Privacy Policy
Last updated: 29 July 2026
This policy explains what personal information Impostor Watch collects, why, who we share it with, and the choices you have. Impostor Watch is a service operated by Raine Trading Ltd (trading as Raine Security), a company registered in England & Wales under company number 16869486, whose registered office is at 12 Baywell Close, Solihull, B90 4UR. In this policy "we", "us" and "our" mean Raine Trading Ltd, and we are the data controller for the personal information described here.
The short version
Impostor Watch watches public records — new domain registrations, SSL certificates, DNS, and public breach data — for signs that someone is impersonating your business. To do that we need a small amount of information from you: who you are, which domains and email addresses to watch, and where to send alerts. We don't need, ask for, or want access to your website, inbox or internal systems. We don't sell your data, and we don't use it for advertising.
What we collect
Information you give us
- Account and contact details — your name, your business name, and the email address you sign up and log in with.
- The assets you ask us to monitor — the domains you want watched, and any email addresses you ask us to check against known data breaches and stealer-log dumps.
- Where to send alerts — the notification email address your reports and alerts go to.
- Messages you send us — anything you include when you contact support or fill in the contact form.
Information we generate or collect automatically
- Monitoring results — the lookalike domains, certificates and findings we discover while watching the public record on your behalf, and our risk assessment of them.
- Breach-exposure results — whether an email address you asked us to watch appears in a known breach or credential leak. We use this to alert you; we do not collect or store the leaked passwords themselves for you to view.
- Basic technical logs — standard server logs (such as IP address, timestamp and request path) generated when you use the site or the portal, kept for security and to keep the service running reliably.
Payment information
When you pay, your card details are entered directly into a secure payment form provided by Stripe and are sent straight to Stripe — your full card number never touches our servers. We receive only a payment confirmation and limited billing metadata (for example, that a payment succeeded, the amount, and a card's last four digits) so we can provision your account, issue receipts and manage your subscription.
Cookies and tracking
The Impostor Watch portal uses a small number of strictly necessary cookies to keep you logged in and to keep your session secure. We do not use advertising cookies or third-party analytics/tracking on the site.
Why we're allowed to use your data (lawful bases)
- To provide the service you've asked for and to take payment — performance of a contract with you.
- To check assets you've explicitly asked us to watch — carried out on your instruction as part of that contract; you confirm at sign-up that you own or are authorised to monitor those assets.
- To keep the service secure, prevent misuse and meet our legal obligations — our legitimate interests and legal obligations.
For the separate, small-scale business outreach pilot described in some of our first-contact emails, see our Outreach Privacy Notice.
Who we share your data with
We don't sell your data. We share it only with the service providers we rely on to run Impostor Watch, and only as far as each needs to do its job. These fall into a few categories:
- Payment processing — we use Stripe to take payments, run subscriptions and issue receipts. Stripe receives your name, email and payment details.
- Hosting and infrastructure — the providers who host our servers and deliver and protect our website process service data on our behalf.
- Email delivery — our email provider sends your alerts, reports and account emails, and so processes your notification email address and the message content.
- Breach and exposure checks — we use LeakRadar, operated by Radar Forge SASU, to check only the domains or email addresses you've authorised us to monitor against known credential-exposure records. For the optional domain preview we keep only aggregate employee, third-party and customer-category counts, the provider name and check/expiry times; we do not keep the raw preview response or retrieve identities or passwords for it. LeakRadar describes its core account and monitoring data as hosted in the EU/EEA.
- Other public-record data providers — specialist providers that let us check authorised assets against public records. They receive only the domain or email address needed to run the check.
We choose providers that offer appropriate security and data-protection safeguards, and we share only the minimum each needs. A current list of the specific providers we use is available on request — email [email protected]. We may also disclose information if the law requires it, or to protect our rights, our users or the public.
How long we keep it
We keep personal information only as long as we need it. In general we retain your account data, monitoring history and findings for up to 2 years, which we consider a reasonable period to provide the service, show you how a risk has changed over time, and meet our own legitimate business and record-keeping needs. The optional aggregate credential-exposure preview is cached for 24 hours and its count-only cache is deleted no later than 30 days after it stops being refreshed, or when the customer or watched domain is deleted. After the applicable period — or sooner if you ask us to close your account and delete your data — we delete it or anonymise it, unless we're required to keep something longer by law.
Your rights
If you're in the UK or EU you have the right to access the personal data we hold about you, to have it corrected or deleted, to object to or restrict certain processing, and to data portability. To exercise any of these, email [email protected]. You also have the right to complain to the UK Information Commissioner's Office (ico.org.uk), though we'd appreciate the chance to put things right first.
Security
We take reasonable technical and organisational measures to protect your data, including handling all card payments through Stripe so that card details never reach our systems. No online service can promise perfect security, but we design Impostor Watch to hold as little sensitive data as possible — notably, we never ask for access to your website, email or internal systems.
Changes to this policy
We may update this policy from time to time. When we make material changes we'll update the date at the top and, where appropriate, let you know by email.
Contact us
Questions about this policy or your data? Email [email protected], or write to us at Raine Trading Ltd, 12 Baywell Close, Solihull, B90 4UR.
