This policy explains how MeasureBoard LLC, a Wyoming limited liability company ("MeasureBoard," "we," or "us"), handles information in connection with getdomaindata.com (the "Service"). MeasureBoard is the data controller. Contact: [email protected], MeasureBoard LLC, 30 N. Gould Street, Suite N, Sheridan, Wyoming 82801.
This policy covers two distinct categories of information:
We collect only the information we need to run the Service. We use Google Analytics and PostHog to count visits, see which pages are read, and catch errors and broken links so we can fix them; where the law requires it we ask permission first, and you can refuse without losing anything. We do not use advertising trackers, we do not engage in cross-site tracking, we do not build advertising profiles, and we do not sell or share the information we collect about you as a visitor or account holder. We keep minimal security logs, a record of your acceptance of our Terms of Service, and, if you create an account, your email address. Our dataset describes domains and websites rather than people. Where personal data appears in it incidentally, it originated from public sources, and Section 6 explains your options, including removal.
| What | Details | Why (lawful basis) |
|---|---|---|
| Account data | Email address; sign-in one-time codes; name and title if you enroll a business account; if you enroll business features, the properties you designate for scanning and our records verifying your control of them | To provide the Service (contract) |
| Terms-acceptance records | Timestamp, IP address, session or account identifier, user-agent, the Terms version and hash accepted, and opt-out elections | To prove contract formation and to establish, exercise, or defend legal claims (legitimate interests; legal obligation where applicable) |
| Security logs | IP address, request path, timestamp, and similar server logs; human-verification (Cloudflare Turnstile) outcomes; rate-limit counters and usage patterns analyzed for abuse detection | Network and information security and abuse prevention (legitimate interests; see Recital 49 GDPR) |
| Dispute and legal correspondence | Name, mailing address, signatures, and the contents of Dispute Notices, arbitration opt-outs, and DMCA notices you send us | Administering dispute-resolution and legal processes (legitimate interests; legal obligation where applicable) |
| Billing data (paid plans, when offered) | Processed by our payment processor; we do not store full card numbers | Contract; legal obligation (tax and accounting) |
| Support messages | Emails you send us | Responding to your inquiry (legitimate interests; contract) |
| Analytics data | Pages viewed on this site, referring page, approximate location derived from IP address, and standard device and browser information, collected by Google Analytics and PostHog. Where you are signed in and analytics are permitted, PostHog events also carry your account identifier so we can relate engagement to usage; Google Analytics never receives it | Your consent where consent is required (EEA, UK, Switzerland); our legitimate interest in understanding which pages are used, elsewhere, subject to the opt-out in Section 3 |
| Error and interaction diagnostics | Collected by PostHog alongside the above: uncaught JavaScript errors, including the error message, the stack trace, and the page it happened on; and clicks that produced no result, which is how we find broken buttons and links. | Your consent where consent is required (EEA, UK, Switzerland); our legitimate interest in keeping the Service working, elsewhere, subject to the opt-out in Section 3 |
| Opt-out and removal requests | Your name, email address (verified by a one-time code), IP address, the domain requested, the attestation you affirmed, and the verification outcome and decision | To verify and honor your request, to prevent fraudulent suppression of domains you do not control, and to keep the records of consumer requests the law requires (legal obligation; legitimate interests) |
| Product communications (account holders) | Your account email; your plan and feature usage (for example, quota consumption) | Service messages (contract); occasional emails about plan features and upgrades, always with an unsubscribe link (legitimate interests; consent where required by your local law) |
We do not seek to collect special categories of data (and do not use any such data if it is incidentally received), and we do not build advertising profiles or track you across other sites. Our use of Google Analytics and PostHog is described in Section 3. We may analyze how accounts use the Service (features used, quota consumption) to improve it and to suggest relevant plan options to account holders.
We use cookies that are strictly necessary to provide the Service you request (session security, sign-in, and abuse prevention), and analytics cookies set by Google Analytics that count visits and tell us which pages are read. We also use PostHog, which sets no cookies at all: where analytics are permitted it keeps an identifier in your browser's local storage so a returning visit is not counted twice, and where consent is required and you have not given it, PostHog runs in memory only and stores nothing on your device. PostHog records more than page views: it reports JavaScript errors so we can fix them, and notes clicks that did nothing so we can find broken controls. It is covered by the same choice as everything else here, and switching analytics off switches all of it off. We set no advertising cookies and no cross-site tracking cookies.
