Last updated: August 30, 2026
1. Information We Collect
1.1 - Information You Provide to Us
1,1,1 - Account and billing information. When you open an account or purchase a service, we collect the information needed to create the account, bill it, and contact you about it: name, billing address, email address, telephone number, and the billing details required to take payment.
1,1,2 - Payment details. Payment card numbers and equivalent payment credentials are submitted directly to our payment processor [3,1,4] and are held by that processor. NameCrane does not store card numbers on its own systems.
1,1,3 - Support information. Support tickets, live chat transcripts, and any information you choose to include in them.
1,1,4 - Domain registration data. Where you register a domain, we additionally collect the registrant data described in Section 4 [4,1].
1.2 - Information We Record Automatically
1,2,1 - Connection and activity data. Our web, mail, control panel, and network systems record IP addresses, timestamps, user agent strings, and similar connection metadata, together with login and account activity history.
1,2,2 - Why we record it. This data is recorded for security, abuse prevention, fraud prevention, and fault diagnosis. It is not used to build advertising or marketing profiles, and it is never shared for those purposes [3,1,1].
1,2,3 - Cookies. Information collected through cookies and similar technologies is covered separately at [8,3].
2. Why We Process Your Information
2.1 - Legal Bases
2,1,1 - Performance of a contract (GDPR Article 6(1)(b)). Creating and operating your account, providing the services you have purchased, billing for them, and responding to your support requests.
2,1,2 - Compliance with a legal obligation (GDPR Article 6(1)(c)). Meeting ICANN and registry requirements for domain registration data, including publication and escrow [4,3]; retaining billing and accounting records as tax and accounting law requires [6,2]; and responding to court orders, subpoenas, and other legally binding demands [3,1,2].
2,1,3 - Legitimate interests (GDPR Article 6(1)(f)). Preventing fraud, abuse, and intrusion; securing our network and platform; protecting NameCrane, our clients, and third parties; and keeping the records needed to establish, exercise, or defend legal claims. You may object to processing carried out on this basis [8,2].
2,1,4 - Consent (GDPR Article 6(1)(a)). Non-essential cookies [8,3] and optional product and feature announcements [9,1,2]. Where we rely on consent you may withdraw it at any time, without affecting processing already carried out.
3. Your Privacy
3.1 - Personal / Contact Information
3,1,1 - Clients' personal and contact information is never sold, rented, or traded, and is never shared with any third party for that third party's own marketing or advertising purposes.
3,1,2 - Clients' personal and contact information is released to law enforcement officials only when a court order, subpoena, or other legally binding demand mandates said release.
3,1,3 - Domain registration data is subject to a further exception to [3,1,1] and [3,1,2]. ICANN and the domain registries require certain registrant data to be disclosed as a condition of a domain name existing at all. Those disclosures are limited to the recipients and purposes set out in Section 4 [4,3], and they apply only to clients who register a domain through NameCrane. They do not apply to hosting, email, or any other service.
3,1,4 - Certain services cannot be provided without the involvement of third-party providers. These are limited to the following categories: payment processing; infrastructure, datacenter, and network providers; and fraud, abuse, and intrusion prevention. NameCrane operates its own outbound mail servers, so account, billing, and support notices are not handled by any third party. Where such a provider is involved, clients' personal and contact information is shared only to the extent that provider needs it to perform its function.
3,1,5 - Providers described in [3,1,4] may use client information to provide their service to NameCrane and to meet their own legal, fraud-prevention, and regulatory obligations. They are never permitted to use it for their own marketing or advertising [3,1,1].
3.2 - Service Data & Privacy
3,2,1 - No staff member, support technician, or any other party will enter or view the contents of a clients' service without first requesting permission to do so via the Support System.
3,2,2 - No data from a clients' service will be recorded, saved, or archived without the clients' knowledge and consent.
3,2,3 - All data related to a service (including Automated Backups [3,3]) is destroyed following a cancellation request or termination of the service, subject to the recovery window at [6,4,4].
3.3 - Automated Backups
3,3,1 - Some services include automated backups as a core feature. Purchase and use of these services implies consent to store these backups on a secured server until the service is cancelled or terminated.
3,3,2 - No staff member, support technician, or any other party will enter or view the contents of a clients' service backups without first requesting permission to do so via the Support System.
