Privacy Policy - DomainDrift
DomainDrift is a DNS reconnaissance and signal scanning platform operated by DRM3 Labs Corp.
This policy supplements the general DRM3 Privacy Policy, which applies to DomainDrift in full. Where this policy is silent, the general policy governs.
Who We Are, and Why We Can Hold This
Who. DomainDrift is operated by DRM3 Labs Corp., a Delaware corporation (Delaware Division of Corporations file number 7080410). DRM3 Labs Corp. is the controller of the personal information described in this notice. Its registered office in Delaware is care of its registered agent, ZenBusiness Inc., 611 South DuPont Highway, Suite 102, Dover, DE 19901, United States. For anything about this notice, and to exercise any of the rights set out below, write to legal@drm3.io - that is the address we monitor.
Why we are allowed to hold it. Two grounds carry nearly all of it:
- Because you asked for the service. Your DRM3 account identity, your DomainDrift session, an API key you mint, the plan resolved against your account, and the alerts, groups and baselines you set up are held because they are necessary to provide the service you signed up for. Without them there is no signed-in DomainDrift.
- Because we have a legitimate interest in keeping the service running and free of abuse. Rate-limit counters, operational and abuse-prevention logs, and the domain catalog itself - including registrant details that a registry, a WHOIS/RDAP service or a public certificate has already published - are held on this basis. That interest is weighed against yours, and it is why these records are kept narrow rather than complete: we do not record your IP address or your full user agent in usage measurement, and we do not store API request content as a product dataset.
Consent is the basis for two things. The first is our own usage measurement, in the UK, EEA and Switzerland, where nothing is stored and no event is sent until you accept. The second is Google Analytics, everywhere in the world: it is a third party that sets its own cookies, so it does not load at all until you accept, and if you never answer the notice it never runs.
Data Practices
DomainDrift resolves publicly available DNS records via DNS-over-HTTPS (Cloudflare). All data DomainDrift collects about domains - DNS records, WHOIS/RDAP responses, TLS certificates, certificate transparency logs, robots.txt, HTTP probe results - is already public. DomainDrift does not create new data about domain owners; it indexes what is already observable by anyone.
Accounts and Cookies
Since June 27, 2026, DomainDrift's web UI is gated by DRM3 single sign-on. Signing in works through your DRM3 account at drm3.network; after sign-in, DomainDrift sets its own session cookie on the domaindrift.io host to keep you signed in. The DRM3 account hub separately sets its own cookie on drm3.network domains; that is covered by the general DRM3 Privacy Policy.
- Cookies are used for authentication sessions, for our own usage measurement, and - only if you accept - for Google Analytics. DomainDrift sets no advertising cookies and does not sell any of this data.
- First-party measurement: DomainDrift sets one measurement cookie (`dd_uid`), an opaque random identifier not derived from your identity, to count visits and feature usage. In the UK, EEA, and Switzerland nothing is stored and no event is sent until you accept; elsewhere a notice is shown with a working opt-out. Events record the page path only (never query strings or form contents), the referring site's hostname only (never its path or query), the three `utm_*` campaign parameters if present, a device class of mobile/tablet/desktop, and your country. Measurement also groups the events of a single VISIT under a short-lived identifier held in your browser tab (`dd_sid`, discarded when the tab closes), records how many seconds you were active on a page, and for about one click in four records WHERE on the page the click landed as a percentage, so we can build an aggregate heat map of which parts of a page get used. We do not record keystrokes, do not capture or replay your screen, and use no session-recording product. If you are signed in, events also carry your account id so we can tell signed-in from anonymous usage. In these first-party events we never record your IP address or your full user agent. Raw measurement events are deleted after 90 days; only daily aggregate counts are kept. That 90 days covers our own measurement events and nothing else - account records, API-key metadata, billing and tax records, and Google Analytics data each have their own clock, set out under How Long We Keep Things below. This data stays inside DomainDrift and is never sold or shared with third parties. The complete field-by-field list is in the Cookie notice.
- Google Analytics: only if you accept, and nowhere before that. Until you press Accept or OK there is no Google script on the page and your browser makes no request to Google Analytics. If you accept, Google receives your IP address, your full user agent, the page path you are on, the site you came from, an approximate location derived from the IP, and sets its own cookies (`_ga` and `_ga_23NQSX0E4Y`). We configure it to report the page path only and never the query string, and we switch off Google signals and ad personalization signals, which are the settings that would join your visit to Google's advertising graph. Google acts as our processor for this. You can withdraw consent at any time through the "Privacy choices" link in the footer of any page; that switches the tag off and deletes its cookies.
- A pseudonymous account identifier, for signed-in users only. If you are signed in to your DRM3 account AND you have accepted the measurement notice, we additionally send Google an opaque identifier for your account. It is not your email address, your name, or your username, and it cannot be turned back into any of them. Its purpose is that DomainDrift is one of several DRM3 apps and Google Analytics otherwise counts the same person separately on each one, because its cookie is tied to a single website; the identifier lets us understand how the apps are used together rather than how each is used in isolation. It is not used for advertising, and the advertising features are switched off. If you are signed out, or you have not accepted, no identifier is sent. Signing out stops it, and so does withdrawing consent.
- A signed-in session is associated with your DRM3 account identity (account id and display name).
- Signed-in users can mint a personal API key; that key is stored associated with the account that created it, along with a last-used timestamp.
