1. Information We Collect
We collect information in the following ways:
Information you provide directly:
- Account details (name, email, password)
- Billing and payment information
- Domain preferences and purchase history
- Communications with our support team
Information collected automatically:
- IP address, browser type, and device information
- Cookies, session data, and analytics (see Section 9)
- Usage data (pages visited, clicks, time on site)
Information from third parties:
- Payment processors (e.g., transaction status)
- Marketing partners and analytics providers
- Domain registrars (for transfer information)
2. How We Use Your Information
We use your information to:
- Create and manage your account
- Process transactions and send order confirmations
- Facilitate domain transfers and manage escrow
- Provide customer support
- Improve our Services through analytics and user feedback
- Send marketing communications (if you opted in)
- Prevent fraud, enforce our Terms of Use, and protect legal rights
- Comply with legal obligations
3. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your data under one or more of the following lawful bases:
- Consent: You have given explicit consent for specific purposes (e.g., marketing emails).
- Contractual Necessity: Processing is necessary to fulfill our contract with you (e.g., completing a domain purchase).
- Legitimate Interests: We have a legitimate interest (e.g., fraud prevention, improving Services) that does not override your rights.
- Legal Obligation: We must process your data to comply with applicable law (e.g., tax reporting).
5. International Data Transfers
RexusDomain may transfer and store your data on servers located outside your country of residence, including in jurisdictions that may not provide the same level of data protection as your home country.
For EEA, UK, or Swiss users, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions (where applicable)
- Other lawful transfer mechanisms
6. Data Retention
We retain your personal data only as long as necessary for the purposes described in this Privacy Policy or as required by law. Generally:
- Account Data: Retained while your account is active and for a reasonable period after closure (typically up to 7 years for legal/tax reasons).
- Transaction Records: Retained for up to 7 years to comply with financial and tax regulations.
- Marketing Data: Retained until you withdraw consent or we no longer have a legitimate interest.
- Logs and Analytics: Typically retained for 12–24 months.
7. Security
We implement industry-standard security measures to protect your data, including:
- Encryption (SSL/TLS) for data in transit
- Secure password storage (hashed and salted)
- Access controls and authentication mechanisms
- Regular security audits and monitoring
However, no method of transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
8. Your Privacy Rights
Depending on your location (especially if you are in the EEA, UK, Switzerland, or California), you may have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request corrections to inaccurate or incomplete data.
- Erasure ("Right to be Forgotten"): Request deletion of your data (subject to legal obligations).
- Restriction of Processing: Request that we limit how we use your data.
- Data Portability: Receive your data in a structured, commonly used format.
- Object: Object to certain types of processing (e.g., direct marketing).
- Withdraw Consent: If processing is based on consent, you may withdraw it at any time.
To exercise these rights, please contact us at [email protected]. We will respond within the timeframes required by applicable law (typically 30 days).
10. Third-Party Links
Our Website may contain links to third-party websites, services, or advertisements. We are not responsible for the privacy practices or content of these external sites. We encourage you to review the privacy policies of any third-party sites you visit.
11. Children's Privacy
RexusDomain does not knowingly collect personal information from individuals under the age of 18. If we learn that we have inadvertently collected data from a child under 18, we will delete it promptly. If you believe we have collected information from a minor, please contact us immediately.
12. Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational reasons. The "Last updated" date at the top of this page will be revised accordingly.
If we make material changes, we may notify you via email or by posting a notice on our Website. Continued use of the Services after changes become effective constitutes your acceptance of the updated Privacy Policy.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
- Email: [email protected]
- Contact Form: Visit our Contact Page
We will respond to your inquiry within a reasonable timeframe as required by applicable law.