This policy describes what DomainOwl actually collects and does today, in plain language. It hasn't been reviewed by a lawyer. If you're relying on this for formal legal compliance (GDPR, CCPA, or similar), have it reviewed before you depend on it.
Who this applies to
This policy covers DomainOwl (referred to as "we", "us", or "DomainOwl"), operated without a separate registered business entity at this time. We act as the data controller for the personal data described in this policy. For any privacy question or request, contact contact@domainowl.io.
What we collect
- Account information — your email address, name (optional), and a hashed password if you sign up with email/password. If you sign in with Google, we receive your name, email, and profile picture from Google.
- Domain portfolio data — whatever you add or import: domain names, registrars, expiry dates, acquisition costs and dates, renewal history, sale records, and any notes you enter. Expiry and registrar data may also be looked up automatically via the public RDAP protocol.
- Billing information — plan, subscription status, and a customer/subscription reference ID from our payment processor, Creem. We do not receive or store your card number; Creem handles that directly.
- Session data — a login session cookie used to keep you signed in. We don't use analytics or advertising cookies.
How we use it
- To run the service: showing your portfolio, calculating P&L, and generating exports.
- To send you email — expiry alerts, weekly digests, password reset links, and billing-related notices — via our email provider, Resend.
- To process payments and manage your subscription, via Creem.
- To look up public registry data (registrar, expiry date, status) for domains you add, via RDAP.
We don't sell your data, and we don't use it for advertising.
Legal basis for processing (GDPR)
If you're in the EU, EEA, or UK, here's the legal basis we rely on for each use of your data:
- Contract — account, portfolio, and billing data, because we need it to provide the service you signed up for.
- Legitimate interest — expiry alerts and digest emails, security logs (like rate-limiting failed sign-ins), and looking up public RDAP data, because these directly support the service and don't override your rights.
- Consent — optional communications you explicitly opt into, if any. You can withdraw consent anytime by adjusting your notification settings or contacting us.
- Legal obligation — billing records we may need to retain for tax or accounting compliance.
Cookies
We use one essential session cookie to keep you signed in. It's strictly necessary for the service to function, so it doesn't require consent under GDPR/ePrivacy rules. We don't use analytics, tracking, or advertising cookies, and we don't run any third-party ad or tracking scripts on the site.
Who we share it with
Only the third parties needed to run the service:
- Creem — payment processing and subscription billing.
- Resend — transactional and alert email delivery.
- Google — if you choose to sign in with Google.
- Domain registries, via the public RDAP protocol, to look up registration data for domains you track — this is a public lookup and doesn't send your personal information to the registry.
Some of these providers may process data on servers outside your country, including outside the EU/EEA/UK. Where that happens, we rely on the provider's own compliance mechanisms (such as Standard Contractual Clauses) to keep that transfer lawful.
Your rights under GDPR (EU/EEA/UK users)
In addition to the controls below, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data (most of this you can do yourself in Settings).
- Erasure — request deletion of your account and data (see "Full deletion" below).
- Restriction — ask us to limit how we use your data in certain circumstances.
- Portability — receive your data in a portable format (our CSV export covers this for your portfolio data).
- Objection — object to processing based on legitimate interest.
- Lodge a complaint — with your local data protection supervisory authority, if you believe we've mishandled your data.
To exercise any of these rights, email contact@domainowl.io. We'll respond within one month, as required by GDPR.
Your data, your control
- Export — download your full portfolio and P&L data as CSV anytime from your dashboard.
- Archive — disable your account yourself from Settings. This locks access but keeps your data intact in case you come back.
- Full deletion — email contact@domainowl.io to request permanent deletion of your account and data. We don't yet have a self-serve delete button — this is a manual process on our end for now.
- Correction — update your name, email, or password anytime from Settings.
Data retention
We keep your data for as long as your account is active or archived. If you request deletion, we remove your account and portfolio data from our production database; some records may persist briefly in backups before they age out.
Children's privacy
DomainOwl isn't directed at children, and we don't knowingly collect data from anyone under 16.
Changes to this policy
If this policy changes materially, we'll update the date at the top of this page. Continued use of DomainOwl after a change means you accept the updated policy.