3,3,3 - All stored backups for a service are destroyed following cancellation or termination of the service, subject to the recovery window at [6,4,4].
4. Domain Registration Data
4.1 - What we collect and why
When you register a domain, we collect the registrant contact data ICANN requires, to provide the domain, operate directory services, and meet ICANN and legal obligations. We no longer collect separate administrative or billing contacts - ICANN removed that requirement in 2025.
4.2 - What's published (RDAP/WHOIS)
Directory data is served over RDAP. Under ICANN's Registration Data Policy, most registrant fields are redacted by default. The public record shows a way to contact the registrant - possibly a web form instead of an email.
4.3 - Who we share domain data with
The registry for your TLD - how much data the registry itself holds depends on whether it's a "thin" or "thick" registry; see the Registry & TLD Policies list; our escrow agent; ICANN where required; and requesters of non-public data, only after review under Registration Data Policy ยง10 (see Disclosure Request). If you use privacy, see Privacy Service Terms.
4.4 - Retention
We retain domain registration data for the ICANN-required period - at least fifteen (15) months after the registration ends or transfers away, or longer where the law requires. Disclosure requests are logged.
4.5 - How to access or correct
Manage your data in your account or contact us. Third-party requests for non-public data go through the Disclosure Request page.
5. Account Status & Retention
5.1 - Active Status
5,1,1 - Any account with at least one active service is considered to be of Active Status.
5,1,2 - Active Status accounts will receive emails relating to their active services, support tickets, maintenance and general announcements.
5.2 - Inactive Status
5,2,1 - An account with no current services is considered to be of Inactive Status.
5,2,2 - Inactive Status accounts will receive emails relating to their support tickets, and general announcements.
5,2,3 - Any Inactive Status account may request to be Closed [5,3] so long as there are no unpaid or overdue invoices on the account.
5.3 - Closed Status
5,3,1 - An account is placed into Closed Status when it goes 12 months with no active services, support tickets, or logins.
5,3,2 - Any existing Account Credit [TOS:4,2] is permanently removed from an account when it enters Closed Status.
5,3,3 - Closed Status accounts will not receive any emails.
5,3,4 - Closed Status accounts may be reverted back to Inactive Status [5,2] by submitting a request through our contact form. We will verify account ownership, including confirmation from the email address associated with the account, before reactivating.
5,3,5 - Closed Status accounts are permanently deleted, and all associated data removed, after 6 months in Closed Status so long as the account is not banned or prohibited from further service.
6. How Long We Keep Your Information
6.1 - General Principle
6,1,1 - We keep personal data only for as long as it is needed for the purpose it was collected for, or for as long as we are required to keep it by law, by ICANN, or by a registry.
6,1,2 - Account lifecycle and deletion timelines are set out in Section 5.
6.2 - Billing and Accounting Records
6,2,1 - Billing and accounting records are retained for seven (7) years from the date of the transaction in order to meet tax, accounting, and chargeback obligations.
6,2,2 - This obligation applies notwithstanding [5,3,5]. Where an account is deleted, billing and accounting records required by law are retained for the period in [6,2,1] and everything not so required is removed.
6.3 - Connection and Security Logs
6,3,1 - Connection and security logs [1,2,1] are retained for no longer than one hundred eighty (180) days and are then deleted or anonymized.
6,3,2 - Where a log record forms part of an active abuse, fraud, or security investigation, it is retained until that investigation concludes.
6.4 - Domain, Backup, and Service Data
6,4,1 - Domain registration data is retained for the ICANN-required period set out at [4,4].
6,4,2 - Service data and automated backups are destroyed following cancellation or termination [3,2,3] [3,3,3], subject to the recovery window at [6,4,4]. Because backups are taken on a rotating schedule, data deleted from a live service may persist in backup storage until that rotation completes.
6,4,3 - No backup is retained for longer than one hundred eighty (180) days. Customer-accessible service backups rotate on a thirty (30) day cycle; some plans will move to a ninety (90) day cycle. NameCrane's own operational backups rotate within one hundred eighty (180) days.
6,4,4 - When a service is cancelled or terminated, we may retain a final copy of its data and backups for up to one hundred eighty (180) days, as storage allows, so that the service can be restored if you return. This copy is used for no other purpose, is destroyed no later than one hundred eighty (180) days after cancellation or termination, and is deleted sooner if you ask us to delete your data [8,2].
