Contact Us

This is the current version of our privacy policy. It replaces any earlier version and applies to vadiweb.com and to correspondence you send us about a brokerage, acquisition, negotiation, portfolio or strategy engagement. Section 11 sets out how you are told when it changes.

1. Who we are and how to contact us

Vadiweb is a private domain brokerage and digital asset advisory firm, headquartered in New York City. For the personal data described below, we are the controller: we decide why it is held and what happens to it.

Contact is by email. There is no telephone line and no contact form anywhere on this site, so a message to one of these addresses is the only way to reach us and the only way we receive information about you:

We reply within one business day. The contact page and the acquisition request page carry the same address; neither submits anything to us on your behalf.

2. What we collect

Very little, because there is very little to collect. This site has no contact form, no newsletter sign-up, no account system and no login. No page on vadiweb.com accepts a submission of any kind. The buttons marked "Contact Us" and "Request Acquisition" open pages that give you an email address.

What you put in an email to us. Your name, your email address, the company you act for, and whatever you decide to tell us about the domain, the budget and the timing. You choose all of it. We do not enrich it from data brokers, and we do not append anything to it from other sources.

Technical data that any web request produces. Your IP address, the URL you asked for, your browser's user agent string and the referring page. The application itself keeps a short table of recent request times in memory, keyed by IP address, so that automated scanning can be rate-limited. A request time older than sixty seconds stops counting and is dropped, addresses that have gone quiet are cleared out as the table fills, and the whole table disappears when the process restarts. None of it is written to disk. When a request fails, the server writes a log line recording the method and the URL asked for. Where our hosting and proxy layer retains access logs, they exist for security, abuse prevention and fault diagnosis, and are not used to profile you.

Analytics, but only if you accept it. No analytics tag is present in the page you are reading unless you have chosen "Accept all" on the cookie banner. Section 7 describes exactly what happens either way.

The site sets no cookies of its own. Our server sends no Set-Cookie header on any page.

3. Confidential enquiry information

This is the section that matters here. An acquisition brief usually names a domain you do not want anyone to know you want, and often reveals the product, the market entry or the rebrand behind it. In the wrong hands that information moves the price of the asset. We treat it as commercially sensitive material, not as marketing data.

  • It is not shared outside the people working your mandate. Nobody else in the firm needs the target name, and nobody else is given it.
  • It is never used to acquire a domain for our own account. We do not bid against you on a name you told us about, before, during or after an engagement.
  • It is never used for another client. If a second party asks us to pursue a name that an existing mandate already covers, we disclose the conflict and either separate the teams or decline the second mandate — we do not run both quietly.
  • It is never published. No case study, no client logo, no "recently acquired" note, no quote, without your written permission. That is why this site names no clients and publishes no transaction figures.

Two practical points about email. First, ordinary email is not encrypted end to end, so if the target name is the sensitive part, describe it in general terms in your first message — the sector, the extension, the character length — and name it once we are engaged. Second, if you would rather have a mutual non-disclosure agreement signed before you describe anything, say so in that first message and we will sign one before you name the domain. Our wider practice is set out on the confidentiality page, and the mechanics of a mandate on how it works.

4. Why we hold it and on what legal basis

Four bases cover everything we do:

  • Legitimate interest. Reading and answering a business enquiry that you addressed to us, and keeping the thread so the next reply makes sense. You can object to this at any time, and we will stop unless we have a legal reason to keep the record.
  • Consent. Analytics only. It is requested on the banner, it is never assumed, and you can withdraw it.
  • Performance of a contract. Once you engage us under a mandate letter, we process what the mandate requires: identifying the target, corresponding with the seller's side, and instructing the escrow provider and registrar to complete the transfer.
  • Legal obligation. Retaining records of a completed transaction where tax, accounting or sanctions law requires it.

5. How long we keep it

An enquiry that does not become an engagement is kept only while it is useful to the conversation you started, and is deleted once that conversation is plainly closed. You do not have to wait for that: ask us at any point and we will delete the correspondence and confirm that we have.

For an engagement, the file is kept for the life of the mandate and afterwards for as long as we are required to keep transaction records, or to defend a claim about the transaction, under the law that applies to it. Rate-limiting entries stop counting after sixty seconds and never leave the memory of a running process. Your cookie choice stays in your own browser until you clear it. Analytics data, if you accepted it, sits with Google under the retention period configured on our analytics property; ask us and we will delete what Google's own controls allow us to delete.

6. Who we share it with

Infrastructure providers, acting as processors. The company that hosts this site and the provider that carries our email necessarily handle the data in transit and at rest. They act on our instructions and for no purpose of their own. We will tell you who they are if you ask.

