Privacy Policy
In short. This site has no accounts and nothing to log in to. It collects personal data in exactly one place — the forms you fill in to make an offer, buy a domain, or refer a buyer — and it loads analytics and advertising scripts from Google that set their own cookies. Everything else on the page works without knowing who you are.
1. Who is responsible
Nikolay Kolev operates this website and is the controller of the personal data described here. Questions, requests, and complaints go to privacy@namegarage.com, and are answered by a person.
2. What you give us, and why
Every field below is one you typed yourself. Nothing on this list is inferred, bought, or collected in the background.
Making an offer
The offer form collects your first name, your email address, the domain and amount you are offering, and — if you choose to fill them in — your last name, phone number, a message, and a proposed payment plan. We need this to read your offer, reply to it, and negotiate. Choosing to send the offer through Telegram instead hands the same details to Telegram's own service.
Buying directly by wire or Gram
The direct-purchase form collects your first name, email address, and — because the domain has to be pushed somewhere — your GoDaddy account email and GoDaddy customer number. Your last name is optional. These go onto the purchase agreement you sign, and the GoDaddy details are used to transfer the name to you. We do not ask for, receive, or store card numbers, bank credentials, or government identification.
Buying through Escrow.com, or paying monthly
These routes collect your email address here and then hand you to Escrow.com, which runs its own identity and payment process under its own privacy policy. Payment details are entered on Escrow.com, not on this site, and we never see them.
Referring a buyer
The referral form collects your name and email address, the domain(s) you are referring, and — about the person you are recommending — their email address and whatever else you choose to add: their name, company, and a short message about how you know them. We use this to attribute a referral commission if that person completes a purchase of one of the domains you named, within the program's window, and so we can reach out to them about those domains — that follow-up is the point of a referral introduction. Registering a lead does not add them to any marketing list, and submitting the form does not itself send them anything; the message it sends is to us, so we can decide whether and how to follow up. We never use a lead's details for anything unrelated to the domain(s) you named. By submitting the form you confirm that they are happy for us to contact them about those domains. See Refer a buyer for the full program terms.
Legal basis
For everything in this section, the legal basis under the GDPR is the performance of, or steps taken at your request before entering into, a contract — for the sale of a domain name, or, for a referral, the referral commission arrangement described at Refer a buyer (Article 6(1)(b)). For the analytics and advertising described in Section 4, the basis is your consent (Article 6(1)(a)), which you may withdraw at any time.
3. Who else sees it
The processors below receive only what their job requires:
- Escrow.com — the escrow facilitator for every non-direct sale. Receives your email address and, once you are on their site, whatever their own process asks of you.
- DocuSeal — prepares and countersigns the purchase agreement for direct wire and Gram sales. Receives the name, email, and GoDaddy details that appear on that agreement.
- Cloudflare — serves every page and runs the security checks in front of them. Processes your IP address and request metadata as part of delivering the site.
- Google — analytics and advertising, described in the next section.
- Telegram — only if you choose the "Send in Telegram" button, which is a deliberate act on your part.
We do not sell personal data, and we do not share it for cross-context behavioural advertising beyond the advertising cookies described below. No personal data is transferred to anyone not on this list.
4. Cookies and similar technologies
The site itself sets no cookies. It stores three things in your browser. The first two stay there and are never sent to us:
- Your colour theme choice, in local storage, so the site does not flip between light and dark as you navigate.
- Your answer to the question below — the word "granted" or "denied" — in local storage, so you are not asked again on every page. Change it from "Cookie settings" in the footer, or clear this site's data in your browser to be asked afresh. There is no server-side record of it.
The third is not yours and is not about you:
- An operator test token, in session storage, which exists only while a member of staff is rehearsing a purchase. Unlike the two above it is sent to us — it accompanies the requests that rehearsal makes, so the transaction, the seller notice and the agreement it produces are recorded as a test rather than acted on as a real sale. It is never set during an ordinary visit, and it identifies the rehearsal, not a visitor.
Three third parties set storage of their own:
- Google Analytics 4 measures which pages are read and which domains draw interest. It sets its own cookies and processes a truncated IP address.
- Google AdSense serves the advertising on some pages and may set cookies or read identifiers to select and measure ads.
- Cloudflare Turnstile checks that an offer, direct purchase, or referral is coming from a person. It reads browser signals and sets a short-lived clearance token. This one is strictly necessary — without it those forms are open to abuse — so it runs regardless of your analytics choice.
Analytics and advertising load only after you agree to them. Until you do, and if you decline, neither script runs and neither sets anything. You can change your mind at any time from the "Cookie settings" link in the footer of every page. If your browser sends a Global Privacy Control signal, we treat that as a refusal and never ask.
5. How long we keep it
Offers and the correspondence around them are kept while the domain is still for sale and for 24 months after the last message between us, so that a returning buyer's history is intact and so a disputed negotiation can be reconstructed. Records of a completed sale — the agreement, the parties, the amount — are kept for seven years, because tax and contract law require it. A referral lead is kept as part of our commercial records — the row is the ledger for whether, and how much, commission is owed on it, so it is not deleted once its window lapses; a sale that syncs late can still be matched against it. We use a lead's contact details to attribute the referral and to reach out to them about the domain(s) named, never for anything unrelated. The access, correction, and erasure rights in Section 6 apply to a lead's details the same as to anything else in this policy, whether you are the referrer or the person referred. Analytics data is retained by Google under the retention window configured in that product. Nothing is kept "just in case".
6. Your rights
Wherever you live, you may ask us to show you the personal data we hold about you, correct it, delete it, or send it to you in a portable form. You may object to processing based on legitimate interests, and you may withdraw consent to analytics and advertising without giving a reason and without affecting anything you have already done on the site.
Write to privacy@namegarage.com. We answer within 30 days. There is no charge, and no account to close first.
If you are in the EU or the UK you also have the right to complain to your national data protection authority. If you are in California, Colorado, or another US state with a comparable law, the same rights apply to you under that law, including the right not to be discriminated against for exercising them.
7. International transfers
The processors named in Section 3 are established in the United States and process data there. Transfers rely on the European Commission's Standard Contractual Clauses or, where the processor is certified, the EU–US Data Privacy Framework.
8. Children
This is a marketplace for domain names sold to businesses and adults. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has sent us something, write to the address above and it will be deleted.
9. Security
Every page and every form is served over HTTPS with HSTS. Offer, purchase, and referral submissions are protected by anti-automation challenges. Access to stored offers and referral leads is limited to the seller. We do not hold payment credentials, so there is no card data here to lose.
10. Changes to this policy
Each version of this policy is published at a permanent dated address alongside the SHA-256 hash of its source, and every prior version stays reachable from the list at the foot of this page. A change is made by publishing a new version, never by editing a published one — so what this policy said on the day you used the site remains verifiable.
Content fingerprint (SHA-256 of this version's source):
60539ce01f5c83041257e497de2c34e4a168e3d5f6d649787d819c37279f6248
Version history
Every version of the Privacy Policy is retained at a permanent dated address, alongside the hash of its source, so the wording in effect at any time can be verified.
- v3.0 — effective 2026-09-05 · Current version · 3530db9322b8…
- v2.0 — effective 2026-08-26 · Superseded 2026-09-05 by v3.0 · 60539ce01f5c…
- v1.0 — effective 2026-08-22 · Superseded 2026-08-26 by v2.0 · a04a4c7bdcbf…