1. Introduction
The DomfoRat extension is available for Chrome/Edge (Chromium) and Firefox. It allows users to browse available expired domain names, filter them, add them to favourites, receive local alerts and open analysis or registration tools when requested.
This policy separately covers the operation of the extension and the processing carried out on domforat.com, particularly when an account is created, a user signs in, an order or payment is made, or a request is sent to DomfoRat. The controller responsible for this processing is Leclerc Jérémy, sole trader, 42B rue du Ballon, 45650 Saint-Jean-le-Blanc, France.
2. Extension and website: data processed
Extension
The extension does not require a user account and does not collect names, email addresses, identifiers, passwords, financial or health data, the content of visited web pages, forms entered by users or personal communications.
The data handled by the extension is related to the operation of the service: public domain names displayed by DomfoRat, associated scores, applied filters, favourites selected by the user, notification status and the local history of domains already viewed.
Website, accounts and orders
Depending on the features used, the website may process the following categories:
- Account: email address, declared identity, password stored only as an irreversible hash, session tokens, and sign-in or activity dates.
- Billing: name, company, contact, address, country and, for a business customer, SIREN, SIRET or VAT number when provided.
- Order and access: offer, price, currency, access duration and dates, payment or refund status, and Stripe session, payment, customer and invoice identifiers.
- Contractual evidence: version of the Terms of Sale, version and hash of the consent wording, selected confirmations, date, browser and HMAC hash of the IP address where such evidence is required.
- Security and support: IP address or hash, browser, URL, timestamp, anti-abuse events and the content of messages sent to DomfoRat.
Full card numbers, security codes and bank authentication data are entered through Stripe and are not stored by DomfoRat.
Purposes and legal bases
- Creating and administering the account, processing the order, providing premium access, managing payment, refunds and support: performance of the contract or pre-contractual steps requested by the user.
- Issuing billing documents and complying with accounting, tax or regulatory obligations: legal obligation.
- Retaining evidence of the order, the Terms of Sale and confirmations, preventing fraud, protecting accounts and ensuring service availability: DomfoRat's legitimate interest in securing its service and defending its rights.
- Responding to requests, claims and exercises of rights: performance of the contract, legal obligation or legitimate interest, depending on the nature of the request.
Required and optional information
Fields marked as required are necessary to create an account, fulfil an order or prepare billing documents. Without them, the relevant operation cannot be completed. Address line 2, business contact and VAT fields are optional where they are not required by the customer's situation.
3. Data processed locally
Processing recorded in the user's browser includes:
- Storage of favourite domains, the list of domains already viewed, new-domain markers and notification status through
chrome.storage.local. - Use of the browser's
Clipboard APIto copy a domain name or promotional code, only after a deliberate user action. - Display of local notifications through
chrome.notificationswhen new domains are detected, unless notifications have been disabled. - Local generation of JSON, CSV or Excel export files containing favourite domains. The file is produced in the browser using the bundled
xlsx.full.min.jslibrary. - A temporary, non-persistent in-memory cache that avoids reloading the same Wayback statistics several times while the popup is in use.
This information remains in the browser's local environment, except for the necessary network requests described below.
4. Permissions used
As declared in manifest.json, the permissions are:
storage: local storage of favourites, notification status, domains already viewed and new-domain markers.notifications: local alerts when new domains appear.alarms: automatic periodic checks in the background.- A host permission limited to
https://domforat.com/*to load the catalogue, topics, Wayback statistics prepared by DomfoRat and pack availability information. - A content script limited to
https://domforat.com/*. It only sends a local signal indicating that the DomfoRat extension is installed; it does not read page content, forms, cookies or browsing history.
5. Network requests
The extension makes HTTPS requests to domforat.com to provide its main functionality: retrieving the domain catalogue, topics, pack availability information and, at the user's request, Wayback statistics for a domain displayed in the list.
When a Wayback panel is opened, the selected domain name may be sent to https://domforat.com/wayback-history.php to return the relevant statistics. This domain name comes from the public catalogue displayed by the extension and is not linked to a user account.
Like any website, domforat.com, its hosting provider and security services such as Cloudflare may process technical logs related to HTTP requests: IP address, date, requested URL, browser type, response status and security signals. These logs are used for security, service availability, abuse prevention and technical diagnostics. They are not used to create advertising profiles.