The escrow provider and the registrar, when a transaction actually proceeds. This one is unavoidable and we would rather state it plainly than bury it. To move a domain, the escrow service needs the identity and payment details of the party funding it, because it is a licensed business with its own regulatory checks, and the registrar needs registrant details to record the new owner. We disclose which providers are involved before anything is sent to them, and nothing is sent until you have approved the transaction. Anonymity toward the seller is preserved separately, through how the transfer is structured and through WHOIS privacy where the registry permits it.

Professional advisers or authorities, where a specific matter requires it or the law compels disclosure.

We do not sell personal information, and we do not share it for anyone else's marketing. There is no mailing list, no advertising pixel and no data broker in this business, which also means there is no "sale" or "sharing" of personal information as California law defines those terms.

7. Cookies and analytics

The banner you may have seen on your first visit offers two choices, "Accept all" and "Essential only". What each one does is worth stating precisely:

  • Your choice is stored in your browser's local storage under the key cookie_consent_vadiweb_v1, with the value all or essential. It is not a cookie and it is not sent to us with your requests.
  • Google Tag Manager is not written into the page source. It is requested by /js/cookie-consent.js only after the stored value is all.
  • Choosing "Essential only" means no request is made to googletagmanager.com at all — no analytics tag, no analytics cookie, nothing loaded and then held back.
  • If your browser blocks local storage, the script stops there: no banner and no analytics.
  • To change your mind, clear this site's data in your browser. The banner returns on your next visit and the choice you make then applies.

The site's content security policy allows scripts from our own origin and from googletagmanager.com and from nowhere else, and fonts only from our own origin. An advertising network, a third-party font service or an external CDN could not execute here even if someone added the markup. Categories and durations are covered further in the Cookie Policy.

8. Your rights

Wherever you are, you can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, or object to our holding it at all. Email [email protected], ideally from the address you wrote to us from, since that is how we locate the correspondence. We will not ask for more identification than we need to match the request to a thread, there is no fee, and there is no account to log into. We acknowledge within one business day, and answer within one month for requests under EU or UK law and within 45 days for requests under US state law, telling you in advance if a permitted extension is needed.

If you are in the EU or the UK

You have the rights of access, rectification, erasure, restriction of processing and data portability; the right to object to processing we base on legitimate interest; and the right to withdraw consent to analytics at any time without affecting what was collected beforehand. You may also complain to your national supervisory authority, or to the Information Commissioner's Office in the United Kingdom.

If you are in a US state with a privacy law

California residents have the rights under the CCPA as amended by the CPRA — to know what is collected and why, to obtain a copy, to correct it, to delete it, to opt out of sale or sharing and of targeted advertising, and to limit the use of sensitive personal information. Comparable rights apply under the laws of states including Colorado, Connecticut, Virginia and Texas. We run no sale, no sharing and no targeted advertising, so an opt-out request has nothing to switch off, but we will confirm that in writing if you send one. You may use an authorised agent, and we will not treat you differently for exercising any of these rights.

9. Security

Every page is served over TLS, and the application sends an HTTP Strict Transport Security header so your browser refuses to load the site over plain HTTP afterwards. It also sends a content security policy, a referrer policy that gives other sites the origin you came from rather than the full URL, and headers that stop another site framing the page or a browser guessing at a file's type. Requests are rate-limited, and a request can only ever resolve to a file inside the published site. Access to enquiry correspondence is limited to the people working the mandate it belongs to.

No method of transmission or storage is perfectly secure, and we will not claim otherwise. Email in particular passes between mail providers we do not control, which is the reason for the staged disclosure described in section 3. One related warning, because this industry attracts it: funds move through the licensed escrow service, not through us. If you ever receive a message that appears to come from Vadiweb asking you to wire money to a new or different account, treat it as fraudulent and confirm with us on the existing thread before sending anything.

10. Children

This is a service for businesses and professional investors. The site is not directed at children, we do not knowingly collect personal data from anyone under 16, and we have no reason to receive any. If we learn that we hold data from a child, we delete it. Write to [email protected] if you believe that has happened.

11. International transfers and changes to this policy

We are based in the United States, so an email you send from the EEA or the United Kingdom is transferred to and stored in the US, as is any file we open for you. Where a transfer of that kind needs a safeguard, we rely on the European Commission's standard contractual clauses, the UK international data transfer addendum, or another mechanism permitted under Chapter V of the GDPR. Ask us and we will tell you which applies to your engagement.

When this policy changes, we say so at the top of this page, and anyone with an open mandate is told by email on the thread we already share. A change to how enquiry information is handled will be written into section 3 rather than added quietly elsewhere, and if we ever introduce a technology that requires consent, we will ask for it again rather than rely on a choice you made about something else.

Related reading: Terms of Service, Cookie Policy, and the FAQ, which answers the practical questions about fees, escrow and timelines that often arrive alongside a privacy question. Anything not answered there: [email protected].