1. Scope and operator
This Privacy Policy applies to the public website, checkout-return flow, and member application at expiredgmbdomains.com (together, the “Service”), operated by Expired GMB Domains (“we,” “us,” or “our”). It does not govern third-party registrars, marketplaces, data providers, or websites linked from the Service.
2. Information we process
Account information
When an account is created after checkout or directly by us, we process its email address and display name, along with its plan, status, reveal allowance, and allowance period. Passwords are stored only as salted cryptographic hashes; we do not store plaintext passwords.
Purchase and payment information
Stripe collects the payment-card and billing information you submit through its hosted checkout. We receive and retain transaction details needed to provision and administer a purchase, such as the checkout and payment identifiers, Stripe customer identifier, email address, amount, currency, payment status, refund or dispute status, and relevant timestamps. We do not receive or store your complete card number or card security code.
Service activity
We process records needed to provide account features, such as watchlist choices, reveal history, saved research settings where used, session creation and expiry times, and allowance usage. Raw session tokens are not stored in the application database.
Messages you send
We process the content of emails and other communications you choose to send, including support, correction, access, privacy, or legal requests.
Technical request data
Our infrastructure provider, Cloudflare, automatically processes technical request information such as IP address, device and browser characteristics, timestamps, and security signals to deliver and protect the Service. We also use Cloudflare Web Analytics for aggregate traffic measurements without setting an analytics cookie. We do not use third-party advertising trackers.
Domain and public business data
The Service also processes domain-registration information, historical web evidence, and public business-profile references from third-party or public sources. This research data is not collected from member account profiles, although a public record may contain information about a business or its representatives.
3. How we use information
We use information to:
- create, authenticate, administer, and secure member accounts;
- process purchases, verify payment, provision memberships, and handle refunds or disputes;
- deliver research results, watchlists, reveals, and allowance information;
- operate, maintain, diagnose, and improve the Service;
- respond to support, privacy, correction, and legal requests;
- prevent abuse, fraud, unauthorized access, and security incidents; and
- comply with applicable law and enforce our Terms of Service.
6. Retention
We retain account information while an account is active and as reasonably needed for administration, security, legal obligations, and dispute resolution. Sessions expire after up to 30 days and may be revoked sooner; unused account-setup sessions expire after one hour. Purchase, refund, and dispute records may be retained as needed for accounting, fraud prevention, tax, legal, and chargeback obligations. Reveal and watchlist records are generally retained while the account and associated domain record remain available. Support messages and infrastructure logs are retained according to operational and provider retention needs. We may keep de-identified or aggregated information that can no longer reasonably identify a person.
7. Security
We use administrative and technical safeguards designed to protect account information, including HTTPS, salted password hashing, hashed session tokens, access controls, and limited account creation. No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security. Please contact us promptly if you suspect unauthorized account access.
8. Your choices and requests
You may ask to access, correct, or delete personal information associated with your account, or ask questions about our data practices, by emailing team@expiredgmbdomains.com. We may need to verify your identity and may retain information where required or permitted by law. Depending on where you live, you may have additional rights and the ability to appeal a response; include your jurisdiction and request details in your message.
9. United States processing
The Service is operated in the United States and uses providers that may process information in the United States and other locations. If you access the Service from another country, your information may be transferred to jurisdictions with different data-protection laws.
10. Children
The Service is intended for business users who are at least 18 years old. We do not knowingly collect personal information from children under 13. Contact us if you believe a child has provided personal information to the Service.
11. Changes to this policy
We may update this Privacy Policy as the Service or legal requirements change. We will post the updated policy here and revise the effective date. Material changes may also be communicated through the Service or by email when appropriate.
12. Contact
For privacy questions or requests, email team@expiredgmbdomains.com. Expired GMB Domains is based in Texas, United States.