Privacy Policy
Effective: 2026-07-30
TL;DR: We collect minimal data needed to run the service. We don't sell your data. We use industry-standard security. You can delete your account and data anytime.
Who controls your data
DomScan is operated by Esteve Castells trading as DomScan. For account, billing, support, security and website data, Esteve Castells is the data controller.
When a customer sends personal data through an API, batch job, webhook or another service feature, the customer normally acts as controller and DomScan acts as processor. The Data Processing Addendum applies to that processing. Data Processing Addendum.
What We Collect
We keep data collection to a minimum. Here's what we store:
Account Information
- Email address - from Google OAuth sign-in
- Name - from your Google profile (optional)
- Profile picture URL - from Google (we don't download it)
- Signup source - the signup landing page, referring site origin, campaign tags, and country code recorded when a new account is created
- Account membership and invitations - your account role, account association, invitation email address, and invitation status
API Usage Data
- API requests - endpoint paths, timestamps, status codes, response times, credit settlement, and privacy-safe JSON previews kept for 30 days; request headers and secret values are never stored
- Batch jobs and webhooks - inputs, results, status, delivery attempts, encrypted webhook secrets and operational metadata, retained for 24 hours
- Credit transactions - for billing and usage tracking
- API keys - hashed, never stored in plaintext
- Support and billing - support messages, delivery records, purchase identifiers, credit-ledger events and accounting records
- Upstream queries - domains, hosts, email addresses or other query values sent to the public or contracted source needed to answer the request
Technical Data
- IP addresses - for signup attribution, rate limiting and security; they may be linked to an account where needed
- User agent - for debugging API issues
What We Don't Collect
- Domain ownership information (we only query public RDAP data)
- Browsing history outside our site
- Passwords or full payment card numbers
Why we process data and our legal bases
- Contract: to create and secure accounts, provide APIs, deliver purchased credits and respond to service requests.
- Legal obligation: to maintain tax, payment and accounting records and respond to lawful requests.
- Legitimate interests: to prevent abuse, investigate errors, protect the service and improve reliability, after balancing those interests against your rights.
- Consent: to run optional Google Analytics 4. You may withdraw consent at any time without affecting earlier lawful processing.
How We Use Your Data
- Service delivery - to process API requests and manage your account
- Billing - to track credit usage and process payments
- Security - to detect abuse, rate limit, and prevent fraud
- Support - to help you when you contact us
- Improvements - aggregated, anonymized usage patterns to improve the API
- Acquisition analysis - to understand which signup sources lead to activation and paid use
Data Storage & Security
Security measures:
- All connections use HTTPS/TLS
- API keys are hashed with SHA-256
- Session tokens are cryptographically signed
- No passwords stored (we use OAuth)
No online service can guarantee absolute security.
Retention
- Privacy-safe API request logs: 30 days.
- Asynchronous batch inputs, results and webhook configuration: 24 hours.
- Session cookie: 30 days. OAuth state: 10 minutes. Anti-abuse cookie: 2 years. Language cookie: 1 year.
- Account, team, payment, accounting and support records: only as long as needed to provide the service, resolve disputes, prevent abuse and meet legal obligations.
- Backup copies: retained according to the backup cycle and protected until overwritten or deleted.
Third Parties
We use the following services:
- Hetzner - Hosts the Node application, PostgreSQL, Valkey and local object storage.
- Cloudflare - DNS/CDN, security, Turnstile, email dispatch and routing, and R2 off-site backups.
- Google - Google OAuth, hosted fonts and optional Google Analytics 4.
- Stripe - Payment processing.
- Cuentica - Accounting and invoice records.
- Telegram - Customer notifications and support.
- Webshare - Proxy for some registry and certificate-transparency requests.
- ZeroBounce - Optional email-address deliverability verification.
See the Subprocessors page for the current provider list, purposes and data categories.
We do not sell, rent, or share your personal data with third parties for marketing.
International transfers
Some providers may process data outside the European Economic Area. Where data protection law requires a transfer safeguard, DomScan uses an applicable lawful mechanism offered by the provider, such as an adequacy decision or the European Commission Standard Contractual Clauses.
Your Rights
You have the right to:
- Access - view all data we have about you
- Export - request a portable copy of data we are required to provide
- Delete - request account deletion, subject to billing, accounting, security, abuse-prevention and backup retention
- Correct - update your information
You may also complain to the Spanish Data Protection Agency, AEPD. aepd.es.
To exercise these rights, visit your account settings or email us.
Questions about privacy? Reach out: