Easy Domain FactoryDomain discovery workspace
TermsPrivacy
Back to workspace

Legal

Privacy Policy

This Policy explains what Easy Domain Factory handles for your account, membership, payments, and synced domain workspace.

Effective August 6, 2026

1. Scope

This Privacy Policy applies to easydomainfactory.com and the related Easy Domain Factory API and services (together, the “Service”). “Easy Domain Factory,” “we,” “us,” and “our” refer to the operator of the Service. It does not cover Stripe, registrars, registries, email providers, hosting companies, or other third-party services that publish their own privacy policies.

2. Information we handle

Account and login information

We store your email address, an internal user identifier, and information needed to secure password-free login. One-time codes are stored as non-reversible hashes, expire quickly, and cannot be used after successful verification. We may also process request time, IP address, failed attempts, and similar security information.

Membership and payment information

We store whether lifetime access is active, a random checkout reference, purchase status, amount and currency, timestamps, and Stripe Checkout Session and Payment Intent identifiers. Stripe may return the email entered at checkout for reconciliation. Access is linked through the random checkout reference—not by assuming the checkout email matches your login email. Stripe processes payment-card and other financial details; we do not receive or store full card numbers.

Workspace data stored with your account

Project briefs, keywords, exclusion lists, generated or imported candidate domains, scores, shortlists, availability results, research details, and notes are stored in our MySQL database and associated with your user identifier. This lets the Service restore and sync projects when you sign in on another supported browser or device.

Information sent when you use API features

When you ask the Service to generate, rescore, or check names, information needed for that request is sent to the API. Depending on the feature, that can include keywords, a base name, naming style, length and TLD preferences, project exclusions, scoring preferences, candidate names, and domains to check. The API processes these requests and persists account project changes. Temporary generated batches may expire as described below.

Support and operational information

If you email us, we receive your address and message contents. Our infrastructure providers may process standard request information such as IP address, browser or device type, requested URL, timestamps, response status, and diagnostic or security events. Do not include passwords, payment-card data, government identifiers, or other sensitive personal information in a project brief or support message.

3. How we use information

  • send and verify login codes and maintain your authenticated session;
  • record and enforce lifetime membership access;
  • reconcile Stripe payments and prevent duplicate or fraudulent fulfillment;
  • provide generation, scoring, comparison, export, and availability-check features;
  • store, restore, and synchronize your account workspace across signed-in devices;
  • with the applicable choice, understand site usage and measure advertising visits and conversions;
  • respond to support requests, protect the Service, and investigate errors or abuse; and
  • comply with law and enforce our Terms.

4. Browser storage, cookies, and analytics

Essential storage

MySQL is the permanent source of truth for your account, membership, projects, and saved domain results; those records are not stored only in your browser. Easy Domain Factory uses browser local storage only for the authentication token, the most recently viewed project, temporary interface preferences, privacy choices, migration progress, and unsaved drafts or caches. Local storage is similar to a cookie but is not automatically attached to every web request. Clearing it signs you out and removes those browser preferences, but does not delete server-side projects, payment records, or membership access.

Optional analytics and advertising technologies

As of this Policy’s effective date, the optional providers described below have not yet been activated. We may enable Google Analytics, Google Ads, and Meta Pixel for site analytics, campaign attribution, conversion measurement, remarketing, relevant advertising, and advertising audience features. When enabled, their operation depends on the browser privacy signals and preferences described below.

  • Google Analytics. When permitted to operate, it may process page URLs and titles, referrers, visit and interaction events, approximate location derived from IP address, browser and device information, and pseudonymous identifiers. Common first-party cookies include _ga and _ga_<container-id>, which Google documents with a default expiration of up to two years.
  • Google Ads. When permitted to operate, Google tags may process ad-click information, campaign parameters, page visits, purchases or other configured conversion events, and browser identifiers for conversion measurement, attribution, remarketing, and ad personalization. Conversion-linking storage may include _gcl_* cookies and a _gcl_ls local-storage entry.
  • Meta Pixel. When permitted to operate, the pixel may process page visits, referral and campaign information, browser and device information, IP address, and configured conversion events for ad measurement, attribution, audience creation, and remarketing. Meta commonly identifies _fbp and _fbc as browser-identification cookies with lifespans of up to 90 days.

Provider behavior, cookie names, and retention can change and may vary with configuration, browser, region, and your provider-account settings. We do not intend to send account email addresses, payment-card information, project briefs, searched domain candidates, or exclusion lists to these browser analytics or advertising tools. Before enabling a new provider or materially different use, we will review the configuration and update this Policy when appropriate.

Your privacy controls

Analytics and advertising technologies may operate by default. Privacy Choices opens with Analytics and Targeted advertising and data sharing enabled, and lets you change either preference at any time. A recognized Global Privacy Control signal automatically disables the targeted advertising and data-sharing preference.

