Privacy Policy

In short. This site has no accounts and nothing to log in to. It collects personal data when you fill in a form — to make an offer, buy a domain, or refer a buyer — and, with each of those, it records where the request came from. Email we send you about an offer or a purchase records whether it was opened and which links were clicked. Both are for online fraud prevention, both are described below, and both are read by a person. The pages also load analytics and advertising scripts from Google that set their own cookies, only after you agree. Everything else on the page works without knowing who you are.

1. Who is responsible

Nikolay Kolev operates this website and is the controller of the personal data described here. Questions, requests, and complaints go to [email protected], and are answered by a person.

2. What you give us, and why

Every field in the four subsections that follow is one you typed yourself. The two subsections after them describe the only things this site records that you did not type: where a request came from, and whether an email we sent you was opened.

Making an offer

The offer form collects your first name, your email address, the domain and amount you are offering, and — if you choose to fill them in — your last name, phone number, a message, and a proposed payment plan. We need this to read your offer, reply to it, and negotiate. Choosing to send the offer through Telegram instead hands the same details to Telegram's own service.

Buying directly by wire or Gram

The direct-purchase form collects your first name, email address, and — because the domain has to be pushed somewhere — your GoDaddy account email and GoDaddy customer number. Your last name is optional. These go onto the purchase agreement you sign, and the GoDaddy details are used to transfer the name to you. We do not ask for, receive, or store card numbers, bank credentials, or government identification.

Buying through Escrow.com, or paying monthly

These routes collect your email address here and then hand you to Escrow.com, which runs its own identity and payment process under its own privacy policy. Payment details are entered on Escrow.com, not on this site, and we never see them.

Referring a buyer

The referral form collects your name and email address, the domain(s) you are referring, and — about the person you are recommending — their email address and whatever else you choose to add: their name, company, and a short message about how you know them. We use this to attribute a referral commission if that person completes a purchase of one of the domains you named, within the program's window, and so we can reach out to them about those domains — that follow-up is the point of a referral introduction. Registering a lead does not add them to any marketing list, and submitting the form does not itself send them anything; the message it sends is to us, so we can decide whether and how to follow up. We never use a lead's details for anything unrelated to the domain(s) you named. By submitting the form you confirm that they are happy for us to contact them about those domains. See Refer a buyer for the full program terms.

What we record about the request

When you submit any of the forms above, or open a checkout, we store — alongside what you typed — the IP address the request came from and the country, region, city, and network operator that Cloudflare, which serves this site, derives from it. We use this for online fraud prevention: to assess whether a submission is genuine before acting on it. It is shown to the seller next to the submission, it is never used to decide automatically — a person reads it, and every offer is answered by a person. It is never used for advertising. It reaches only the seller — by email and, for offers, through the seller's private Telegram chat (see Telegram in Section 3) — and no one else in Section 3 besides Cloudflare, which produced it. Offers sent through Telegram carry no such record; Telegram does not pass an address to us.

Email engagement

Email we send you about your offer or purchase — a counter, a message from the seller, a payment prompt, a thank-you code — contains a tracking image and tracked links. When your mail client loads the image, or you follow a link, we record the time, the IP address, and the same derived location as above. We use this for online fraud prevention and to know whether a counter or a payment prompt actually reached you, so a stalled negotiation can be followed up rather than assumed dead. Every such email says so in its footer. Reading the plain-text version, or blocking remote images, prevents the open from being recorded while the email still works; the links still work either way, and following one is recorded. Many mail providers load images through their own servers, in which case the location recorded is theirs, not yours, and we mark it as such.

Legal basis

For the four form subsections, the legal basis under the GDPR is the performance of, or steps taken at your request before entering into, a contract — for the sale of a domain name, or, for a referral, the referral commission arrangement described at Refer a buyer (Article 6(1)(b)). For the request record and the email engagement record, the basis is our legitimate interest in preventing online fraud and in conducting the negotiation you started (Article 6(1)(f)); you may object to either at any time by writing to the address in Section 1, and where your local law requires consent for email tracking, the footer of each email is where we tell you and how to avoid it. For the analytics and advertising described in Section 4, the basis is your consent (Article 6(1)(a)), which you may withdraw at any time.

3. Who else sees it

The processors below receive only what their job requires:

We do not sell personal data, and we do not share it for cross-context behavioural advertising beyond the advertising cookies described below. No personal data is transferred to anyone not on this list.

4. Cookies and similar technologies

The site itself sets no cookies, and the tracking image in our email sets nothing in your browser or mail client. The site stores three things in your browser. The first two stay there and are never sent to us:

The third is not yours and is not about you:

Three third parties set storage of their own:

Analytics and advertising load only after you agree to them. Until you do, and if you decline, neither script runs and neither sets anything. You can change your mind at any time from the "Cookie settings" link in the footer of every page. If your browser sends a Global Privacy Control signal, we treat that as a refusal and never ask.

5. How long we keep it

Offers and the correspondence around them are kept while the domain is still for sale and for 24 months after the last message between us, so that a returning buyer's history is intact and so a disputed negotiation can be reconstructed. Records of a completed sale — the agreement, the parties, the amount — are kept for seven years, because tax and contract law require it. A referral lead is kept as part of our commercial records — the row is the ledger for whether, and how much, commission is owed on it, so it is not deleted once its window lapses; a sale that syncs late can still be matched against it. We use a lead's contact details to attribute the referral and to reach out to them about the domain(s) named, never for anything unrelated. The request record and the email engagement record described in Section 2 are kept with the offer, purchase, or lead they belong to, under that record's window above, and are deleted with it. The access, correction, and erasure rights in Section 6 apply to all of it, whether you are a buyer, a referrer, or the person referred. Analytics data is retained by Google under the retention window configured in that product. Nothing is kept "just in case".

6. Your rights

Wherever you live, you may ask us to show you the personal data we hold about you, correct it, delete it, or send it to you in a portable form. You may object to processing based on legitimate interests — including the request record and the email engagement record — and you may withdraw consent to analytics and advertising without giving a reason and without affecting anything you have already done on the site.

Write to [email protected]. We answer within 30 days. There is no charge, and no account to close first.

If you are in the EU or the UK you also have the right to complain to your national data protection authority. If you are in California, Colorado, or another US state with a comparable law, the same rights apply to you under that law, including the right not to be discriminated against for exercising them.

7. International transfers

The processors named in Section 3 are established in the United States and process data there. Transfers rely on the European Commission's Standard Contractual Clauses or, where the processor is certified, the EU–US Data Privacy Framework.

8. Children

This is a marketplace for domain names sold to businesses and adults. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has sent us something, write to the address above and it will be deleted.

9. Security

Every page and every form is served over HTTPS with HSTS. Offer, purchase, and referral submissions are protected by anti-automation challenges. Access to stored offers, referral leads, request records, and email engagement records is limited to the seller. We do not hold payment credentials, so there is no card data here to lose.

10. Changes to this policy

Each version of this policy is published at a permanent dated address alongside the SHA-256 hash of its source, and every prior version stays reachable from the list at the foot of this page. A change is made by publishing a new version, never by editing a published one — so what this policy said on the day you used the site remains verifiable.