Privacy Policy

Applicable to all services offered by Namekart  |  Last revised: May 15, 2026

On this page

  1. Introduction
  2. About Us
  3. Scope and Applicability
  4. Information We Collect
  5. Legal Basis for Processing
  6. How We Use Your Information
  7. Disclosure and Sharing of Your Information
  8. WHOIS, RDAP, and Domain Registration Data
  9. International Data Transfers
  10. Data Retention
  11. Cookie Policy
  12. Your Data Subject Rights
  13. Data Security
  14. India Specific Disclosures
  15. Children’s Privacy
  16. Third Party Websites and Services

1.Introduction

Namekart Private Limited (“Namekart”, “we”, “us”, or “our”) operates the websites www.namekart.com, along with associated domain registration, brokerage, marketplace, and AI-powered brand intelligence services (collectively, the “Services”).

This Privacy Policy explains how we collect, use, disclose, store, transfer, and protect personal information that you provide to us or that we collect about you when you use our Services, visit our websites, register a domain name, or otherwise interact with us. It also describes your rights under applicable privacy laws, including the Digital Personal Data Protection Act, 2023 (“DPDPA”), General Data Protection Regulation (“GDPR”), and other relevant data protection frameworks.

2.About Us

Entity Name: Namekart Private Limited

Registered Office: Sector 13, Pocket B, Dwarka, New Delhi – 110075, India

Corporate Identification Number (“CIN”): U67190DL2012PTC245663

Website: www.namekart.com

Privacy Contact: [email protected]

Where required under applicable law, Namekart acts as the “Data Controller”, “Business”, or “Data Fiduciary” in relation to your personal data.

3.Scope and Applicability

This Privacy Policy applies to all individuals worldwide who interact with our Services, including but not limited to:

  • Visitors to www.namekart.com;
  • Registered account holders and customers;
  • Domain registrants;
  • Domain buyers and sellers using our marketplace or brokerage services;
  • Businesses using our API or white-label services;
  • Newsletter subscribers, event attendees, and prospective customers.

Where our Services are used on behalf of another individual (e.g., an agent or reseller registering a domain for a client), it is that user’s responsibility to ensure the underlying registrant has been informed of this Privacy Policy.

4.Information We Collect

4.1 Information You Provide Directly

When you register an account, purchase or transfer a domain, or use our Services, you may provide:

Account and Identity Information

  • Full name, username, and profile photograph;
  • Email address, mailing address, telephone number;
  • Password (stored in hashed or encrypted form, never in plaintext);
  • Login credentials and authentication data;
  • Business name, type, and registration details (for professional accounts).

Financial and Payment Information

All payment transactions are processed by PCI-DSS-compliant third-party payment processors. We do not store full credit/debit card numbers, CVV codes, or bank account details. We retain:

  • Transaction identifiers, amounts, dates, and currency;
  • Last four digits of the payment card and card brand;
  • Billing name and address;
  • Payment status, invoices, and receipts.

Communications and Support Data

  • Content of emails, live-chat, or support tickets you send us;
  • Dispute resolution submissions (e.g., UDRP-related correspondence);
  • Feedback, survey responses, and testimonials.

4.2 Information We Collect Automatically

Usage and Log Data

  • IP address, browser type and version, operating system;
  • Pages visited, search queries on our platforms, time and date of visits;
  • Referring URL and exit pages;
  • Server access logs retained for security and fraud investigation.

Device Information

  • Device identifiers (device ID, advertising ID where permitted);
  • Mobile device type, model, and carrier (for mobile app users);
  • Screen resolution and language preference.

Cookies and Tracking Technologies

We use cookies, pixel tags, local storage, and similar technologies to:

  • Operate and secure our Services;
  • Remember user preferences;
  • Analyse usage and performance;
  • Improve functionality;
  • Deliver marketing communications where permitted.

Depending on your jurisdiction, we may request consent before placing non-essential cookies. You may manage cookie preferences through your browser settings or our cookie management tools.

4.3 Information from Third Parties

  • Identity verification data from KYC/AML service providers (for high-value domain transactions);
  • Publicly available WHOIS and RDAP data;
  • Data from domain registries (e.g., registry-push updates, zone files);
  • Fraud and risk intelligence from our payment processors.

5.Legal Basis for Processing

The table below sets out each processing purpose and its corresponding legal basis under GDPR.

