Privacy Policy
Controller: Andrew Reinhard d/b/a Domainvane, 148 Coleto Trail, Bastrop, TX 78602. Effective date: September 29, 2026.
This policy explains how Domainvane handles information when providing certificate and domain-expiry monitoring. For an agency's client hostnames and client labels, the agency generally determines why they are processed and Domainvane acts on its instructions; for account, billing, security, and business records, Andrew Reinhard d/b/a Domainvane determines the purposes. The DPA note describes this working allocation for owner and counsel review.
Data we collect
| Category | Data |
|---|---|
| Account and session | Email address, scrypt password hash and salt, plan, hashed session identifier, CSRF secret, timestamps, and limited user-agent and IP-derived security data |
| Monitoring | Normalized hostname, port 443, pause state, TLS certificate fingerprint, issuer, subject, validity and diagnostic results; RDAP expiry, provenance, and responding server |
| Alerts and reports | Notification settings, encrypted webhook URLs, alert delivery records, client label, selected hostnames, and a hash of each report token |
| Billing | Stripe customer and subscription identifiers, plan, status, billing-period dates, and webhook-event identifiers; Stripe receives and processes payment details |
| Support and operations | Messages sent to the support mailbox, request metadata and structured logs that omit secrets, and operational failure information |
| Product analytics | First-party server rows for events such as signup, domain added, checker run, alert sent, plan change, public check, report view, page view, and rate limiting |
The public checker receives one hostname to perform a check but does not store that hostname in the product database. Analytics for that action record only its outcome. Domainvane does not store raw certificate chains, plaintext passwords, raw session ids, raw report tokens, or full payment-card numbers.
How and why we use data
We use data to create and secure accounts; perform requested TLS and RDAP checks; show dashboards and report pages; where enabled, deliver transactional messages and customer-configured webhooks; where enabled, administer plans and Stripe billing; respond to support; prevent abuse and access to non-public networks; troubleshoot and maintain the service; measure product operation; and comply with law and enforce agreements.
Customers must have a lawful basis and authority for hostnames, labels, recipients, and destinations they provide. Do not place sensitive personal information in free-text labels or support messages.
Recipients and subprocessors
| Provider | Purpose and data |
|---|---|
| Hetzner | VM hosting for the application and live database; account, monitoring, report, log, and operational data. The owner must confirm the selected hosting region before approval. |
| Cloudflare | Authoritative DNS, CDN/security edge, named tunnel to the application, and Email Routing for the support mailbox; request metadata and support-email routing data as applicable |
| Stripe | Checkout, monthly subscription payments, billing portal, and billing webhooks; billing identity, payment details supplied to Stripe, customer and subscription records |
| Postmark | Transactional account and monitoring email; recipient address, message content including relevant hostname and finding, and delivery metadata |
RDAP registries receive the queried domain, and the monitored host receives a TLS connection with its hostname as SNI. These are necessary destinations of a requested check, not vendors selected to store the account. A webhook receiver is selected by the customer. We do not use an advertising network, browser analytics service, or support-desk product in the current application.
Retention
Account, settings, hostnames, reports, and live billing references remain while the account exists, unless the customer deletes individual content sooner. TLS and RDAP history and first-party analytics are pruned by the configured history-retention job, currently 30 days by default. Sessions expire after the configured lifetime, currently 14 days by default, or are removed at logout or account deletion.
Account deletion hard-deletes the live user, sessions, settings, reports, billing rows, account-address outbox records, account rate-limit buckets, domains, check history, alerts, and notifications in one transaction. It de-links retained analytics from the user and scrubs email-, hostname-, and token-named properties. There is no live-database restore or self-service data export.
Local backup files expire under the configured backup period, currently 14 days by default; a backup made before deletion can contain deleted records until it expires. Stripe, Postmark, Cloudflare, and the support mailbox keep records under their own settings, legal duties, and policies, and account deletion does not erase those external records. The owner must set and approve production log and support-mail retention.
Cookies
Domainvane uses only the first-party sid session cookie and csrf request-protection cookie in the current application. It does not use analytics or advertising cookies. See the Cookie Notice.
Security
Controls include salted scrypt password hashes, hashed session and report tokens, encrypted webhook URLs, CSRF protection, HTTPS-only external webhooks and RDAP, and an address guard for outbound checks. No system is completely secure. Domainvane does not claim SOC 2, ISO 27001, or whole-database encryption.
Your choices and rights
You can update monitoring data, revoke reports, delete hostnames, cancel billing, log out, or delete the account through the product. Privacy questions and applicable access, correction, deletion, restriction, objection, or portability requests may be sent to the support address displayed by Domainvane. We may need to verify the requester and may retain information where law permits or requires it.
International use, children, and changes
Provider locations can involve international transfers. The owner must confirm the Hetzner region and any transfer mechanism before approval. Domainvane is a business service not directed to children, and users must be legally able to agree to the Terms.
Material changes will be posted with a revised effective date and, when reasonably practical, notified through the service or account email.
This policy and related questions are governed as applicable under the laws of Texas, without limiting mandatory privacy rights.