Support Register

Legal

Privacy Policy

1. Who we are

Raffled UK Limited ("we", "us", "our") operates the Dot.st network: Dot.st, DropCatch.st, and Premium.st (together, the "Services"). We act as data controller for personal data processed through these Services.

Registered office: [insert registered address]
Company number: [insert Companies House number]
Privacy contact: privacy@dot.st (subject line: Privacy Request)

2. Scope

This Privacy Policy explains how we collect, use, store, share, and protect personal data when you:

  • create or use a network account;
  • register, renew, or transfer .st domains;
  • place backorders or use DropCatch tools;
  • list, buy, bid, or negotiate on Premium.st;
  • top up your wallet, pay invoices, or request payouts;
  • contact support or submit abuse reports;
  • browse our sites (including cookies and similar technologies).

It should be read with our Terms of Service and cookie disclosures on each site.

3. Personal data we collect

Category Examples Typical source
Identity & account Name, email, password hash, account IDs You
Contact & billing Billing address, VAT number, invoice details You
Registry contacts Registrant/admin/tech/billing contacts for domains You
Transaction Orders, bids, backorders, wallet ledger, invoice numbers You / our systems
Payment Payment method brand/last4/expiry, Stripe customer IDs, payout bank details You / Stripe
Communications Support tickets, emails, negotiation messages You
Abuse & security Abuse report content, verification tokens, IP logs You / automated
Technical IP address, user agent, session IDs, timestamps, error logs Automated
Marketing Preferences if you opt in You

We do not store full card numbers or CVV. Card data is handled by Stripe (and any future PCI-compliant processor we disclose).

4. How we use personal data

We use personal data to:

  • provide and operate the Services you request;
  • register and manage domains with the .st registry;
  • process payments, wallet top-ups, refunds, and seller payouts;
  • verify identity, prevent fraud, and enforce our policies;
  • communicate about orders, auctions, backorders, renewals, and security;
  • respond to support and abuse reports;
  • comply with legal, tax, and registry obligations;
  • improve, secure, and debug our platform (aggregated/anonymised where feasible).

5. Legal bases (UK GDPR / GDPR)

Where UK GDPR or EU GDPR applies, we rely on:

  • Contract — processing necessary to provide Services you request;
  • Legal obligation — tax, accounting, registry, and law-enforcement requirements;
  • Legitimate interests — security, fraud prevention, service improvement, and network integrity, balanced against your rights;
  • Consent — where required (e.g. non-essential cookies or optional marketing).

You may withdraw consent where processing is consent-based without affecting prior lawful processing.

6. Automated decision-making and fraud prevention

We use automated checks (including Google reCAPTCHA v3 with v2 fallback) on registration, login, password reset, checkout, and other sensitive forms to distinguish humans from abuse. reCAPTCHA is operated by Google LLC under Google's Privacy Policy and Terms.

We may also use automated scoring for fraud, spam, and account risk. You may contact us to request human review of decisions that produce legal or similarly significant effects, where applicable law requires.

7. Sharing and processors

We share personal data only as needed with:

Recipient type Purpose
Stripe Payments, saved cards, Connect/payout features if enabled
SMTP/email providers Transactional email
.st registry / EPP partners Domain registration data per registry policy
Hosting & infrastructure Servers, databases, backups
Professional advisers Legal, accounting, insurance
Authorities Where required by law or to protect rights and safety

We use data processing agreements with processors where required. A current sub-processor list is available on request to privacy@dot.st.

We do not sell personal data in the conventional sense.

8. International transfers

Data may be processed in the United Kingdom, European Economic Area, and United States (e.g. Stripe, Google). Where transfers require safeguards, we use UK IDTA/Addendum, EU Standard Contractual Clauses, or equivalent mechanisms.

9. Retention

We retain personal data only as long as necessary for the purposes above, including:

  • Account data — while active plus a reasonable period after closure for disputes and legal obligations;
  • Financial records — typically 6 years from the end of the UK financial year (tax/accounting);
  • Registry/WHOIS data — per registry policy and registrar obligations;
  • Security logs — typically up to 24 months unless needed for investigations;
  • Abuse reports — for investigation, compliance, and defence of claims.

We may anonymise data for analytics and retain anonymised records indefinitely.

10. Your rights

Depending on your location, you may have rights to:

  • access a copy of your personal data;
  • rectify inaccurate data;
  • erase data (subject to exceptions);
  • restrict or object to certain processing;
  • data portability where processing is automated and based on contract/consent;
  • withdraw consent where applicable;
  • complain to the ICO (UK): ico.org.uk or your local supervisory authority.

To exercise rights, email privacy@dot.st with sufficient detail to identify you. We may request proof of identity. We respond within one month (extendable where complex).

11. Security

We implement appropriate technical and organisational measures (encryption in transit, access controls, logging, staff training). No system is 100% secure; report suspected breaches to security@dot.st.

12. Children

The Services are not directed at children under 16. We do not knowingly collect children's data.

13. Third-party links

Our sites link to third parties (registrars, payment pages, social platforms). Their privacy practices are their own responsibility.

14. Changes

We may update this policy by publishing a new version with an effective date. Material changes may be notified by email or prominent notice.

15. Contact

Data controller: Raffled UK Limited
Email: privacy@dot.st
Postal: [registered office address]

Effective date: June 2026
Version: 1.0

Obtain qualified UK/EU privacy counsel review before production, especially for Stripe, reCAPTCHA, registry WHOIS, and cross-border transfers.