Legal

Privacy Policy

Last updated October 6, 2026

TemplateThis is a good-faith template drafted for the CustomDomain™ project. It is not legal advice and must be reviewed and adapted by qualified counsel before you rely on it in production.

This policy explains how CustomDomain™ handles personal data when you use our hosted service, embed our widget, connect a domain, or visit our sites. CustomDomain™ is embed-first infrastructure, so we play two roles: a controller for our own customer accounts and site visitors, and a processor for the end-user and domain data our customers send us. Both are covered below.

1. Who we are and our two roles

CustomDomain™ ("CustomDomain™," "we," "us," or "our") provides custom-domain onboarding for SaaS platforms: automatic DNS configuration, automatic TLS/SSL, a reverse-proxy edge, an optional domain registrar, and monitoring. The software is self-hostable; we also operate a hosted version (the "Service") at app.customdomain.ai.

The operating legal entity, its registered address, and its data protection registrations are to be confirmed by counsel before launch. Under data-protection law we act in two capacities:

  • As a controller, for personal data about our direct customers (the SaaS platforms and developers who hold CustomDomain™ accounts), prospects, and visitors to our websites (for example, account and billing data and site analytics).
  • As a processor (or sub-processor), for the personal data our customers submit to the Service about their end-users and domains (for example, the custom domains being connected, DNS records, and end-user identifiers passed through the widget). We process that data only on our customers' documented instructions under the Data Processing Addendum (DPA).

2. Scope

This policy applies to the hosted Service and our public web surfaces. It does not apply to third-party services you reach through the Service (such as your own DNS provider), to our customers' own products, or to deployments you self-host; in a self-hosted install you are the operator and this policy does not govern the data you process (see section 13).

3. Personal data we collect

3.1 Customer account data (we are the controller)

  • Identity and login: name, email address, and either a hashed password or a Google sign-in identifier, managed by our authentication layer.
  • Organization and configuration: workspace/tenant name, applications, API keys (stored only as salted or hashed values), webhook endpoints, team members, and roles.
  • Billing data: plan, subscription status, and usage counts. Card payments are handled by our payment processor (Stripe); we do not receive or store full card numbers.
  • Terms acceptance: the version of the Terms of Service and Privacy Policy you agreed to, when, and whether you agreed on the sign up form or on the page that asks existing accounts. Nothing else is kept with it: no IP address and no browser details.
  • Support and communications: messages you send us and related metadata.

3.2 End-user and domain data (we are the processor)

  • Domain and DNS data: the custom domains being connected, the DNS records we compute and apply, verification status, certificate status, and origin/health information.
  • End-user identifiers: identifiers our customers pass through the embedded widget or API to associate a connection with one of their end-users, plus short-lived, application-scoped tokens.
  • Bring-your-own DNS credentials: when an end-user authorizes automatic DNS changes, the provider access token is used server-side to apply the requested records and is then discarded. We do not retain it unless the person who supplied it explicitly chooses to save it for reuse on their other domains (an opt-in offered in our customer console, off by default, and applied only after the records were written successfully). A saved token is encrypted at rest (AES-256-GCM), is never returned to the browser, is used only to apply DNS records for that same provider account, and can be deleted at any time from the console. Separately, where a connection is set up through a provider's managed (Domain Connect) authorization flow, the authorization that provider issues is stored for that connection, also encrypted at rest, so the records can be re-applied or removed later; it is deleted when managed mode is turned off or the domain is disconnected.
  • Registrant details (registrar feature only): if a customer uses the domain-purchase feature, the registrant contact information required by the registry (name, postal address, email, phone) is processed to register the domain.

