |
We do not sell personal data, use it for advertising, or make decisions about you by automated means that have legal or similarly significant effects.
4. AI processing — and no training
Book content may be sent to an AI language model provider to smooth the wording of your book, and illustrations may be generated by an AI image model provider. These providers act as our processors, receive only what is needed for that task, and are engaged on terms that do not permit them to use your content to train their models. We never use your content to train AI models. No personal data is sent to image models.
5. Who we share data with
We share personal data only with service providers who help us run Doorlyn, under contracts that require them to protect it and use it only on our instructions:
- website hosting and content delivery providers;
- database, authentication and file storage providers;
- AI language and image model providers (see section 4);
- our payment provider, which also acts as an independent controller for its own fraud-prevention and legal obligations;
- email delivery providers; and
- professional advisers, and authorities where the law requires it.
6. International transfers
Some providers process data outside the UK and European Economic Area, including in the United States. Where they do, we rely on adequacy decisions (such as the UK–US data bridge and the EU–US Data Privacy Framework) or on safeguards such as the UK International Data Transfer Agreement or Addendum and the EU Standard Contractual Clauses. You can ask us for more information about these safeguards.
7. How long we keep it
| Data | How long |
|---|---|
| Book content when you make a book without an account | Not stored on our servers after your book is returned to you. Your draft and last book stay in your own browser until you clear them. |
| Books saved to an account | Until you delete them or your account; removed from backups within 30 days after that |
| Account data | While your account is open, then deleted within 30 days of closure |
| Consent records for subscriptions | 3 years after the subscription ends |
| Billing and tax records | 6 years from the end of the financial year they relate to |
| Support messages | 2 years from the last message |
| Server logs | 30 days |
| Monthly usage cookie | 40 days |
8. Your rights
You have the right to:
- access the personal data we hold about you and receive a copy;
- have inaccurate data corrected;
- have your data deleted — you can delete your account and books yourself from the account page;
- restrict or object to our processing, including processing based on legitimate interests;
- receive your data in a portable format; and
- withdraw any consent you have given, without affecting processing that has already taken place.
To use these rights, email support@taylorjacs.shop. We respond within one month. If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the UK Information Commissioner’s Office (ico.org.uk) or, if you live in the EU, to your local data protection authority.
9. Security
We use encryption in transit (HTTPS), access controls, hashed passwords and providers with recognised security certifications. Payment card data is handled only by our PCI DSS compliant payment provider. No system is perfectly secure; if a breach affects your data in a way that creates a high risk to you, we will tell you.
10. Children
Doorlyn is for adults running homes for guests or tenants. It is not directed at children, and we do not knowingly collect data from anyone under 18.
11. Cookies
We use essential cookies and browser storage only. See the Cookie Policy.
12. Changes
We will update this policy when our practices change and show the date at the top. If a change materially affects how we use your data, we will tell account holders by email before it takes effect.