Legal
Privacy Policy
Last updated: August 15, 2026
This Privacy Policy explains what information WebTrustScore ("we", "us") collects when you use the website at webtrustscore.com and the scanning API, how we use it, and the third-party services involved. By using the service you agree to this policy.
Information we collect
- Scan submissions. The domain name you submit, and — if you are signed in — a record joining that domain to your account, kept for 365 days and then deleted automatically. This record is per submission, not a total: it lets us see demand domain by domain. We do not store your IP address in it.
- Scan results. The computed WebTrustScore, factor values, evidence summaries, and timestamps we generate for a submitted domain. These describe a website, not a person.
- Account data. If you create an account: your email address, a salted password hash, and optionally a display name and profile picture. Your scan history is linked to the account.
- Sign-in data. Depending on how you sign in, we also store a server-side session record; for two-factor authentication, an encrypted shared secret and one-way hashes of your recovery codes; for passkeys, the credential identifier, its public key and the authenticator model; and for social sign-in, the provider name and the stable account identifier that provider gives us, plus the email address it returns.
- Saved lists. If you use bulk scaning, the list of domains you are working on is stored against your account so it follows you between devices, along with your ordering and which result each row was showing. If you create a share link, the domain names in it are stored for 90 days and then deleted automatically; the link itself contains only a random code and none of the names.
- Domains you verify. If you prove ownership of a domain, we store the domain, the verification token, and your settings for it — monitoring, public score pages, and whether it may appear in public listings.
- Feedback you send. If you dispute a WebTrustScore we store your comment and, if you volunteer one, the contact detail you give us so we can reply.
- Technical data. Your IP address and basic request metadata, used for rate limiting and abuse prevention. Our hosting provider also keeps operational request logs for up to 7 days, after which they are deleted automatically. These cannot be searched or removed on request.
How we use information
- To look up public facts about the submitted domain and calculate its WebTrustScore.
- To cache results and reuse recent lookups so repeated scans are faster and cheaper.
- To maintain an internal score history that improves the model over time.
- To operate your account, including sign-in, billing, and the features your plan includes.
- To protect the service through rate limiting and abuse detection.
We do not sell your data, and we do not use it for advertising.
Cookies and analytics
We use a strictly necessary cookie to keep you signed in to your account. Where analytics is enabled on this site, we use Google Analytics, and you will see a consent banner the first time you visit: analytics storage is denied until you accept, and you can change your mind at any time from the cookie settings link in the footer. Analytics receives the address of the page you are on. We do not send it your account identifier.
What is public
- Score pages. A scanning result can be opened by anyone who has its link. Nothing on that page identifies who requested it.
- Public listings. Domains may appear in our public directory and on public "notable domains" rankings. If you have verified a domain, you can opt it out of those listings from your account, and that choice is kept even if you later delete your account.
- Blockchain attestations. Every scanning produces a signed attestation that we hold in our own database. Separately, and only if you verify ownership of a domain and choose to publish one, an attestation can be written to the Base public blockchain. That record contains the domain, its score and band, the model version, a digest, the date, and that ownership was verified — it does not contain your wallet address, email, name, or account identifier. Once published it is permanent: neither we nor anyone else can edit or erase it. We can mark it revoked, which flags it as no longer current but removes nothing. If you never publish one, nothing about you is on any blockchain.
Third-party services
To deliver the service and collect evidence, we use:
- Cloudflare — hosting, edge compute, and storage for the site, API, score records, and evidence.
- Public RDAP / DNS resolvers — domain registration facts and DNS configuration used as evidence.
- The Internet Archive — historical presence of a domain, used as evidence.
- Google Web Risk and abuse.ch URLhaus — threat and blocklist intelligence used as evidence.
- Stripe — payment processing if you buy a paid plan. We never see or store your card details. Stripe holds its own customer record, which includes the billing details you give it.
- Google Analytics — where enabled, and only after you accept the consent banner.
- Google Fonts — web fonts are loaded from Google on every page, which discloses your IP address and browser to Google as part of that request.
- Our email provider — sends account emails such as verification and monitoring alerts. Messages sent to us through the contact form arrive as email only; they are not stored in our database.
When you scan a domain, we make requests to that domain and to the services above. Those third parties handle data under their own terms and privacy policies.
Data retention
Two things are deleted automatically: the per-submission records described above, after 365 days, and the domain names behind a share link, after 90 days. Cached third-party lookups expire within hours to a day.
Everything else — score records and their evidence, your account, your saved lists, your verified domains, feedback you have sent — is kept until you delete it or delete your account. We do not currently expire it on a schedule, and we would rather say so than imply a retention period we do not operate.
Deleting your account
You can delete your account yourself, from the Profile section of your account page. It asks you to type your email address and to confirm with your password — or, if you sign in with a provider rather than a password, with a link we email you. Deleting is permanent.
What is removed:
- Your account, display name and profile picture.
- Every sign-in method: password, passkeys, two-factor enrolment and recovery codes, and any linked social accounts.
- Your saved bulk lists and any share links, which stop working immediately.
- Your verified domains, their monitoring, and their public score pages.
- Your plan record and any unused credits.
- You are signed out on every device.
What is not, and why:
- Score records stay, unlinked. A score describes a website, not you, and other people rely on it — public rankings, the directory, and other members' saved lists all point at the same records. We remove the link between those records and you rather than delete work that is not only yours.
- Payment records stay at Stripe. Completed transactions are financial records with their own retention requirements. We unlink your billing profile, but we cannot delete Stripe's copy; contact Stripe directly for that.
- Blockchain attestations stay. If you published one, it is permanent — see above.
- Operational logs age out on their own within 7 days and cannot be removed selectively.
- Your account on our other site is separate. WebTrustScore accounts are independent of accounts on our sister site; deleting one does not delete the other.
If you have an active subscription, cancel it first — otherwise you would keep being charged for an account that no longer exists. The deletion page will tell you if this applies.
Your choices
Because we evaluate publicly registered domain names, results generally concern the name itself rather than individuals. You can opt a verified domain out of public listings, turn off monitoring, delete individual scanning records from your history, decline analytics cookies, and delete your account entirely. For anything else, contact us at the address below.
Browser extension
Our browser extension stores your settings and a short-lived cache of recent results in your own browser. That data never reaches us. Removing the extension removes it.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the "Last updated" date above.
Contact
Questions about privacy, or want a copy of what we hold? Email contact@webtrustscore.com.