This Cookie Policy ("Policy") explains how DoorCall AI, Inc. ("DoorCall AI," "we," "us," or "our") uses cookies and similar technologies on the website located at doorcall.ai and within the authenticated DoorCall AI application (collectively, the "Services"). This Policy supplements the Privacy Policy and should be read together with it. Capitalized terms not defined in this Policy have the meanings given in the Privacy Policy.
1. What Cookies Are
1.1 Definition. A cookie is a small text file placed on your device by a website or application you visit. Cookies allow the site to recognize your device, remember information about your visit, and, in some cases, track your activity across sites and over time. This Policy uses "cookies" to refer collectively to cookies and functionally similar technologies, including local storage, session storage, and pixels.
1.2 Session and Persistent Cookies. A session cookie is deleted automatically when you close your browser. A persistent cookie remains on your device for a defined period, or until you delete it, and is used to recognize your device across multiple visits.
1.3 First-Party and Third-Party Cookies. A first-party cookie is set by DoorCall AI directly. A third-party cookie is set by a domain other than doorcall.ai, typically by a service provider whose technology is embedded in the Services.
2. Categories of Cookies We Use
2.1 Strictly Necessary Cookies
These cookies are essential to the operation of the Services and cannot be disabled without materially impairing functionality you have requested. They are set without consent, as permitted under applicable law for cookies necessary to provide a service the user has explicitly requested.
| Cookie | Purpose | Duration |
|---|---|---|
dc_session |
Authenticates a signed-in user and maintains their session. Set as HttpOnly, Secure, and SameSite=Lax, and is never accessible to client-side scripts. | 14 days |
dc_org |
Remembers which workspace a signed-in user last accessed, subject to server-side verification of membership on every request. Set as HttpOnly and Secure. | 180 days |
sb-*-auth-token (Supabase-managed deployments) |
Maintains an authenticated session issued by our authentication provider. Set as HttpOnly and Secure. | Session, refreshed while active |
| CSRF and origin-verification tokens | Protect state-changing requests, including sign-in, sign-up, and configuration changes, from cross-site forgery. | Session |
| Load-balancing and routing cookies set by our hosting infrastructure | Ensure requests are routed correctly and reliably within our cloud infrastructure. | Session |
2.2 Functional Cookies
These cookies remember choices you make to provide enhanced, more personal functionality. Where required by applicable law, these cookies are set only with your consent.
| Cookie | Purpose | Duration |
|---|---|---|
| Interface preference cookies | Remember display preferences, such as date-range selections and view preferences within the dashboard. | 12 months |
| Onboarding-progress markers | Track completion of the guided setup flow so that returning users resume where they left off. | 90 days |
2.3 Analytics Cookies
These cookies help us understand how the Services are used, so that we can measure feature adoption, diagnose faults, and improve reliability. Where required by applicable law, these cookies are set only with your consent, and analytics data is not used for cross-context behavioral advertising.
| Cookie category | Purpose | Duration |
|---|---|---|
| First-party product analytics | Records feature usage and error events keyed to workspace and user identifiers, not to Caller identity. | Up to 24 months |
2.4 Third-Party Cookies
Where a Customer or DoorCall AI enables a third-party integration that sets its own cookies, including a payment processor's fraud-prevention cookies during checkout, that third party's cookie practices are governed by its own privacy and cookie disclosures, which are referenced at the point the integration is invoked. DoorCall AI does not permit third-party advertising or cross-context behavioral-advertising cookies within the authenticated application.
3. Why We Use Cookies
We use cookies to: authenticate users and maintain secure sessions; remember which workspace a user is working in; protect the Services against cross-site request forgery and other attacks; remember display and configuration preferences; measure feature usage and diagnose faults; and enforce rate limits and abuse protections central to the security of the Services.
4. Consent and Your Choices
4.1 Necessary Cookies. Strictly necessary cookies are set automatically because they are required to deliver a service you have requested, such as remaining signed in. These cookies cannot be individually declined without preventing use of the authenticated application.
4.2 Consent for Non-Essential Cookies. Where applicable law requires consent before a non-essential cookie is set, including functional and analytics cookies described in Sections 2.2 and 2.3, we will request that consent through a cookie banner or equivalent mechanism presented on your first visit, and will not set those cookies until consent is given. You may withdraw consent at any time using the mechanism described in Section 4.4, and withdrawal does not affect the lawfulness of processing before withdrawal.
4.3 Global Privacy Control. Where your browser transmits a Global Privacy Control signal or an equivalent opt-out preference signal, we treat that signal as a valid request to decline non-essential cookies and to opt out of the sale or sharing of Personal Information, to the extent either occurs.
4.4 Managing Cookies. You may manage or withdraw consent to non-essential cookies at any time through the cookie-preference control available at the foot of the website, or by adjusting your browser settings to block, delete, or receive notice before a cookie is set. Instructions for common browsers are available at the browser publisher's support site. Blocking strictly necessary cookies will prevent you from signing in to the authenticated application.
4.5 Do Not Track. Because no common industry standard for responding to a browser "Do Not Track" signal has been adopted, the Services do not currently respond differently to that signal, and we instead honor the Global Privacy Control signal described in Section 4.3.
5. Cookies Within the Authenticated Application
5.1 Necessity of Session Cookies. The authenticated portion of the Services cannot function without the strictly necessary cookies described in Section 2.1, because they are the mechanism by which a signed-in user's identity and workspace membership are verified on every request.
5.2 No Advertising Cookies. DoorCall AI does not place advertising or cross-context behavioral-advertising cookies within the authenticated application, and does not permit a Customer to embed such cookies through its workspace configuration.
6. Retention
Each cookie's duration is set out in the tables in Section 2. On expiry, a cookie is not renewed unless the underlying activity, such as an active session, recurs. You may delete a cookie before its expiry using your browser settings.
7. Changes to This Policy
We may amend this Policy from time to time in accordance with Section 20 of the Privacy Policy. Where an amendment introduces a new category of non-essential cookie, we will seek consent for that category in accordance with Section 4.2 before it is set. The "Last Updated" date at the head of this Policy identifies the date of the most recent revision.
8. Contact
Questions concerning this Policy may be directed to privacy@doorcall.ai.