Legal
Privacy Policy
This Policy explains what Easy Domain Factory handles for your account, membership, payments, and synced domain workspace.
Effective August 4, 2026
1. Scope
This Privacy Policy applies to easydomainfactory.com and the related Easy Domain Factory API and services (together, the “Service”). “Easy Domain Factory,” “we,” “us,” and “our” refer to the operator of the Service. It does not cover Stripe, registrars, registries, email providers, hosting companies, or other third-party services that publish their own privacy policies.
2. Information we handle
Account and login information
We store your email address, an internal user identifier, and information needed to secure password-free login. One-time codes are stored as non-reversible hashes, expire quickly, and cannot be used after successful verification. We may also process request time, IP address, failed attempts, and similar security information.
Membership and payment information
We store whether lifetime access is active, a random checkout reference, purchase status, amount and currency, timestamps, and Stripe Checkout Session and Payment Intent identifiers. Stripe may return the email entered at checkout for reconciliation. Access is linked through the random checkout reference—not by assuming the checkout email matches your login email. Stripe processes payment-card and other financial details; we do not receive or store full card numbers.
Workspace data stored with your account
Project briefs, keywords, exclusion lists, generated or imported candidate domains, scores, shortlists, availability results, research details, and notes are stored in our MySQL database and associated with your user identifier. This lets the Service restore and sync projects when you sign in on another supported browser or device.
Information sent when you use API features
When you ask the Service to generate, rescore, or check names, information needed for that request is sent to the API. Depending on the feature, that can include keywords, a base name, naming style, length and TLD preferences, project exclusions, scoring preferences, candidate names, and domains to check. The API processes these requests and persists account project changes. Temporary generated batches may expire as described below.
Support and operational information
If you email us, we receive your address and message contents. Our infrastructure providers may process standard request information such as IP address, browser or device type, requested URL, timestamps, response status, and diagnostic or security events. Do not include passwords, payment-card data, government identifiers, or other sensitive personal information in a project brief or support message.
3. How we use information
- send and verify login codes and maintain your authenticated session;
- record and enforce lifetime membership access;
- reconcile Stripe payments and prevent duplicate or fraudulent fulfillment;
- provide generation, scoring, comparison, export, and availability-check features;
- store, restore, and synchronize your account workspace across signed-in devices;
- respond to support requests, protect the Service, and investigate errors or abuse; and
- comply with law and enforce our Terms.
4. Browser storage, cookies, and analytics
MySQL is the permanent source of truth for your account, membership, projects, and saved domain results; those records are not stored only in your browser. Easy Domain Factory uses browser local storage only for the authentication token, the most recently viewed project, temporary interface preferences, migration progress, and unsaved drafts or caches. Local storage is similar to a cookie but is not automatically attached to every web request. Clearing it signs you out and removes those browser preferences, but does not delete server-side projects, payment records, or membership access.
The current Service does not intentionally use advertising cookies, cross-site tracking, or third-party analytics. Necessary technical mechanisms may still be used by browsers and infrastructure to deliver and secure the Service.
5. When information is shared
- Stripe. Stripe hosts checkout, processes payment, and sends signed payment events used to activate access.
- Email providers. Our configured email provider receives the address and login-message content needed to deliver your code.
- Infrastructure providers. Database, hosting, security, and operational providers process information on our behalf.
- DNS and registration-data services. Availability checks send the queried domain through DNS and to RDAP or similar services.
- Legal and safety reasons. We may disclose information to comply with law, protect rights or safety, or prevent fraud and abuse.
- Business changes. Information may be reviewed or transferred during a financing, reorganization, merger, acquisition, or asset sale.
We do not sell personal information or share it for cross-context behavioral advertising, and we do not use your workspace to show targeted advertisements.
6. Retention
Projects remain with your account until you delete them or request eligible account deletion. Generated and similar-name batches are ordinarily eligible to expire after 30 days; imported results, favorites, and results with research or notes are retained with the project. Login codes expire within minutes, while related security records may be retained briefly to enforce limits and investigate abuse. Payment and transaction records may be retained as needed for accounting, fraud prevention, dispute resolution, and legal compliance. Backups may take additional time to cycle out.
7. Security
We use safeguards including short-lived single-use code hashes, signed access tokens, database authorization checks, random checkout references, signed Stripe webhooks, and idempotent payment processing. No storage or transmission method is completely secure, so we cannot guarantee absolute security. You are responsible for protecting access to your email, browser, device, exports, and registrar account.
8. Your choices and privacy rights
You can review and change workspace data, export candidates, delete projects, sign out, or clear browser data. Deleting a project removes its active server-side project data, subject to limited backup, security, dispute, and legal retention. Clearing browser storage alone does not delete the account copy.
Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, or an objection regarding personal information we control, and to appeal or complain to a regulator. Email support@easydomainfactory.com to make a request. We may verify your identity and retain information when law permits or requires it. We will not discriminate against you for exercising a right.
9. International processing
The Service and its providers may process information in countries other than the one where you live. Those countries may have different data-protection laws. Where required, we use legally recognized safeguards for international transfers.
10. Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child provided personal information, contact us. A higher minimum age may apply where you live.
11. Changes to this Policy
We may update this Policy as the Service or legal requirements change. We will post the updated version here and revise the effective date. If a change is material, we will provide additional notice when reasonably appropriate.
12. Contact us
Questions or privacy requests can be sent to support@easydomainfactory.com.
