NameBest.com

Privacy policy, in the order it matters

Applies tonamebest.com and the NameBest console
ControllerNameBest, reachable at [email protected]
UpdatedSeptember 2026
Written forThe GDPR, and readable without a lawyer

The short version

NameBest generates business names from a brief and checks each one against the domain registry. To do that we hold your email address, your briefs and your shortlists, plus the ordinary technical records needed to run and secure the service.

We do not sell personal data, we do not use your naming briefs to train anything, and we do not run advertising trackers on the product. You can ask for your data at any time, and you can ask us to delete it.

Who is responsible for your data

NameBest, the operator of namebest.com, is the controller of the personal data described here. We can be reached at [email protected], and that address is answered by a person rather than by a ticket queue.

If you are in the European Economic Area or the United Kingdom, the rights described under "Your rights" below are the ones the General Data Protection Regulation gives you, and this policy is written to be read against it.

What we collect

Account data. The email address you sign up with, an optional name, the four digit code used to confirm the address, and the settings on your account.

Naming data. The briefs you write, the names generated from them, the availability answers those names received, and the shortlists you keep.

Billing data. Where you take a paid plan, the plan, its status and the records needed for invoicing and tax. Card details are handled by the payment provider and are never stored on our servers.

Technical data. IP address, browser type, pages requested, and the campaign or referrer you arrived from. This is used for security, abuse prevention and understanding traffic in aggregate.

Correspondence. If you write to us, the message and our reply.

Why we process it, and on what basis

To provide the service you asked for: generating names, running registry lookups, keeping your shortlists, and operating your account. The lawful basis is performance of a contract with you.

To bill you and to keep the records tax law requires. The basis is contract, and legal obligation for the retention part.

To keep the service working and safe: rate limits, abuse prevention, security logging, and aggregate analytics on how pages are used. The basis is our legitimate interest in running a service that is not overwhelmed or defrauded.

To answer you when you write to us, which is also legitimate interest, and to send service email about your account, which is contract.

We do not use your data for advertising and we do not build profiles of you for anyone else.

Your naming briefs

A naming brief describes a product or a company that nobody has announced yet, and it is treated accordingly.

A brief you submit is sent to our server and from there to the language model that writes candidates. It is not used to train that model, it is not used to train anything of ours, it is not sold, and it cannot appear in another customer's results.

The worked example that runs when a page loads is generated locally from a fixed brief and involves no model call at all. The registry lookups on that example are real.

Who we share it with

Hosting and infrastructure, which stores the application and the database.

The language model provider that generates name candidates, which receives the brief and returns the names. It does not receive your identity.

Domain registries, which receive the name being looked up through RDAP. A registry query contains a domain name and nothing about you.

Email delivery, which sends confirmation codes and service messages, and the payment provider, which handles cards and invoices.

We may disclose data where the law requires it, or to protect the rights and safety of our users and of the service. We do not sell personal data, and we do not share it for anyone else's marketing.

International transfers

Some of the providers above operate outside the European Economic Area. Where personal data is transferred out of the EEA or the United Kingdom, the transfer is covered by the European Commission's standard contractual clauses or an equivalent lawful mechanism.

How long we keep it

Account data and naming data are kept while the account exists, and are deleted when you delete the account or ask us to delete them.

Billing records are kept for as long as tax and accounting law requires, which is longer than the account itself and is not something we can shorten on request.

Technical logs are kept for a short period for security and abuse investigation, and then removed or aggregated so they no longer identify anyone.

Security

Traffic is encrypted in transit, including the registry lookups. Access to production data is limited to the people who need it to run the service, and the marketing site is kept separate from production systems.

No system is perfectly secure, so the more useful commitment is that we collect as little as we can get away with: an email address, your briefs, and the records needed to bill and secure the service. We do not claim any certification we do not hold.

Your rights

You can ask for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, ask us to restrict or object to processing based on legitimate interest, and ask for your data in a portable form.

You can withdraw consent where we relied on it, and you can unsubscribe from any non-essential email at any time. Service email about your own account continues while the account exists.

To exercise any of these, write to [email protected]. We answer within one month, which is the period the GDPR sets, and usually much faster. If you believe we have handled your data badly, you may complain to your national supervisory authority.

Cookies and analytics

We use the cookies needed to keep a session working and to protect forms against cross site request forgery. Those are strictly necessary and cannot be switched off without breaking the site.

Analytics is used in aggregate to understand which pages are read and where visitors arrive from. There is no advertising pixel on the product surface and no third party session recording.

Children

The service is for business use and is not directed at children. We do not knowingly collect data from anyone under sixteen. If you believe we have, write to us and it will be deleted.

Changes to this policy

When this policy changes materially we update the date at the top of the page and, where the change affects you directly, we say so by email. Continuing to use the service after a change means the updated policy applies.

Contact

Anything about this policy, or any request about your own data, goes to [email protected]. The terms of service cover the rest of the relationship.