Dommate · Legal

Privacy Policy

Effective: 2026-04-29 · Version: v1.8
Operator: Dommate
Authoritative version: English. Translations are not provided for legal text.

0. Roles and Contact

Data Controller: the Dommate platform operator (personal information handler under PIPL; data controller under GDPR semantics). The registered legal entity is available on request via the contact email below.

Processors / sub-processors: Cloudflare (incl. Turnstile + Email Service), DNSPod International (Tencent), GitHub, Alibaba Cloud (IaaS VM host in Tokyo), Resend (legacy fallback, conditional) — see §4 and §5.

Privacy & Data Protection Contact: contact@dommate.com (please prefix subject with [Privacy]). No dedicated DPO designated; this address is the unified point of contact.

Dommate follows the principle of minimum necessity. We do not sell user data nor use it for behavioral ad targeting.

1. Information We Collect

Account data

  • Email address (required for login).
  • GitHub user ID, login, public email (if using GitHub OAuth).
  • Session cookie.

Application data

  • Domain label and suffix.
  • Purpose description.
  • NS records.
  • Blog URL (if using blog verification).

Access & Audit data

Recorded on all state-changing operations:

  • Login / logout.
  • Submit, revoke, review applications.
  • Blog verification start / complete.
  • Abuse report submission (IP recorded even when not logged in).
  • Admin actions.

Fields: client IP, User-Agent (on requests carrying a session cookie), timestamp, action, target ID, structured metadata.

Automated abuse prevention

  • Turnstile verification result (retained ≤ 24h).
  • Rate limit counters (Redis, sliding window).

2. Information We Do NOT Collect

  • Passwords (passwordless login).
  • ID cards, passports, or student IDs.
  • Payment information (service is free).
  • Precise geolocation.
  • Third-party trackers or Google Analytics.

3. How We Use Information

  • Provide and maintain the Service.
  • Review applications.
  • Abuse prevention.
  • Respond to abuse reports.
  • Legal compliance.

4. Sharing with Third Parties

Third-party providers
ProviderRolePurposeData
Cloudflare, Inc.Processordommate.com edge proxy / WAF / Turnstile + Cloudflare Email Service (transactional magic-link email)Request headers, IP; Turnstile collects browser-side fingerprint / event data; Email Service handles recipient address + email body (incl. login token) + sender identity. See CF privacy policy
DNSPod International (Tencent Cloud)ProcessorAuthoritative DNS for the five suffixes (net.rich / edu.rich / ii.pe / pa.ax / ac.chat)Domain FQDN, NS hostnames, DNS-level query source IP
GitHub, Inc.Independent controllerOAuth + eligibility checkOAuth state, read:user, user:email
Alibaba Cloud (Tokyo, Japan)ProcessorIaaS VM host (operator self-runs Debian 13 + docker compose; no third-party PaaS tenant in the middle)All runtime data (Postgres / Redis / app logs)
Resend, Inc. (legacy fallback, conditionally active)ProcessorFallback outbound email path when Cloudflare Email Service is unavailable; active only if the operator configures RESEND_API_KEYRecipient email address, email body (incl. login token), sender identity. See Resend privacy policy

We do not share with ad networks, data brokers, or behavioral analytics.

5. Cross-border Transfer

  • Cloudflare (incl. Email Service send nodes): US, EU, Singapore.
  • DNSPod International (Tencent Cloud): Singapore, Hong Kong, Tokyo (anycast node distribution).
  • GitHub: US.
  • Resend (legacy fallback, only when enabled): US.
  • Alibaba Cloud (Tokyo IaaS ECS): Tokyo.

By using the Service you consent to data possibly being stored or processed in those regions. Per PIPL Art. 38 we rely on standard contractual clauses and technical measures (HTTPS, TLS 1.2+, encryption at rest).

6. Retention

The table below lists retention in the live production database.

Retention periods
DataRetention
Account dataDeleted within 30d of account deletion
Sessions7d after expiry or logout
Magic link token (hash)7d after expiry
Audit log2 years
Abuse reports5 years (compliance)
Revoked delegation metadataPermanent; label not reassigned
Turnstile result≤ 24h

Backup carve-out: daily Postgres dumps are stored in an encrypted restic repository (daily 14 / weekly 8 / monthly 12 / yearly 5); oldest yearly snapshots may live up to 5 years. These snapshots are used for full disaster restoration only — never for day-to-day queries, exports, or data-request responses. When you delete your account the live database is purged within 30 days, but pre-deletion snapshots may still contain your historical data until they age out under the retention policy.

