Last updated 9 September 2026.
Draft pending legal review. This describes our intended practice and has not yet been reviewed by counsel or checked against GDPR, CCPA or state privacy law obligations.
Account data. Name, email address, company name, phone number, and the password hash. We never store a password in a readable form.
Verification data. Legal entity name, registered address, tax or company registration number, RIR organisation handle, abuse and NOC contacts, and the intended use of the space. Owners and Tenants are both verified before transacting.
Transaction data. Leases, invoices, payment status and payout details. Card numbers are handled by our payment processors and never reach our servers.
Technical data. IP address, browser user-agent, pages visited and actions taken, recorded in an activity log for security and support purposes.
To verify that an Owner controls the space they are listing and that a Tenant is a real organisation; to generate Letters of Authorization, which by their nature name the parties; to create registry objects where required; to bill and pay; to investigate abuse; and to meet our legal obligations.
An Owner and Tenant in a lease see each other's company identity — this is inherent in an authorisation document naming both. Company details appear in registry objects and reassignment records where a registry requires it. Payment processors receive what they need to take payment. We do not sell personal data and do not share it for advertising.
Monitoring queries public DNS blocklists about IP addresses, not about people. Those queries reveal the addresses being checked to the blocklist operator. We query authoritative nameservers directly rather than through public resolvers.
Account and verification data for as long as the account is open, then seven years after closure where retention is required for tax and anti-fraud purposes. Activity logs for twelve months. Lease and invoice records for seven years. Blacklist history for the life of the monitor.
You may ask for a copy of the data we hold about you, ask us to correct it, ask us to delete it where we are not required to keep it, object to processing, or ask for it in portable form. Write to info@ipv4hub.net and we will respond within thirty days.
Deleting an account does not remove records we must retain — an executed authorisation, or an invoice — but we will restrict their use to those purposes.
Traffic is encrypted in transit. Passwords are hashed. Every login requires a one-time code sent to your registered email address. Access to production data is limited to staff who need it. Credentials are held outside the web root and outside version control.
We set a session cookie to keep you logged in. It is required for the site to work and carries no advertising identifier. We do not use third-party advertising or cross-site tracking cookies.
Our systems are located in the United States. If you are in the EEA or UK your data will be transferred there. Appropriate safeguards for those transfers are part of the outstanding legal review noted at the top of this page.
Material changes will be notified by email to registered users. Questions or requests: info@ipv4hub.net.