Privacy
Last updated 12 July 2026. Written to be read, not skimmed past.
Who is responsible
Dream Ops B.V., based in Edam, The Netherlands, is the data controller for domainrating.org. Full company details are on the imprint page. For anything privacy-related, email [email protected].
What we store
- Account data. Your email address, a password hash (never the password), an optional display name, and, if you sign in with Google, the account identifier Google provides. Deleting your account removes all of it.
- Tracked domains. The domains you track, when you started tracking them, and any note you attach. There is deliberately no reverse lookup: nobody can see who tracks a domain.
- Rate-limit counters. Short-lived counters keyed by a one-way hash of your IP address, kept only long enough to enforce fair-use limits. Raw IP addresses are not stored.
- Contact messages. Messages sent through the contact form are delivered to our support mailbox and kept as ordinary email only as long as needed to handle them. Include only what you’re comfortable emailing.
What we don’t do
- No advertising trackers and no third-party analytics scripts.
- No selling or sharing of any data.
- No lookups of your domains against third-party services; scores come from public Common Crawl data only.
Verification fetches
If you verify ownership of a domain, we fetch that domain’s DNS records or homepage to check for your verification token, and re-check periodically while the verification stands. These fetches happen because you asked for them and are described on the bot page.
Cookies
One session cookie, set only when you log in, used solely to keep you logged in. No cookies are set for visitors who just check scores, which is why there is no cookie banner.
We send email only to verify your address, reset your password, and confirm account changes. Transactional email is delivered through Amazon SES. There is no marketing list.
Infrastructure and international transfers
The site runs on Amazon Web Services in the United States behind Cloudflare; both act as processors of the traffic data needed to serve requests, subject to their own terms. Because the servers are in the US, personal data is processed there, with appropriate safeguards as required by the GDPR.
Your rights
Under the GDPR you can request access to, correction of, deletion of, and a copy of your personal data. Most of this is self-service on the account page; for anything else, email [email protected]. If you believe we’ve handled your data wrongly, you can complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens.
Retention
Account data is kept until you delete the account. Rate-limit counters are short-lived by design. Contact emails are kept only as long as needed to handle the request.
Contact
Questions or deletion requests: email [email protected]. Account deletion is also self-service on the account page.