How we ask. In the European Economic Area, the United Kingdom and Switzerland, nothing is stored on your device for analytics unless you accept it: the Service shows a consent banner with an equally weighted Accept and Decline, and declining changes nothing else about your access. Elsewhere, analytics are on by default and the Service shows a notice carrying a one-click control to turn them off. Wherever you are, if your browser sends a Global Privacy Control signal we treat it as a refusal: Google Analytics is switched off and PostHog is not loaded at all. Your choice is remembered on your device, and you can change it at any time from the notice or by clearing the site's stored data.
| Cookie | Purpose | Duration |
|---|---|---|
| Session cookie | Holds your signed session, including your human-verification status and the Terms version you accepted | 2 hours |
| Authentication cookies | Keep you signed in to your account | For the duration of your signed-in session, refreshed while you remain active |
| Turnstile (Cloudflare) | Bot and abuse prevention on gated actions | Per Cloudflare's widget lifetime |
Google Analytics (_ga, _ga_*) | Counts visits and distinguishes repeat visits from new ones. Only set where you have accepted, or where analytics run by default and you have not turned them off | Up to 2 years |
The Turnstile widget is provided by Cloudflare, acting as our processor; it receives technical connection data for the sole purpose of distinguishing people from automated abuse. Google Analytics is provided by Google, which receives your IP address, the pages you view on this site, and standard device and browser information; Google may process that data outside your country, including in the United States. We do not send Google your name, email address, or account identifier, and we have not enabled Google's advertising features or data sharing.
PostHog receives the same categories of information and processes it in the United States. If you are signed in and analytics are permitted, we also send PostHog the opaque identifier of your account, so we can see how the Service is actually used and by which kinds of customer. We never send either provider your name or email address. We do not enable session recording, so neither one records your screen, and neither captures what you type into a form. Error reports can include the address of the page you were on and the technical detail of the fault itself. If you refuse analytics, or your browser sends a Global Privacy Control signal, PostHog is not loaded and no identifier is sent. If our storage practices change again, we will update this policy and, where required, request consent first.
We do not sell or share Account and Visitor Data (including as "sell" and "share" are defined under U.S. state privacy laws), and we have not done so in the preceding 12 months. We disclose it only to:
Because we do not sell or share personal information, opt-out preference signals such as Global Privacy Control are honored: a valid GPC signal turns analytics off wherever you are, and we treat it as an opt-out of sale and sharing. Because we do not track visitors across third-party websites and run no advertising, a browser "Do Not Track" header changes nothing beyond what GPC already does.
The Service itself provides paid access to Public-Source Data (Section 6). That dataset describes domains. Where it incidentally includes information about an individual, that information was, to our reasonable belief, lawfully made available to the general public, and it is therefore excluded from the definition of "personal information" under U.S. state privacy laws. If you believe information about you appears in the dataset, Section 6 provides a free removal channel, with no account required.
| Data | Retention |
|---|---|
| Security and server logs | 90 days, then deleted (longer only if needed for an active investigation) |
| Terms-acceptance records | Life of the account plus 6 years (for accountless acceptances, 6 years from acceptance); the IP address in the record is truncated or hashed after 12 months |
| Dispute and legal correspondence | Resolution of the matter plus 6 years |
| Account data | Until you delete your account, then removed within 30 days (backups purge on their normal cycle) |
| Billing records | As required by tax and accounting law |
| Opt-out and removal request records | 6 years from the request (the exclusion itself remains in force indefinitely); the IP address in the record is truncated or hashed after 12 months |
| Crawled page content | Held only transiently for processing; see Section 6 |
| Public-Source Data (derived facts about domains) | Retained while relevant to the Service, including as historical time-series observations; suppressed domains are removed from the Service, including historical views, and excluded from future crawls |
What we do. We operate automated measurement systems that observe publicly accessible information about internet domains: public web pages, DNS records, TLS certificates and Certificate Transparency logs, and public registration (RDAP) data. From these observations we derive and retain facts about domains, such as hostnames, detected technologies, DNS and hosting configuration, and site classifications. We do not retain the content of crawled pages beyond the short period needed to process them: pages are held only transiently in our processing pipeline, are never made available through the Service, and are then discarded. Only the derived facts described above are retained. We do not collect from behind logins or paywalls, we do not bypass CAPTCHAs, and we do not seek out personal or special-category data.