6.5 - Legal Hold
6,5,1 - Where information is subject to a legal claim, investigation, or preservation demand, it is retained until that matter is resolved, regardless of the periods above.
7. Security
7.1 - How We Protect Your Information
7,1,1 - We use technical and organizational measures appropriate to the risk, including encryption of data in transit, access controls on the systems that hold personal data, least-privilege administrative access, and monitoring for unauthorized access.
7,1,2 - Staff access to the contents of a client service or its backups additionally requires the client's permission, requested through the Support System [3,2,1] [3,3,2].
7,1,3 - No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you believe your account has been compromised, contact us immediately.
7,1,4 - Personal data breaches are handled under [8,4].
8. Your Rights & Cookies
8.1 - Controller vs processor
For domain registration data, we're a controller (with the registry and ICANN). For content you host with us, we're your processor.
8.2 - Your rights (GDPR/UK GDPR/CCPA)
Access, correct, delete, or port your data, or object to certain processing, by emailing privacy@namecrane.com or via our privacy request form. No discrimination for exercising your rights.
8.3 - Cookies
We use the cookies needed to operate this site and your account, such as login sessions and the shopping cart, plus fraud-prevention cookies: our fraud-screening provider [3,1,4] sets a device-identification cookie, and our payment processor sets its own fraud-prevention cookies. These are used only to detect and block fraudulent orders, never for advertising [3,1,5]. We do not use analytics or advertising cookies. See our Cookie Policy for a list of each cookie we set.
8.4 - Breach notification
If a personal-data breach occurs, we notify regulators and affected people as required by law (including the GDPR 72-hour timeline).
9. Communications and Your Choices
9.1 - Types of Email
9,1,1 - Service messages. Billing notices, support ticket replies, maintenance and security notices, and domain expiry and renewal reminders are part of providing the service and are sent for as long as the relevant service is active [5,1,2]. These cannot be turned off while the service is active, because some of them are required by ICANN.
9,1,2 - Product and feature announcements. We occasionally send announcements about new products and features. These are optional. You can turn them off in the email preferences in your account at any time, or by using the unsubscribe link in the message.
9,1,3 - We do not sell, rent, or trade your email address, and we do not send marketing on behalf of any third party [3,1,1].
10. Children's Information
10.1 - Age
10,1,1 - Our services are not directed to, and are not intended for use by, children. We do not knowingly collect personal data from anyone under the age of 16.
10,1,2 - If we become aware that we hold personal data collected from a child under 16, we will delete it and close any associated account, unless we are legally required to retain it.
11. Changes to This Policy
11.1 - Notice of Changes
11,1,1 - We may update this policy. The date at the top of this page reflects the most recent revision.
11,1,2 - For material changes we will give at least thirty (30) days' notice, posted on this page and sent to the email address on your account. Changes required by a new or amended law, ICANN policy, or registry policy may take effect immediately.
12. Contact, Complaints, and Supervisory Authorities
12.1 - Who Is Responsible for Your Data
12,1,1 - The data controller for the information described in this policy is NameCrane LLC, 30 N Gould St, Ste 10226, Sheridan, WY 82801, United States.
12,1,2 - Privacy questions and data rights requests may be sent to privacy@namecrane.com or made through our privacy request form.
12.2 - Complaints
12,2,1 - We would prefer to resolve any concern directly, and ask that you contact us first. Doing so is not a precondition to the rights below.
12,2,2 - If you are in the EEA or the UK, you have the right to lodge a complaint with a data protection supervisory authority - in the country where you live, where you work, or where you believe an infringement has taken place. In the UK this is the Information Commissioner's Office. A list of EEA authorities is published by the European Data Protection Board.
13. United States State Privacy Rights
13.1 - Sale, Sharing, and Opt-Out Signals
13,1,1 - We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, as the California Consumer Privacy Act defines those terms [3,1,1].
13,1,2 - We carry out no processing that an opt-out preference signal such as Global Privacy Control would apply to.
13,1,3 - We do not use sensitive personal information to infer characteristics about you.
13,1,4 - You will not be denied service, charged a different price, or given a different level of quality for exercising any privacy right [8,2].
