Privacy policy
Updated 11 September 2026. This notice covers the registry, account panel and registry-operated parking and dialog pages. Independently hosted customer websites have their own operators and policies.
Service operator: Yourseoboard LLC
Correspondence address: 400 Harbour Pl Dr, Apartment 1262, Tampa, FL 33602
Country: United States
Contact for service, cancellation and privacy requests: hostmaster@uk.app.
Information we process
- Accounts: name, email, a hashed password for email sign-in, verification state, sessions and authentication identifiers. If you choose Google or GitHub sign-in, we receive identifiers and profile information such as your verified email, display name and avatar URL.
- Registry use: names, DNS records, redirects, subscription status, expiry dates, token metadata and change audits. Audit records can include the request IP and changed configuration.
- Billing: Stripe customer, subscription and invoice identifiers; amounts, currency, dates, receipt links, balance transactions, and confirmation email recipients and processing status. Stripe collects payment details through checkout and its portal; we do not store full card numbers or card security codes.
- Technical operation: web and application logs, IP addresses, timestamps, requested paths, errors, DNS operational information and rate-limiting state.
- Support and abuse: correspondence, reporter contact information and submitted evidence. Authorised administrators can review service email and reports to handle requests.
- Optional AI dialogs: when you use a registry-operated dialog, your question and recent conversation context go to the configured model service to generate an answer. The application stores the question, answer, name, IP and timing. Do not submit passwords, payment details or sensitive personal information.
Purposes and legal bases
We use account, registration and payment information to provide the requested service, authenticate access, publish DNS changes, process billing and send service notices. Logs and abuse evidence help protect users, diagnose failures and investigate misuse. Financial and dispute records also support accounting and legal obligations.
Where data protection law requires a legal basis, service delivery relies on performance of the contract or steps you request before entering it; security, troubleshooting and abuse prevention rely on legitimate interests balanced against your rights; required record-keeping and valid legal demands rely on legal obligations. Where consent is required for an optional use, it must be obtained separately and may be withdrawn.
Public DNS and WHOIS
DNS records are public. They may reveal a server or home IP, mail routing, verification values and other information you enter. Anyone can query and cache them. Do not publish secrets in DNS. Removing a record does not remove copies already collected elsewhere.
Public WHOIS shows availability or status and relevant information such as dates and nameservers. It does not publish the account owner's name or email. This does not make the registered name or its DNS records private.
Providers and disclosures
Hosting, DNS, email delivery and backup infrastructure process information needed for operation. Stripe processes payments; Google and GitHub process sign-in when selected. Their privacy notices explain independent processing: Stripe, Google and GitHub.
The site loads Google Fonts, causing your browser to contact Google's font servers. Configured threat checks can submit a hostname or URL to URLhaus and Google Web Risk. If messaging reminders are enabled for your chosen contact channel, the delivery provider receives the destination and reminder content. AI dialog processing is described above.
We do not sell account information. Information may be disclosed to service providers, professional advisers or authorities where necessary for operation, legal obligations or a claim. Providers can process data outside your country. Applicable transfer requirements depend on the provider, destination and governing law; contact us for the arrangements relevant to your information.
Cookies
Session and security cookies support sign-in, request protection and account functionality rather than advertising profiles. Third-party pages you choose to visit, including payment and sign-in services, have their own cookie policies. Blocking necessary cookies can prevent account access.
Retention and deletion
Account and registry information is kept while needed to operate registrations and resolve related requests. Names moved to the bin normally retain DNS configuration for up to 30 days unless permanently deleted sooner. Deleting a name does not automatically erase account, audit, payment, support or backup records.
Other retention depends on maintaining an active account, resolving incidents or disputes, applicable accounting and legal duties, and backup rotation. There is currently no single automatic deletion deadline for all logs or account-deletion button. Contact us to request deletion or details about a particular record. Requests may require identity verification, and some records may need to be retained where the law permits or requires it.
Your choices and rights
You can manage DNS and API tokens and export a name's DNS configuration in the panel. For other personal data access, correction, account closure or deletion, write to the operator contact above from your account email. Depending on applicable law, you may also have rights to restriction, objection, portability and withdrawal of consent. We may request proportionate proof of identity.
You may complain to the data protection authority responsible for your jurisdiction. Where UK data protection law applies, contact the Information Commissioner's Office. Account and billing information is necessary for paid registration; optional social sign-in and dialogs are not required for email registration.
Security and updates
Access controls, password hashing, HTTPS and scoped credentials help protect information, but no service can guarantee complete security. Protect your account and report suspected unauthorised access promptly. This notice is updated when processing changes; the date above identifies the version.