Privacy Policy
Last updated: February 24, 2026
Domain Pilot ("we," "us," "our," or "Domain Pilot") recognizes the importance of privacy, security, and transparency. This Privacy Policy describes how we collect, use, process, store, and share your personal information when you visit our website at domainpilot.io, use our web application, mobile applications, API, or otherwise interact with our services (collectively, the "Service").
Protecting your private information is our priority. We have developed this policy to help you understand how we collect, use, communicate, and protect your personal information.
This Privacy Policy is incorporated into and forms part of our Terms of Service. By accessing or using the Service, you agree to this Privacy Policy. If you do not agree with this Privacy Policy, please do not use the Service.
Key Principles
Our privacy practices are built on these core principles:
- Transparency: We clearly explain what data we collect and why
- Zero-Knowledge Security: Your registrar API credentials are encrypted so we cannot access them
- Data Minimization: We only collect data necessary to provide our Service
- User Control: You have rights over your personal data
- Compliance: We comply with GDPR, CCPA, and other applicable privacy laws
1. Information We Collect
We collect several types of information from and about users of our Service. The personal information we collect, and how we use it, varies depending upon the nature of our relationship and interactions with you.
1.1 Information You Provide to Us
Account Registration Information:
- Full name
- Email address
- Username and password
- Company name and business information (for business accounts)
- Phone number (optional)
- Billing address
Registrar API Credentials:
- API keys, tokens, and authentication credentials for third-party domain registrars (GoDaddy, Namecheap, Cloudflare, etc.)
- Registrar account usernames and identifiers
- Note: These credentials are encrypted using zero-knowledge encryption (see Section 4)
Domain and DNS Information:
- Domain names you monitor or manage
- DNS records and configurations
- Domain registration and expiration dates
- Nameserver information
- Registrar account information
Payment Information:
- Credit card details, billing address, and payment method
- Transaction history and invoice records
- Note: Payment card information is processed by our third-party payment processors (e.g., Stripe) and is not stored on our servers
Support and Communication Information:
- Communications with our support team (emails, chat logs, support tickets)
- Feedback, survey responses, and testimonials
- Call recordings (if you contact us by phone, with notice)
Profile and Preference Information:
- Notification preferences (email, SMS, push notifications)
- Dashboard customization settings
- Time zone and language preferences
- Alert thresholds and monitoring configuration
1.2 Information We Collect Automatically
Usage Information:
- IP address and approximate geographic location
- Browser type and version
- Operating system and device information
- Pages visited, features used, and time spent on the Service
- Clickstream data and navigation paths
- Access times and dates
- Referring website addresses
- Search queries within the Service
Domain Monitoring Data:
- Uptime and downtime events
- Response times and performance metrics
- SSL certificate status and expiration
- DNS query results
- Domain expiration check results
- Historical monitoring data and trends
Device Information:
- Device identifiers (e.g., mobile device ID, advertising ID)
- Device manufacturer and model
- Mobile network information
- Push notification tokens
Cookies and Similar Technologies:
- Session cookies and persistent cookies
- Web beacons, pixel tags, and clear GIFs
- Local storage and cache data
For more details, see Section 7 (Cookies and Tracking Technologies).
