This Privacy Policy explains how Vianames LLC, trading as OrbitFour ("OrbitFour," "we," "us," or "our"), a Michigan limited liability company and an ICANN-accredited domain registrar (IANA ID 3873), collects, uses, shares and protects personal information when you use our website and services. We are committed to handling your information transparently and giving you control over it.
Our privacy promise. We safeguard the information you share with us using appropriate security measures. We do not sell your personal information, and we do not share it for cross-context behavioural or targeted advertising. We share your information only as described in this Policy — for example, as needed to register and maintain your domain, to comply with ICANN and other regulatory requirements, or as required by law. You can opt out of marketing communications at any time.
1. Who We Are and How to Contact Us
For personal data we process about you, the data controller is Vianames LLC, trading as OrbitFour. You can reach our privacy team at:
Email: privacy@orbitfour.com
Mail: Vianames LLC d/b/a OrbitFour Attn: Privacy 77 Monroe Center NW, STE 600 Grand Rapids, MI 49503 United States
2. Scope
This Policy applies to personal information we collect through our website, your account, and our domain registration, DNS, WHOIS privacy, parking and landing page, and related services.
It does not apply to third-party websites or services we link to. Nor does it apply to content published at a domain registered through us where that content is hosted elsewhere — we do not control it. It does apply where we host the content ourselves, which is the case for parking and landing pages we provide; see Section 15.
3. Personal Information We Collect
Account and identity data. Name, email address, postal address, telephone number, login credentials and two-factor authentication settings.
Domain registration data. The registrant, administrative, technical and billing contact details associated with each domain, plus nameservers, domain status and registration dates. This data is subject to the rules described in Section 6.
DNS and zone data. The DNS records you create and the nameserver configuration for your domains. Zone contents may contain personal data where you choose to place it there — for example in a TXT record — and that choice is yours.
Content you publish. Content, images and settings you supply for a parking page or landing page we host on your behalf.
Billing, payment and tax data. Billing contact details, transaction records, and any VAT identification number you supply together with the result of its validation. Where we are required to determine the tax chargeable on your order, we also record location evidence, which may include your billing address, the country derived from your IP address and the country of issue of your payment card. Card data is processed by our payment processor; we do not store full payment card numbers.
Communications and support data. Messages you send us, support tickets, and the content of notices and complaints.
Abuse reports and data disclosure requests. Where a third party reports abuse or requests access to non-public registration data, we collect that person's identity, contact details, asserted legal basis and supporting material. If you are such a requester, this Policy describes how we handle your data too.
Technical and usage data. IP address, browser type and version, operating system, referring URL, pages requested and timestamps, collected through server logs and the technologies described in Section 8.
Marketing preferences. Your communication settings and any record of an opt-out.
4. How We Use Your Information
We use personal information to:
- create and administer your account;
- register, renew, transfer and manage your domains, and operate DNS, WHOIS privacy, parking and landing page services;
- operate WHOIS, RDAP and other required registrar functions, and respond to lawful requests for registration data;
- process payments, and determine, charge, report and remit applicable taxes;
- provide customer support;
- send service and transactional messages, including expiration reminders and registration data accuracy notices required by ICANN;
- detect, investigate and prevent fraud, abuse, DNS abuse and security incidents;
- receive and act on notices about content we host;
- comply with our legal, regulatory and contractual obligations, including the ICANN Registrar Accreditation Agreement (RAA) and applicable EU law; and
- where permitted, send marketing communications you can opt out of at any time.
4.1 Automated Decision-Making
We use automated checks to screen orders, accounts and domains for fraud, payment risk and DNS abuse. Some of these checks are performed by our payment processor using its own risk models. They may decline a transaction, place an order on hold, or suspend a domain or account pending review. We also apply automated processing when verifying the accuracy of registration data.
Where such a decision produces legal effects concerning you or similarly significantly affects you, you have the right to obtain human intervention, to express your point of view and to contest the decision. Contact privacy@orbitfour.com and a member of our team — not an automated system — will review it.
5. Legal Bases for Processing
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR and UK GDPR.
| Purpose | Legal basis |
|---|---|
| Creating and administering your account; registering, renewing, transferring and managing domains; providing DNS, parking and landing pages; support | Performance of a contract |
| Collecting, transmitting and escrowing registration data; WHOIS/RDAP operation; accuracy verification; responding to lawful access requests; tax determination, invoicing and reporting; acting on notices about hosted content | Compliance with a legal obligation, including the RAA, ICANN policies and applicable EU law |
| Securing and improving our services; preventing fraud and abuse; measuring site usage in aggregate; defending legal claims; running our business | Legitimate interests, where not overridden by your rights |
| Marketing communications | Consent, which you may withdraw at any time |
Where we rely on legitimate interests, you may object as described in Section 12. You can obtain a summary of the balancing we carried out by writing to privacy@orbitfour.com.
