Skip to main content
HOME|LEGAL • PRIVACY POLICY
UK GDPR • DATA PROTECTION ACT 2018 • EFFECTIVE SEPTEMBER 2026

Privacy Policy & Data Hygiene

SubdomainWatch is engineered with privacy-by-design principles: zero advertising trackers, ephemeral edge processing, and strict multi-tenant database isolation.

1. Data Controller & Scope

Under the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018, SubdomainWatch acts as the Data Controller for account registration details and billing identity, and as a Data Processor when executing automated DNS and attack surface reconnaissance on behalf of authenticated organizations.

TRANSIENT TECHNICAL PROCESSING (GEO-CURRENCY)

2. Ephemeral Edge Localization & Zero IP Persistence

When you visit SubdomainWatch, edge routing proxies (Vercel Edge Network / Cloudflare) evaluate standard incoming HTTP country headers (e.g., x-vercel-ip-country, cf-ipcountry) strictly to present relevant pricing currencies:

  • United Kingdom (GB) → Great Britain Pounds (£ GBP)
  • Eurozone (EU) → Euros (€ EUR)
  • Rest of World → US Dollars ($ USD)
Zero Storage Guarantee: Your IP address is evaluated ephemerally in volatile memory during edge request dispatch. It is never logged in our database, never written to cookies, never used for behavioral profiling, and never shared with third-party data brokers. Consequently, no consent banner is required under the UK Privacy and Electronic Communications Regulations (PECR).

3. Categories of Data Collected

A. Account & Identity Data:

Email address, hashed password (managed securely via Supabase Auth), organization workspace name, and billing references (Stripe Customer ID).

B. Attack Surface Telemetry:

Monitored apex domains, enumerated subdomains, public DNS records (A, AAAA, CNAME, MX, TXT), TLS certificate validity periods, and detected dangling CNAME incidents.

C. Notification Endpoints:

Incident delivery email addresses and customer-configured Slack Incoming Webhook URLs.

4. Cookies & Local Storage Policy

SubdomainWatch uses strictly essential cookies only to manage authenticated sessions (Supabase Auth JWT tokens stored in secure, HttpOnly, SameSite=Lax cookies).

We do NOT load third-party analytics (e.g. Google Analytics), tracking pixels, advertising retargeting tags, or cross-site fingerprinting scripts.

5. Multi-Tenant Data Isolation & Security

All perimeter scan telemetry, incident records, and organization settings are partitioned using PostgreSQL Row-Level Security (RLS). Every query executed in the Defense Console is cryptographically bound to the authenticated user's organization_id.

6. Your Statutory Rights (UK GDPR)

You have the right to request access to, rectification of, or erasure of your personal data, and to restrict or object to processing. To exercise these rights or request account deletion, contact privacy@subdomainwatch.com.