Privacy Policy
This policy explains how Register.ly collects, uses, stores, and protects information when you use our website and services.
Who we are
ASTRO REGISTER DOMAINS INC., trading as Register.ly (“Register.ly,” “we,” “us,” or “our”), is a Saskatchewan corporation with corporation number 102080612. For the personal information described in this Privacy Notice, Register.ly generally acts as the organization responsible for that information and, where applicable, as the data controller.
Scope of this Notice
This Privacy Notice explains how we collect, use, disclose, retain, and protect personal information when you visit or interact with our websites; create or administer an account; search for, register, renew, transfer, or manage a domain; purchase or use hosting, cloud, SSL, backup, licensing, or related services; contact sales, billing, support, abuse, or security teams; receive communications; or otherwise interact with Register.ly.
This Notice applies when Register.ly determines the reasons and methods by which personal information is processed. If we process personal information contained in Customer Content solely on a customer’s documented instructions, the customer generally acts as the controller, and Register.ly acts as the processor or service provider. That processing is governed by the applicable Data Processing Addendum (“DPA”).
Third-party registries, certificate authorities, payment providers, licensors, and other organizations may independently determine how they process personal information. Their own privacy notices apply to that independent processing.
Personal information we collect
The information we collect depends on your relationship with us, the Service, legal and registry requirements, and the features you use.
| Category | Examples | Typical source |
|---|---|---|
| Identity and contact | Name, organization, job title, postal address, email address, telephone number, country, language, and authorized-user information. | You; account administrators; business contacts; registries or other providers. |
| Account and authentication | Customer and account identifiers, usernames, authentication status, permissions, account settings, recovery details, and login history. | You; account administrators; our systems and security tools. |
| Orders and services | Products, domains, service configurations, renewal settings, transaction history, licences, resource use, and service interactions. | You; our systems; registries; certificate authorities; vendors. |
| Billing and payment | Billing contact and address, currency, tax information, invoice and payment status, transaction identifiers, payment method type, and limited card details such as brand or last digits where provided by a processor. | You; payment processors; banks; fraud-prevention providers. |
| Domain registration | Registrant and contact data, domain, nameserver and registration details, eligibility evidence, verification records, correspondence, and registry transaction history. | You; registrant or account contacts; registries; registrars; public or restricted registration-data services. |
| Verification and compliance | Identity or authority documents, company documents, eligibility evidence, sanctions or fraud checks, consent records, and compliance decisions. | You; authorized representatives; verification providers; public authorities or sources where lawful. |
| Support and communications | Tickets, emails, chat or call records where enabled, attachments, survey responses, complaint records, and troubleshooting information. | You; your users; support systems; service providers. |
| Technical and usage | IP address, device and browser data, timestamps, URLs, referring pages, session and security events, cookie identifiers, API activity, DNS or network events, and diagnostic logs. | Your device; our services; security, analytics, and network providers. |
| Marketing preferences | Subscriptions, communication preferences, campaign engagement, and suppression records. | You; communication and analytics tools. |
| Customer Content | Files, databases, messages, backups, hosted content, or other data placed in a Service. We generally process this on the customer’s instructions under the DPA. | Customers and their authorized users. |
Information about other people
If you provide personal information about a registrant, administrative contact, technical contact, employee, customer, or other individual, you must be authorized to do so and provide any notice required by law. You should not provide more information than the Service requires.
Information we do not intentionally request
Do not submit sensitive personal information, government identifiers, payment card data, health information, or special category data through support tickets or ordinary communications unless we specifically request it through an approved secure process and it is necessary for the stated purpose.