6. Domain Registration Data, WHOIS/RDAP and Disclosure
When you register a domain, ICANN rules and EU law govern how the associated registration data is collected, escrowed, transferred to the registry and published. The key points are set out below.
6.1 Default redaction
Under ICANN's Registration Data Policy, which contracted parties were required to implement by 21 August 2025 and which carries forward the prior Temporary Specification, most registrant contact information is redacted from public WHOIS/RDAP output by default. Public records typically show the domain name, status, nameservers, key dates and registrar information, but not your personal contact details.
6.2 Optional privacy service
For additional protection — for example for organisational registrants whose data is not redacted by default, or for extensions that still publish contact data — you may use our WHOIS Privacy Service, described in our WHOIS Privacy Service Terms.
6.3 Transfers required for registration
We transmit registration data to the relevant registry operator, and deposit it with an ICANN-approved data escrow agent, as required by ICANN. ICANN, registry operators and the escrow agent process this data as independent controllers under their own policies, not on our instructions. See Section 7.1.
6.4 Requests for non-public registration data
Third parties with a legitimate interest — such as law enforcement, intellectual property rights holders and security researchers — may request access to non-public registration data. Requests reach us through ICANN's Registration Data Request Service (RDRS) or directly, at privacy@orbitfour.com.
We assess every request individually. We disclose non-public data only where we have a lawful basis, where the request is duly substantiated, and where the requester's legitimate interest is not overridden by your rights and freedoms. Where we are not legally prohibited from doing so, we may notify you that a request concerning your domain has been received.
6.5 Accuracy obligations
You must keep your registration data accurate and complete, update it within seven days of any change, and respond to accuracy verification requests within fifteen days, as described in the Domain Registration Agreement. These obligations apply even when your data is redacted or you use the privacy service.
6.6 Providing registration data is a requirement
Providing registration data is a contractual and regulatory requirement, not optional. ICANN's Registration Data Policy and the Registrar Accreditation Agreement require us to collect the registrant, administrative, technical and billing contact data described in Section 3, and to transmit it to the registry operator and to our escrow agent. Union law imposes parallel obligations on entities providing domain name registration services. If you do not provide this data we cannot register or maintain a domain name for you, and an existing registration may be suspended or cancelled following a failed accuracy verification.
7. How We Share Your Information
We share personal information in the following categories. The distinction between recipients who act on our instructions and those who do not matters to your rights: we can direct the former, but not the latter.
7.1 Independent controllers
These recipients determine their own purposes and means and do not act on our instructions. We cannot instruct them to delete or restrict data they hold, and their own privacy notices govern what they do with it.
- Registry operators for your domain's TLD, which receive registration data as required to register and maintain the domain.
- ICANN and its designated agents, including the data escrow provider, as required by the RAA and ICANN policies.
- Our payment processor, in respect of the fraud prevention, anti-money-laundering, sanctions screening and financial regulatory purposes it pursues on its own account. For other aspects of payment processing it acts on our instructions and falls under Section 7.2.
7.2 Service providers acting on our instructions
These providers process personal data only on our documented instructions, under contracts meeting Article 28 of the GDPR. They include providers of hosting and infrastructure, authoritative DNS, network security and bot management, payment processing, transactional email, customer support tooling, application error monitoring, and analytics.
You can obtain a current list of these providers, including where each is established, by writing to privacy@orbitfour.com.
7.3 Legal, regulatory and safety disclosures
We disclose personal information to law enforcement, government authorities, courts and other parties where required by valid legal process, to comply with law, to enforce our agreements, or to protect the rights, safety and security of OrbitFour, our users or the public. Where we receive a civil subpoena seeking your personal information, we will use reasonable efforts to notify you before disclosure unless we are prohibited from doing so.
7.4 Corporate transactions
We may disclose personal information to a successor entity in connection with a merger, acquisition or sale of assets, subject to this Policy.
7.5 What we do not do
We do not sell your personal information. We do not share it for cross-context behavioural advertising or targeted advertising. We do not permit third-party advertising networks to collect data through our site.
