Last updated: 26/12/2021
1. Scope, portals and roles
This Privacy Policy explains how Rocket Domains collects, uses, shares, stores and protects personal data when you visit Rocket Domains websites, including parking pages, use the customer account and billing portal at my.rocket.domains, create an account, place an order, pay an invoice, register or manage domains, use hosting, cloud, email, workspace, bookings, security, backup, SEO, registry, design, portal or related services, contact support, receive service notices or marketing, or otherwise interact with Rocket Domains.
Rocket Domains may provide the Services through its own websites and portals, customer account and billing systems, provisioning systems, control panels, external login pages, webmail pages, branded portals, white-labelled portals and third-party product dashboards. When you access a portal or login page that is branded by Rocket Domains or linked from Rocket Domains, the underlying technology may be operated by Rocket Domains, a supplier, a processor, a subprocessor, an independent controller or a combination of those parties, depending on the service.
Rocket Domains is usually a controller for account, billing, identity, domain registration, payment metadata, service administration, security, abuse, support, legal, customer relationship and direct marketing data. Rocket Domains may act as a processor for customer content and end-user data that business customers upload, host, route, store or process through the Services. Payment providers, domain registries and registrars, branded third-party product providers and certain portal, authentication and infrastructure providers may act as independent controllers, processors or subprocessors under their own terms and privacy notices.
2. Personal data we collect
We may collect account and identity data; contact details, including name, email address, postal address and telephone number; company, billing and tax-related information where applicable; domain registrant and verification data; order, invoice, subscription, renewal, cancellation and support information; service usage and provisioning records; technical logs; IP addresses; device, browser, operating-system and approximate-location information; authentication, session and security data; DNS records; website, hosting, database, email-routing, workspace, booking and product-configuration data; abuse reports; legal correspondence; marketing preferences; and communications with Rocket Domains.
For the customer account and billing portal, we may process login credentials, session identifiers, shopping cart/order details, service selections, invoice status, renewal settings, support tickets, account preferences, language and currency preferences, fraud-prevention signals, security logs, IP address, user-agent data and device/browser information. For external or white-labelled product portals, we may process authentication tokens, account identifiers, portal usage records, technical logs, service configuration data and security events needed to deliver the requested service.
For payments, Rocket Domains uses third-party payment providers such as Stripe and PayPal. Rocket Domains does not generally receive or store full payment-card numbers. We may receive transaction identifiers, payment status, payment method type, last four digits, billing address, card expiry metadata, fraud/risk results, dispute/chargeback information, payer details and other payment metadata needed to process, reconcile, refund, secure or dispute payments. Stripe, PayPal and similar payment providers may collect and process payment, device, fraud-prevention and authentication data under their own terms and privacy notices.
For email and workspace services, we may process mailbox identifiers, email addresses, routing metadata, logs, anti-abuse signals, spam/malware/security events, authentication records, account settings, aliases, forwarding rules, storage usage and support records. Email content and customer content are not routinely reviewed by Rocket Domains, but may be processed technically to transmit, store, secure, filter, support, restore, investigate abuse or comply with law.
As of this version, Rocket Domains does not intentionally use Google Analytics, advertising cookies, retargeting pixels, social-media tracking pixels or comparable optional tracking technologies on its public website or customer account area. If this changes, Rocket Domains will update this Policy and the Cookie Notice and will deploy consent or preference controls where required.
Domain search and availability logs.
When you search for, check the availability of, configure, register, transfer, renew or manage a domain name, Rocket Domains may collect and process technical information connected with that activity. This may include the domain name or search term entered, requested TLD or extension, search results, timestamps, IP address, user-agent, device/browser information, session identifiers, account identifier where logged in, referrer URL, rate-limit status, fraud or abuse signals, error messages and related technical logs.
