Privacy Policy
RDAPWatch checks the public DNS, TLS and registration configuration of domains. Most of what the service handles is public infrastructure data, not personal data. This page describes exactly what we do store about you.
What we collect
- Your email address — only if you create an account. It is the account identifier and the address alerts are sent to. There is no password: sign-in works by emailing you a one-time link.
- The domains you monitor, and the results of the checks we run against them (scores, statuses, and the raw DNS/TLS/RDAP records those checks read).
- Alert state — which issues opened and resolved on your domains and when we emailed you about them.
- Product events — coarse actions such as "a check was started" or "a domain was added", used to understand which parts of the product get used.
- Your IP address, transiently — held as a short-lived counter to rate-limit anonymous checks. The counter expires about an hour after it is written and is never joined to an account.
- Alert channel settings — a Slack webhook URL or Telegram chat ID, if you choose to add one.
What we do not collect
- No passwords — we never have one to lose.
- No payment card details. Checkout is handled by Lemon Squeezy, which is the merchant of record; we receive only a customer reference and your plan.
- No advertising or cross-site tracking cookies, and no third-party ad networks.
- We do not sell or rent personal data, and we do not share it for others' marketing.
Running a check on a domain you don't own
Every check reads only publicly published records — DNS, the certificate a server presents, RDAP registration data, and public DNS blocklists. Report pages are public and may be indexed by search engines, so treat a report URL as public. If a report about a domain you control should not be public, email us and we will remove it and block it from being regenerated.
How long we keep things
- Check results: about 90 days, then automatically deleted.
- Cached public reports: one hour.
- Rate-limit counters: about one hour.
- Sign-in links: 30 minutes, and single-use.
- Account, domains and alert history: until you delete the account, then removed along with everything linked to it.
Who else processes this data
- Cloudflare — hosting, database and caching.
- Resend — sends sign-in links, alerts and the weekly digest.
- Lemon Squeezy — payments and invoicing, as merchant of record.
- Slack / Telegram — only if you configure those alert channels.
- Public DNS resolvers and DNSBL / RDAP / Certificate Transparency operators — queried to perform checks. They see the domain being checked, not who asked.
Your choices
You can see everything we hold about you from your dashboard, remove any monitored domain at any time, and delete your account — which erases your email, domains, check history and alerts. Alert emails relate to a service you asked for; to stop them, remove the domain or close the account. For access, correction, export or deletion requests, email privacy@rdapwatch.com and we will respond within 30 days.
Children
The service is for domain owners and operators and is not directed at children under 16.
Changes
If this policy changes materially we will update the date above and, for account holders, say so by email before the change takes effect.
This policy describes our actual practices in plain language. It is not legal advice; if you need a policy audited against a specific regime (GDPR, CCPA, or your own DPA), have a lawyer review it.