How and why we use personal information
We use personal information only for identified and appropriate purposes. Where the GDPR or a similar law requires a legal basis, the applicable basis is set out below. More than one basis may apply depending on the context.
| Purpose | Activities | GDPR basis where applicable |
|---|---|---|
| Provide and administer Services | Create accounts; process orders; register or manage domains; issue certificates; provision cloud or hosting; deliver support; authenticate users. | Contract; steps requested before a contract; legitimate interests in operating the Service. |
| Billing and records | Invoice, collect and reconcile payments; manage tax and accounting records; address billing disputes. | Contract; legal obligation; legitimate interests in financial administration. |
| Domain and provider compliance | Transmit required data to registries, registrars, ICANN mechanisms, escrow providers, certificate authorities, licensors, or authorities; verify eligibility and contacts. | Contract; legal obligation; legitimate interests; consent where specifically required. |
| Security and abuse prevention | Protect accounts and infrastructure; detect fraud, malware, spam and abuse; log events; investigate incidents; enforce policies. | Legitimate interests; legal obligation; protection of rights and systems. |
| Improve and operate | Monitor reliability and performance; diagnose errors; understand feature use; plan capacity; improve support and user experience. | Legitimate interests; consent for non-essential cookies or tracking where required. |
| Communicate | Send service, renewal, security, policy, transaction, and support messages. | Contract; legal obligation; legitimate interests. |
| Market Services | Send newsletters or offers; measure campaigns; maintain preferences and suppression lists. | Consent where required; otherwise legitimate interests subject to opt-out and applicable law. |
| Legal and corporate | Comply with law and valid process; establish, exercise or defend claims; conduct audits; manage transactions or reorganizations. | Legal obligation; legitimate interests. |
Consent
Where we rely on consent, you may withdraw it at any time using the method presented when consent was collected or by contacting us. Withdrawal does not affect processing already carried out lawfully, and it does not prevent processing based on another lawful ground.
Domain-name registration data
Domain services require information to be shared within the domain-name ecosystem. Depending on the extension and transaction, we may disclose registration data to the applicable registry, upstream registrar, registry service provider, data escrow provider, ICANN or an ICANN-designated mechanism, dispute-resolution provider, verification provider, and competent authority.
For .LY domains, information is processed as required to submit and administer requests under the then-current NIC.LY Domain Name Registration Regulations and related .LY Registry procedures. Category-restricted or short names may require additional evidence of eligibility or authorization.
Registration data is not necessarily published in full. Some data may appear in RDAP, WHOIS, or another registration data service; be redacted; or be disclosed through a lawful access request process, depending on the extension, registry policy, applicable law, and privacy or proxy service. We do not promise that a privacy or proxy service is available for every extension or registrant.
Domain registration records may need to be retained after a registration ends to meet registry, ICANN, legal, accounting, security, dispute, or evidence requirements. Applicable retention must be documented in the retention schedule below.
Payments
Payments may be processed by third-party payment providers. Payment-card details are processed by payment providers. Register.ly does not intentionally retain card security codes and generally receives only limited transaction and payment-method information. We may receive a payment token, a transaction identifier, a payment status, a method type, a card brand, expiry information, and limited card digits.
Payment providers process information in accordance with their own privacy notices and legal obligations. We use payment and billing information to complete transactions, prevent fraud, reconcile accounts, address disputes and chargebacks, and meet tax and accounting requirements.
Cookies and similar technologies
Our websites and client services may use cookies, local storage, pixels, or similar technologies. Our Cookie Notice and available privacy controls describe the active categories, purposes, choices, and retention periods.
| Category | Purpose | Control |
|---|---|---|
| Strictly necessary | Security, authentication, session management, load balancing, checkout, and saved privacy choices. | Used where necessary to provide a requested service; blocking may prevent functionality. |
| Preferences | Remember language, region, display, or user choices. | Consent or browser controls where required. |
| Analytics | Understand traffic, performance, errors, and aggregated feature use. | Activated only with consent where required. |
| Advertising/marketing | Measure campaigns or personalize advertising, if such tools are actually used. | Activated only with legally valid consent where required; must be verified before publication. |
You can change non-essential cookie choices through https://register.ly/privacy-policy/#cookie-preferences. Browser settings may also block or delete cookies, but they do not necessarily control all similar technologies.