We use this information to provide domain search and registration functions, return availability results, troubleshoot errors, maintain service reliability, detect and block malicious bots, scraping, credential-stuffing, spam, abuse, fraudulent orders, excessive automated queries and DDoS or denial-of-service activity, apply fair-use and rate limits, protect registry/registrar systems, investigate security incidents, comply with registry, registrar, ICANN, ccTLD, legal and law-enforcement requirements, and enforce our Terms.
Access to domain search and availability logs is limited to authorised Rocket Domains personnel and authorised service providers, contractors, registrars, registry service providers, infrastructure providers, security providers, support providers, legal advisers and other Rocket Protected Parties who need access for the purposes described in this Policy. We may also disclose relevant logs to registries, registrars, payment providers, law enforcement, regulators, courts, dispute-resolution providers or complainants where required or permitted by law, policy, contract or abuse-handling processes.
Routine domain search and technical logs are normally retained for a limited period needed for service operation, security, troubleshooting, abuse prevention and rate-limit analysis. Security, abuse, fraud, dispute, payment, domain-registration, legal or enforcement records may be retained for longer where necessary to protect Rocket Domains, its users, registries, registrars, service providers and the public, to comply with law or contractual obligations, or to establish, exercise or defend legal claims. Exact retention periods may vary depending on the type of log, whether the user was logged in, the relevant service, technical storage cycles, supplier systems, abuse indicators, legal holds and registry/registrar requirements.
3. How we use personal data and legal bases
We use personal data to provide, bill, provision, renew, suspend, secure, support, migrate, restore, improve and terminate Services; register and manage domains; operate customer portals, product dashboards and login pages; authenticate users; process payments; prevent fraud, spam, abuse, hacking, malware and security incidents; provide invoices, receipts and service notices; communicate with you; deliver lawful marketing; comply with domain, registry, registrar, payment, tax, accounting, sanctions, export-control, consumer, data-protection and other legal obligations; respond to support, abuse, legal and regulator requests; enforce terms; protect rights; and manage Rocket Domains’ business.
Our legal bases may include performance of a contract, steps before entering a contract, legitimate interests, legal obligation, consent, vital interests where relevant, and establishment, exercise or defence of legal claims. Legitimate interests include secure portal operation, fraud prevention, abuse prevention, service reliability, account administration, business record keeping, supplier management, network and information security, dispute handling, customer support and enforcement of legal rights. Where you are a business customer controller using Rocket Domains as processor, the Data Processing Addendum governs our processing of customer personal data on your documented instructions.
4. Sharing personal data
We may share personal data with Rocket Protected Parties and with categories of recipients reasonably necessary to provide, secure, bill, renew, support, migrate, improve, enforce or lawfully operate the Services. These categories may include customer account and billing platform providers; payment providers and fraud-prevention providers; registries, registrars, registry service providers and ICANN-related bodies; DNS, CDN, cloud, hosting, email, security, backup, workspace, booking, SEO, app, support and infrastructure providers; professional advisers; insurers; banks; dispute-resolution providers; identity-verification providers; debt recovery providers; regulators; law enforcement; courts; and parties involved in mergers, restructuring or business transfers.
Rocket Domains does not need to publicly name every backend, white-labelled or infrastructure provider in this Privacy Policy. Public disclosures may identify recipient categories, while Rocket Domains maintains private supplier, subprocessor and transfer records. Rocket Domains may identify specific providers privately to authenticated business customers, regulators, auditors, law enforcement, domain authorities or others where required by law, contract, DPA, registry policy or due-diligence obligations.
For domain services, registrant data may be published or disclosed through WHOIS/RDAP, data-disclosure procedures, registry/registrar requirements, ICANN policies, law enforcement requests, court orders, UDRP/URS/local disputes and legitimate-interest request processes. Privacy/proxy masking does not guarantee that data will never be disclosed.
