Privacy Policy
How Domainfolio handles account, buyer, AI, analytics, provider, and payment data.
Data We Collect
We collect account data such as name, email, role, session state, balance ledger entries, portfolio domains, landing settings, offers, buyer messages, and transfer status.
For buyers, we collect email verification state, offer details, messages, checkout state, and transaction references needed to complete payment and transfer workflows.
Domain And AI Data
Discovery prompts, selected extensions, generated candidate domains, AI scores, suggested prices, and generated landing copy may be stored for audit, debugging, cost control, and product improvement.
When external AI providers are connected, prompts and related context may be sent to those providers according to the configured model and provider settings.
Analytics
Landing pages can record views, buy-now clicks, contact clicks, verified offers, buyer messages, referrer, country, device, and similar operational metadata where allowed.
Domainfolio can also store first-party marketing attribution such as UTM parameters, ad click IDs, visitor IDs, session IDs, consent state, registration, discovery, checkout, and purchase events so Super Admins can understand campaign performance.
Analytics are used to show portfolio performance, detect abuse, debug landing delivery, measure advertising outcomes, and report platform activity to users and Super Admins.
Payments And Providers
Payment details are handled through the configured payment provider, such as Stripe. Domainfolio stores payment IDs, status, amount, commission, payout, transfer references, and webhook outcomes.
Domain provider, DNS provider, email provider, and messaging provider integrations may receive the minimum data needed to register domains, publish landings, send verification links, route messages, and process transfers.
Cookies And Local Storage
The web app may use browser storage for sessions, after-login redirects, locale preferences, local demo behavior, first-party attribution, visitor/session IDs, and marketing consent preferences.
Optional Google, Meta, TikTok, or tag manager scripts load only after the relevant analytics or advertising consent is granted in the web app.
Production deployments should configure secure session handling, HTTPS, provider secrets, and retention policies before public launch.
Advertising And Conversion Signals
When configured and allowed by consent and platform policy, Domainfolio may send advertising platforms conversion events such as page views, searches, registrations, checkout starts, offers, messages, or purchases.
Server-side conversion events can include campaign context, event IDs for deduplication, value and currency, page URL, country, click IDs, and hashed identifiers such as email hashes where appropriate. Payment card data, registrant profile data, and sensitive provider payloads are not sent as advertising conversion data.
Security And Retention
Passwords are stored as hashes, magic links and verification tokens are stored as hashes, and production secrets must live only in the hosting provider environment.
We keep operational records for as long as needed to provide the service, handle disputes, meet business obligations, debug provider issues, and maintain an audit trail.
User Choices
Users can edit portfolio pricing, landing copy, contact preference, sale status, and selected communication paths from the product surfaces that support those settings.
Requests about account data, buyer data, or domain transaction records should be sent to the Domainfolio operator listed by the production deployment.