8. Cookies and Similar Technologies
We use cookies and similar technologies — including data stored in your browser's local and session storage — to operate the site, keep it secure, remember your preferences and understand how the site is used. We do not use third-party advertising cookies, we do not track you across other websites, and we do not share usage data with advertising networks.
The table below lists what we use.
| Name | Type | Set by | Purpose | Duration |
|---|---|---|---|---|
| Session cookie | Cookie | OrbitFour | Keeps you signed in and protects against cross-site request forgery | Session |
phx:theme |
Local storage | OrbitFour | Remembers your light or dark display preference | Until you clear it |
__cf_bm, cf_chl_* |
Cookie | Cloudflare | Bot management and security challenges that protect the site from attack | Up to 30 minutes |
_cfPre_tabId |
Session storage | Cloudflare | Associates a security challenge with your browser tab | Session |
_sab |
Cookie | OrbitFour | First-party analytics identifier, used to measure how the site is used | Until you clear it |
_sab_pv_* |
Session storage | OrbitFour | Prevents the same page view being counted twice | Session |
__stripe_mid |
Cookie | Stripe | Payment fraud prevention | 1 year |
__stripe_sid |
Cookie | Stripe | Payment fraud prevention | 30 minutes |
Our analytics are first-party: the data is collected by us, for us, and is not shared with advertisers or data brokers.
Your choices. You can block or delete cookies through your browser settings, and most browsers let you do this for individual sites. Blocking the session, security or preference items above will stop parts of the site working correctly. You can also use your browser's private browsing mode, which discards this storage when you close the window.
Where the law requires your consent before non-essential storage is placed on your device, we obtain it in the manner required at the time.
9. Data Retention
We retain personal information only as long as necessary for the purposes described in this Policy and for the periods required by ICANN policy and applicable law.
| Category | Retention period | Reason |
|---|---|---|
| Registration contact data | Life of the registration + 2 years | RAA data retention requirements |
| Data escrow deposits | Per the escrow agreement | ICANN escrow specification |
| Account records | Life of the account + 2 years | Contract; defence of legal claims |
| Billing, tax and invoice records | 10 years | Tax and VAT record-keeping obligations |
| DNS and zone configuration | Life of the domain with us | Provision of the service |
| Parking and landing page content | Until you remove it, or 90 days after the service ends | Provision of the service |
| Support tickets | 3 years from closure | Legitimate interest in service quality |
| Abuse reports, content notices and outcomes | 2 years | RAA and DNS abuse obligations; evidence of our decisions |
| Server and security logs | 90 days | Security legitimate interest |
| Marketing suppression list | Indefinite | Necessary to keep honouring your opt-out |
Where a period above conflicts with a legal hold, an active fraud or abuse investigation, or a longer statutory obligation, we retain the data for as long as that requires and no longer.
Backups. Our database is protected by a rolling seven-day point-in-time recovery window. When we delete data, it may persist in that window for up to seven days before expiring automatically. We do not edit backup media selectively, and data you have asked us to delete is not reinstated if a backup is restored.
10. Data Security
We use administrative, technical and physical safeguards designed to protect personal information against loss, misuse and unauthorised access. These include encryption of data in transit and at rest, two-factor authentication available on every account, transfer locks applied by default, role-based access control, logging and monitoring, and free DNSSEC on every domain. We require our service providers to maintain comparable measures.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a personal data breach occurs that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay, and we will notify the competent supervisory authority as required by law.
11. International Data Transfers
We are established in the United States. Personal data relating to you is processed in the United States and, where a registry operator, escrow agent or service provider operates elsewhere, in the countries in which those parties operate.
Our application and its database are hosted in the United States, in the state of Oregon. Traffic to our website passes through a global content delivery and security network. DNS for domains you manage with us is operated by a provider established in the European Union, and application error monitoring is provided by a company established in the Netherlands; data handled by those providers is not transferred outside the EEA by us.
Where we transfer personal data originating in the EEA, the United Kingdom or Switzerland to a country that has not been the subject of an adequacy decision, we rely on:
- the EU-U.S. Data Privacy Framework, the Swiss-U.S. Data Privacy Framework and the UK Extension, where the recipient is certified under them;
- the European Commission's Standard Contractual Clauses (Decision 2021/914), together with the UK International Data Transfer Addendum where United Kingdom data is involved; and
- for the transfers required by ICANN policy — to registry operators and to our data escrow agent — the terms mandated by the Registrar Accreditation Agreement and the applicable Registry-Registrar Agreement.