5. International transfers
Rocket Domains is based in the United Kingdom and provides services worldwide. Personal data may be processed in the UK, EEA, France, Canada, the United States and other countries where Rocket Domains, its customers or its providers operate. Transfer mechanisms may include UK adequacy regulations, EU adequacy decisions, the EU Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, Data Privacy Framework participation where applicable, contract safeguards, transfer risk assessments, supplementary measures and other lawful transfer mechanisms.
For Canada and Quebec-related processing, Rocket Domains will use reasonable contractual and organisational measures intended to provide comparable protection and will conduct transfer/outsourcing assessments where required. Customers remain responsible for their own transfer assessments where they are controllers and choose to use the Services internationally.
6. Retention
We retain personal data for as long as needed to provide Services, maintain accounts, comply with law, resolve disputes, enforce terms, maintain security, handle abuse, comply with tax/accounting obligations and support backups or restoration. Retention varies by data type. Account, billing and transaction records may be kept for at least seven years; security logs and abuse records may be kept as needed for security and enforcement; customer content may be deleted after termination according to technical retention cycles, backup schedules, supplier rules and applicable law.
We may retain limited records after deletion requests where necessary for legal compliance, fraud prevention, abuse prevention, chargeback defence, tax/accounting records, suppression lists, domain disputes, litigation holds or enforcement.
7. Security
We use reasonable administrative, technical and organisational measures designed to protect personal data, including access controls, authentication, logging, supplier controls and security monitoring where appropriate. No internet service, portal, payment flow, webmail system, hosting platform, backup tool or cloud service can guarantee perfect security, uninterrupted access, error-free operation or complete protection against unauthorised access, malware, ransomware, credential compromise, misconfiguration, supplier failure, device compromise, browser extension risks, phishing or human error. You must use strong passwords, 2FA where available, secure devices, updated software and independent backups.
8. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, object, port, withdraw consent, opt out of marketing, complain to a regulator, and obtain information about sharing or international transfers. To exercise rights, contact legal@rocket.domains. We may need to verify identity and may redirect requests about customer-controlled content to the relevant customer controller.
UK users may contact the UK Information Commissioner’s Office. EEA users may contact their local supervisory authority. Canadian users may contact the Office of the Privacy Commissioner of Canada or applicable provincial regulator. US state privacy rights may apply depending on state law and Rocket Domains’ legal thresholds.
9. Marketing, cookies, fonts and tracking
We may send service messages, security notices, renewal reminders, invoices, account communications and legally required notices. We send marketing where permitted by law and you may opt out at any time. Cookies and similar technologies may be used for essential operation, authentication, checkout, payment, fraud prevention, security, load balancing, service preferences, language, currency, shopping cart, product provisioning and support.
Rocket Domains’ current position is that it does not intentionally use analytics cookies, advertising cookies, retargeting cookies, social-media pixels or comparable optional tracking technologies on its public website or client portal. If non-essential cookies or similar technologies are introduced, Rocket Domains will update the Cookie Notice and provide consent, objection or preference controls where required by law.
Rocket Domains websites may use web fonts. Where fonts are self-hosted by Rocket Domains, the font request is handled like other website content. Where fonts are loaded remotely from a font provider such as Google Fonts, the provider may receive technical request data such as IP address, requested URL, user-agent and referrer. Rocket Domains should prefer self-hosted fonts where practicable to reduce third-party data sharing and international transfer issues. See the Cookie and Tracking Notice for more information.
10. Children and sensitive data
The Services are not directed to children under 18 and must not be used to collect children’s data without all legally required consents and agreements. You must not process special category data, protected health information, regulated financial data, criminal offence data, biometric data, children’s data at scale, classified data, export-controlled technical data or other sensitive/regulated data through the Services unless the service description allows it and you have all required legal bases, safeguards and written agreements.
11. Changes and contact
We may update this Privacy Policy to reflect operational, legal, technical or supplier changes. Contact legal(at)rocket.domains for privacy questions, rights requests, supplier/subprocessor queries, law enforcement requests or data protection concerns.