Privacy
What we hold,
and what we
don't.
How we collect, use, and protect information across luckiest.co.
Effective
Mar 1, 2026
Last Updated
May 12, 2026
Version
4.2.0
Jurisdiction
California, USA
Reading Time
8 min
Summary
The version
in human words.
- 01We collect the minimum data needed to rent you a domain: account, billing, and DNS activity. Nothing more.
- 02We never sell your data. Period. No ad networks, no data brokers, no 'partners'.
- 03You can export everything we have on you, or delete your account, from your dashboard at any time.
- 04Subprocessors are listed below by name. We update the list when it changes.
- 05GDPR, CCPA, and CPRA rights are honored regardless of where you live.
01/Your Data
What we collect
We collect three buckets of information, all of which are required to operate the marketplace: account data you give us, billing data your payment provider gives us, and operational telemetry generated by using the product.
Account & identity
- Email address and password hash (we never store plaintext).
- Display name and optional profile photo.
- Business name and tax identification, where required for invoicing.
- Verification documents only when you exercise a rent-to-own buyout.
Billing
- Last four digits of the card and brand. The full PAN never touches our servers.
- Billing address and country, for sales tax / VAT.
- Transaction history: rentals, renewals, refunds, payouts.
Operational telemetry
- DNS records you publish and updates you make.
- Login events: timestamp, IP, user-agent string.
- Marketplace search queries and viewed listings (used to improve recommendations).
- Support transcripts when you write to us.
02/Lawful Use
How we use it
Every use of personal data at Luckiest maps to one of four lawful bases under GDPR Article 6: contract performance, legitimate interest, legal obligation, or your explicit consent.
- Contract
- Provisioning your rental, taking payment, providing DNS, sending receipts.
- Interest
- Security monitoring, fraud detection, internal product analytics on aggregated data.
- Obligation
- Tax records, ICANN/registrar compliance, lawful court orders, anti-money-laundering checks.
- Consent
- Marketing email, the newsletter, and any optional research surveys you opt into.
We do not use your data to train machine-learning models that are offered to third parties. The internal models that score brandability and detect typo-squatting are trained only on public domain metadata, never on your private DNS records or login activity.
04/Your Rights
Your rights
We extend GDPR-grade rights to every Luckiest user worldwide, irrespective of which jurisdiction protects you on paper. The controls live on your Profile page under Privacy & Data.
- Access
- Download a full export of your account, billing, DNS, and support history as JSON.
- Correction
- Edit any inaccuracy directly, or write to us if you can't reach the UI.
- Deletion
- Close your account; we purge personal data within 30 days, save legal-hold records.
- Portability
- Take your export and bring it to anyone you like. The schema is documented.
- Objection
- Opt out of marketing, recommendations, or operational analytics in one click.
- Restriction
- Pause processing while a complaint is being investigated.
Residents of California (CCPA / CPRA), the EEA and UK (GDPR), Brazil (LGPD), and Virginia (VCDPA) have specific additional protections; those rights are honored without requiring proof of residency. To exercise a right, use the dashboard or email get+privacy@luckiest.co.
05/Retention Clock
Retention
We hold data only as long as we need to. The table below is the governing schedule. Exceptions exist only where law requires longer retention (tax, sanctions, fraud).
- Account
- Until you delete it. After deletion, 30 days in cold storage before purge.
- DNS Logs
- 90 days of rolling history; aggregated stats beyond that.
- Billing
- 7 years, as required by US and EU tax authorities.
- Support
- 3 years from last interaction, then anonymized.
- Backups
- Encrypted at rest; rotated out within 35 days.
06/Hard Locks
Security
We run a SOC 2 Type II program audited annually by a Big Four firm. The latest report is available under NDA on request.
What we do
- TLS 1.3 in transit; AES-256 at rest on every primary store.
- Least-privilege production access, hardware-key 2FA required for staff.
- Quarterly penetration tests and an always-on bug-bounty program.
- Customer 2FA via authenticator app or hardware key, free on every account.
What you should do
- Enable 2FA on day one. The 30 seconds is worth it.
- Use a unique password. A password manager makes this painless.
- Be skeptical of any email asking you to 'verify' DNS via a link. We never do that.
We will notify affected users of any confirmed breach within 72 hours of discovery, in accordance with GDPR Article 33, regardless of whether you reside in the EU.
07/Under Sixteen
Children
Luckiest is not directed at children under 16. We don't knowingly collect personal data from anyone under 16. If you believe a minor has registered, write to get+privacy@luckiest.co and we'll close the account and purge the data.
08/Change Log
Changes to this policy
Material changes are announced by email at least 30 days before they take effect, and the change log lives below this document. The version number above the masthead bumps on every release (major.minor.patch). Patch releases are typos.
- 4.2.0 (May 12, 2026)
- Added Brazil (LGPD) to the named jurisdictions. Clarified backup retention.
- 4.1.0 (Mar 1, 2026)
- Switched transactional email subprocessor from Mailgun to Postmark.
- 4.0.0 — Jan 14, 2026
- Complete rewrite for plain-English readability. No substantive changes.
Related Documents
Questions, takedowns, requests
Privacy isn't a checkbox. Reach the team directly.
Subject-access requests, deletion requests, or anything that smells like a data incident: write to our privacy desk and we'll respond within 30 days (usually within 3).