Renewatch
Start monitoring

Privacy policy

Effective 31 August 2026 · Terms of service

Renewatch (https://renewatch.com) is the controller of the personal data described here. This page is written from what the software actually does, and it is short because the software stores little. Questions, or any request about your data: alerts@renewatch.com.

What we store, and for how long

  • Your email address, and the name your sign-in provider sent with it — this is the account, kept until you delete it. It is used to sign you in and to send the alerts you asked for. Nothing else: no newsletters, no marketing, and it is never shared for advertising.
  • The domains you watch and any DKIM selector you told us — kept until you remove them or delete the account.
  • Sign-in codes — a hash of the code, your email and the requesting IP address, kept for the code's ten-minute life and purged within a day. The IP exists to stop one machine requesting codes for strangers' mailboxes.
  • A Stripe customer reference if you subscribe — an opaque ID, kept until you delete the account. Card numbers never reach us; Stripe holds those.

What a domain check observes — expiry dates, nameservers, mail records, certificates — is public information about a domain, read from the registry and the DNS, and is not tied to a person.

What we deliberately do not have

  • No passwords. Sign-in is by one-time code or by Google/Microsoft, so there is no password of yours to lose.
  • No analytics, no trackers, no advertising scripts. Pages are served entirely from renewatch.com; fonts included, your browser contacts no third party by reading this site.
  • No stored Cloudflare credentials. If you connect Cloudflare to repair a DNS record, the token is used for that one operation and immediately revoked.

Cookies

Only cookies the service cannot work without, which is why there is no consent banner — none of them track you, and EU law (ePrivacy art. 5(3)) requires consent only for cookies beyond these:

  • rw_session — keeps you signed in, for up to 30 days.
  • rw_pending, rw_oauth, rw_cf — carry a sign-in or account-connection across its redirect, for ten minutes at most.

Who processes data for us

Four companies handle data to run the service, each under its own data-processing terms: Cloudflare (hosting and database), Resend (delivers the alert emails), Stripe (payments), and — only when you choose to sign in with them — Google or Microsoft (identity). US providers operate under the EU–US Data Privacy Framework. When you run a check on an unregistered domain, its name (never yours) is sent to the registry's RDAP service and to Porkbun's public price API.

Legal bases

Running the account, the watches and the alerts is performance of our contract with you (GDPR art. 6(1)(b)). Abuse limits — the sign-in IP, rate limiting — are our legitimate interest in keeping the service available (art. 6(1)(f)). Billing records are retained by Stripe under their legal obligations.

Your rights

You can access, correct, export or erase your data, object to processing, and complain to your supervisory authority. Erasure needs no request: the account page has a delete button that removes the account and everything on it, immediately. For anything else, write to alerts@renewatch.com and it is handled by a person.