1. Data We Collect
When you use DomainAuctions we collect the following personal data:
- Account information — email address and password (hashed).
- Activity data — IP address, browser user-agent string, referrer, pages visited, request method and timestamp for every request you make.
- Transaction data — bids placed, auctions created, purchases made, and watchlist activity.
2. Why We Collect It
- Platform operation — to run auctions, process purchases, and manage your account.
- Abuse prevention — to detect and investigate fraudulent bids, shill bidding, and other misuse.
- Legal compliance — to meet our obligations under applicable law.
3. Legal Basis (GDPR)
We process your data on the following bases:
- Contract — processing necessary to provide the auction service you signed up for.
- Legitimate interest — abuse prevention and platform security.
- Consent — you consent to our terms and this policy when registering.
4. Data Retention
We retain activity logs for up to 12 months. Account and transaction data is retained for as long as your account exists. You may request deletion at any time (see below).
5. Your Rights
Under GDPR you have the right to:
- Access — download a copy of all data we hold about you.
- Rectification — correct inaccurate personal data.
- Erasure — request deletion of your account and personal data.
- Portability — receive your data in a machine-readable format (JSON).
You can exercise your right to data export and account deletion from your Dashboard.
6. Cookies
We use essential cookies required for the site to function (authentication, anti-forgery tokens, cookie consent preference). We do not use third-party tracking or advertising cookies.
7. Data Sharing
We do not sell or share your personal data with third parties, except where required by law or to protect against fraud.
8. Contact
For any privacy-related questions or requests, please use our Contact page.