The short version. We collect your email address, the domains you ask us to watch, and what we find when we check them. We use that to run the service and to email you when something about your domains changes. We do not sell your data. Analytics and live chat stay switched off until you accept them in the cookie banner.
Who we are
Domain Lab is operated by Domain Lab LLC, a Minnesota limited liability company (file number 1531233500023), wholly owned by Objective Labs, LLC. For everything in this policy, Domain Lab LLC is the data controller.
For any privacy question or request, email support@domainlab.app and put "Privacy" in the subject line. We answer privacy requests within one month.
What we collect and why
Everything below is either something you gave us or something the service produced while doing the job you asked it to do. Each row names the lawful basis we rely on under the UK and EU General Data Protection Regulation.
| What | Why | Lawful basis |
|---|---|---|
| Email address and password | To create your account, sign you in and send service messages. | Performance of your contract with us |
| Domains you add | They are the thing we monitor. Without them there is no service. | Performance of contract |
| Scan results — WHOIS and RDAP records, SSL certificate details, DNS records | To detect changes, expiries and misconfigurations and tell you about them. | Performance of contract |
| Change events and alert history | To show your timeline and to avoid sending you the same alert twice. | Performance of contract |
| Notification settings — email addresses, Slack webhooks, Pushover keys, custom webhooks | To deliver alerts where you asked. Stored encrypted. | Performance of contract |
| Registrar credentials, if you connect one | To import your domain list automatically. Stored encrypted, never displayed back. | Consent, withdrawable by disconnecting |
| Billing details | To take payment. Card numbers go straight to Stripe and never reach our servers. | Performance of contract and legal obligation |
| API keys and request counts | To authenticate API calls and enforce your plan's rate limits. | Performance of contract |
| Free tool lookups — the domain searched and the page you came from | To keep the free Domain Status Checker working and see which tools are worth building. | Our legitimate interest in running and improving the tool |
| Your IP address, when you use the contact form | Passed to Cloudflare Turnstile to confirm you are not a bot. Not stored by us. | Our legitimate interest in preventing abuse |
| Analytics — pages viewed, approximate region, device type | To understand which parts of the site get used. | Your consent, given in the cookie banner |
| Live chat messages | To answer you when you start a chat. | Your consent, given in the cookie banner |
Emails we send you
There are two kinds, and they work differently.
Alerts and service messages. Expiry warnings, DNS and certificate changes, failed scans, password resets, billing notices. These are the product. You control which ones you get and how, in your notification settings, but you cannot switch off essentials like billing and security notices while you have an account.
Product updates and offers. Because you gave us your email address when you signed up for Domain Lab, we may also send you news about Domain Lab itself: new monitoring features, changes to your plan, tips for getting more from the service, and occasional offers on our own related products. This is the "soft opt-in" that applies to existing customers. We will never send you someone else's marketing, and we will never pass your address to another company for theirs.
Every one of these carries an unsubscribe link, and using it stops that category immediately without affecting your alerts. You can also opt out at any time by emailing us.
Automated analysis
On paid plans, Domain Lab can send a domain's current state to a large language model to produce a short written explanation of what changed and whether it matters. We use Google Gemini, with Groq and xAI as fallbacks when it is unavailable. What we send is the domain's technical record: registration dates, nameservers, certificate details and DNS entries.
These explanations are advisory. They do not make decisions about you, they do not affect your account, your billing or your access, and nothing in the service is decided by automated means in the sense of Article 22 of the GDPR.
Information about people who are not our customers
Public WHOIS and RDAP records sometimes contain the registrant's name, postal address, phone number or email address. When a Domain Lab user monitors a domain, we retrieve and store that public record so we can detect when it changes.
We rely on our legitimate interest, and our users' legitimate interest, in monitoring the registration status of domains that matter to them. We do not build profiles from this data, we do not market to registrants, we do not sell or publish it, and we never enrich it from other sources. If you are a domain registrant and want to know what we hold about you or want it removed, email support@domainlab.app.
Who else sees your data
We use the providers below to run the service. Each one only gets what it needs for its job, each is bound by a written agreement, and none of them may use your data for their own purposes. We update this list when it changes.
| Provider | What it does | What it sees |
|---|---|---|
| Supabase | Database, sign-in and backend functions | All account and monitoring data |
| Cloudflare | Site hosting, DNS lookups, bot protection | IP address and request details |
| Stripe | Payments and subscriptions | Email and billing details |
| Resend | Sending email | Email address, name, plan, activity |
| Gemini analysis, and Analytics if you accept it | Domain records; site usage | |
| Groq | Fallback analysis model | Domain records |
| xAI | Second fallback analysis model | Domain records |
| Tawk.to | Live chat, if you accept it | Chat messages and page context |
| Pushover | Push alerts, if you set them up | Alert content and your device key |
| Slack | Alerts to a webhook you supply | Alert content |
| Porkbun | Registrar sync, if you connect it | Your domain list |
Beyond these, we disclose data only when the law requires it, or to protect our rights or someone's safety. If Domain Lab is ever sold or merged, your data moves with the service and we will tell you before that happens.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
Where your data is held
Domain Lab is a US company and our database runs in the United States. If you are in the United Kingdom, the European Economic Area or Switzerland, your data is transferred to the United States and other countries where our providers operate.
For those transfers we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and, where a provider is certified, the EU-US and UK-US Data Privacy Framework. You can ask us for a copy of the safeguards that apply to a particular provider.
How long we keep things
| Data | Kept for |
|---|---|
| Account details | Until you delete your account |
| Domains and their latest scan | Until you remove the domain or close your account |
| Scan history | Your plan's history window, plus 30 days. The most recent scan for a domain is always kept while the domain is. |
| Change events and alert history | Your plan's history window, minimum 90 days |
| AI explanations | As long as the event they describe |
| Free tool lookups | 12 months |
| Billing and tax records | 7 years, as US tax law requires |
| Backups | Up to 30 days after deletion, then overwritten |
Your rights
Wherever you live, you can ask us to give you a copy of your data, correct it, delete it, send it to you in a portable format, restrict what we do with it, or object to processing we base on legitimate interests. Where we rely on your consent, you can withdraw it at any time, and doing so does not make what we did beforehand unlawful.
To exercise any of these, email support@domainlab.app. We will not charge you, and we will not treat you differently for asking. We may need to confirm you control the account before we act.
If you are in the UK or EEA and you think we have got this wrong, you can complain to your national data protection authority. In the UK that is the Information Commissioner's Office. We would rather you told us first so we can fix it.
Keeping it safe
Notification settings and registrar credentials are encrypted before they are stored, using a key derived separately for each user, and registrar credentials are never shown back to you or to us. Every database table enforces row-level security, so one account cannot read another's rows. Traffic is encrypted in transit. Payment card details never touch our servers.
No system is perfectly secure. If a breach ever affects your personal data and creates a real risk to you, we will tell you and the relevant regulator without undue delay.
Children
Domain Lab is a tool for people running websites and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us their details, email us and we will delete the account.
Changes to this policy
When we change this policy we update the effective date at the top. If a change materially affects your rights, we will email you before it takes effect.