3.3 Technical data (both roles)

  • Session and security: first-party session and CSRF cookies (see the Cookie Policy).
  • Cookie choice: whether you confirmed or changed the optional analytics and marketing cookies, which are on until you change them (and off if your browser sends Global Privacy Control or Do Not Track). Once you choose, it is stored in a cookie shared across customdomain.ai and, when you are signed in, on your account with a history of changes. Until then nothing about it is stored.
  • Usage events: a random, first-party visitor id and the pages you view on our sites (the page path, the referring page without its query string, and campaign tags), linked to your account once you sign in. No IP address is stored with these page view events (the logs described under “IP addresses and domain lookups” below are separate).
  • Optional analytics (on until you turn them off): our product analytics tool (PostHog) receives your IP address when your browser contacts it, uses it to estimate your approximate location (country and city), and keeps it with the page views and actions it records in the console. We use it to understand how people get started, not to identify you or to advertise to you. If you turn analytics off, or your browser sends Global Privacy Control or Do Not Track, the tool does not load and receives nothing.
  • Session recordings (on until you turn analytics off): Unless you turn it off, we record how you use CustomDomain™ (clicks, scrolling and page views, never what you type other than a domain name) to improve it. A recording replays our pages and the console as they appeared on your screen. On the home page, the docs, the free tools and the sign up page, a visit is recorded before you have an account, under an anonymous id; if you then sign up, that recording is linked to your new account. Everything you type into a field is replaced with asterisks, so what you type is not recorded, except a domain name you type into a field that asks for one. The recording also shows what the page displays, such as the names of your domains and DNS records. The pages for signing in, resetting a password, verifying an email address, accepting an invitation, billing and agent access are never recorded. The screens for API keys, webhook signing secrets, tokens and security settings are never recorded either, and anything that shows a secret is blanked wherever it appears. We do not record the browser console, network requests or the contents of other sites' frames, such as Stripe's card form. Once you are signed in, a recording is tied to your account id, never to your email address or name, and is deleted after 30 days. Turn it off in Cookie settings (Settings, then Privacy), or send Global Privacy Control or Do Not Track, and recording stops at once.
  • Connect widget funnel: when someone uses the connect widget on a customer's site, we count which step they reached and whether it worked. Those counts carry a random session id, the DNS provider, an error code and timing. They do not carry the domain, a cookie or an account. We also keep the IP address and country of the request with each step (see below). The customer sees the counts in their own analytics, and we send the same anonymous counts to our analytics tool, without the IP address or the country.
  • IP addresses and domain lookups: when you search for, check, price, connect or buy a domain, through the console, the widget, the API, our MCP server or an AI agent, we record the domain name that was typed (never the suggestions we show back), what happened, the workspace it was for, the time, and the IP address and country of the request. We also keep the IP address of each sign in and of each account or workspace change in the audit log. We use them for security, abuse prevention and support, and not to advertise to you or to sell. They are visible to us and, for audit events, to your own workspace's administrators. Each IP address is kept for as long as your account exists, and is deleted when the account is deleted.
  • Domain checks: when you enter a domain (to search for, check, price, connect or buy it), or sign up with an address at your company's own domain, we check from our own servers whether that domain responds on the public internet, to help you connect it. We read its public DNS records (such as its nameservers, addresses and mail settings) and make one ordinary request for its home page over HTTPS, or over HTTP if HTTPS is not available, which introduces itself as CustomDomainBot. We keep what the domain publicly answers: those records, whether it responded and with what status, where it redirects, the page title and the size of the page, and whether its certificate was valid. We keep no other page content and send no cookies or credentials. We check a domain at most once a day, and the result is a fact about the domain, not about your account. To ask us not to check a domain, write to [email protected].
  • Push notifications: if you turn on push notifications, we store your browser's push endpoint and keys so we can deliver them, the browser's name (for example Chrome on macOS) so you can tell your devices apart in Settings, and when each was added and last used, all linked to your account and workspace. We read your browser's user agent to make that name and do not keep it. You can remove a device in Settings at any time, which deletes them.
  • Server logs: request method, path, status, and timing. Our request logs are designed to exclude tokens, request bodies, and query strings.
  • Audit events: security- and account-relevant events for integrity and troubleshooting, with the IP address of the request that caused them.

We do not use advertising cookies. Optional analytics tools run until you turn them off, and not at all if your browser sends Global Privacy Control or Do Not Track; see the Cookie Policy.

4. How and why we use it (purposes and legal bases)

Where the EU/UK GDPR applies and we act as a controller, we rely on the legal bases below. Where we act as a processor, the legal basis is our customer's, and we process only on their instructions.

PurposeExample dataLegal basis (controller)
Provide and operate the Service (accounts, connecting domains, issuing certificates)Account data, domain/DNS dataPerformance of a contract
Billing and fraud preventionBilling data, usage countsContract; legal obligation
Security, abuse prevention, and service integrityLogs, audit events, IP addresses and domain lookupsLegitimate interests (securing the Service)
Product improvement and troubleshootingAggregated usage, error dataLegitimate interests
Recording how the console is used, to improve it (on until you turn analytics off)A replay of clicks, scrolling and page views, with typed text and secrets hiddenLegitimate interests, with an opt-out in Cookie settings
Service and transactional communicationsEmail, account statusContract; legitimate interests
Marketing emails (where sent)Email, preferencesConsent or legitimate interests, with opt-out
Legal compliance and defense of claimsAs neededLegal obligation; legitimate interests

Where we rely on legitimate interests, we have weighed those interests against your rights. You may object to processing based on legitimate interests (see section 10).

5. When we act as a processor

For end-user and domain data (section 3.2), our customer is the controller and decides the purposes of processing. We:

  • process that data only on the customer's documented instructions;
  • impose confidentiality on personnel with access;
  • apply the technical and organizational measures described in our Security page;
  • engage sub-processors only under written terms and with notice of changes (see the Sub-processors list);
  • assist the customer with data-subject requests and with breach notification; and
  • delete or return the data at the end of the engagement, subject to legal retention.

These commitments are contractual under our Data Processing Addendum. If you are an end-user of one of our customers and want to exercise your rights, please contact that customer (the controller); we will support them in responding.