Processing PurposeLegal Basis (GDPR)Notes
Account creation and managementArt. 6(1)(b), ContractNecessary to perform our contract with you
Domain registration and managementArt. 6(1)(b), Contract; Art. 6(1)(c), Legal obligationRegistry agreements and ICANN policies impose mandatory data collection
Payment processingArt. 6(1)(b), ContractNecessary for billing
Fraud prevention and platform securityArt. 6(1)(f), Legitimate interestsOur legitimate interest in protecting the platform and users from fraud
Compliance with legal obligations (tax, AML, court orders)Art. 6(1)(c), Legal obligationIndian law, FEMA, IT Act obligations
WHOIS / RDAP publicationArt. 6(1)(c), Legal obligation; Art. 6(1)(f), Legitimate interestsRegistry agreements, ICANN policies; limited to non-sensitive contact data
Marketing and promotional communicationsArt. 6(1)(a), Consent (EU/UK); Opt-out basis elsewhereConsent withdrawn at any time via unsubscribe
Analytics and service improvementArt. 6(1)(f), Legitimate interestsBalanced against user rights; pseudonymised where possible
Domain dispute resolution (UDRP etc.)Art. 6(1)(c), Legal obligation; Art. 6(1)(f), Legitimate interestsDisclosure required by ICANN dispute resolution policies

6.How We Use Your Information

6.1 Service Delivery

  • Registering, renewing, transferring, and managing domain names on your behalf;
  • Processing payments and issuing invoices;
  • Providing customer support and responding to enquiries;
  • Sending transactional notifications (registration confirmations, renewal reminders, expiry notices).

6.2 Security and Fraud Prevention

  • Detecting, investigating, and preventing fraudulent registrations, cybersquatting, or abusive use;
  • Monitoring for malware, phishing, or illegal content associated with registered domains;
  • Verifying registrant identity in high-risk transaction scenarios;
  • Enforcing our Terms of Service.

6.3 Marketing and Communications

With your consent (or on an opt-out basis where permitted by applicable law), we may send you:

  • Newsletters and product updates;
  • Domain availability alerts and price-drop notifications for watchlisted domains;
  • Information about new TLD launches, including .AI auctions;
  • Partner offers and industry research reports.

You may withdraw consent or opt out at any time via the unsubscribe link in any email, or via Settings in your account.

6.4 Legal and Compliance

  • Meeting our obligations under Indian law (IT Act 2000, DPDPA 2023, Companies Act, 2013 and FEMA);
  • Responding to court orders, subpoenas, regulatory investigations, or law enforcement requests;
  • Establishing, exercising, or defending legal claims;
  • Complying with equivalent laws in other jurisdictions.

7.Disclosure and Sharing of Your Information

We do not sell your personal information. We share personal data only as described below:

7.1 Service Providers and Sub-Processors

We engage trusted third-party service providers who process data on our behalf (acting as Data Processors under GDPR). These include:

  • Cloud infrastructure providers;
  • Payment processors;
  • Email and communication platforms;
  • Analytics and monitoring tools;
  • Identity verification (KYC/AML) services for high-value transactions;
  • Customer support software.

All sub-processors are bound by Data Processing Agreements (“DPAs”) and are required to maintain appropriate technical and organisational measures.

7.2 Domain Marketplace Transactions

If you buy or sell a domain through our marketplace or brokerage service, we share relevant information with the counterparty to the transaction (e.g., buyer name for escrow; seller confirmation). We use escrow mechanisms and minimise disclosure to what is strictly necessary to complete the transaction.

7.3 Legal Authorities and Dispute Resolution

  • In response to lawful legal process (court orders, government requests, regulatory demands) in applicable jurisdictions;
  • To UDRP/URS panelists or arbitration providers in domain dispute proceedings;
  • To law enforcement where we reasonably believe disclosure is necessary to prevent crime, protect rights, or comply with legal obligations;
  • To protect the rights, property, or safety of Namekart, our users, or the public.

Where legally permitted, we will notify you of any request for your personal data before disclosing it, unless prohibited by law or where notification would defeat the purpose of the request.

7.4 With Your Consent

We may share your personal data with third parties for specific purposes only where you have provided your explicit, informed, and specific consent for such disclosure or use.

8.WHOIS, RDAP, and Domain Registration Data

Depending on the TLD’s registry policies, the following information may appear in publicly accessible WHOIS/RDAP records:

  • Domain name and registration/expiration dates;
  • Registrar name, registrar URL, and IANA registrar ID;
  • Name servers;
  • Registrant name and organisation (or redacted);
  • Registrant country;
  • Administrative and Technical contact details (may be proxied).

9.International Data Transfers

Namekart is headquartered in India and operates globally. In connection with providing the Services, your personal data may be transferred to, stored in, or processed in jurisdictions outside your country of residence, including jurisdictions where our service providers, infrastructure providers, registries, or business partners are located. Where required under applicable law, we implement appropriate safeguards for such transfers in accordance with applicable data protection laws.