1.3 Information from Third-Party Sources
Registrar APIs:
- Domain portfolio information from your connected registrars
- Domain registration details, ownership information, and billing data
- DNS configurations retrieved via registrar APIs
- Registrar account metadata
Public Sources:
- WHOIS information (when publicly available)
- DNS records from public DNS servers
- SSL certificate information from public certificate databases
- Domain availability and registration data
Business Partners and Affiliates:
- Information from our marketing partners and affiliates
- Referral information from partner programs
- Event registration information from co-sponsors
Social Media Platforms:
- Information you choose to share when connecting social media accounts
- Public profile information from social networks
Analytics and Advertising Partners:
- Information from analytics services (e.g., Google Analytics)
- Advertising effectiveness data
- Market research and demographic data
1.4 Customer Data vs. Your Personal Data
Important Distinction:
Your Personal Data (covered by this Privacy Policy):
- Information about you as a Domain Pilot user
- Your account information, payment details, and usage data
- We are the "data controller" for this information
Customer Data (NOT covered by this Privacy Policy):
- Domain data and DNS configurations you manage through Domain Pilot
- Uptime monitoring results for domains you own or manage
- We act as a "data processor" for this information
- You (or your organization) are the "data controller"
- Your own privacy policy governs this data, not ours
2. How We Use Your Information
We use the personal information we collect for the following purposes:
2.1 Providing and Operating the Service
- Account Management: Creating and maintaining your user account
- Service Delivery: Providing domain monitoring, DNS management, and uptime tracking services
- API Integration: Connecting to your registrar accounts using your encrypted API credentials
- Notifications: Sending alerts about domain expirations, downtime, and other monitoring events
- Support: Providing customer support and responding to your inquiries
- Feature Access: Enabling access to premium features based on your subscription plan
2.2 Improving and Developing the Service
- Analytics: Analyzing how users interact with the Service to improve functionality
- Research and Development: Developing new features and services
- Performance Optimization: Monitoring and improving Service performance and reliability
- Bug Fixes: Identifying and resolving technical issues
- User Experience: Personalizing your experience and customizing the Service interface
2.3 Communications
- Service Communications: Sending transactional emails (e.g., password resets, subscription confirmations)
- System Notifications: Alerting you about Service updates, maintenance, and security issues
- Marketing Communications: Sending newsletters, promotional offers, and product updates (with your consent)
- Surveys and Research: Requesting feedback about the Service
- Community Engagement: Facilitating participation in user communities and events
2.4 Security and Fraud Prevention
- Account Security: Detecting and preventing unauthorized account access
- Fraud Detection: Identifying and preventing fraudulent activity and abuse
- Spam Prevention: Detecting and blocking spam and malicious content
- System Security: Monitoring for security threats and vulnerabilities
- Incident Response: Investigating security incidents and breaches
2.5 Legal Compliance and Protection
- Legal Obligations: Complying with applicable laws, regulations, and legal processes
- Law Enforcement: Responding to lawful requests from government authorities
- Rights Protection: Protecting our legal rights and interests
- Dispute Resolution: Resolving disputes and enforcing our Terms of Service
- Auditing: Conducting internal audits and quality assurance
2.6 Business Operations
- Billing and Payments: Processing payments and managing subscriptions
- Accounting: Maintaining financial records and tax compliance
- Business Transactions: Facilitating mergers, acquisitions, or asset sales
- Vendor Management: Managing relationships with service providers
- Business Analytics: Generating business intelligence and reporting
2.7 Aggregated and De-Identified Data
We may aggregate and de-identify personal information so it can no longer identify you. We use this anonymized data for:
- Industry research and benchmarking
- Service improvements and innovation
- Market analysis and trends
- Public reporting and statistics
- Academic research partnerships
We do not sell, rent, or lease your personal information to third parties.
3. How We Collect Information
We collect information through various methods:
3.1 Direct Collection
You Provide to Us:
- During account registration and setup
- When connecting registrar accounts
- Through forms on our website and in our applications
- Via customer support interactions (email, chat, phone)
- When participating in surveys or providing feedback
- During payment and subscription management
- When configuring monitoring and notification settings
3.2 Automatic Collection
Automatically Logged:
- Through cookies and similar tracking technologies
- Via web server logs and analytics tools
- From your browser and device when you use the Service
- Through mobile app usage and interaction data
- From API requests and responses
3.3 Third-Party Collection
From External Sources:
- Registrar APIs: Domain and DNS data from registrars you've connected
- Public Databases: WHOIS information and public DNS records
- Analytics Services: Usage statistics from Google Analytics and similar tools
- Payment Processors: Payment confirmation and transaction data
- Marketing Partners: Lead generation and referral information
- Social Media: Profile information if you connect social accounts
4. Data Security and Encryption
Protecting your data is our highest priority. We implement industry-leading security measures to safeguard your information.
