1. Scope and operator
This Privacy Policy applies to the public website, checkout-return flow, and member application at expiredgmbdomains.com (together, the “Service”), operated by Expired GMB Domains (“we,” “us,” or “our”). It does not govern third-party registrars, marketplaces, data providers, or websites linked from the Service.
2. Information we process
Account information
When an account is created after checkout or directly by us, we process its email address and display name, along with its plan, status, reveal allowance, and allowance period. Passwords are stored only as salted cryptographic hashes; we do not store plaintext passwords.
Purchase and payment information
Stripe collects the payment-card and billing information you submit through its hosted checkout. We receive and retain transaction details needed to provision and administer a purchase, such as the checkout and payment identifiers, Stripe customer identifier, email address, amount, currency, payment status, refund or dispute status, and relevant timestamps. We do not receive or store your complete card number or card security code.
Newsletter subscription
If you request a free download or ask to join our newsletter, we process the email address you enter, a label recording which page or offer it came from, and the times the request and your confirmation were recorded. We send a confirmation email and add the address to our newsletter list only after you click the link in it, so an address entered by someone else is never added. The lawful basis is your consent, which you can withdraw at any time using the unsubscribe link in any newsletter. Requests that are never confirmed are deleted automatically once the confirmation link expires. Newsletter subscribers are kept on a list separate from members, and subscribing does not create an account.
Service activity
We process records needed to provide account features, such as watchlist choices, reveal history, saved research settings where used, session creation and expiry times, and allowance usage. Raw session tokens are not stored in the application database.
Messages you send
We process the content of emails and other communications you choose to send, including support, correction, access, privacy, or legal requests.
Technical request data
Our infrastructure provider, Cloudflare, automatically processes technical request information such as IP address, device and browser characteristics, timestamps, and security signals to deliver and protect the Service. We do not run any analytics product, and we do not use third-party advertising or tracking scripts. The Service loads no third-party scripts of any kind; its content security policy permits scripts only from this website.
Domain and public business data
The Service also processes domain-registration information, historical web evidence, and public business-profile references from third-party or public sources. This research data is not collected from member account profiles, although a public record may contain information about a business or its representatives.
3. How we use information
We use information to:
- create, authenticate, administer, and secure member accounts;
- process purchases, verify payment, provision memberships, and handle refunds or disputes;
- deliver research results, watchlists, reveals, and allowance information;
- operate, maintain, diagnose, and improve the Service;
- respond to support, privacy, correction, and legal requests;
- send members occasional product announcements about new features and material changes to the Service. Every such message includes a one-click unsubscribe, and unsubscribing has no effect on your membership or on the account, security, and transactional emails we still need to send you;
- deliver the free download you requested and, where you have confirmed your address, send newsletters containing tips, new videos, and occasional offers. Every such message includes a one-click unsubscribe;
- prevent abuse, fraud, unauthorized access, and security incidents; and
- comply with applicable law and enforce our Terms of Service.
6. Retention
We retain account information while an account is active and as reasonably needed for administration, security, legal obligations, and dispute resolution. Sessions expire after up to 30 days and may be revoked sooner; unused account-setup sessions expire after one hour. Purchase, refund, and dispute records may be retained as needed for accounting, fraud prevention, tax, legal, and chargeback obligations. Reveal and watchlist records are generally retained while the account and associated domain record remain available. Support messages and infrastructure logs are retained according to operational and provider retention needs. We may keep de-identified or aggregated information that can no longer reasonably identify a person.
7. Security
We use administrative and technical safeguards designed to protect account information, including HTTPS, salted password hashing, hashed session tokens, access controls, and limited account creation. No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security. Please contact us promptly if you suspect unauthorized account access.
8. Your choices and requests
You may ask to access, correct, or delete personal information associated with your account, or ask questions about our data practices, by emailing team@expiredgmbdomains.com. We may need to verify your identity and may retain information where required or permitted by law. Depending on where you live, you may have additional rights and the ability to appeal a response; include your jurisdiction and request details in your message.
You can stop receiving product announcements at any time using the unsubscribe link in any of those messages, or by emailing us. Doing so does not cancel or change your membership, and we will still send the account, security, and transactional messages required to operate it — password resets, receipts, and notices about your access.
9. United States processing
The Service is operated in the United States and uses providers that may process information in the United States and other locations. If you access the Service from another country, your information may be transferred to jurisdictions with different data-protection laws.
10. Children
The Service is intended for business users who are at least 18 years old. We do not knowingly collect personal information from children under 13. Contact us if you believe a child has provided personal information to the Service.
11. Changes to this policy
We may update this Privacy Policy as the Service or legal requirements change. We will post the updated policy here and revise the effective date. Material changes may also be communicated through the Service or by email when appropriate.
12. Contact
For privacy questions or requests, email team@expiredgmbdomains.com. Expired GMB Domains is based in Texas, United States.