Whose data can appear. The dataset describes domains and the organizations behind them, not individuals. It can incidentally include personal data that was already public, such as a business contact address published on a website's own pages, or the registration details of a domain registered by an individual (registration data for individuals is now largely redacted at the registry level). Where that occurs, we process the data on the basis of our legitimate interest in providing internet-infrastructure intelligence and supporting security and market research, taking into account that the data was published by or about the domain itself, that our collection is minimal, and that page content is not retained beyond transient processing. Site classifications are applied to domains at a deliberately coarse level and are not used to infer characteristics of individuals.
Recipients of Public-Source Data are users and customers of the Service.
Our crawler and how to opt out. All of our automated requests identify our user-agent, "Mozilla/5.0 (compatible; getdomaindata/1.0; +https://getdomaindata.com/bot)", and honor robots.txt, and requests from our primary crawler infrastructure support reverse-DNS verification. Domain owners can exclude their sites via robots.txt (user-agent token "getdomaindata") or through our opt-out registry at getdomaindata.com/bot; exclusions are applied to future crawls via a suppression list, and if a suppressed domain ever reappears because of an error, tell us and we will remove it promptly. Abuse reports: [email protected].
Your right to object; removal and correction. You may object at any time to our processing of personal data about you within Public-Source Data. If you find data about your domain, or personal data about yourself, in the Service, contact [email protected] or use the form at getdomaindata.com/bot. We will correct or suppress the record, add the domain to our suppression list so that future crawls do not re-ingest it, and respond within one month (for complex or numerous requests we may extend by up to two further months and will tell you within the first month).
We are a U.S. company and process data in the United States, which may provide different data-protection standards than the law of your jurisdiction. Analytics data collected under Section 3 is processed by Google and by PostHog, both in the United States, and may therefore be transferred outside your country. Where the GDPR or UK GDPR applies and a restricted transfer occurs, we implement appropriate safeguards, such as Standard Contractual Clauses (with the UK Addendum where relevant).
Everyone. Regardless of where you live, you may ask us what information we hold about you, ask us to correct or delete it, or object to our processing of it, by contacting [email protected]. We verify requests proportionately (if we cannot verify your request, we will tell you what more we need), respond within one month (45 days for U.S. state-law requests; for complex or numerous requests we may extend as applicable law allows and will tell you within the first period), and do not discriminate against you for exercising your rights. We charge nothing unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline it, as applicable law permits. You may submit a request through an authorized agent; we may verify the agent's authority and your identity.
EEA and UK residents. Where the GDPR or UK GDPR applies to our processing, you additionally have the rights of access, rectification, erasure, restriction, portability, and objection under Articles 15 through 21 of the GDPR and UK GDPR, the right to withdraw consent where processing is based on consent, and the right to lodge a complaint with your supervisory authority.
U.S. state residents. Depending on your state, you may have rights to know, access, correct, and delete personal information, to opt out of its sale or sharing and of targeted advertising (we do none of these), and to appeal a refusal. To appeal, reply to our decision email; we will re-review your request with a fresh assessment and respond within 45 days.
Non-users whose information appears in Public-Source Data may use the removal channel described in Section 6. No account is required.
We use least-privilege access controls, encrypted transport, server-side-only credentials, minimal retention (including the no-page-content design described in Section 6), and monitored infrastructure. No method of transmission or storage is perfectly secure. If a breach affects your personal data, we will notify you and the relevant regulators as required by law.
The Service is not directed to minors, and our Terms of Service require users to be at least 18 years old. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us personal data, contact [email protected].
We version this policy and record each version with its effective date. The current version and its effective date are available on request. For material changes, we will give notice on the Service, and by email to Account Holders, before the change takes effect; that notice states the effective date.
MeasureBoard LLC, 30 N. Gould Street, Suite N, Sheridan, Wyoming 82801. Privacy: [email protected]. Abuse and crawler matters: [email protected]. Data-protection questions from EU and UK residents: same addresses.