4.1 Zero-Knowledge Encryption for API Credentials
Your registrar API credentials are protected by zero-knowledge encryption:
What This Means:
- Your API keys are encrypted using AES-256 encryption (or equivalent)
- Encryption keys are derived from your account password
- We cannot decrypt or access your API credentials in plain text
- Even Domain Pilot employees cannot view your registrar API keys
- Credentials are only decrypted temporarily in secure, isolated environments during authorized API operations
How It Works:
- Client-Side Encryption: When possible, API credentials are encrypted in your browser before transmission
- Secure Storage: Encrypted credentials are stored separately from encryption keys
- In-Memory Decryption: Credentials are decrypted only in memory during active API calls
- Immediate Purging: Decrypted credentials are immediately cleared from memory after use
- Isolated Processing: API operations occur in secure, isolated computing environments
Important: Your account password is the key to decrypting your stored API credentials. If you lose your password and cannot recover it through our password reset process, we cannot retrieve your encrypted API credentials. You will need to re-enter all registrar API keys after password recovery.
4.2 Comprehensive Security Measures
Encryption:
- TLS/SSL Encryption: All data transmitted between your browser/device and our servers is encrypted using TLS 1.2 or higher
- Data at Rest: All sensitive data stored in our databases is encrypted using AES-256 encryption
- End-to-End Encryption: Notification channels (where supported) use end-to-end encryption
Access Controls:
- Multi-factor authentication (MFA) for user accounts
- Role-based access control (RBAC) for team accounts
- Principle of least privilege for internal system access
- Strong password requirements and policies
Infrastructure Security:
- Secure cloud hosting with industry-leading providers (AWS, Google Cloud, etc.)
- Network firewalls and intrusion detection systems
- DDoS protection and rate limiting
- Regular security vulnerability scanning
- Automated threat detection and monitoring
Operational Security:
- Regular security audits and penetration testing
- Security incident response procedures and 24/7 monitoring
- Employee security training and background checks
- Secure software development lifecycle (SDLC)
- Third-party security assessments and certifications
Compliance:
- SOC 2 Type II compliance (in progress/planned)
- GDPR compliance for European users
- CCPA compliance for California residents
- Regular compliance audits
4.3 Security Limitations
No system is 100% secure. While we implement strong security measures, we cannot guarantee absolute security. We are not responsible for unauthorized access resulting from:
- Compromise of your account password or credentials
- Phishing attacks or social engineering targeting you
- Malware, keyloggers, or viruses on your devices
- Vulnerabilities in third-party services or infrastructure
- Advanced persistent threats or zero-day exploits
- Circumstances beyond our reasonable control
4.4 Your Security Responsibilities
You play a critical role in security:
- Strong Passwords: Use unique, complex passwords for your Domain Pilot account
- Password Protection: Never share your password or leave your account logged in on shared devices
- MFA Enabled: Enable multi-factor authentication when available
- Device Security: Keep your devices and software updated with latest security patches
- Registrar Security: Ensure your registrar accounts have strong security settings
- Minimum Permissions: Grant only necessary permissions when creating registrar API keys
- Activity Monitoring: Regularly review your account activity logs
- Report Incidents: Immediately report suspected security breaches to security@domainpilot.io
5. How We Share Your Information
We do not sell, rent, or lease your personal information to third parties. We share your information only in the following limited circumstances:
5.1 Service Providers and Processors
We share information with trusted third-party service providers who perform services on our behalf:
Payment Processing:
- Stripe, PayPal, or other payment gateways
- Process payments and manage subscriptions
- Subject to their own privacy policies
Email and Communication Services:
- SendGrid, Mailgun, or similar email delivery services
- Twilio or similar SMS notification providers
- Push notification services (Firebase, Apple Push Notification Service)
Cloud Infrastructure:
- Amazon Web Services (AWS), Google Cloud Platform, or similar hosting providers
- Cloud storage and computing services
- Database hosting and management
Analytics and Monitoring:
- Google Analytics or similar web analytics services
- Application performance monitoring (APM) tools
- Error tracking and logging services
Customer Support:
- Help desk and ticketing systems
- Live chat services
- Customer relationship management (CRM) platforms
Security Services:
- DDoS protection providers
- Web application firewall (WAF) services
- Security monitoring and threat intelligence
All service providers:
- Are contractually obligated to protect your information
- May only use your information to provide services to us
- Are required to comply with applicable privacy laws
5.2 Registrar APIs
We access your registrar accounts on your behalf:
- Using the encrypted API credentials you provide
- To retrieve domain information, DNS records, and account details
- To perform actions you authorize (e.g., DNS updates, domain renewals)
- Subject to the registrar's own terms of service and privacy policy
Important: We are a data processor when accessing your registrar accounts. Your registrar is the data controller for data in your registrar account.
