1. Who's responsible for your data
The controller of personal data on aidomains.si is Muhammad Younus, the person who owns the domains in the main portfolio and runs the marketplace and partner program. There's no company, team or agency behind the site. When this policy says "I" or "me", it means him. You can reach me at hello@aidomains.si, and every message is read by me personally.
This policy covers the website at aidomains.si, its forms, the partner and seller dashboards, and the emails sent about them. It doesn't cover Escrow.com, Stripe, Google or any other service you use to complete a deal. They have their own policies, linked below.
2. What I collect, and when
You can read every page of this site without giving me anything. Data is only collected when you do one of the things below.
- When you make an offer or a buy request: the domain, the amount, whether it's an offer or a buy-now request, your name, your email, your optional message, the country your request came from (worked out by Cloudflare from the connection, not from GPS) and, if a partner referred you, which partner. This is stored so I can reply, keep a record of the negotiation and credit the right partner.
- When you send a message through the contact form: your name, email, the topic you picked, your message and your country. Contact messages aren't saved in the site's database. They're emailed straight to my inbox and kept there like any other email.
- When you join the new-domains list: your email, the page you signed up on, your country and a hashed version of your IP address. It's used for one thing only: telling you when new .si names go up for sale.
- When you create a partner account: your name, email, a securely hashed password, your chosen link code, your USDT network and wallet address, and the date you joined. Later I also record the clicks, offers and sales credited to your link, and the transaction hash of each payout.
- When you create a seller account: your name, email and a securely hashed password. For each domain you list: the name, price, minimum offer, category, your pitch and description, the result of the DNS ownership check, the review status and any note I add, and your payment reference (a USDT transaction hash with its network, or a Stripe payment ID).
- When you arrive through a partner's link: the partner's code, which domain the link pointed to, your country, your browser's user-agent string (it says which browser and device type you use) and a hashed version of your IP address. This is how partners' clicks are counted without storing who you are.
- When you confirm your email with a code: a hashed copy of the 6-digit code for 10 minutes, and a count of wrong tries. The code itself is never stored in readable form.
- When you log in: a random session token linked to your account, and, if a password is wrong, a short-lived counter tied to a hash of your email and a hash of your network address. That's what stops someone guessing passwords.
- When you browse: Google Analytics records which pages are viewed, roughly which city and country visitors are in, device and browser type, where the visit came from, and actions such as searching the site, opening a domain page or sending an offer. With an offer it records the domain and amount, never your name or email.
3. What I don't collect
- Card numbers. If you pay a listing fee by card, you type your card details into Stripe's own checkout page, and they never reach this site.
- Your raw IP address. It's used for a moment to apply rate limits and then only a salted hash is kept, where one's needed at all.
- Precise location, contacts, photos, or anything from your device beyond what a normal web request sends.
- Payment details for a domain purchase. Those go to Escrow.com, which you deal with directly.
- Identity documents. The .si registry may ask a buyer for ID during a transfer, but that goes to the registry and the registrar, not to me.
4. Why I use it (the legal bases)
If you're in the EU, EEA, UK or Switzerland, data protection law asks me to name the reason for each use. Here they are:
- To take steps you asked for, or to perform a contract with you: answering your offer, setting up an escrow sale, running your partner or seller account, publishing your listing and paying your commission.
- Legitimate interests: keeping the site safe from spam, fake sign-ups and password guessing; checking that an email address is real before accepting a form; counting partner clicks fairly; and keeping records so a disputed sale or commission can be checked. I've weighed these against your privacy, which is why IP addresses are hashed and partners only see part of a buyer's email.
- Consent: Google Analytics cookies for visitors in the EU, EEA, UK and Switzerland, and the new-domains email list. You can withdraw consent at any time, and it doesn't affect anything done before you withdrew it.
- Legal obligations: keeping sale and payment records for as long as tax and accounting rules require.
5. Automated email checks
Every form checks your email address before it's accepted, so that offers and sign-ups come from real people I can actually reply to. The checks run automatically, in this order:
- the address has a valid format;
- it isn't a common typo of a big provider, such as "gmial.com", in which case you're asked to fix it;
- its domain isn't on a public list of temporary or disposable email services;
- its domain can receive email (a DNS lookup for mail servers, sent through Cloudflare, which only includes the domain part of the address);
- the mailbox itself looks real, checked by EmailVerify.io, which receives the full address for this purpose only.
If a check says no, the form tells you why and nothing is saved. The result is remembered for a short time against a one-way hash of the address, not the address itself. These checks can occasionally get it wrong, for example with a brand-new company domain. If your real address was refused, email me from it and I'll sort it out by hand. That's your right to a human decision, and I'm happy to give it.
6. Who else handles your data
I don't sell, rent or trade personal data, and I don't share it with advertisers. These services handle some of it so the site can work:
- Cloudflare, Inc. hosts the site, its database and its short-term storage, routes email sent to @aidomains.si, runs the Turnstile bot check on forms and answers the DNS lookups used in the email checks. Cloudflare's privacy policy.
