Privacy Policy

Version history · 9 October 2026
9 October 2026Current versionRewritten: who we are, purposes and legal bases, buyer research and what sellers see, domain transfers, cookies, processors, transfers outside the EEA, retention, your rights and the right to object.
1 November 2024

Summary

Nameshift BV runs a marketplace where people buy and sell domain names. This privacy policy explains which personal data we process, why, on what legal basis, who receives it and how long we keep it. In short:

  • We process what you give us (account, inquiries, offers, payments, domain transfers), what your use of the site produces (visits, device and IP data), and, when you contact a seller, public information we look up about you.
  • When you send an inquiry or offer, the seller of the domain sees who you are, your offers, your activity on Nameshift and a short summary of public information about you. See Inquiries, offers and what sellers see.
  • We do not sell your personal data.
  • You can object to research about you and to marketing at any time, and you have the other rights described under Your rights.

Who we are

The controller of your personal data is:

Nameshift BV

Steenplaetsstraat 6, 2288 AA Rijswijk, the Netherlands

Chamber of Commerce (KvK) 95363017 · VAT NL867101623B01

Privacy questions and requests: contact@nameshift.com

We have not appointed a data protection officer; the address above reaches the people responsible for privacy at Nameshift.

Whose data this policy covers

  • Visitors of nameshift.com and of domain landing pages hosted by Nameshift.
  • Buyers: people who send an inquiry or offer, buy a domain or bid in an auction.
  • Sellers: account holders who list domains, including people who represent a company.
  • Newsletter subscribers, affiliates and API users.
  • Anyone who contacts us, for example through the chat.

Our role

Nameshift is the controller for everything described in this policy. When we pass a buyer's details to a seller (see Inquiries, offers and what sellers see), the seller becomes an independent controller of what they receive and is responsible for how they use it.

What we process and why

For each purpose below you find the data we use, the legal basis under Article 6 of the GDPR, and how long we keep it. Where the basis is our legitimate interest, the interest is named.

Running your account

  • Data: name, email address, password (stored as a hash), company details, language, two-factor settings, account history.
  • Basis: performance of our agreement with you (Article 6(1)(b)).
  • Retention: as long as your account exists. When you close your account we delete or anonymise this data within 30 days, except what we must keep for the reasons below.

Inquiries, offers, sales and domain transfers

  • Data: the domain you are interested in, your name, email address, company (if given), your messages and offers, the agreed price, and for a transfer the registrant details described under Domain transfers and WHOIS.
  • Basis: taking steps at your request before an agreement, and performing it (Article 6(1)(b)).
  • Retention: 2 years after the last activity on the inquiry or sale; invoices and payment records 7 years (below).

Payments, payouts and bookkeeping

  • Data: payment method, transaction details, invoices, bank account details of sellers, VAT details.
  • Basis: performance of the agreement (Article 6(1)(b)) and our legal obligations under Dutch tax law (Article 6(1)(c)).
  • Retention: 7 years, as Dutch tax law requires (article 52 Algemene wet inzake rijksbelastingen). Card details are entered directly with our payment providers; we do not receive or store full card numbers.

Verifying sellers before payouts

  • Data: identity or company verification results, and the documents and information you provide to our verification provider; the name on your bank account.
  • Basis: our legitimate interest in preventing fraud and paying the right account holder, and our legal obligation to comply with sanctions law (Article 6(1)(f) and (c)).
  • Retention: as long as you receive payouts, and 5 years after that, to handle disputes and fraud investigations.

Auctions

  • Data: your bids and, before a bid of 1,000 or more, your phone number, which we verify with a one-time code by text message, phone call or WhatsApp.
  • Basis: performance of the agreement (Article 6(1)(b)) and our legitimate interest in preventing fake bids (Article 6(1)(f)).
  • Retention: bids as for sales above; the verified phone number as long as your account exists.

Researching buyer inquiries

Described in full under Inquiries, offers and what sellers see.

  • Basis: our legitimate interest in handling inquiries carefully, preventing fraud and informing sellers (Article 6(1)(f)).
  • Retention: 180 days after your last inquiry.

Security and preventing abuse

  • Data: IP address, device and browser data, login events, and a risk score from Google reCAPTCHA on sign-up and on the inquiry and offer forms.
  • Basis: our legitimate interest in keeping the platform and our users safe from spam, fraud and abuse (Article 6(1)(f)).
  • Retention: security logs up to 6 months, unless needed longer to investigate an incident.

Customer support

  • Data: your chat and email conversations with us, and when you are logged in, your name, email address and account id, so we know who we are talking to.
  • Basis: performance of the agreement, or our legitimate interest in answering questions from people without an account (Article 6(1)(b) and (f)).
  • Retention: 2 years after the conversation ends.

Newsletter and marketing

  • Data: email address, name, subscription status and when and where you subscribed.
  • Basis: your consent (Article 6(1)(a)). As a customer we may also email you about similar services of our own, which you can refuse in every email (article 11.7 Telecommunicatiewet).
  • Retention: until you unsubscribe; we then keep only a record that you unsubscribed, so we do not email you again.

Website analytics and cookies

Described under Cookies and analytics.

Inquiries, offers and what sellers see

When you send an inquiry or offer for a domain on Nameshift, three things happen.