You may request further information about the safeguards that apply to a particular transfer by writing to privacy@orbitfour.com.
12. Your Privacy Rights
12.1 European Economic Area and United Kingdom
Subject to applicable law, you have the right to:
- access the personal data we hold about you and obtain a copy of it;
- have inaccurate data corrected and incomplete data completed;
- have your data erased in certain circumstances;
- restrict our processing in certain circumstances;
- object to processing carried out on the basis of legitimate interests, and to object at any time to direct marketing;
- receive data you provided to us in a structured, commonly used and machine-readable format, and have it transmitted to another controller where technically feasible;
- not be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you, and to obtain human review of such a decision, as described in Section 4.1;
- withdraw consent at any time where we rely on it, without affecting processing already carried out; and
- lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement.
Because we have no establishment in the Union, the one-stop-shop mechanism does not apply to us and you are not restricted to a single lead authority.
12.2 California
Subject to applicable law, California residents have the right to know what personal information we collect and how we use and disclose it; to access, delete and correct personal information; to opt out of the "sale" or "sharing" of personal information; and to limit the use of sensitive personal information. We do not sell or share personal information as those terms are defined under California law. We will not discriminate against you for exercising your rights. You may use an authorised agent to submit a request.
12.3 How to exercise your rights
Contact privacy@orbitfour.com or write to the postal address in Section 1.
We will verify your request proportionately — usually by asking you to authenticate to your account, or by confirming from the email address on the registration record. We will respond within one month. Where a request is complex or you have made several, we may extend that period by up to two further months and will tell you why within the first month.
Some limits apply and we will always explain which we are relying on:
- We may be required to retain registration data, or to decline erasure, to comply with ICANN policy, the RAA or applicable law.
- A domain cannot be maintained without accurate registrant contact data. A request to erase that data is therefore, in substance, a request to end the registration, and we will explain the consequences and confirm your choice before acting.
- We may decline where an active fraud, abuse or security investigation would be prejudiced, or where complying would adversely affect the rights of others.
13. Age Requirements
Our services are directed to adults. You must be at least 18 years old, or the age of majority in your jurisdiction, to hold an account with us, as set out in our Website Terms of Use. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will take appropriate steps to delete it.
14. Marketing and Communications
We send transactional and service messages — such as expiration reminders and registration data accuracy notices — that you cannot opt out of while you hold an active account or registration, because they are necessary to provide the service or required under the RAA.
You may opt out of marketing emails at any time using the unsubscribe link in those messages or by contacting us. When you opt out we add you to a suppression list, which we keep indefinitely for the sole purpose of continuing to honour your choice.
15. Content You Publish
Where we host a parking page or landing page for you, you decide what appears on it and you remain responsible for that content. We store it and make it available to the public at your request.
Anyone may notify us that content we host is illegal, using the mechanism described in our Registrar Abuse Policy or by using our Report Abuse page. We process the notifier's identity and contact details, and the substance of the notice, in order to assess and act on it. We may remove or disable access to content, or suspend the service, where we conclude it is illegal or breaches our terms.
Where we become aware of information giving rise to a suspicion that a criminal offence involving a threat to the life or safety of a person has taken place or is likely to, we will inform the relevant law enforcement authorities.
16. Third-Party Links
Our site may link to third-party websites and services. We are not responsible for their privacy practices, and we encourage you to review their policies.
17. Changes to This Policy
We may update this Policy from time to time. We will post the updated Policy with a new "Last updated" date. For material changes we will provide additional notice, such as by email or a prominent notice on the site, before they take effect. Where a change requires your consent, we will ask for it rather than infer it from your continued use.
18. Governing Law and Disputes
This Policy is governed by the laws of the State of Michigan, and any dispute relating to it is governed by Section 14 of our Website Terms of Use, to the extent permitted by applicable law.
If you are a consumer habitually resident in the European Economic Area or the United Kingdom, Section 14.5 of those Terms applies to you and prevails over any conflicting provision. Nothing in this Policy or those Terms deprives you of the protection of mandatory provisions of the law of your country of habitual residence, or of your right to bring proceedings in the courts of that country.
19. Related Policies
- Website Terms of Use
- Domain Registration Agreement
- WHOIS Privacy Service Terms
- Prepaid Balance Terms
- Registrar Abuse Policy
- Registrant Rights and Benefits
- Domain Lifecycle Policy
- TLD Requirements
- All legal documents
Version: 2.1.1 · Last Updated: 15 September 2026 · Effective Date: 15 September 2026