Privacy policy
This policy explains what personal data domaining.id collects when you browse the marketplace or submit an enquiry, why we collect it, who it is shared with, and how you can ask us to correct or delete it.
Last updated: [to be confirmed]
1. Who we are
domaining.id operates a marketplace for domain names, websites and digital products. For the purposes of applicable data protection law — including the EU/UK General Data Protection Regulation (GDPR) and Indonesia's Personal Data Protection Law (UU PDP No. 27/2022) — we act as the controller of the personal data described in this policy.
2. What we collect
We collect only what we need to respond to you and to run the marketplace safely:
- Enquiry details you type into a form: name, email address, optional phone number, city/province/country, your message, intended use, and any offer, lease term or monthly amount you propose.
- Seller submissions: the asset you want to sell, its asking price and supporting details, plus the contact details you supply.
- Account data if you register: email address, name and password (stored only as a salted hash by our authentication provider — we never see it).
- Technical data: IP address, browser user-agent string, the page you submitted from, the referring page, and any campaign parameters in the link you followed.
- Listing views: an anonymous, hashed session identifier so we can count how many people viewed a listing. This identifier is not linked to your name or email and cannot be reversed back to you.
3. IP address & approximate location
When you submit a form we record the IP address the request came from, and we look up the approximate city, region and country associated with it. This is deliberate and we want to be explicit about it: high-value domain enquiries attract fraudulent and automated submissions, and this signal is one of the main ways we detect them and apply rate limits.
The location we derive is approximate — typically city-level at best — and is inferred from the IP address alone. We do not collect GPS or precise device location, and we do not use this data to build an advertising profile of you.
4. Why we collect it
- To reply to your enquiry and negotiate, complete or decline a transaction.
- To operate lease-to-own payment plans and keep a record of payments made.
- To prevent fraud, spam and abuse, and to enforce submission rate limits.
- To keep accurate business and accounting records where the law requires it.
- To measure interest in a listing in aggregate.
We do not sell your personal data, and we do not share it with advertising networks.
5. Legal basis
Where GDPR applies, we rely on performance of a contract or steps taken at your request before entering one (responding to your enquiry, running a payment plan), our legitimate interests in preventing fraud and securing the marketplace (technical data, IP and derived location), legal obligation (tax and accounting records), and consent for anything optional such as non-essential cookies or marketing email, which you can withdraw at any time.
Where the Indonesian PDP Law applies, we process on the equivalent grounds of contractual necessity, legitimate interest, legal obligation and consent, and we honour the data subject rights it grants.
6. Who we share it with
We share personal data only with service providers that help us operate:
- Our database and authentication provider, which hosts the records described above.
- Our email delivery provider, to send you confirmations and replies.
- A spreadsheet mirror of enquiries used internally by our team to work through incoming requests.
- An IP geolocation service, which receives the IP address only, never your name or email.
- Professional advisers, or authorities where we are legally required to disclose.
Some of these providers operate outside your country. Where personal data is transferred internationally, we rely on the provider's standard contractual clauses or an equivalent safeguard.
7. How long we keep it
- Enquiries that do not lead to a transaction: up to 24 months from the last contact, then deleted or anonymised.
- Completed transactions and payment plans: retained for as long as required by tax and accounting law, typically up to 10 years.
- Technical data (IP, user-agent): up to 12 months, after which it is removed from the enquiry record.
- Hashed view identifiers: up to 12 months; they are anonymous throughout.
- Account data: for as long as your account exists, plus a short period after closure.
8. Your rights
Subject to the law that applies to you, you can ask us to give you a copy of the personal data we hold about you, correct it if it is wrong, delete it, restrict or object to how we use it, or provide it in a portable format. You can also withdraw consent where we relied on it, and lodge a complaint with your local data protection authority.
We will respond to a verified request within 30 days. We may need to keep certain records (for example, a completed transaction) even after a deletion request, where the law requires us to.
9. Cookies & analytics
We use a small number of strictly necessary cookies to keep you signed in and to remember your cookie choice. Any non-essential analytics cookies are only set after you accept them in the cookie banner, and you can change your choice at any time.
10. Security
Data is transmitted over TLS and stored with row-level access controls so that a record is only readable by you and by our staff who need it. Passwords are hashed by our authentication provider. No system is perfectly secure, but we take reasonable technical and organisational measures appropriate to the sensitivity of the data.
11. Contact us
To exercise any of the rights above, or to ask a question about this policy, contact us through the contact page. Please include enough detail for us to locate your records — the reference number from your enquiry is the fastest way.