6. Recipients, processors and third-party services
The extension contains buttons or links that open external services, only after user action: Google Search, Wayback Machine, Haloscan, Netim, DomfoRat, Goremandise and various tools or partners displayed in the Tools tab.
Some links may include the selected domain name in the URL, for example for a Google search, Haloscan analysis, Wayback lookup or registration search at Netim. These services are operated by third parties and apply their own privacy policies.
DomfoRat does not sell user data or transfer favourites, local history or extension settings to these services. Opening an external link is voluntary and takes place outside the extension.
Website data is accessible to the publisher only as needed and to the providers required to operate the service: o2switch for hosting and email, Cloudflare for DNS, caching and security, and Stripe for payments and related documents. Each provider processes only the data needed for its role and also applies its own privacy policy.
Depending on the locations selected by these providers and their subprocessors, some technical or payment data may be processed outside the European Economic Area. Such processing must then rely on a mechanism recognised by the GDPR, such as an adequacy decision or standard contractual clauses. Further information may be requested from DomfoRat or found in the relevant providers' policies.
7. Retention and deletion
Favourites, notification preferences, domains already viewed and new-domain markers are stored locally in chrome.storage.local until the user deletes them, resets the browser or uninstalls the extension.
JSON, CSV and Excel exports are created locally and saved only when the user initiates the download. DomfoRat does not receive these files.
The extension does not use cookies for its internal operation.
The following criteria and periods apply to the website:
- Account and profile data is retained for as long as the account is maintained or until it is closed or deleted on request, subject to information that must remain archived to comply with a legal obligation or defend a right.
- Evidence of orders, payments, access and consent is retained throughout the contractual relationship and then in intermediate archives for the applicable limitation period, generally five years. Invoices and accounting records are retained for ten years from the end of the relevant financial year.
- A sign-in session is valid for a maximum of thirty days. An account creation or password reset link is valid for thirty minutes; once expired, it no longer provides account access.
- Application security events from the domain APIs are deleted after thirty days. Logs held by the hosting provider, Cloudflare, Stripe or the email service follow the retention periods defined by those providers and their own obligations.
- Support requests and requests to exercise rights are retained for the time needed to process them and then, where necessary, for the period needed to demonstrate the response provided.
The website uses cookies or tokens that are strictly necessary for sign-in, secure account creation after payment and anti-abuse protection. Cloudflare may also set technical security cookies. DomfoRat does not use them for behavioural advertising.
8. Security
All requests from the extension to DomfoRat use HTTPS. Local data is limited to what is strictly necessary for the extension's visible features. The extension contains no behavioural advertising, does not load remote code to execute its logic and does not use analytics in the popup.
The extension operates mainly in its popup and does not collect the content of websites visited by the user. The content script declared on domforat.com is used only to signal the presence of the extension to the DomfoRat website.
For the website, passwords and sensitive tokens are stored as hashes, payments are delegated to Stripe, communications use HTTPS and access to data is limited to service needs. As no system can guarantee absolute security, any confirmed incident is handled in accordance with applicable obligations.
9. Chrome Web Store commitment
The use of information processed by the DomfoRat extension complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.
- Data is used only to provide or improve the extension's visible features.
- No user data is sold or transferred to data brokers, advertising platforms or personalised advertising services.
- No user data is used for advertising targeting, retargeting or creditworthiness assessment.
- No human reads the user's local data except in response to an explicit support request, a security requirement or a legal obligation.
10. Changes
This policy may be updated to reflect changes to the extension or applicable rules. The last-updated date will be changed on this page.
11. Rights and contact
Any data subject may request access to, rectification or deletion of their data, restriction of processing, object to processing on grounds relating to their situation, request data portability where the conditions are met and withdraw consent where processing is based on consent. These rights may be exercised with Leclerc Jérémy, sole trader, at [email protected] or by post at 42B rue du Ballon, 45650 Saint-Jean-le-Blanc, France.
The request must make it possible to identify the relevant account or order. Proof of identity will be requested only where there is reasonable doubt and only to the extent necessary. A complaint may be lodged with the CNIL if the person believes that their rights have not been respected.