5.3 Business Transfers
In connection with any merger, acquisition, reorganization, sale of assets, or similar business transaction:
- Your information may be transferred to the acquiring entity
- You will be notified via email and/or prominent notice on our website
- This Privacy Policy will continue to apply unless you consent to a new policy
- You may have the option to delete your account before the transfer
5.4 Legal Requirements and Protection
We may disclose your information when required by law or to protect our rights:
Legal Compliance:
- In response to lawful requests from government authorities
- To comply with court orders, subpoenas, or legal processes
- To comply with applicable laws and regulations
- To cooperate with law enforcement investigations
Rights Protection:
- To enforce our Terms of Service
- To protect our legal rights and interests
- To defend against legal claims or litigation
- To prevent fraud, abuse, or illegal activity
- To protect the safety and security of users or the public
5.5 With Your Consent
We may share your information with third parties when you explicitly consent:
- Social media platforms (if you choose to connect accounts)
- Integration partners (if you authorize third-party integrations)
- Business partners for co-marketing or events (with opt-in consent)
- Public testimonials or case studies (with explicit permission)
5.6 Aggregated and De-Identified Data
We may share aggregated or de-identified data that cannot identify you:
- For research, analytics, and industry benchmarking
- In public reports and statistics
- With academic or research institutions
- For business intelligence and market analysis
6. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
6.1 Retention Periods
Active Accounts:
- Personal information is retained while your account is active
- Usage data is retained for service improvement and analytics
- Historical monitoring data is retained according to your subscription plan
Closed Accounts:
- Most personal information is deleted within 30 days of account closure
- Certain information may be retained longer for legal and business purposes
- Backup copies may persist for up to 90 days
Legal and Regulatory Compliance:
- Financial records retained for 7 years (or as required by law)
- Support tickets and communications retained for 3 years
- Legal hold data retained until the matter is resolved
- Audit logs retained for 1 year (or as required for compliance)
6.2 Factors Affecting Retention
We determine retention periods based on:
- The nature of the information and purpose of collection
- Length of our ongoing relationship with you
- Legal obligations and regulatory requirements
- Need for information in connection with legal claims
- Business needs and operational requirements
6.3 Data Deletion
When You Delete Your Account:
- You can request account deletion through your account settings
- We will delete or anonymize your personal information within 30 days
- Some information may be retained as described in Section 6.1
- Registrar API credentials are immediately deleted upon account closure
Right to Deletion:
- You may request deletion of your personal information (see Section 8)
- We will comply with deletion requests subject to legal exceptions
- Certain information may be retained for legal or operational purposes
7. Cookies and Tracking Technologies
We use cookies and similar technologies to provide, improve, and personalize the Service.
7.1 What Are Cookies?
Cookies are small text files stored on your device by your web browser. They contain information that can be read by web servers and help websites remember your preferences and activity.
