Privacy Policy
Last updated: draft — pending legal review. This document is a placeholder reflecting what the application actually collects and processes, not lawyer-reviewed legal text.
1. Who this applies to
This policy covers data collected by Domain Watch, operated by an individual freelance developer (no registered company), when you create an account and use the service at domainwatch.rynne.dev.
2. What we collect
- Account data: your email address and a hashed password (or magic-link sign-in, if used instead — we never store passwords in plain text).
- Watchlist data: the domain names you add to your watchlist, their checked status history (registered, available, expiring, in redemption, pending delete, etc.), and your per-event notification preferences.
- Billing data: your subscription tier and Stripe customer / subscription identifiers. Full payment card details are handled entirely by Stripe and never pass through or are stored by Domain Watch.
- Operational data: records of email notifications sent to you (for delivery troubleshooting) and basic product-usage events (for example, that a signup or plan upgrade occurred) used to understand how the service is used.
We do not collect data about domains beyond what is necessary to check and report their registration status — we do not, for example, scrape or store WHOIS/RDAP contact data for domains other than the availability/expiry/status fields the product is built around.
3. How we use it
- To operate your watchlist and send you status-change email alerts.
- To authenticate you and maintain your session.
- To process subscription payments via Stripe.
- To understand product usage and improve the service (aggregate/behavioral events, not sold or shared for advertising).
- To detect and prevent signup abuse (rate limiting, disposable-email checks).
4. Third parties we share data with
- Stripe — payment processing for paid subscription tiers.
- Our transactional email provider (currently SendGrid, or a local/no-op provider outside production) — to deliver verification and alert emails.
- Public domain registries/registrars, indirectly — we query their RDAP/WHOIS services to check the status of domains you watch. We only send the domain name being checked, not any of your account information.
We do not sell your personal data.
5. Data retention
Account and watchlist data is retained for as long as your account is active. Archiving a watched domain removes it from your active watchlist but its history may be retained for a period for support/debugging purposes. You can request deletion of your account and associated data at any time (see “Your rights” below).
6. Your rights
You may request access to, correction of, or deletion of your personal data by contacting the support address listed in your account settings. Depending on your location, you may have additional rights under applicable law (for example GDPR, if you are in the EU/UK).
7. Security
Passwords are hashed, not stored in plain text. Access to production data is limited to the service operator. No method of storage or transmission is 100% secure, and this policy does not constitute a guarantee against data breaches.
8. Changes to this policy
This policy may be updated as the service evolves. Material changes will be reflected by updating the “last updated” note above.
9. Contact
Questions about this policy, or requests regarding your data, can be sent to the support address listed in your account settings.