Preview — this site is not live. Checkout is not connected. These policies are published and apply from their effective date.

Policies

DoersRise Privacy Policy

Effective date: 5 October 2026

1. Who this covers

DoersRise is a brand operated by Genufly LLC, a New York limited liability company ("Genufly LLC", "we", "us"). This policy explains what Genufly LLC does with information in connection with the Mobile Detailer Message-to-Booking Kit.

  • Legal notice address: Genufly LLC, 276 5th Avenue, Ste 704-1444, New York, NY 10001
  • Contact: support@doersrise.com

2. Two separate sets of records, and why that matters to you

Your purchase involves two organisations:

Whop operates the checkout and delivers the files. Whop collects and holds your payment and account information, and it does so under its own privacy policy and its own control. We do not control how Whop collects, uses or keeps that information, and this policy does not describe Whop's practices. For those, read Whop's privacy policy and direct requests about Whop's records to Whop.

Genufly LLC (DoersRise) holds a deliberately small set of records about the transaction, described below. We built our systems to keep as little as possible.

3. What we receive, and what we keep — these are different

This distinction is important and we state it plainly rather than imply we never see anything.

What passes through our systems

When you buy, Whop sends our server an automated notification (a "webhook") about the event. That notification can contain more about you than we keep. Depending on which version of Whop's message format is sent, it can include:

  • contact and identity details — an email address, a name or username, a phone number, billing or shipping address details;
  • payment details — a card's brand, last four digits and issuing range;
  • verification results — what the card issuer returned when it checked the billing address, the cardholder name and the security code;
  • fraud and risk information — Whop's own risk score for the transaction and the factors behind it;
  • platform references, credentials and links — internal Whop identifiers, and credentials or sign-in links Whop generates for the checkout.

This list describes categories rather than a fixed inventory of fields. The notification is Whop's, and what it contains is Whop's to change.

Our server:

  1. receives that notification in memory;
  2. verifies its cryptographic signature to confirm it genuinely came from Whop;
  3. reads out a fixed, pre-defined list of fields and nothing else;
  4. discards the rest.

We do not store the notification. There is no archive of these messages. Our database has no column that holds one. So your email address, name, phone number, address and card descriptors pass through our server transiently and are not written to our records.

What we actually keep

RecordWhat it contains
Delivery recordWhop's identifier for the notification, our own Whop account identifier, the type of event, Whop's message-format version, and when we received it
Payment recordWhop's payment identifier, the event type, the amount as text, together with a record of how that text was obtained and which message format the notification used, the currency, the product and plan identifiers, a pseudonymous Whop user identifier, the payment status, and the payment and event timestamps
Failure markerWhere a notification could not be processed: Whop's identifier for it, the event type, a SHA-256 fingerprint of the delivered message (a one-way fingerprint, not the message), Whop's payment identifier where it could be read, a classification of what went wrong, database error codes, structural diagnostics, how many times the delivery was retried, when it was first and last seen, and whether and how it was resolved
Product-improvement noteIf we ever record what we learn from customer feedback, support messages or refund reasons, we keep it as a short theme and summary recorded against the product, not against you, with no name or email address. We are not doing this today — no such record exists — and we are describing it here so that this policy stays accurate if we start

Two points about that table:

  • The fingerprint lets us recognise whether the same message arrived again, or changed, without retaining the message. A fingerprint cannot be turned back into the content.
  • The structural diagnostics record only field names and the type of value found at each (for example: "this field was present and was text"). They never record the value itself. The names we record come from a fixed list in our code, with one exception: where a notification cannot be processed — because its format is one we do not recognise, or because a field we require is missing — we also record that notification's own top-level field names, so the problem can be diagnosed at all. Those are names only — each limited in length, at most forty of them, and never the values behind them.

The pseudonymous Whop user identifier is an opaque reference issued by Whop. We use it to tie a payment record to a purchase. It is not your name or your email.

When you visit our website

We set no cookies on visitors and use no third-party analytics — there is no tracking script of any kind on the site.

Our web server does keep ordinary access logs, as almost all web servers do: the IP address the request came from, the page requested, the time, the browser's user-agent string, the page that referred your browser to us where your browser sends one, and the response our server returned. That log is rotated daily and deleted after about two weeks.

Our web server also keeps a separate error log, which records the same IP address and request where a request fails. Because it is rotated only when it has something in it, entries there can persist for a month or more. We are telling you that rather than let the two-week figure above stand for everything.

Operational and security logs

Our server writes operational logs so that failures can be diagnosed. These contain identifiers, event types, error classifications, database error codes and the structural diagnostics described above — not the contents of notifications.

These logs are held in three places on our own infrastructure, with different lifetimes:

  • the system journal, bounded by disk size rather than by any fixed period, so it can hold entries for a long time — at the time of writing, several months;
  • the system log files, which rotate weekly and are kept for about a month;
  • the database's own container log, which has no configured size or time limit at all, so entries there persist until the database container is replaced.

We would rather tell you that than imply a single tidy schedule we do not actually configure. None of these three records the contents of a notification.

If you contact support

If you email support@doersrise.com, we hold that correspondence: your email address, whatever you choose to tell us, and our replies. That mailbox is operated by a third-party email provider on our behalf.

Please do not send us payment card details. We never need them and have no use for them.