7.2 Types of Cookies We Use
Essential Cookies (Required):
- Session management and authentication
- Security and fraud prevention
- Load balancing and performance
- Cannot be disabled without affecting Service functionality
Functional Cookies (Optional):
- Remember your preferences and settings
- Personalize your dashboard and interface
- Store language and timezone preferences
- Enhance user experience
Analytics Cookies (Optional):
- Google Analytics or similar web analytics
- Measure Service usage and performance
- Track page views, sessions, and user flows
- Help us improve the Service
Marketing Cookies (Optional):
- Advertising and remarketing campaigns
- Measure advertising effectiveness
- Deliver targeted advertisements
- Track conversions from marketing campaigns
7.3 Other Tracking Technologies
Web Beacons (Pixel Tags):
- Small graphics in emails and web pages
- Track email opens and link clicks
- Measure campaign effectiveness
Local Storage:
- HTML5 local storage for offline functionality
- Store larger amounts of data than cookies
- Persist across browser sessions
Session Storage:
- Temporary storage for current session only
- Cleared when you close your browser
7.4 Third-Party Cookies
Third parties may set cookies when you use our Service:
- Google Analytics: Web analytics and user behavior tracking
- Advertising Networks: Ad delivery and remarketing
- Social Media Platforms: Social sharing and login features
- Payment Processors: Secure payment processing
Each third party has its own privacy policy governing their use of cookies.
7.5 Managing Cookies
Browser Controls:
- Most browsers allow you to control cookies through settings
- You can block, delete, or receive warnings about cookies
- Disabling cookies may affect Service functionality
Opt-Out Tools:
- Google Analytics Opt-Out: https://tools.google.com/dlpage/gaoptout
- Network Advertising Initiative: http://www.networkadvertising.org/choices/
- Digital Advertising Alliance: http://www.aboutads.info/choices/
Do Not Track (DNT):
- Some browsers send "Do Not Track" signals
- We currently do not respond to DNT signals
- This may change as industry standards develop
8. Your Privacy Rights and Choices
Depending on your location, you may have certain rights regarding your personal information.
8.1 Universal Rights (Available to All Users)
Access Your Information:
- Request a copy of the personal information we hold about you
- Receive information about how we process your data
Correct Your Information:
- Update inaccurate or incomplete personal information
- Correct errors in your account profile
Delete Your Information:
- Request deletion of your personal information
- Close your account and remove your data
Opt-Out of Marketing:
- Unsubscribe from marketing emails using the link in emails
- Update your notification preferences in account settings
- Contact us to opt out of other marketing communications
Data Portability:
- Export your domain data and monitoring history
- Receive your data in a structured, machine-readable format
8.2 Additional Rights for EEA/UK Residents
Under GDPR and UK GDPR, you have additional rights:
Right to Object:
- Object to processing based on legitimate interests
- Object to direct marketing at any time
Right to Restrict Processing:
- Limit how we process your information in certain circumstances
Right to Withdraw Consent:
- Withdraw consent for processing that requires your consent
- Does not affect the lawfulness of processing prior to withdrawal
Right to Lodge a Complaint:
- File a complaint with your local data protection authority
- List of EU Data Protection Authorities: https://edpb.europa.eu/about-edpb/board/members_en
- UK Information Commissioner's Office: https://ico.org.uk/
8.3 Additional Rights for California Residents
Under CCPA/CPRA, California residents have specific rights:
Right to Know:
- Categories of personal information collected
- Sources from which information was collected
- Business purposes for collection
- Categories of third parties with whom we share information
- Specific pieces of personal information collected about you
Right to Delete:
- Request deletion of personal information
Right to Opt-Out:
- Opt out of "sale" or "sharing" of personal information
- We do not sell personal information in the traditional sense
- We may share data with advertising partners (see Section 5)
Right to Correct:
- Request correction of inaccurate personal information
Right to Non-Discrimination:
- You will not be discriminated against for exercising your rights
8.4 How to Exercise Your Rights
Submit a Request:
- Email: privacy@domainpilot.io
- Account Settings: Some rights can be exercised directly in your account settings
Verification:
- We will verify your identity before processing requests
- You may need to provide additional information for verification
- We will respond to requests within the timeframes required by law (typically 30-45 days)
Authorized Agents:
- You may designate an authorized agent to make requests on your behalf
- We may require proof of authorization and identity verification
9. International Data Transfers
Domain Pilot is based in the United States, and your information may be stored and processed in any country where we or our service providers operate facilities.