1. We look up public information about you. To check that an inquiry is genuine, to prevent fraud and to give the seller context, we look up publicly available information about you and the organisation behind your email address. We start from what you entered (email address, name, company name if given, the domain) and the IP address the inquiry came from, and we use:

  • public business registers: the Dutch Chamber of Commerce (KVK), the Global LEI Index (GLEIF) and the EU VAT validation service (VIES);
  • CompanyData (companydata.com), a commercial company-information provider, for details about the organisation behind your email domain;
  • the public website at your email domain, which we read automatically;
  • a web search for you, your company and the domain, carried out and summarised by an AI model;
  • information about your IP address: the network operator and approximate location (city level).

We do not research addresses at free email services (such as Gmail) for company details, and we do not use your information to train AI models. The AI models are accessed through OpenRouter, and only models with zero data retention are used: your request is used to produce the answer and is not stored or used for training. We keep company details, the network and approximate location of your IP address, and a summary of a few sentences about you with links to the public pages it is based on.

2. We connect your visits to your inquiry. Our site statistics count pageviews on Nameshift and on domain landing pages we host. When you submit an inquiry, offer or purchase, we link your earlier and later visits in your browser to it, using a code derived from your email address (a one-way hash) stored in your browser.

3. The seller receives your details. The seller of the domain sees:

  • your name, company and the messages and offers you send;
  • the summary of public information about you;
  • your activity: the pages you viewed on their domain, the offers you entered, and other domains on Nameshift you looked at.

Whether to accept an offer is up to the seller. None of this leads to decisions made solely by automated means with legal or similarly significant effects for you. The one automated step is the reCAPTCHA spam check: if it rates a submission as very likely automated, the form is not sent. If that happens to you, contact us and we will pass your inquiry on.

Domain transfers and WHOIS

When you buy a domain, it is transferred to you through our registrar partner Openprovider. For that we register you as the domain's holder (registrant) with your first and last name, company name, company registration number (or, for some domain extensions that require it, a personal identification number), postal address and language. We use our own phone number and a forwarding address instead of your email address.

The registrar passes these details to the registry of the domain extension (for example SIDN for .nl). Depending on the registry's rules, some of them may be published in the public WHOIS or RDAP database; most registries no longer publish the details of private individuals.

Cookies and analytics

We use cookies and similar technologies (such as local storage):

  • Necessary: to keep you logged in, remember your cookie choice and protect forms against abuse. No consent needed.
  • Statistics: to count visits and understand how the site is used, including the link between visits and inquiries described above.
  • Marketing: to measure our advertising and show relevant ads, through tags loaded by Google Tag Manager.
  • Chat: the Crisp chat widget.

We only use statistics and marketing cookies after you consent in the cookie banner. You can change or withdraw your choice at any time through the cookie settings link at the bottom of every page; the cookie declaration there lists every cookie, its purpose and how long it lasts.

Who receives your data

  • Sellers, as described under Inquiries, offers and what sellers see, and buyers, who see the seller's details needed to complete a sale.
  • Registrars and registries, for domain transfers.
  • Service providers (processors) working on our instructions, under a data processing agreement: - payments and payouts: Stripe, Mollie, Airwallex; - seller verification: Sumsub; - phone verification: Twilio; - spam protection: Google reCAPTCHA; - VAT and bookkeeping: Quaderno, SnelStart; - customer chat: Crisp; - newsletter: Mailchimp; - email delivery: Mailchimp Transactional (Mandrill), with Brevo as backup; - buyer research: OpenRouter and the AI model providers it routes to, IPinfo and CompanyData; - hosting, storage and delivery: Fly.io, Vultr, Google Firebase, Cloudflare, Amazon Web Services, Neon, Storyblok; - app push notifications: Expo.
  • Authorities, when the law requires it, for example the tax authorities or the police with a valid order.

Transfers outside the European Economic Area

Some of these providers are based in, or use servers in, the United States or another country outside the EEA. We only transfer data when one of these applies: the European Commission has decided the country protects data adequately (for example the United Kingdom); the recipient is certified under the EU-US Data Privacy Framework; or we have agreed the European Commission's standard contractual clauses with the recipient. You can ask us for a copy of the safeguards that apply.

Data you must provide

You need to give us your name and email address to send an inquiry, and the details asked at checkout, payout set-up and domain transfer to complete those steps. Without them we cannot provide that service. Everything else is optional.

Your rights

You have the right to:

  • access the personal data we hold about you and get a copy;
  • have it corrected if it is wrong or incomplete;
  • have it deleted, unless we must keep it, for example for tax law;
  • restrict our use of it while a complaint about it is being handled;
  • receive the data you gave us in a common format, or have it sent to another company (portability);
  • withdraw consent at any time, for the newsletter or cookies, without affecting what happened before.

Send your request to contact@nameshift.com. We answer within one month and may ask you to confirm your identity first.

You can also complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, or the authority in the EU country where you live.

Your right to object

Where we process your data on the basis of our legitimate interest, you can object at any time, on grounds relating to your situation. This includes the research we do on buyer inquiries and the linking of your visits. We then stop, unless we have compelling legitimate grounds that override your interests, or need the data to establish or defend legal claims. When you object to the research on inquiries, we delete what we found and record your objection so we do not look you up again.

You can always object to direct marketing, and we will then stop without exception. Use the unsubscribe link in any email or write to contact@nameshift.com.

Security

We protect your data with encryption in transit and for sensitive fields at rest, two-factor and passkey login, access limited to the staff who need it, and hosting in the European Union for our main systems. If a data breach is likely to put you at high risk, we will tell you.

Children

Our services are intended for people aged 18 or over, in line with our terms and conditions. We do not knowingly collect data from children.

Changes to this policy

When we change this policy we publish a new version on this page and keep the earlier versions in the version history above. If a change matters for how we use your data, we tell account holders by email before it takes effect.