Third-Party Services on Our Pages
Three third parties receive data when you load a DomainDrift page. None is an advertising network, and we sell nothing to any of them. Only one of them sets cookies, and that one does not load until you accept.
| Service | What it is | Sets cookies | What it receives | When |
|---|---|---|---|---|
| Google Analytics 4 | Google's web analytics product. Google Ireland Limited / Google LLC, acting as our processor under Google's data processing terms | Yes (`_ga`, `_ga_23NQSX0E4Y`) | Your IP address, user agent, the page path, the referring site, and an approximate location derived from the IP. For signed-in users, also a pseudonymous account identifier, which is not an email, a name, or a username. We configure it to receive the path only and never the query string, and we switch off Google signals and ad personalization signals | Only after you press Accept or OK. Before that the script is not on the page and nothing is sent |
| Cloudflare Web Analytics | Cookieless page-view and performance measurement | No. It stores nothing on your device and reads nothing back | Your IP address, user agent, referrer, and the page URL. Cloudflare states it does not use this to fingerprint or track individuals across sites | On every public page. Because it stores nothing on your device, there is nothing for you to consent to |
| Google Fonts | Webfont hosting (`fonts.googleapis.com`, `fonts.gstatic.com`) | No | Your IP address and user agent, when your browser requests the font files | On page load. This is what makes the page readable, not measurement |
Neither Google Analytics nor Cloudflare Web Analytics runs on an operator console or on any page behind the sign-in gate.
Cloudflare is also our hosting and network provider, so it necessarily processes all traffic to this site as a service provider.
Google Analytics data may be processed in the United States. Google covers that transfer by Standard Contractual Clauses and by its certification under the EU-US Data Privacy Framework.
Your Choice About Measurement
Google Analytics does not load until you press Accept or OK, wherever in the world you are. Not "loads and waits": the script is not in the page and your browser makes no request to Google until you have agreed.
In the UK, EEA, and Switzerland, DomainDrift stores nothing non-essential and sends no usage event until you press Accept on the notice. Decline means nothing is stored and nothing is sent, and we remember only that you declined. Everywhere else, our own measurement runs with the notice shown and Opt out turns it off, deletes the identifier, and blocks Google Analytics.
To change your mind, use the "Privacy choices" link in the footer of any page. It reopens the same notice with the same two buttons. Withdrawing consent switches Google Analytics off through Google's own opt-out mechanism and deletes its cookies from your browser; a script that has already loaded cannot be unloaded, so it stops collecting rather than disappearing. Clearing site data for `domaindrift.io` also resets the choice.
The full field-by-field list of what a usage event contains is in the Cookie notice.
Your consent choice is stored in your browser's `localStorage`, not in a cookie, so declining leaves nothing in your cookie jar.
API Access
Programmatic API access requires an API key for rate limiting and access control. Service keys are associated with service identity; personal keys minted by signed-in users are associated with that user's DRM3 account. Request rate limiting uses client IP addresses held in short-lived in-memory counters. API request content is not stored as a product dataset; standard operational logs may exist for debugging and abuse prevention.
Scanned Domains and Opt-Out
DomainDrift maintains a catalog of domains it scans. DNS is a public protocol, but DomainDrift operates an opt-out registry: a domain owner can request removal, which deactivates the domain in the catalog and blocks it from being re-added while the opt-out stands. Request via the DRM3 publisher opt-out process (drm3.io/publisher-opt-out, DomainDrift section) or support@drm3.io. If you believe DomainDrift is displaying inaccurate information about your domain, contact us.
How Long We Keep Things
Different data has different clocks. There is no single number that covers all of it.
- Our own raw usage measurement events: 90 days. After that only daily aggregate counts remain. This is the 90-day figure above, and it covers our own measurement events only.
- Google Analytics: 14 months, the longest a standard Google Analytics property allows, and it is held by Google rather than by us. Google's aggregate reporting continues past it. Deletion is requested through Google; tell us and we will make that request on your behalf.
- Account records and API-key metadata: for as long as the account is open, and for 24 months after it is closed. That means the DRM3 account identity attached to your DomainDrift session, the API keys minted under it and their last-used timestamps, the plan resolved against the account, and the alerts, groups and baselines you created.
- Billing and tax records: 7 years. We are required to keep these, so they survive the closure of an account.
- The domain catalog is not account data. DNS records, WHOIS/RDAP responses, certificates and probe results about a domain are an observed record of a public namespace, and are not deleted when an account closes. To have a DOMAIN removed there is a separate route, set out under Scanned Domains and Opt-Out above.
To close your DomainDrift access, or to ask us to delete what we hold about you, write to legal@drm3.io.
Your Privacy Rights
DRM3 Labs Corp. honors data-protection and privacy rights under the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA).
- To access, correct, delete, port, or object to the processing of information about you, contact legal@drm3.io. This is the data-protection contact for every DRM3 product, DomainDrift included.
- We do not sell personal information, and we receive nothing of value for any of the disclosures described above. We also do not share it for cross-context behavioral advertising as the CPRA uses that term: Google Analytics runs with Google signals and ad personalization signals switched off, which are the settings that would make it an advertising disclosure, and we run no advertising. If you would rather Google had none of it, decline the notice or withdraw through the "Privacy choices" link, which is the control the CPRA opt-out right asks for and it is on every page.
- To have a DOMAIN removed from the scanning catalog, use the opt-out route set out under Scanned Domains and Opt-Out above. That is a different process from a request about your own personal information.
These rights, and the general handling of personal information across DRM3 products, are set out in the general DRM3 Privacy Policy, which this notice supplements.
General Privacy Policy · Terms of Use · support@drm3.io