Privacy Policy
Last Updated: March 31, 2026 | Effective Date: March 31, 2026
1. Introduction
audit.domains ("we," "us," or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our domain valuation service ("Service").
2. Information We Collect
2.1 Information You Provide
- Account Information: Name, email address, password
- Payment Information: Billing address, payment method details (processed securely by Square - we do not store full credit card details)
- Domain Data: Domain names you search, appraise, or save
- Profile Information: Optional preferences, settings, and customization choices
- Communications: Support messages, feedback, and correspondence
2.2 Information Collected Automatically
- Usage Data: Pages viewed, features used, time spent, click patterns
- Device Information: Browser type, operating system, device identifiers
- Location Data: IP address, general geographic location
- Cookies: See Section 7 for cookie details
- Analytics: We use Google Analytics
2.3 Information from Third Parties
- Authentication: If you sign in with Google or Apple
- Payment Processor: Transaction data from Square (subscription status, payment history, billing information)
- Public Data: Domain registration data, WHOIS information, market sales data from our curated, price-verified sales database
3. How We Use Your Information
We use collected information for the following purposes:
- Provide Services: Process domain valuations, generate reports, save your data
- Account Management: Create and manage your account, authenticate users
- Billing: Process payments, send invoices, manage subscriptions
- Communication: Send service updates, respond to inquiries, provide support
- Improve Service: Analyze usage patterns, optimize algorithms, fix bugs
- Marketing: Send promotional emails (you can opt out anytime)
- Security: Detect fraud, prevent abuse, enforce our Terms
- Legal Compliance: Comply with laws, regulations, and legal requests
- Research: Develop new features, improve valuation accuracy
4. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), we process your data based on:
- Contract: To provide services you've requested
- Consent: When you've given explicit permission (e.g., marketing emails)
- Legitimate Interests: To improve our service, prevent fraud
- Legal Obligation: To comply with applicable laws
5. Data Sharing and Disclosure
We do not sell your personal information. We may share your data with:
5.1 Service Providers
- Payment Processor: Square processes payments and manages subscriptions. Square collects and processes payment information in accordance with their own privacy policies and applicable regulations.
- Supabase: Database and authentication services
- Google Analytics: Usage analytics
- Email Services: Transactional emails (if configured)
Payment Processor Data: When you make a purchase, your payment information is processed by Square, our payment processor. We do not store your full credit card details. Square may collect and process personal data including billing address, payment method details, and transaction history in accordance with their privacy policy and applicable data protection laws.
5.2 Legal Requirements
We may disclose your information if required by law, court order, subpoena, or to protect our rights or safety.
5.3 Business Transfers
If audit.domains is acquired or merged, your data may be transferred to the new owner.
5.4 Aggregated Data
We may share anonymized, aggregated data that cannot identify you (e.g., market trends, usage statistics).
6. Data Security
We implement industry-standard security measures to protect your data:
- Encryption: HTTPS/TLS for data in transit, encryption at rest for sensitive data
- Access Controls: Limited employee access on a need-to-know basis
- Secure Hosting: Supabase infrastructure with SOC 2 compliance
- Password Protection: Passwords are hashed using bcrypt
- Regular Audits: Security reviews and vulnerability assessments
However, no method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
7. Cookies and Tracking Technologies
7.1 Types of Cookies We Use
- Essential Cookies: Required for authentication and core functionality
- Preference Cookies: Remember your settings (theme, language)
- Analytics Cookies: Track usage patterns to improve our service
- Marketing Cookies: (If enabled) Track ad campaign effectiveness
7.2 Managing Cookies
You can control cookies through your browser settings. Note that disabling essential cookies may prevent you from using certain features.
8. Data Retention
We retain your data for as long as necessary to provide our services and comply with legal obligations:
- Account Data: Until you delete your account, plus 30 days
- Domain Searches: Stored while you have an active account
- Payment Records: 7 years for tax and accounting purposes
- Analytics Data: 26 months (Google Analytics default)
- Support Communications: 3 years or as required by law
9. Your Privacy Rights
Depending on your location, you may have the following rights:
9.1 GDPR Rights (EU/EEA Users)
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your data ("right to be forgotten")
- Restriction: Limit how we process your data
- Portability: Receive your data in a machine-readable format
- Object: Object to processing based on legitimate interests
- Withdraw Consent: Revoke consent at any time
- Complain: Lodge a complaint with your data protection authority
9.2 CCPA Rights (California Users)
- Know: What personal information we collect and how we use it
- Delete: Request deletion of your personal information
- Opt-Out: Opt out of the "sale" of personal information (we don't sell data)
- Non-Discrimination: Equal service even if you exercise privacy rights
9.3 How to Exercise Your Rights
To exercise any of these rights, email us at [email protected] with your request. We will respond within 30 days.
10. Children's Privacy
Our Service is not intended for children under 18. We do not knowingly collect personal information from children. If you believe we have collected data from a child, contact us immediately at [email protected].
11. International Data Transfers
Your data may be transferred to and processed in the United States or other countries where our service providers operate. We ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses approved by the European Commission
- Service providers with adequate data protection certifications
- Compliance with GDPR requirements for international transfers
12. Do Not Track Signals
Some browsers offer "Do Not Track" settings. We respect these signals and will not track users who have enabled them.
13. Third-Party Links
Our Service may contain links to third-party websites. We are not responsible for their privacy practices. We encourage you to review their privacy policies before providing any information.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the new policy on this page
- Updating the "Last Updated" date
- Sending an email notification (for significant changes)
Your continued use of the Service after changes constitutes acceptance of the updated policy.
15. Contact Information
For privacy-related questions or to exercise your rights, contact us:
Your Consent
By using audit.domains, you consent to this Privacy Policy and our data practices. If you do not agree, please do not use our Service.