When we disclose personal information
We do not sell personal information. We disclose it only as needed for the purposes described in this Notice, with consent where required, or as permitted or required by law.
| Recipient category | Reason for disclosure |
|---|---|
| Domain ecosystem | Registries, registrars, ICANN mechanisms, escrow and registry service providers, dispute-resolution providers, and registration-data request services. |
| Service delivery | Infrastructure, data-center, cloud, network, DNS, security, backup, email, certificate, license, and managed-service providers. |
| Business operations | Payment, tax, accounting, banking, communications, customer support, CRM, analytics, KYC, fraud-prevention, and professional advisers. |
| Account organizations | The customer organization, its account owner and authorized users, or a person authorized to manage a domain or Service. |
| Authorities and claimants | Courts, regulators, law enforcement, tax authorities, registry authorities, or other parties where disclosure is lawful and appropriately verified. |
| Corporate transactions | A buyer, investor, lender, adviser, or successor in a proposed or completed financing, reorganization, merger, acquisition, or sale, subject to appropriate confidentiality and legal safeguards. |
Service providers
Service providers may process information only for the contracted purpose and under appropriate confidentiality, security, and data-protection obligations. The DPA describes our subprocessor framework, and current subprocessor information is available through our website, client area, contractual documentation, or on request.
International processing and transfers
Register.ly serves customers internationally and may use providers or infrastructure in more than one country. Personal information may therefore be stored, accessed, supported, or otherwise processed outside your country. It may be subject to lawful access by courts, law enforcement, regulators, registries, or national authorities in those locations.
Where European Economic Area, United Kingdom, Swiss, or other law restricts international transfers, we use an applicable safeguard, such as an adequacy decision, approved contractual clauses, or another lawful mechanism, together with supplementary measures where required. For relevant EEA transfers, this may include the European Commission’s Standard Contractual Clauses.
Retention
We retain personal information only for as long as reasonably necessary for the identified purposes, including service delivery, registry and license requirements, security, fraud prevention, backup cycles, accounting, tax, dispute resolution, legal claims, and compliance. We then delete, anonymize, or securely isolate it, unless longer retention is required or permitted by law.
| Record | Retention period |
|---|---|
| Account and contract records | Active account or contract plus 7 years. |
| Invoices, payments, and tax records | 6 years after the relevant transaction or financial year, according to applicable law. |
| Domain registration and verification | For the period during which Register.ly sponsors or manages the registration and for at least 15 months after the sponsorship ends or an inter-registrant transfer occurs, as required by the applicable ICANN Registration Data Policy. Retain transaction and financial records separately where the six-year financial period applies. |
| Support tickets and communications | 3 years after the ticket or matter is closed. Delete unnecessary identity documents and sensitive attachments within 90 days after resolution. Passwords, private keys, recovery codes, and other credentials should be removed immediately after use and should not ordinarily be requested through tickets. |
| Security and access logs | 12 months from collection. High-volume diagnostic logs that are not security-relevant may be kept for 90–180 days. 6 years after the investigation or related account action is closed, where needed to establish, exercise, or defend legal claims. Records unrelated to a substantiated incident should be deleted earlier. |
| KYC and eligibility documents | While the relevant domain or restricted Service remains active and for 2 years after it ends. For rejected requests, retain for 12 months. Extend retention only where required by a registry, law, active dispute, fraud investigation, or legal hold. Store the verification result longer where necessary instead of retaining the complete identity document. |
| Marketing records | Until consent is withdrawn, the person opts out, or there has been 24 months of inactivity, whichever occurs first. Evidence of consent and relevant campaign records should be retained for 6 years after the last marketing communication or withdrawal where needed to demonstrate compliance. |
| Customer Content after termination | Provide a 30-day export window after termination, unless immediate restriction or deletion is required for security, abuse, law, or the nature of the Service. Delete active production copies within 30 days after the export window ends. Delete remaining backup copies through normal rotation within a maximum of 90 days after production deletion. |
Retention periods may differ if a dispute, legal hold, security incident, chargeback, or authority request requires preservation. Aggregated or irreversibly anonymized information may be retained longer because it no longer identifies an individual.
Security
We use administrative, technical, and physical safeguards appropriate to the nature and sensitivity of the information and the risks involved. These may include access controls, authentication, encryption in transit, logging and monitoring, vulnerability and patch management, backups, personnel confidentiality, vendor review, and incident-response procedures.