6. How we share data

We share personal data only as needed to run the Service:

  • Sub-processors: vetted vendors that host, secure, or support the Service. See the current Sub-processors list (AWS, Stripe, Cloudflare, Let's Encrypt, and the domain registrar, among others).
  • At your direction: the DNS providers and registries you or your end-users choose to connect. Those providers are independent controllers of the data you send them.
  • Legal and safety: where required by law or to protect rights, safety, and the integrity of the Service.
  • Business transfers: in a merger, acquisition, or asset sale, subject to this policy.

We do not sell personal data, and we do not "share" it for cross-context behavioral advertising as those terms are defined under U.S. state privacy laws.

7. International data transfers

We are based in, and primarily host the Service in, the United States (our infrastructure runs in a U.S. region). If you are in the EEA, the UK, or Switzerland, your personal data may be transferred to the United States and other countries.

For such transfers we rely, as applicable, on the EU-U.S. Data Privacy Framework and its UK Extension and Swiss-U.S. framework where a recipient is certified, and otherwise on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), supported by a transfer risk assessment. You can request a copy of the relevant transfer safeguards using the contact details in section 15.

8. Data retention

We keep personal data only as long as needed for the purposes above:

  • Account data: for the life of your account, then deleted or anonymized within a reasonable period after closure, except where we must retain records (for example, tax and accounting).
  • Session recordings are deleted after 30 days.
  • End-user/domain data: per our customer's instructions and the DPA; returned or deleted at the end of the engagement.
  • Bring-your-own DNS tokens: not retained by default; used to apply the requested records, then discarded. A token the user explicitly chose to save is kept, encrypted, until it is revoked in the console. A stored managed-connection (Domain Connect) authorization is kept for as long as that connection is managed, and is deleted when managed mode is turned off or the connection is removed.
  • Operational logs (request and container logs) are rotated automatically and retained only briefly for security and troubleshooting.
  • Audit events are different: they are compliance evidence, so they are append-only and are not rotated out, and the IP address of the request stays with the event. An organization’s administrators can review their own audit trail at any time, and it is never shared across organizations.
  • IP addresses (domain lookups, connect widget steps, sign ins and audit events) are kept for as long as the account exists, for security, abuse prevention and support. The domain, the result, the country and the time on a lookup stay with them.
  • Domain check results are facts about a public domain, not about you, and are not tied to your account. We keep the latest result for each domain and its last 30 changes, and remove them for a domain on request.

9. Security

We apply technical and organizational measures appropriate to the risk, including encryption in transit, encryption of sensitive secrets at rest, tenant isolation, least-privilege access, and network hardening. Details, and how to report a vulnerability, are on our Security page. No method of transmission or storage is perfectly secure, but we work continuously to protect your data.

10. Your privacy rights

10.1 EEA / UK (GDPR)

Subject to conditions and exemptions, you may have the right to access, rectify, erase, restrict, or object to processing, to data portability, and to withdraw consent. You also have the right to lodge a complaint with a supervisory authority (in the UK, the ICO).

10.2 United States (California and other states)

Depending on your state, you may have the right to know, access, delete, and correct personal information, to opt out of sale/sharing and of certain targeted advertising and profiling, and to limit the use of sensitive personal information, with a right to non-discrimination for exercising them. We do not sell or share personal information for cross-context behavioral advertising. We honor recognized opt-out preference signals, including Global Privacy Control (GPC), where applicable.

10.3 How to exercise your rights

Contact us at [email protected]. We will verify your request and respond within the timeframes required by law. You may use an authorized agent where permitted. If your data was submitted to us by one of our customers (we are the processor), we will refer or assist that customer, who is the controller.

11. Cookies

Essential cookies keep you signed in and secure. Optional analytics and marketing cookies are on until you change them, and off if your browser sends Global Privacy Control or Do Not Track; one choice covers customdomain.ai, its docs and the console, and when you are signed in it is saved to your account. Analytics includes recording how you use the console (section 3.3), under the same switch. A random first-party visitor id measures visits across our sites. We do not use advertising cookies. See the Cookie Policy for details.

12. Children

The Service is a business tool and is not directed to children. We do not knowingly collect personal data from children under 16 (or the applicable age of digital consent). If you believe a child has provided us personal data, contact us and we will delete it.

13. Self-hosting

If you deploy the self-hosted software yourself, you operate the software and control the data it processes. In that case we are neither controller nor processor for your deployment, and this policy does not apply to it. You are responsible for your own privacy compliance.

14. Changes to this policy

We may update this policy from time to time. We will change the "last updated" date above and, for material changes, provide a more prominent notice. Continued use of the Service after an update means you accept the revised policy.

15. Contact, Data Protection Officer, and EU/UK representatives

Privacy questions and requests: [email protected]. Our data protection contact can be reached at [email protected].

To be appointed before EU/UK launch: if we target the EEA or UK without an establishment there, we will appoint an Article 27 EU representative and a UK representative and publish their contact details here. Until appointed, these are placeholders for counsel to complete.