Privacy policy
DotMoose collects personal information for reasonable purposes connected to providing, securing, supporting, and billing for our services.
Information we collect
This can include your name, contact information, account details, billing and transaction information, domain registration information, support messages, service configuration, IP addresses, authentication and security logs, and technical information generated while you use our services. If you apply to a DotMoose reseller/agency or Canadian charity program, it can also include business or organization name, role, intended use, expected service count, charity registration number, community-program eligibility evidence, authority-verification information, approval/decision history, program entitlements, and annual review dates.
How we use information
We use personal information to create and manage accounts, process orders and renewals, register and manage domains, provision and support services, review and administer reseller/agency, charity, fire-department, or volunteer-program eligibility, verify applicant authority and charity status, prevent duplicate or fraudulent benefit claims, prevent fraud and abuse, maintain security, communicate about your account, understand site and checkout performance when optional analytics is enabled, and meet legal or regulatory requirements.
Service providers and disclosures
We disclose information when it is reasonably needed to deliver a service, process a payment, register a domain, operate infrastructure, investigate abuse or security incidents, or comply with law. Recipients can include payment processors, registrars and registries, infrastructure and network providers, analytics providers, security and support providers, and government or legal authorities where required.
For DotMoose Object Storage, customer object data is stored in Canada. DotMoose service-control systems authenticate DotMoose-issued virtual credentials and operate the storage service. Customer virtual secrets and backend credentials are kept in restricted service-control systems and are not intentionally exposed as analytics data.
For Managed Application Hosting, application and PostgreSQL workload data is hosted in Canada. DotMoose operational systems process service configuration, deployment image references, backup metadata, health state and support instructions needed to operate the environment. Application/database secrets are kept in restricted service-control locations and are not intentionally included in analytics.
Third-party processing
Some account, payment, domain-registration, support, analytics, or operational information can be processed by third-party service providers under their own service locations and contractual terms. DotMoose limits those disclosures to what is reasonably needed for the applicable service or legal requirement.
Retention
We retain personal information only as long as reasonably needed for the purpose it was collected, to provide an active service, resolve disputes, prevent abuse, maintain business records, or satisfy legal and accounting requirements.
Backup Storage service data is normally retained for 30 days after service termination before permanent deletion. During that recovery window, DotMoose may send escalating deletion reminders. A customer can contact support before purge to request a recovery hold and a temporary SFTP export window; operational, support, dispute, security, recovery, or legal holds may also extend retention. Once the retained service data is permanently purged, it cannot be recovered. Account, billing, tax, security, abuse-prevention, and other business records can have different retention periods because they serve different purposes.
Object Storage service data is also normally retained for 30 days after service termination before the managed bucket is permanently purged. This service-level retention does not restore individual objects that were deleted while the service was active when bucket versioning was not enabled. Object Storage account, billing, security and operational records can be retained separately where reasonably required.
Security
We use administrative and technical safeguards appropriate to the sensitivity of the information, including access controls, encrypted connections, system hardening, logging, and separation of customer workloads where appropriate.
Cookies and optional analytics
Our website and client systems may use cookies and similar storage for sign-in, security, checkout, session continuity, and preferences. Optional Google Analytics and Microsoft Clarity collection is not loaded unless you choose Allow analytics. We use consented analytics to understand navigation, product interest, checkout progress, conversion outcomes, and site errors without intentionally sending customer names, email addresses, purchased or searched domain names, support contents, or WHMCS customer IDs as analytics event parameters.
Your analytics preference is shared across DotMoose subdomains so the storefront-to-checkout journey can remain attributable. You can clear DotMoose site storage to reset the choice. Advertising storage and advertising personalization remain disabled. DotMoose does not sell personal information.
Necessary only still permits first-party operational telemetry needed to measure site reliability and aggregate funnel health. This telemetry does not use an analytics cookie or stable visitor/session identifier and does not send events to Google or Microsoft. The dedicated telemetry record is limited to allowlisted event type, DotMoose page path/category, DotMoose destination path, referring hostname, timestamp, and site hostname; it deliberately excludes the visitor IP address, user agent, cookies, form contents, customer identity, searched/purchased domain names, and support content. For the domain-search funnel, Necessary-only telemetry records only aggregate search/result/cart event types and a coarse action/result class such as registration, transfer, available, unavailable, premium, or error. It does not record the searched name, TLD, price, authorization code, or search text. Separate web/security logs may record connection information such as IP addresses for security, abuse prevention, and service operations.
Access and correction
You may request access to personal information we hold about you or ask us to correct information that is inaccurate or incomplete. We may need to verify your identity and may be required or permitted to withhold some information under applicable law.
Privacy questions and complaints
Send written privacy requests or complaints to the DotMoose Privacy Officer at hello@dotmoose.com. Include enough information for us to understand the request without sending passwords or unnecessary sensitive information.
Changes
We may update this policy when our services, providers, or legal obligations change. The date at the top shows the current version.