No method of transmission, storage, or security is guaranteed to be completely secure. You are responsible for protecting account credentials, using multi-factor authentication where available, managing authorized users, securing devices and applications under your control, and promptly notifying us of any suspected compromise.
Your privacy rights
Your rights depend on where you live and the law applicable to the processing. They may include the rights listed below, subject to identity verification and lawful exceptions.
- Ask whether we hold personal information about you and request access to it;
- Request correction of inaccurate or incomplete information;
- Request deletion or erasure;
- Request restriction of processing;
- Object to processing based on legitimate interests or to direct marketing;
- Receive certain information in a portable format;
- Withdraw consent where processing relies on consent;
- Request information about disclosures, safeguards, or automated decisions where applicable; and
- Complain to an applicable privacy or data-protection authority.
To exercise a right, contact [email protected]. Describe your request and the account or relationship involved. We may request information reasonably necessary to verify identity and authority. We will respond within the period required by applicable law. We may deny or limit a request where law permits, including to protect another person’s rights, preserve security, meet registry or legal duties, or establish or defend claims, and will explain the decision where required.
Canadian privacy complaints
You may first raise a concern with our Privacy Officer. If unresolved and PIPEDA applies, you may contact the Office of the Privacy Commissioner of Canada. Provincial privacy authorities or other regulators may also have jurisdiction depending on the circumstances.
EEA and UK rights
Where the GDPR or UK GDPR applies, you may lodge a complaint with the supervisory authority in the country where you live or work or where the alleged infringement occurred. Where required by applicable law, details of any appointed representative or data protection officer will be published in this Notice.
Marketing communications
Service, security, billing, renewal, policy, and support messages are not marketing and may continue while needed to administer your account or Services. You can unsubscribe from marketing email through the link in the message or by contacting us. We may retain a minimal suppression record so we do not send marketing you declined.
We do not combine acceptance of the Terms with optional marketing consent. Where consent is required for electronic marketing or tracking, we will request it separately.
Automated decision-making
We may use automated tools to detect fraud, abuse, account compromise, payment risk, or prohibited activity and to prioritize review. We do not make decisions based solely on automated processing that produce legal or similarly significant effects without appropriate notice, safeguards, and a lawful basis. If that changes, we will provide the information and rights required by applicable law.
Children
The Services are intended for adults and organizations and are not directed to children. You must be at least 18 years old to create an account or purchase Services. We do not knowingly collect personal information directly from children for their own use of the Services. If you believe a child has provided information contrary to this Notice, contact us so we can investigate and take appropriate action.
Personal-information incidents
We maintain procedures to investigate and respond to suspected loss, unauthorized access, use, alteration, or disclosure of personal information. Where required, we will notify affected individuals, customers acting as controllers, privacy authorities, or other competent bodies within the applicable timeframe. If an incident affects Customer Personal Data processed on a customer’s behalf, the DPA governs our notification and cooperation obligations.
Third-party services and links
Our Services may link to or integrate with third-party websites and services. We do not control their independent privacy practices. Review their privacy notices before providing information or enabling an integration. A link does not mean that Register.ly endorses the third party’s privacy practices.
Changes to this Notice
We may update this Notice to reflect changes in our Services, practices, providers, technology, or legal obligations. We will post the revised Notice with a new “Last updated” date. If a change materially affects how we use personal information, we will provide additional notice where required, such as by account message or email. We will request new consent if required by law; continued use is not treated as consent where valid consent is legally required.
Contact us
Questions, requests, or complaints about this Notice or our privacy practices should be directed to:
- Privacy Officer — ASTRO REGISTER DOMAINS INC., trading as Register.ly
- Email: [email protected]
- Postal address: 3537 GREEN MOSS LANE, REGINA, SASKATCHEWAN, CANADA, S4V 1L5
- Support portal: https://my.register.ly
We will acknowledge and investigate privacy complaints in accordance with applicable law. Please do not send identity documents or sensitive information by ordinary email unless we specifically instruct you to use an approved secure method.