Legal

Privacy Policy

Last updated: 16 July 2026

Draft — pending legal review. This is a working template, not reviewed legal advice. Replace the bracketed placeholders and have a qualified lawyer review this document before relying on it.

1. Who is responsible for your data

[ENTITY], registered in [JURISDICTION] (“we”, “us”), operates SparkleDomain and is the data controller for the personal data described in this policy. You can reach us at [CONTACT EMAIL].

This policy explains what we collect, why, who we share it with, and the rights you have. It applies to the SparkleDomain website and service, and should be read alongside our Terms of Service.

2. What we collect

Information you give us. When you create an account we collect your first and last name, username, email address and a password. Your password is never stored in plain text — we store only a salted hash of it. We also record whether you opted in to our newsletter and the fact and time of your acceptance of the Terms.

Information from your use of the Service. We store the domains and queries you check, the results and reports generated for you, and your saved lists, so we can show you your history and apply plan quotas.

Billing information. If you buy a paid plan, our payment provider processes your payment and returns to us your plan, its status and billing period, and a transaction reference. We do not receive or store your card details, wallet keys or crypto credentials.

Technical information. We process your IP address, browser and device type, and request logs, for security, abuse prevention, rate limiting and debugging.

3. Why we use it, and our legal bases

  • To provide the Service — creating your account, authenticating you, running valuations and analyses, and keeping your history. Legal basis: performance of our contract with you.
  • To take payment and manage subscriptions. Legal basis: performance of our contract with you.
  • To keep the Service secure — preventing abuse, fraud, scraping and unauthorised access, including via CAPTCHA and rate limiting. Legal basis: our legitimate interests in protecting the Service.
  • To send service emails — password resets, security notices, and billing notifications. Legal basis: performance of our contract, and our legitimate interests.
  • To send marketing emails — product updates and domain industry insights, only if you opted in. Legal basis: consent, which you may withdraw at any time.
  • To improve the Service — understanding which features are used and diagnosing faults, using aggregated or pseudonymised data where practical. Legal basis: our legitimate interests.
  • To comply with legal obligations, including accounting and tax record-keeping. Legal basis: legal obligation.

4. Who we share it with

We do not sell your personal data. We share it only with providers who process it on our behalf, under contract, and only as needed to run the Service:

  • CoinGate — payment processing for crypto checkout.
  • Cloudflare — Turnstile CAPTCHA on our sign-up form, and network security.
  • [HOSTING PROVIDER] — application and database hosting.
  • [EMAIL PROVIDER] — sending transactional and, where you consented, marketing email.
  • Domain data sources — we query third-party registry, WHOIS and SEO data providers to produce your results.

We may also disclose data where required by law, or to establish, exercise or defend legal claims, or as part of a merger, acquisition or sale of assets — in which case we will notify you before your data becomes subject to a different privacy policy.

5. International transfers

Some of our providers are located outside [JURISDICTION]. Where we transfer personal data internationally, we rely on an appropriate safeguard — such as an adequacy decision or Standard Contractual Clauses — to protect it. [CONFIRM THE SAFEGUARD THAT APPLIES TO YOUR PROVIDERS.]

6. Cookies

We use a small number of strictly necessary cookies to keep you signed in and to protect our forms. These are required for the Service to function and cannot be switched off in our systems. [IF YOU ADD ANALYTICS OR MARKETING COOKIES, LIST THEM HERE AND ADD A CONSENT BANNER — CONSENT IS REQUIRED BEFORE THEY LOAD.]

7. How long we keep it

We keep your account data for as long as your account is open. If you delete your account, we delete or anonymise your personal data within [RETENTION PERIOD, e.g. 30 days], except where we must keep records for longer to meet legal obligations (billing records are typically retained for [X] years) or to resolve disputes. Security and request logs are kept for [LOG RETENTION PERIOD].

8. Security

We protect your data with encryption in transit, hashed passwords, access controls, and CAPTCHA and rate limiting on sensitive endpoints. No system can be guaranteed completely secure, but we take reasonable steps to protect your data and will notify you and any relevant regulator of a breach where the law requires it.

9. Your rights

Depending on where you live, you may have the right to access a copy of your data; to correct inaccurate data; to have your data deleted; to restrict or object to processing; to data portability; and to withdraw consent at any time, without affecting processing carried out before withdrawal.

You can update your details from your dashboard, and unsubscribe from marketing email using the link in any such email or by turning off the newsletter option in your account. To exercise any other right, email us at [CONTACT EMAIL] — we will respond within the period required by law (generally one month). If you believe we have handled your data improperly, you have the right to complain to your local data protection authority.

10. Children

The Service is not directed to children and is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us at [CONTACT EMAIL] and we will delete it.

11. Changes to this policy

We may update this policy from time to time. We will update the “last updated” date above and, where the change is material, notify you by email or an in-product notice before it takes effect.

12. Contact

For any privacy question, or to exercise your rights, contact [CONTACT EMAIL], or write to [ENTITY], [REGISTERED ADDRESS], [JURISDICTION].