9.1 Data Transfer Mechanisms
For Transfers from EEA/UK: We ensure adequate protection through:
- Standard Contractual Clauses (SCCs): EU/UK-approved data transfer agreements
- Adequacy Decisions: Transfers to countries deemed adequate by the EU/UK
- Additional Safeguards: Supplementary measures to ensure data protection
For Transfers from Other Regions:
- We comply with applicable data transfer laws and regulations
- Implement appropriate safeguards as required by law
9.2 Service Provider Locations
Our service providers may be located in:
- United States
- European Union
- United Kingdom
- Other countries where we operate
A complete list of subprocessors and their locations is available upon request.
9.3 Your Rights Regarding International Transfers
- You have the right to obtain information about the safeguards we use for international transfers
- Contact us at privacy@domainpilot.io for details about data transfer mechanisms
10. Children's Privacy
Domain Pilot is not intended for use by children under 16 years of age.
We do not knowingly collect personal information from children under 16. If you are under 16, please do not:
- Register for an account
- Use the Service
- Provide any personal information to us
If you believe we have collected information from a child under 16:
- Contact us immediately at privacy@domainpilot.io
- We will promptly delete the information
Parents and Guardians:
- If you believe your child has provided personal information to us, please contact us
- We will take steps to delete the information and terminate the account
11. Third-Party Services and Links
The Service may contain links to third-party websites, services, and applications.
11.1 Third-Party Websites
We are not responsible for:
- Privacy practices of third-party websites
- Content or security of external sites
- Information you provide directly to third parties
We recommend:
- Reviewing privacy policies of third-party websites before providing information
- Understanding how third parties collect and use your data
11.2 Third-Party Integrations
Registrar Integrations:
- Subject to each registrar's privacy policy and terms of service
- We act as a data processor when accessing your registrar accounts
- Examples: GoDaddy, Namecheap, Cloudflare
Other Integrations:
- Social media platforms (for login or sharing)
- Payment processors (for subscription management)
- Communication services (for notifications)
11.3 Social Media Features
Social sharing buttons and features:
- May allow third parties to collect information about you
- Subject to the privacy policies of social media platforms
- May track your activity across websites and services
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
12.1 Notice of Changes
How We Notify You:
- We will post the updated Privacy Policy on this page
- Update the "Last Updated" date at the top of this policy
- For material changes, we will provide prominent notice:
- Email notification to your registered email address
- In-app notification when you next log in
- Notice on our website homepage
12.2 Your Acceptance of Changes
Continued use of the Service after changes constitutes acceptance:
- Review this Privacy Policy periodically
- Check the "Last Updated" date for recent changes
- Contact us if you have questions about changes
If you do not agree with changes:
- You may close your account
- Contact us to exercise your data rights before the changes take effect
12.3 Material Changes
Material changes may include:
- New uses of personal information
- Changes to data sharing practices
- Significant changes to your rights
- Changes to our data security practices
We will provide at least 30 days' advance notice of material changes.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices:
Email:
- Privacy Inquiries: privacy@domainpilot.io
- Security Issues: security@domainpilot.io
Response Time:
- We will respond to privacy inquiries within 30 days
- Complex requests may require additional time (up to 90 days with notice)
- Urgent security issues will be addressed immediately
By using Domain Pilot, you acknowledge that you have read, understood, and agree to this Privacy Policy.
Domain Pilot - Never lose a domain again.