Privacy Policy

Last updated: 2 September 2026

Overview

Name Done Ltd (“we”, “us”) operates the Name Done autocomplete API and associated websites at namedone.com, auth.namedone.com, and portal.namedone.com. This policy explains what data we collect, why we collect it, and how we keep it safe.

We are committed to data minimisation. We only collect what is necessary to provide the service, and we do not sell your data to anyone.

Account Data

When you create an account, we store your email address and an authentication password (stored as a salted hash by Amazon Cognito). Your email is used for account verification, password resets, and essential service notifications.

API Usage Data

To operate and protect the service, we log API requests. Each log entry includes your API key identifier, the data type queried, a timestamp, and the response time. We use this data to monitor service health, enforce rate limits, and detect abuse. Query content (what your users type) is not persisted in logs beyond the time needed to serve the request.

Authentication Tokens

When you sign in, we issue authentication tokens stored in cookies scoped to .namedone.com so that the portal can read your session. These cookies contain a signed JWT with your user ID and role. They expire after one hour and are refreshed automatically. No passwords are stored in cookies.

Data We Do Not Collect

  • We do not track your browsing behaviour across other websites.
  • We do not use third-party advertising or analytics trackers.
  • We do not sell or share your data with third parties for marketing.
  • We do not store the text your users type into autocomplete fields beyond the time needed to serve the response.

Data Sources

The autocomplete data we serve is derived from open government data sources. We do not collect personal data from these sources. See our Data Sources page for full attribution.

Infrastructure

All data is stored and processed within AWS in the EU (London) region. Account data is encrypted at rest using AWS KMS. API traffic is served over HTTPS. Access to infrastructure is restricted to authorised personnel and logged.

Data Retention

We retain your account data for as long as your account is active. API usage logs are retained for 90 days for operational purposes, then automatically deleted. You may request deletion of your account and associated data at any time by emailing hello@namedone.com.

Your Rights

Under the UK GDPR, you have the right to access, correct, or delete your personal data, and to object to certain processing. To exercise any of these rights, contact us at hello@namedone.com. We will respond within 30 days.

Children's Privacy

Name Done is a developer tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a minor has created an account, please contact us and we will delete it.

Changes to This Policy

We may update this policy from time to time. Material changes will be notified by email to registered users. The “last updated” date at the top of this page reflects the most recent revision.

Contact

Questions about this policy or your data? Email us at hello@namedone.com.