- Google LLC provides Google Analytics and the Gmail inbox where offers, contact messages and sign-up notices arrive. Analytics runs with Google signals switched off and advertising storage denied, and its data is deleted after 14 months. Google's privacy policy.
- EmailVerify.io receives an email address when a form checks that the mailbox exists, and nothing else.
- Escrow.com receives a buyer's and seller's details only once both agree to go ahead with a sale, because every sale is paid through an Escrow.com transaction. Escrow.com's privacy policy.
- Stripe processes card payments for listing fees, when card payments are switched on. Stripe's privacy policy.
- Public blockchains. If you pay a listing fee or receive a commission in USDT, the transaction, the wallet addresses and the amount are public on that network by design. I can't delete them, and nobody else can either.
- Partners see the offers credited to their link with the buyer's email partly hidden (for example "jo***@gmail.com"). They never see a buyer's full email, name or message.
- Marketplace sellers receive a buyer's offer amount, and the buyer's name and email only once the buyer and seller both want to go ahead. Buyers get the seller's contact details at the same point.
- Authorities, only if the law requires it, and I'll tell you if I'm allowed to.
7. International transfers
Cloudflare, Google, Stripe and Escrow.com are based in the United States and run services around the world, so your data may be processed outside your own country. Where the law requires it, these providers rely on the EU Standard Contractual Clauses or the EU-US Data Privacy Framework to protect data leaving the EU, EEA, UK or Switzerland. I run the site myself from outside the EU, and I apply this policy the same way wherever you are.
8. How long it's kept
| What | How long |
|---|---|
| Offers and buy requests | Up to 3 years after the last contact about them, so a sale or a partner's credit can be checked later. Deleted sooner if you ask and no sale is open. |
| Completed sales and commission payouts | As long as tax and accounting rules require, then deleted. |
| Partner and seller accounts | Until you ask me to close them. Account details are deleted within 30 days of closing, except sale and payment records that must be kept. |
| Partner link clicks | While the partner's account is open, so their credit can be checked. |
| New-domains list | Until you unsubscribe. The address then stays on file marked "unsubscribed" so it isn't added back by mistake. Ask and I'll delete it completely. |
| Contact messages | In my inbox, as normal correspondence, for up to 3 years or until you ask me to delete them. |
| Login sessions | 30 days, or until you log out (1 day for the owner's admin session). Expired sessions are deleted automatically every 30 minutes. |
| Email check results | 30 days for an address that passed, 1 to 7 days for one that was refused, stored against a hash of the address. |
| Email confirmation codes | 10 minutes, hashed. |
| Failed-login and rate-limit counters | Between 1 minute and 1 hour, against hashed values only. |
| Google Analytics data | 14 months, then deleted by Google. |
9. How it's protected
- The whole site runs over HTTPS, and browsers are told never to load it any other way.
- Passwords are stored as PBKDF2 hashes with 100,000 rounds and a unique salt per account. I can't see your password, and nobody who got a copy of the database could read it either.
- The login cookie can't be read by scripts on the page, is only sent over HTTPS and isn't sent to other websites.
- Accounts lock for 30 minutes after 8 wrong passwords, and a network is paused after too many failed logins.
- Forms are protected by Cloudflare Turnstile and rate limits, and the site refuses form posts sent from other websites.
- A strict content security policy stops the pages loading scripts from anywhere I haven't approved.
No system is perfectly secure. If a breach ever put your data at risk, I'd tell you and the relevant authority as quickly as the law requires, and explain what happened in plain words.
10. Your rights
Wherever you live, you can ask me to:
- show you the data I hold about you, and give you a copy in a common format;
- correct anything that's wrong;
- delete it, unless I have to keep a record of a sale or payment;
- stop or limit using it, including objecting to uses based on legitimate interests;
- withdraw a consent you gave, such as analytics cookies or the email list.
Email hello@aidomains.si from the address the data is linked to, so I know the request is really yours. I'll reply within one month, and usually within a couple of days. It's free. If you're in the EU, EEA or UK and you're unhappy with my answer, you can complain to your local data protection authority. If you're in California, note that I don't sell or share personal information for advertising, so there's nothing to opt out of.
11. Children
This site sells domain names and pays commissions, so it's meant for adults. You need to be 18 or older to make an offer, list a domain or join the partner program. I don't knowingly collect data from anyone younger. If you think a child has sent me their details, tell me and I'll delete them.
12. Cookies
There's a full list of every cookie and browser setting the site uses, with how long each one lasts and how to turn them off, in the cookie policy.
13. Changes to this policy
If I change how the site uses personal data, I'll update this page and its date first. If the change matters to people who already have an account, I'll email them before it takes effect. Older versions are available if you ask.
14. Contact
Anything about your data: hello@aidomains.si. You'll get a reply from me, not an automated system.