Privacy Policy
Last updated: July 17, 2026
This Privacy Policy explains how DomePlus (“DomePlus”, “we”, “us”, or “our”) collects, uses, shares, and protects personal information when you visit domeplus.com, create an account, use our control panel, APIs, or purchase panel plans or Care / project services.
By using the Service, you acknowledge this Policy. If you do not agree, do not use the Service.
1. Who this Policy covers
This Policy applies to:
- Visitors to our marketing site
- Account holders and team members who use the panel
- People who contact us (support, sales, waitlist, contact forms)
- Customers who purchase Care, Managed, or Project services
If you are an agency using a client portal, you are responsible for providing an appropriate privacy notice to your own clients for data you collect from them.
2. Information we collect
2.1 Account and profile data
- Name, email address, password (stored hashed), and account preferences
- Company / agency name when you provide it
- Authentication data for optional Google sign-in / SSO linking
- Two-factor authentication settings and related security events
2.2 Billing and payment data
- Plan selections, invoices, payment status, and subscription metadata
- Billing address or tax-related fields when required
- Payment processor references (for example Stripe customer / subscription IDs)
- Crypto payment references when you use crypto checkout
Card numbers and crypto wallet secrets are handled by payment processors — we do not store full card PAN data on DomePlus servers.
2.3 Server and product metadata
- Server names, IPs, regions/providers you record, and connection status
- Resource metrics needed for the panel (CPU, RAM, disk, and similar)
- Site / app metadata (domains, stack type, deployment status)
- Security feature status you enable (for example Fail2Ban, WAF helpers, scan summaries)
- Backup job configuration and status (destination type, schedules, success/failure) — not the full contents of your backup archives stored in your cloud
2.4 Support and service requests
- Support ticket contents, attachments you upload, and related correspondence
- Care / Managed / Project request details (domain, notes, checklists)
2.5 Marketing and communications
- Contact form, waitlist, and lead form submissions
- Email preference / transactional mail logs needed to operate the Service
2.6 Technical and usage data
- IP address, browser/user agent, device and approximate location derived from IP
- Pages and features used, referring URLs, and diagnostic logs
- Cookies or similar technologies needed for sessions, CSRF protection, and security (for example Turnstile / CAPTCHA when enabled)
3. Information we do not routinely access
DomePlus connects to your servers to manage configuration and deliver features you enable. We do not treat your website content, databases, or customer PII stored inside your applications as our primary product database.
- We do not store your site files or database dumps as a general hosting archive on DomePlus when backups go to your cloud destinations.
- Staff may access server configuration or site content only when needed to investigate abuse, maintain the Service, or fulfill a support / Care request you open.
- White-label and client-portal branding you upload (logo, colors, brand name) is stored to render the panel for you and your clients.
4. How we use information
- Provide, secure, and improve the Service
- Authenticate users, prevent fraud, and enforce Acceptable Use
- Process subscriptions, Care orders, renewals, and receipts
- Send transactional email (password reset, billing, ticket updates)
- Respond to support and deliver Care / project work
- Monitor reliability, debug, and security events
- Comply with law and respond to lawful requests
- With consent or as otherwise permitted, send product updates or marketing (you can opt out of non-essential marketing)
5. Legal bases (EEA/UK and similar)
Where GDPR or similar laws apply, we process personal data under one or more of these bases:
- Contract — to provide the account, panel, billing, and support you request
- Legitimate interests — to secure and improve the Service, prevent abuse, and understand product usage in a privacy-respecting way
- Consent — where required (for example certain cookies or marketing)
- Legal obligation — tax, accounting, and compliance requirements
6. How we share information
We do not sell your personal information. We share data with:
- Payment processors (card and crypto) to complete charges and prevent fraud
- Infrastructure and email providers that host or send on our behalf
- Security / CAPTCHA providers when enabled (for example Cloudflare Turnstile)
- OAuth providers you choose (for example Google) for sign-in
- Cloud / storage / CDN providers you connect when you authorize those integrations
- Professional advisors or authorities when required by law or to protect rights and safety
- Successors in a merger, acquisition, or asset sale, subject to this Policy or equivalent protection
Subprocessors act on our instructions and are expected to implement appropriate safeguards.
7. International transfers
We may process data in countries other than yours. Where required, we use appropriate transfer mechanisms (for example standard contractual clauses or equivalent safeguards) for transfers from the EEA/UK.
8. Retention
- Account and billing records are kept while your account is active and for a reasonable period afterward for invoices, disputes, and legal retention.
- Support tickets and Care records are retained as needed to deliver service and maintain history.
- After account deletion, we aim to delete or anonymize personal data within 30 days, except data we must keep longer for legal, security, or accounting reasons.
- Server-side logs may be retained for shorter operational windows and then rotated.
9. Security
We use industry-standard measures appropriate to a SaaS control panel, including encrypted transport (HTTPS), hashed passwords, access controls for staff tools, and optional customer 2FA. No system is perfectly secure; please protect your credentials and report suspected incidents to [email protected] or [email protected].
10. Your rights
Depending on your location, you may have rights to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete data (subject to legal exceptions)
- Export / portability of data you provided
- Object to or restrict certain processing
- Withdraw consent where processing is consent-based
- Lodge a complaint with a supervisory authority
To exercise rights, email [email protected]. We may need to verify your identity. Agencies acting for end clients should route client-data requests through the agency account holder where the agency is the controller.
11. Children
The Service is not directed to children under 16 (or the minimum age required in your country). We do not knowingly collect personal data from children. If you believe we have, contact us and we will take appropriate steps.
12. Cookies and similar technologies
We use cookies and similar technologies that are necessary for login sessions, security, and basic site operation. If we use optional analytics or marketing cookies, we will present choices where required by law. You can control cookies through your browser settings; disabling necessary cookies may break login or forms.
13. Third-party links and your sites
Our site may link to third-party sites. Their privacy practices are their own. Content and personal data collected by websites you host on your servers are governed by your policies and processors — not this Policy — except for the limited metadata and support access described above.
14. Changes to this Policy
We may update this Policy from time to time. We will change the “Last updated” date and, for material changes, may provide additional notice. Continued use of the Service after an update means you acknowledge the revised Policy.
15. Contact
Privacy requests: [email protected]
General support: [email protected]
Legal: [email protected]
Also see our Terms of Service.