10.Data Retention

We retain personal data for as long as necessary to fulfil the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements. The following retention periods apply:

Data CategoryRetention PeriodRationale
Active account dataDuration of account + 3 years, subject to earlier deletion where legally permissibleContract performance; dispute resolution
Domain registrant data (active)Duration of registration + 2 years after expiryICANN Registrar Accreditation Agreement – minimum retention obligation
Domain registrant data (expired/cancelled)2 years post-expiry / cancellationICANN obligation; legal claims
Transaction and billing records7 yearsIndian Companies Act, income tax law
WHOIS data escrow copiesPer ICANN data escrow policyRegistry-registrar agreement and escrow obligations
Support tickets and communications3 years after closureDispute resolution; quality assurance
Server and security logs12 monthsSecurity investigation; fraud detection
Marketing consent recordsUntil withdrawal + 3 yearsProof of consent under GDPR Art. 7(1)
KYC/AML verification data5 years post-transaction or account closurePMLA rules / AML obligations

Following expiry of the applicable retention period, we will securely delete or anonymise your personal data. Where deletion or anonymisation is not technically feasible (for example, due to backup system limitations), we will securely isolate the data and restrict any further processing to what is strictly necessary for legal, regulatory, or security purposes.

11.Cookie Policy

We use cookies and similar tracking technologies on www.namekart.com.

11.1 Types of Cookies We Use

  • Strictly Necessary Cookies: Essential for the website to function (e.g., session authentication, load balancing, shopping cart). These cannot be disabled.
  • Functional Cookies: Remember your preferences (language, currency, notification settings). Disabled without loss of core functionality.
  • Analytics Cookies: Measure website usage and performance (e.g., Google Analytics configured with IP anonymisation and no cross-site tracking). Requires consent in EU/UK.
  • Marketing and Targeting Cookies: Used to deliver relevant advertisements and measure campaign performance. Require explicit opt-in consent in the EU/UK/EEA.

11.2 Managing Cookies

You may manage cookie preferences at any time via:

  • Our Cookie Consent Banner (shown on first visit);
  • The Cookie Preferences Centre accessible at the bottom of every page;
  • Your browser settings: most browsers allow you to refuse or delete cookies.

Withdrawing consent for cookies does not affect the lawfulness of prior processing.

12.Your Data Subject Rights

Depending on your jurisdiction, you may have the following rights with respect to your personal data. We are committed to honouring these rights promptly and without undue burden.

  • Access personal data;
  • Correct inaccurate data;
  • Delete or erase personal data;
  • Restrict or object to processing;
  • Withdraw consent;
  • Request portability of data;
  • Opt out of certain disclosures or marketing;
  • Lodge complaints with a regulatory authority.

Certain rights may be subject to legal or contractual limitations, including obligations applicable to domain registrars and registry operators.

12.1 Exercising Your Rights

To exercise any of the above rights, please submit a request to:

Email: [email protected]

Subject line: “Data Subject Request | [Your Name] | [Type of Request]”

We may need to verify your identity before processing your request to prevent unauthorised disclosure.

13.Data Security

We implement comprehensive technical and organisational security measures to protect your personal data against unauthorised access, accidental loss, alteration, disclosure, or destruction. Our security programme includes, but is not limited to:

  • Encryption of data in transit using TLS 1.2 / 1.3 (HTTPS enforced across all domains);
  • Encryption of sensitive data at rest (AES-256 or equivalent);
  • Password hashing using industry-standard algorithms (bcrypt/scrypt);
  • Multi-factor authentication (“MFA”) for account access;
  • Role-based access controls and least-privilege access for employees;
  • Regular penetration testing and vulnerability assessments;
  • Security Information and Event Management (“SIEM”) monitoring;
  • Domain-specific security: DNSSEC support, registrar lock (EPP status codes), and Domain Guard features to prevent unauthorised transfers.

No method of electronic transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee absolute security. In the event of a personal data breach, we will notify affected data subjects and relevant supervisory authorities in accordance with applicable laws and take mitigatory measures.

14.India Specific Disclosures

For purposes of the DPDPA, Namekart acts as a Data Fiduciary in relation to personal data processed under this Privacy Policy. India-based users may contact our Grievance Officer.

Email: [email protected]

We will address grievances and requests in accordance with applicable law.

15.Children’s Privacy

Our Services are not directed to children and are not intended for use by individuals below the age permitted under applicable law. We do not knowingly collect personal data from children. If we become aware that personal data of a child has been collected in violation of applicable law, we will take reasonable steps to delete such data.

16.Third Party Websites and Services

Our Services may contain links to third-party websites, registries, payment providers, or external services. We are not responsible for the privacy practices or content of third-party services. We encourage users to review the privacy policies of such third parties before interacting with them.

© Namekart Private Limited. This Privacy Policy was last revised on May 15, 2026.