We check both the Sec-GPC: 1 request header and navigator.globalPrivacyControl. Privacy records stored on your device contain the preference values, timestamp, Policy version, source, and compliance mode, without an account identifier. Google consent signals initially deny analytics storage, ad storage, advertising user data, and ad personalization until the privacy context and saved preference are applied. When targeted advertising is off, our controls deny Google advertising storage, user data, and personalization, revoke Meta consent, and attempt to delete accessible first-party advertising cookies and conversion-linker storage. Browser restrictions prevent us from deleting third-party or inaccessible cookies, which you can remove through browser controls.

5. When information is shared

  • Stripe. Stripe hosts checkout, processes payment, and sends signed payment events used to activate access.
  • Email providers. Our configured email provider receives the address and login-message content needed to deliver your code.
  • Infrastructure providers. Database, hosting, security, and operational providers process information on our behalf.
  • DNS and registration-data services. Availability checks send the queried domain through DNS and to RDAP or similar services.
  • Analytics and advertising providers. Google Analytics and Google Ads are analytics and advertising technology providers. When those tools operate under the applicable privacy mode and preference, Google may receive the analytics, advertising, browser, device, and conversion information described above under the Google Privacy Policy.
  • Social-media advertising providers. Meta is a social-media and advertising technology provider. When Meta Pixel operates under the applicable privacy mode and preference, Meta may receive the browser, device, page, campaign, audience, and conversion information described above under the Meta Privacy Policy and Cookies Policy.
  • Legal and safety reasons. We may disclose information to comply with law, protect rights or safety, or prevent fraud and abuse.
  • Business changes. Information may be reviewed or transferred during a financing, reorganization, merger, acquisition, or asset sale.

We do not sell personal information for money and do not use private workspace content to personalize advertisements. Some laws may define disclosure through advertising cookies, pixels, remarketing, or audience tools as “sharing,” “targeted advertising,” or a “sale” even when no money changes hands. Where those laws apply, disabling Targeted advertising and data sharing in Privacy Choices or sending a recognized Global Privacy Control signal is treated as an opt-out for future browser-based advertising disclosures covered by that choice.

6. Retention

Projects remain with your account until you delete them or request eligible account deletion. Generated and similar-name batches are ordinarily eligible to expire after 30 days; imported results, favorites, and results with research or notes are retained with the project. Login codes expire within minutes, while related security records may be retained briefly to enforce limits and investigate abuse. Payment and transaction records may be retained as needed for accounting, fraud prevention, dispute resolution, and legal compliance. Backups may take additional time to cycle out.

If optional analytics or advertising tools are enabled, pseudonymous event and campaign data may be retained according to our configured provider settings and the provider’s policies. Browser identifiers may remain until their configured expiration or until you clear them; disabling a category prevents future use by our tags but does not itself erase data already held by Google or Meta.

7. Security

We use safeguards including short-lived single-use code hashes, signed access tokens, database authorization checks, random checkout references, signed Stripe webhooks, and idempotent payment processing. No storage or transmission method is completely secure, so we cannot guarantee absolute security. You are responsible for protecting access to your email, browser, device, exports, and registrar account.

8. Your choices and privacy rights

You can review and change workspace data, export candidates, delete projects, sign out, or clear browser data. Deleting a project removes its active server-side project data, subject to limited backup, security, dispute, and legal retention. Clearing browser storage alone does not delete the account copy.

Privacy Choices lets you disable Analytics or opt out of targeted advertising and certain data sharing. You may also use browser controls, Global Privacy Control, and provider privacy controls. These controls are available through the site footer and workspace navigation.

Depending on where you live, you may have rights to confirm whether we process your information; know or access its categories, specific pieces, sources, purposes, and recipient categories; correct or delete it; obtain a portable copy; restrict or object to processing; withdraw consent; opt out of targeted advertising or a sale or sharing; limit certain uses of sensitive information; and appeal or complain to a regulator. We do not knowingly use sensitive personal information to infer characteristics or personalize advertising.

Use Privacy Choices for a browser-based advertising opt-out. Email support@easydomainfactory.com for other requests or an appeal, and state the right you want to exercise. An authorized agent may submit a request where law permits. We may verify identity or authority for account-specific requests and retain information when law permits or requires it. We will not discriminate against you for exercising a privacy right.

9. International processing

The Service and its providers may process information in countries other than the one where you live. Those countries may have different data-protection laws. Where required, we use legally recognized safeguards for international transfers.

10. Children

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child provided personal information, contact us. A higher minimum age may apply where you live.

11. Changes to this Policy

We may update this Policy as the Service or legal requirements change. We will post the updated version here and revise the effective date. If a change is material, we will provide additional notice when reasonably appropriate.

12. Contact us

Questions or privacy requests can be sent to support@easydomainfactory.com.

© 2026 Easy Domain FactoryQuestions? support@easydomainfactory.com