Privacy Policy
Last updated 31 August 2026
1. Who we are
DomSec HQ ("we", "us", "our") provides domain email-security and web-security scanning and monitoring at domsechq.com. This policy explains what personal data we collect, why, and what rights you have over it. If you have questions, email [email protected].
2. What we collect
- Account data — your email address and a hashed (never plain-text) password when you sign up.
- Domain data — the domain names you choose to monitor, and the results of the security checks we run against them (DNS records, certificate details, security headers, and similar).
- Billing data — handled entirely by Stripe. We never see or store your card number; we keep only your Stripe customer and subscription IDs, so we know which plan you're on.
- Technical data — your IP address, used briefly to enforce rate limits and stop abuse. A session cookie keeps you logged in.
- Anonymous checks — if you check a domain without an account, we process the request to show you a result but don't tie it to any identity.
- Aggregate site analytics — see Section 5. This does not identify you personally.
3. How we use it
To run the checks you ask for, monitor domains on your behalf, send you degradation-alert emails if you're on a paid plan, process payments, prevent abuse of the free tier, understand how the site is used in aggregate so we can improve it, and respond to support requests.
4. Who we share it with
We use two third-party processors: Stripe for payment processing and Mailtrap for sending account and alert emails. Each processes data under its own privacy policy. Our site analytics (Section 5) run entirely on our own infrastructure and are not shared with, or processed by, any third party. We do not sell your data, and we don't share it with anyone else except where required by law.
5. Cookies and analytics
DomSec HQ uses a single essential session cookie to keep you signed in when you have an account. Beyond that, we run Umami, an open-source, self-hosted analytics tool that we operate ourselves on our own infrastructure — no analytics data is sent to Google, Meta, or any other third party. Umami does not use cookies and does not collect personally identifiable information: it records aggregate metrics like page views, referring sites, and browser/device type, using a rotating identifier that cannot be used to track you individually across visits or across other websites. There is no advertising and no cross-site tracking on this site.
6. How long we keep it
We keep your account data and monitoring history for as long as your account exists. If your account is deleted, your monitored domains and check history are deleted along with it.
7. Your rights
You can ask us to access, correct, or delete your personal data, or object to how we use it, at any time by emailing [email protected]. We don't yet have a self-service "delete my account" button in the product — email us and we'll action it directly.
8. Security
Passwords are hashed with Argon2 and never stored or logged in plain text. Payment details never touch our servers at all — Stripe handles that end to end.
9. International transfers
Stripe and Mailtrap may process data outside the UK/EEA as part of their own infrastructure. Both provide standard contractual safeguards for doing so.
10. Children
DomSec HQ is not directed at, and we don't knowingly collect data from, anyone under 13.
11. Changes to this policy
If we make material changes to this policy, we'll update the date at the top of this page. Continuing to use DomSec HQ after a change means you accept the updated policy.
12. Contact
Questions about this policy or your data: [email protected].