Privacy Policy
Last updated: August 2026
Tidy Names ("we", "us", or "our") operates the tidynames.com website and associated services. This Privacy Policy explains what information we collect, how we use it, and the choices you have regarding your data. By using Tidy Names, you agree to the collection and use of information in accordance with this policy.
Tidy Names is a product of Elevelay Ltd, a company registered in Scotland (SC898093). Elevelay Ltd is the data controller responsible for the personal data described in this policy, and is the company you are contracting with when you use the Service.
Information We Collect
Account information. When you create an account, we collect your name and email address. You sign in with a one-time email link (magic link) or with your Microsoft work, school, or personal account. If you sign in through Microsoft, we receive the basic profile information (name and email) it shares with us. We do not store passwords.
Domain data. When you connect a registrar account, we retrieve domain names, registration dates, expiry dates, DNS records, and registrar metadata. This data is used exclusively to provide the Tidy Names service and is never sold or shared with third parties for marketing purposes.
Usage analytics. If you accept analytics cookies, we collect usage data including pages visited, features used, and session duration. This information helps us improve the product and diagnose technical issues. We do not use third-party advertising trackers.
How We Use Your Information
Service provision. We use your account and domain data to operate Tidy Names, including syncing domains from your registrar accounts, displaying your dashboard, and managing your organisation and team settings.
Alerts and notifications. We use your email address to send expiry alerts, sync failure notifications, and product updates. You can adjust notification preferences or unsubscribe from non-essential emails at any time.
Product improvement. Consent-based usage data is used to understand how the product is used, prioritize features, and identify performance issues. We do not build advertising profiles from your data.
Data Storage and Security
All data is stored on servers located in the United States. Data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256 encryption. Registrar API credentials are encrypted using AES-256-GCM with per-credential encryption keys and are never stored in plaintext or exposed in application logs.
Access to production systems is restricted to authorized personnel using multi-factor authentication. We conduct regular security reviews and monitor for unauthorized access attempts. In the event of a data breach, we will notify affected users within 72 hours in accordance with applicable regulations.
Third-Party Services
Registrar APIs. We connect to registrar APIs (Cloudflare, GoDaddy, Namecheap, Porkbun, and others) using credentials you provide. We request only the minimum permissions required to read domain and DNS data. We never make changes to your domains, DNS records, or registrar account settings.
Payment processing. Payments are processed by Stripe. We do not store credit card numbers or bank account details on our servers. Stripe's privacy policy governs how your payment information is handled.
Infrastructure. Our application is hosted on Vercel and our data is stored with Neon. We use Resend to send email, Brevo for our contact-form and waitlist records and any marketing email you opt in to, Microsoft for optional single sign-on, PostHog for product analytics (which loads only after you accept analytics cookies), Sentry for error monitoring, and Upstash for rate limiting. We do not use cross-site advertising trackers.
Sub-processors. A full, up-to-date list of the third parties that process data on our behalf - including what each one does and where it is located - is published at tidynames.com/legal/subprocessors.
Your Rights
Access. You may request a copy of the personal data we hold about you at any time by contacting us at the email address below.
Deletion. You may request deletion of your account and all associated data. Upon receiving a deletion request, we will remove your data within 30 days, except where retention is required by law.
Retention. Operational records are kept only as long as they are useful: activity and audit logs for up to 12 months, sign-in history (IP address and browser details) for up to 12 months, billing event records for up to 18 months, and notification and delivery records for 90 days or less. Data belonging to a deleted organisation is permanently removed 30 days after deletion.
Export. You may export your domain data in CSV format at any time from your dashboard. If you need a full data export in a different format, contact us and we will accommodate your request.
Contact
If you have questions about this Privacy Policy or want to exercise any of the rights described above, contact us at privacy@tidynames.com. We will respond within 10 business days.