7. Security

  • Site-wide HTTPS + HSTS.
  • HttpOnly + Secure + SameSite=Lax cookies.
  • Origin / CSRF validation on authenticated writes.
  • Magic link tokens stored as SHA-256 hash only.
  • At-rest encryption: Alibaba Cloud encrypted block storage for DB/Redis + restic client-side AES-256 encryption on backups.
  • Turnstile bot mitigation.
  • Worker lease + fencing to prevent state corruption.

No system is absolutely secure; we do not claim perfection.

8. Your Rights

Under PIPL, GDPR, and other applicable laws, you have the rights to:

  • Access / copy: at /dashboard footer click "Export my data" to download a JSON copy (rate-limited 1/hour).
  • Rectification: currently via email request; self-service in roadmap.
  • Deletion.
  • Withdraw consent.
  • Complain to a supervisory authority.

Email contact@dommate.com (subject [Privacy]); we respond within 15 business days.

9. Cookies

We use only these three; only the first carries identity:

  • __edurich_session: login session cookie, HttpOnly + Secure + SameSite=Lax.
  • NEXT_LOCALE, NEXT_THEME: locale / theme preference. Client-side only, non-HttpOnly, no identity. 1 year expiry.
  • Cloudflare security cookies (anti-bot).

No ad or third-party analytics cookies.

9.1. Publicly Published Delegation Metadata

To meet PSL-review transparency expectations, the following fields are public via WHOIS / RDAP / the /whois page to any anonymous visitor:

  • Full domain (FQDN)
  • Suffix / status (active / pending / revoked)
  • NS records (only when active)
  • Created / updated / activated / revoked timestamps
  • Operator and abuse contact

We do not publish applicant email, GitHub login, real name, purpose, reviewer notes, abuse ticket content, or IP. Choose your domain label without embedding real names or PII. The "recent active domains" sample on /whois is the same already-public set.

Applying implies consent to publish these fields. Revocation keeps the record queryable with status `revoked`; per ToS §7, previously-used labels are never reassigned.

10. Minors

The Service is not directed to users under 14 (aligned with PIPL's threshold for special minor protection).

11. Changes

Material changes are notified via email at least 14 days in advance.

Revision Log
2026-04-29 · v1.8 · DNSPod sub-processor row expanded from "four suffixes" to "five suffixes" (added authoritative DNS hosting for *.ac.chat)
2026-04-24 · v1.7 · Production infrastructure moved to self-managed Debian 13 + docker compose + Caddy + restic backups; §4 Zeabur processor row replaced with Alibaba Cloud (IaaS host in Tokyo); §5 cross-border Zeabur entry synced; §7 at-rest encryption note updated to include restic client-side AES-256
2026-04-21 · v1.6 · Outbound email primary path switched from Resend to Cloudflare Email Service; Resend kept as conditional legacy fallback (only active when RESEND_API_KEY is configured); §4 Cloudflare row expanded to include Email Service data scope; §5 Resend US entry re-tagged as conditional
2026-04-21 · v1.5 · Four-suffix disclosure: service scope expanded to `*.pa.ax`; DNSPod International (Tencent Cloud) disclosed as sub-processor (authoritative DNS for all four suffixes); Cloudflare no longer manages suffix zones
2026-04-20 · v1.4 · Anti-automation switched from hCaptcha to Cloudflare Turnstile; §4 hCaptcha row removed (Turnstile folded into the Cloudflare row), §5 cross-border updated accordingly
2026-04-20 · v1.3 · Operator brand unified to Dommate (main site moved to dommate.com); all contact emails and policy URLs moved to dommate.com; §9 Cookies scope unified to .dommate.com
2026-04-20 · v1.2 · Added §9.1 WHOIS / RDAP public field list; §9 Cookies clarifies NEXT_LOCALE / NEXT_THEME preference cookies
2026-04-19 · v1.1 · Explicit data controller / processor roles; added third-party captcha provider; clarified IP/UA collection scope; minimum age 14; contact email unified to contact@dommate.com
2026-04-19 · v1.0 · Initial release

12. Contact