4. Why we hold it

PurposeWhy
Recording your purchaseSo there is a record that you bought the Kit
Reconciling paymentsSo there is a record of our own that a purchase can be checked against. We do not currently have programmatic access to Whop's payment records, so we cannot run that comparison automatically today
Detecting failed or lost notificationsSo a purchase is not silently missed because a notification failed to reach us
Security and integrityVerifying signatures, detecting duplicate or malformed messages, investigating problems
SupportAnswering you when you contact us
Legal and accounting obligationsKeeping the records we are required to keep

We do not use any of it for advertising or profiling, we do not sell it, and we do not share it with anyone for their own marketing.

5. Who else is involved

  • Whop — checkout, payment processing and file delivery, as an independent organisation with its own policy.
  • Infrastructure and hosting providers — our server, and the backup copies we store off-host, which are encrypted before they leave our server.
  • Our email provider — the support mailbox.
  • Professional advisers — accountants or lawyers, where genuinely needed.
  • Card issuers and payment networks — where a payment is disputed or a chargeback is defended, as described in the Refund Policy.
  • A successor — if the business is reorganised or sold, as clause 17 of the Terms permits.
  • Authorities — where we are legally required to disclose something, or to establish or defend legal claims.

6. How we protect it

  • Notifications from Whop are cryptographically verified before they are acted on; an unverified or mis-signed message is refused.
  • The payload is not retained, so there is no store of it to be exposed.
  • Credentials are stored outside the application, in files readable only by the system's administrative account, and are supplied to the service when it starts. To be accurate rather than flattering: the secrets the application itself needs are present in the running process, as they must be for it to work — its database connection, the key it uses to verify Whop's signatures, the key that signs staff sign-in sessions, and the credentials it uses to read and write our own file storage. The credentials it does not need are never available to it at all: the database owner password, the Whop API key, and the key that encrypts our backups.
  • Database access uses least-privilege accounts.
  • Database backups that we store off-host are encrypted on our own server before upload, so the storage provider never holds readable data, and we have proven by test restore that an encrypted backup can actually be recovered rather than assuming it. Backups are currently taken at release boundaries rather than on an automatic schedule.
  • Two database copies from September 2026 are also held on the server itself, taken before a release and before a database change. Being accurate rather than flattering again: those copies are not encrypted. They are readable only by the administrative accounts that operate the server, and they never leave it.
  • Access to production systems is limited to those who operate them.

No system is perfectly secure, and we do not claim otherwise.

7. Where it is held

Our server is located in the United States, and information relating to your purchase is handled there.

Our encrypted backups are held with a cloud storage provider. We have not pinned those backups to a particular storage region, so we do not tell you where the encrypted copies physically sit — we would rather say that than name a country we have not actually configured.

We do not claim any specific legal mechanism for transferring information outside the United States, because we have not put one in place. Saying otherwise would not be true.

8. How long we keep it

We do not currently run an automatic deletion schedule for the records we hold about you. We would rather tell you that plainly than describe a tidy lifecycle our systems do not perform. Logs are the exception, and they are covered below.

What that means in practice:

  • purchase and payment records are kept while they are needed for accounting, tax and dispute-handling purposes, and are not deleted automatically;
  • failure markers are marked resolved when the underlying problem is fixed, and the record is kept rather than removed;
  • support correspondence stays in the mailbox;
  • website access logs are deleted automatically, after about two weeks — but the web server's error log is not bounded by a calendar period, as section 3 explains;
  • of the three operational log stores in section 3, one rotates weekly, one is bounded only by disk size, and one is not bounded at all.

Records are therefore retained until we delete them — in response to a request under section 9, or as part of a review — rather than on a timer.

Apart from the log rotation described above, we do not publish fixed retention periods for the records we hold about you. A published period is a commitment the system has to enforce to be true, and for those records ours does not currently enforce one. Telling you the actual position is more useful than a number that quietly does not hold.

One limitation worth stating: backups are kept for disaster recovery, and a deletion request cannot reach a backup immediately. We do not currently expire backups automatically — a backup is deleted only when we delete it. The same is true of any copy held from before a change to what we store: an older backup still contains what the system held at the time it was taken.

9. Your rights

Depending on where you live, you may have the right to ask us to:

  • tell you what information we hold about you;
  • correct it if it is wrong;
  • delete it;
  • provide a copy in a portable form;
  • restrict or object to a particular use;
  • withdraw consent, where we relied on consent.

To exercise any of these, email support@doersrise.com. We will ask for enough information to be confident we are dealing with the right person, and will respond within the time any applicable law requires.

Two honest limits, and one practical point:

Our purchase and payment records hold no name and no email address. What links you to them is Whop's order or payment reference, together with the pseudonymous account identifier Whop gives us. Please include an order or payment reference when you write to us; without one we may not be able to identify your purchase records at all.

Support correspondence is different, and we would rather you knew it. If you have emailed us, that correspondence sits in our mailbox under the address you wrote from. It is covered by the rights above, and we can find it without any Whop reference.

  • Some records we must keep for accounting, tax or legal-claim reasons, and we may not be able to delete those on request.
  • Most of what identifies you personally sits with Whop, not with us. If you want your purchase information corrected or erased, you will usually need to make that request to Whop as well. We will tell you so rather than let you assume one request covers both.

If you believe we have handled your information improperly, you may complain to your local data protection authority where that right applies.

10. Children

The Kit is sold to people running or starting a business, and is not directed at children. We do not knowingly collect information from children.

As in the Terms, we require capacity to enter the agreement rather than setting a numerical age limit.

11. Changes to this policy

If we change this policy we will post the updated version and change the effective date. Where a change is significant, and we hold a way to contact you, we will make reasonable efforts to tell you.

12. Contact

Genufly LLC (operating as DoersRise) 276 5th Avenue, Ste 704-1444, New York, NY 10001 support@doersrise.com