Privacy policy
Last updated 3 September 2026.
1. Who we are
This site is operated by Domaina, the data controller for the purposes of the EU/UK GDPR. To exercise a right described below, contact Domaina Support and identify the request as a privacy request.
2. What we collect, and why
- Inquiries and offers — the name, email address, optional phone number, offer amounts and messages you submit, so the seller can respond and complete a sale you ask for (performance of a contract / legitimate interest).
- Transaction records — if a sale completes, the price, date and your name/email on the receipt (legal obligation: accounting).
- Technical protection — submission counts for rate limiting and a captcha check. Inquiry submissions record an IP address for abuse prevention (legitimate interest).
- Page-view counts — per-domain daily totals with no IP, cookie or identifier attached.
3. Cookies
The public site sets no Domaina advertising cookies. A session cookie is used when you sign in. If a third-party analytics tool is enabled (Google Analytics or Plausible), that tool's script runs on public pages under its own policy; Plausible is cookie-free.
4. Messages we send
We use the contact details you provide for account, support, and transaction messages. If SMS is available and you provide a phone number, transactional texts include opt-out instructions. Email and text providers process those messages under their service and data-processing terms. Domaina does not import messages sent to a support mailbox.
5. Sharing
Inquiry and offer details are shared with the seller for the domain you contact. Transaction details are shared with the payment or escrow provider selected for that transaction. We also share data with service providers that operate Domaina and with authorities where the law requires it. We never sell personal information, and we do not share it for cross-context behavioral advertising (the CCPA/CPRA sense of "sell or share").
6. Retention
Conversations are kept while the transaction or a follow-up remains plausible, then removed on request. Completed-sale records are kept as long as tax law requires. Backup copies may remain until they expire under the applicable retention schedule.
7. Your rights
Depending on where you live (EU/UK GDPR, California CCPA/CPRA, and similar laws elsewhere), you may have rights to access, correct, delete, or receive a copy of your personal data, to object to or restrict processing, and to complain to your data protection authority. Submit a request through Domaina Support; we respond within the statutory deadline and do not discriminate for exercising a right.
8. International transfers
The site is hosted in the United States. Where data of EU/UK residents is processed, the processors above rely on standard contractual clauses or an adequacy framework.
9. Optional identity document review
If you ask Domaina to review your identity, you may upload up to three PDF, JPEG, or PNG documents through your signed-in account. We use those documents only for the manual account review you requested. They are not used for advertising, automated facial recognition, or a public badge, and a Domaina review does not replace verification required by a bank, payment provider, tax authority, or regulator.
The files are restricted to authorized Domaina administrators and stored with authenticated encryption. Support users, other buyers and sellers, and the public cannot open them. We remove the encrypted document content 30 days after a final verified or changes-requested decision. If you replace an undecided submission, that earlier document set is removed 30 days after replacement. Eligible account deletion removes it sooner. Minimal review status and audit records remain, and an encrypted backup may remain only until that backup expires under the applicable retention schedule.
You can use the privacy-request route described above to ask for access, correction, restriction, or deletion. We will explain any legal or security reason that prevents an immediate deletion.
10. Agreement and acceptance records
What we collect. When you accept an agreement on Domaina we record: the agreement's version and the exact text shown to you (and a cryptographic hash of it); the UTC timestamp of your acceptance, taken from our server; the IP address your connection presented; the user-agent string your browser sent; the page you accepted on and the label of the control you activated; your email address and account identifier; and the domain name, amount and currency the agreement concerned.
Why we collect it. To be able to establish, exercise and defend legal claims, and to prevent and investigate payment fraud. Concretely: if a payment is reversed, this is the evidence we submit to the payment provider and card issuer. It is also what lets us answer a question about what you agreed to with a fact rather than a recollection.
Our lawful basis. Legitimate interests (Article 6(1)(f) UK/EU GDPR) — our interest in defending payment disputes and preventing fraud, and the equal interest of honest buyers and sellers in a marketplace where agreements can be proved. We have assessed this against your interests and consider it proportionate, because the data is limited to what a payment provider actually asks for, it is never used for advertising or profiling, and it is never sold. Where the acceptance is itself the formation of a contract with you, we also rely on Article 6(1)(b) (performance of a contract).
How long we keep it. For the longer of 24 months from the acceptance, or the period during which a claim connected with the transaction could still be brought. Twenty-four months is not arbitrary: card scheme dispute rules allow an issuer to look back at transactions up to 390 days old, and a dispute can itself run for months after that.
Your rights. You can ask us for a copy of your acceptance records at any time, and we will provide them. Because these records exist to prove what happened, we cannot alter them, and we will normally decline a request to erase one while a transaction it relates to could still be disputed — that is the "establishment, exercise or defense of legal claims" exemption, and we will tell you when we are relying on it and for how long. You may object to our processing on legitimate-interest grounds and we will consider it on its merits.
Who sees it. Nobody, unless a payment is disputed or a legal claim is made. In that case: the payment provider (for example Stripe or PayPal), the acquiring bank, the card issuer, and any dispute-resolution or arbitration body handling the case. We do not sell this data, we do not use it for marketing, and we do not share it with the other party to your transaction except where it is the evidence in a dispute between you.
9. Who processes data for us
We use a small number of providers to run Domaina, and each sees only what it needs: Stripe and PayPal for payments and payouts, an email provider for transactional messages, and our hosting and backup infrastructure in the United States. Payment card numbers are handled entirely by the payment provider on their own pages — a card number never reaches Domaina, and what we store is a token, the brand, the last four digits and the expiry date.
Where we introduce a new provider that handles personal data, we will list it here before it starts.
10. If you are in California
Under the California Consumer Privacy Act as amended, you may ask what personal information we have collected about you, why, and who we shared it with; ask for a copy; ask us to correct or delete it; and limit the use of sensitive information. You may exercise these rights without being treated differently for doing so.
We do not sell your personal information for money. Where analytics is enabled on our public pages, the cookie it sets may count as “sharing” for cross-context behavioural advertising under California law, and you may tell us to stop. To make any request under this section, use Domaina support — we will verify it is you before we act, and answer within the time the law allows.
11. Security, and telling you when something goes wrong
We protect accounts with hashed passwords, an optional second factor, session revocation, and access controls that scope every read and write to the account it belongs to. Backups are taken and kept under a retention schedule.
No service is immune. If a breach affects your personal information we will tell you and the regulators that require it, within the time the law sets, and we will say what happened, what was affected, and what to do about it.
Domaina is not for children. It is not directed at anyone under 18, we do not knowingly collect information from them, and if we learn we have, we delete it.
12. Changes
Updates appear on this page with a new date. See also the terms of use.