What we collect
- A cookie-based session id (random UUID) so we can save your watchlist and alerts before you sign in.
- Your email address when you create an account, free or paid (for login, notifications, and account recovery).
- Your alert rules, watchlists, support tickets, and portfolio/caught-claim records.
- Product analytics — see the Analytics section below for the full list.
What we don't do
- We don’t sell your data. Ever.
- We don’t build advertising profiles.
- We don’t share your watchlist or alerts with anyone.
- We don’t use Google Analytics, Meta Pixel, or any other third-party tracker.
Analytics
We use self-hosted Matomo to understand how visitors use the site (pages viewed, click patterns, referring sources). Matomo runs on our own server — no data is sent to Google, Meta, or any third-party analytics provider.
For each visit, Matomo records: the pages you view, the time of visit, your approximate country, your browser and device type, your screen resolution, and the referring URL. Your approximate country is derived from your IP address. Before storage, the IP is masked to /24 (the last octet is removed — e.g. 203.0.113.0) so we cannot identify individual devices from analytics records.
Consent: visitors in the EU, EEA, and UK see a banner and Matomo does not load until you click Accept. Visitors elsewhere are tracked by default unless your browser sends Do-Not-Track or Global Privacy Control, both of which we honor. Decline always wins, and clicking Decline after a previous Accept also clears the Matomo cookies on this device.
We also keep a small first-party event log (user_events) for product telemetry — page-view counts, feature usage, and conversion funnels. This relies on legitimate interest (GDPR Art. 6(1)(f)) and is retained for 90 days, then permanently deleted. You can object to this processing through the privacy support form below.
Third parties
- Stripe — billing and payment processing. Sees your email, billing address (if supplied), and payment method.
- Resend — transactional and digest email delivery. Sees your email and the contents of messages we send you.
- Cloudflare — CDN, DNS, Turnstile anti-bot, and abuse protection. Sees IPs and request metadata as a pass-through.
- Telegram (optional) — if you link a Telegram chat for alerts, we send those alerts via the Bot API. Telegram sees the alert content.
- Sentry — error monitoring. Receives stack traces and masked request context when something breaks. No PII bodies.
- Matomo — analytics software we self-host. Matomo.org does not receive your NameNotifier analytics data.
- ICANN CZDS, Wayback Machine, and keyword/enrichment APIs — domain data sources. They do not receive personal account, watchlist, alert, or payment data from us.
Data retention
- Account data (email, alert rules, watchlist) — until you delete your account.
- Alert delivery history (what we sent you, when) — 90 days.
- Domain-status observation log — 180 days.
- Admin audit log — 365 days.
- Product analytics (Matomo) — 24 months, IP-masked.
- Support tickets — until resolved + 90 days for follow-up reference.
Permanent corpus (zone-file diffs, DQS scoring outputs) is retained indefinitely as business records. Domain-status observations are about domains, not people; if a row is tied to a user action such as a watchlist, alert, support ticket, or caught claim, it follows the relevant account retention path above.
Rights
You can request deletion of your account and associated personal data at any time through the
privacy support form. Depending on where you live, you may have rights to access, export, correct, delete, restrict, or object to processing of your personal data.
Security
We use reasonable technical and organisational measures to protect personal data, including HTTPS, access controls, limited production access, secret management, and operational logging. No online service is completely secure, so we cannot guarantee absolute security.
Children
NameNotifier is not intended for children or anyone under 18. We do not knowingly collect personal data from children.
International processing
Your data may be processed in countries other than where you live, depending on our infrastructure and service providers.
Cookies
nn_session (or __Host-nn_session in production) - session identifier, httpOnly, 30 day TTL. Required for login and the watchlist to work.nn_visit - random pseudonymous visit correlation id, httpOnly, 30 day TTL. Ties first-party analytics events to a session without directly identifying you.nn_cookie_consent - your Accept/Decline choice, stored in localStorage on this device. Used to gate Matomo without re-prompting on every visit._pk_id.* / _pk_ses.* - Matomo first-party analytics cookies. 13 months / 30 min TTL respectively. Set only after consent (EU/EEA/UK) or unless your browser sends Do-Not-Track or Global Privacy Control.
All cookies are first-party (namenotifier.com origin). We do not use third-party tracking cookies.