1. Who we are
Raffled UK Limited ("we", "us", "our") operates the Dot.st network: Dot.st, DropCatch.st, and Premium.st (together, the "Services"). We act as data controller for personal data processed through these Services.
Registered office: [insert registered address]
Company number: [insert Companies House number]
Privacy contact: privacy@dot.st (subject line: Privacy Request)
2. Scope
This Privacy Policy explains how we collect, use, store, share, and protect personal data when you:
- create or use a network account;
- register, renew, or transfer .st domains;
- place backorders or use DropCatch tools;
- list, buy, bid, or negotiate on Premium.st;
- top up your wallet, pay invoices, or request payouts;
- contact support or submit abuse reports;
- browse our sites (including cookies and similar technologies).
It should be read with our Terms of Service and cookie disclosures on each site.
3. Personal data we collect
| Category | Examples | Typical source |
|---|---|---|
| Identity & account | Name, email, password hash, account IDs | You |
| Contact & billing | Billing address, VAT number, invoice details | You |
| Registry contacts | Registrant/admin/tech/billing contacts for domains | You |
| Transaction | Orders, bids, backorders, wallet ledger, invoice numbers | You / our systems |
| Payment | Payment method brand/last4/expiry, Stripe customer IDs, payout bank details | You / Stripe |
| Communications | Support tickets, emails, negotiation messages | You |
| Abuse & security | Abuse report content, verification tokens, IP logs | You / automated |
| Technical | IP address, user agent, session IDs, timestamps, error logs | Automated |
| Marketing | Preferences if you opt in | You |
We do not store full card numbers or CVV. Card data is handled by Stripe (and any future PCI-compliant processor we disclose).
4. How we use personal data
We use personal data to:
- provide and operate the Services you request;
- register and manage domains with the .st registry;
- process payments, wallet top-ups, refunds, and seller payouts;
- verify identity, prevent fraud, and enforce our policies;
- communicate about orders, auctions, backorders, renewals, and security;
- respond to support and abuse reports;
- comply with legal, tax, and registry obligations;
- improve, secure, and debug our platform (aggregated/anonymised where feasible).
5. Legal bases (UK GDPR / GDPR)
Where UK GDPR or EU GDPR applies, we rely on:
- Contract — processing necessary to provide Services you request;
- Legal obligation — tax, accounting, registry, and law-enforcement requirements;
- Legitimate interests — security, fraud prevention, service improvement, and network integrity, balanced against your rights;
- Consent — where required (e.g. non-essential cookies or optional marketing).
You may withdraw consent where processing is consent-based without affecting prior lawful processing.
6. Automated decision-making and fraud prevention
We use automated checks (including Google reCAPTCHA v3 with v2 fallback) on registration, login, password reset, checkout, and other sensitive forms to distinguish humans from abuse. reCAPTCHA is operated by Google LLC under Google's Privacy Policy and Terms.
We may also use automated scoring for fraud, spam, and account risk. You may contact us to request human review of decisions that produce legal or similarly significant effects, where applicable law requires.
7. Sharing and processors
We share personal data only as needed with:
| Recipient type | Purpose |
|---|---|
| Stripe | Payments, saved cards, Connect/payout features if enabled |
| SMTP/email providers | Transactional email |
| .st registry / EPP partners | Domain registration data per registry policy |
| Hosting & infrastructure | Servers, databases, backups |
| Professional advisers | Legal, accounting, insurance |
| Authorities | Where required by law or to protect rights and safety |
We use data processing agreements with processors where required. A current sub-processor list is available on request to privacy@dot.st.
We do not sell personal data in the conventional sense.
8. International transfers
Data may be processed in the United Kingdom, European Economic Area, and United States (e.g. Stripe, Google). Where transfers require safeguards, we use UK IDTA/Addendum, EU Standard Contractual Clauses, or equivalent mechanisms.
9. Retention
We retain personal data only as long as necessary for the purposes above, including:
- Account data — while active plus a reasonable period after closure for disputes and legal obligations;
- Financial records — typically 6 years from the end of the UK financial year (tax/accounting);
- Registry/WHOIS data — per registry policy and registrar obligations;
- Security logs — typically up to 24 months unless needed for investigations;
- Abuse reports — for investigation, compliance, and defence of claims.
We may anonymise data for analytics and retain anonymised records indefinitely.
10. Your rights
Depending on your location, you may have rights to:
- access a copy of your personal data;
- rectify inaccurate data;
- erase data (subject to exceptions);
- restrict or object to certain processing;
- data portability where processing is automated and based on contract/consent;
- withdraw consent where applicable;
- complain to the ICO (UK): ico.org.uk or your local supervisory authority.
To exercise rights, email privacy@dot.st with sufficient detail to identify you. We may request proof of identity. We respond within one month (extendable where complex).
11. Security
We implement appropriate technical and organisational measures (encryption in transit, access controls, logging, staff training). No system is 100% secure; report suspected breaches to security@dot.st.
12. Children
The Services are not directed at children under 16. We do not knowingly collect children's data.
13. Third-party links
Our sites link to third parties (registrars, payment pages, social platforms). Their privacy practices are their own responsibility.
14. Changes
We may update this policy by publishing a new version with an effective date. Material changes may be notified by email or prominent notice.
15. Contact
Data controller: Raffled UK Limited
Email: privacy@dot.st
Postal: [registered office address]
Effective date: June 2026
Version: 1.0
Obtain qualified UK/EU privacy counsel review before production, especially for Stripe, reCAPTCHA, registry WHOIS, and cross-border transfers.