Domain Registrar WHOIS Privacy Comparison
This matrix compares documented identity collection, registration-data treatment, retention, reporting, and transfer controls; it does not test providers or name a preferred path.
/* Not legal advice. This page is research, not compliance guidance. */ /* */
Registrar privacy is a chain of collection, publication, disclosure, and control
A WHOIS privacy label alone does not answer what a domain path collects, what registration data it publishes or redacts, who can receive a disclosure, or which transfer controls apply.
This comparison keeps those questions separate. Its frozen roster contains four registrar paths and one custom-domain mail path that depends on an external registrar. The final row remains in the matrix because it represents a real way a reader may use an alias domain, but registrar-only fields stay documented as not applicable instead of being borrowed from whichever registrar supplies the domain. That boundary prevents a mail service from being presented as a registrar and prevents one provider's controls from being assigned to another.
The table follows the path from account entry to domain control. Signup identifiers, payment identifiers, and later verification triggers describe different collection moments. Operating entity, retention, and deletion describe a different layer: who publishes the relevant terms and what those documents say about defined records. WHOIS redaction, a privacy or proxy identity, and RDAP treatment describe related but non-equivalent registration-data mechanisms. Transfer locks describe control mechanics, while source availability, assessment records, and request reporting describe three distinct forms of accountability evidence.
Every displayed value comes from a current persisted cell for the named row and attribute. Product, plan, region, platform, claim type, source class, source URL, capture date, and observation version remain attached to that cell. A typed unknown therefore reports the evidence state for one field; it is not filled from another field and is not converted into a favorable or unfavorable product conclusion.
The privacy-tool comparison methodology explains the evidence labels, correction path, and alphabetical-by-operating-entity display order used here. The related email-alias comparison covers the address layer that may sit above an alias domain. Neither page turns masking or redaction into a claim that every underlying actor stops collecting identity information.
What each path collects at signup, purchase, and later verification
Signup identifiers, payment identifiers, and later verification triggers are three separate comparison fields because they describe different actors, workflows, and moments of collection.
The signup field reports only the identifiers and collecting actors tied by the captured source to account creation or initial use. The payment field separately reports the trigger, identifier type, requiredness, collecting actor, retained-by field, plan, region, and exceptions documented for a purchase or related review. The later-verification field reports a later event and the additional identifier requested when the source establishes both. A statement in one column never supplies a missing value in another.
This separation matters because a path can have more than one actor. The visible brand, legal operating entity, payment participant, registrar, registry, and mail provider are not assumed to be interchangeable. The matrix preserves the actor named by each cell. When a source does not identify the actor, plan, region, or platform, the missing element remains typed as unknown rather than being inferred from the surrounding product description.
The row for the custom-domain mail path keeps its own account and plan requirements in these columns. It does not inherit the signup or payment requirements of an external registrar. Conversely, the registrar rows do not inherit requirements from the mail path. The table records only what the exact current cell establishes for its own product tuple.
These columns document published evidence, not a walkthrough of account creation. No account was created, no payment was made, and no later-verification event was triggered for this page. A requirement described in a captured document remains a vendor-stated claim at the scope printed with the cell; it is not upgraded into an independently observed result.
| Jurisdiction | Signup identifiers | Payment identifiers | Later verification |
|---|---|---|---|
| Cloudflare RegistrarCloudflare Registrar says its agreement is governed by California law, without regard to conflict-of-law principles.source | Cloudflare Registrar lists a minimum of two letters for first name.source | Cloudflare Registrar requires credit-card information to pay registrar fees unless an Enterprise Subscription Agreement Order Form or Insertion Order provides otherwise.source | Cloudflare Registrar says ICANN requires registrant email verification for domains purchased through it; unverified or expired verification causes a domain hold and replacement of nameservers, which are restored after verification is completed.source |
| GandiGandi's domain-registration terms identify Gandi SAS as the French registrar and describe it as a simplified joint stock company.source | Gandi says account creation requires choosing a username, email address, and password.source | Gandi says a user may register a credit card through the account for automatic debit, while card numbers are processed by its partner bank rather than collected or stored by Gandi.source | Gandi says it may request proof of identity when an order is placed to limit fraud.source |
| NamecheapNamecheap's terms identify Namecheap, Inc., its subsidiaries, and its sister companies collectively as Namecheap.source | Namecheap's signup form requests first name, last name, email address, username, and password.source | Namecheap says payment methods may include a valid credit or debit card, electronic check, PayPal, Bitcoin, or another method it accepts, while it may require a particular payment means or a change of payment provider.source | Namecheap's terms require government-issued photo identification or government-issued business identification, plus anything else it deems necessary, to verify identity.source |
| PorkbunPorkbun says Porkbun LLC's Domain Name Registration Agreement governs domain-registration and related services obtained from it.source | Porkbun says it may collect information relating to the creation of an account, such as an email address, phone number, mailing address, fax number, username, and password.source | Porkbun says it may collect personal data when products or services are purchased or a domain transfer is initiated, including, for example, a first and last name, mailing address, postal code, email address, phone number, payment account such as PayPal or Stripe, or credit-card information.source | Porkbun says it requires photo-ID verification for a subset of new accounts based on geographic regions and other signals where verification can help combat potential abuse.source |
| Proton MailProton AG operates the services and, being domiciled in Switzerland, is governed by the laws and regulations of Switzerland.source | Proton says no personal information is necessary to create an account and an external email address may be provided for notifications or password recovery.source | Proton relies on third parties to process credit-card, PayPal, and Bitcoin transactions, shares necessary payment information with them, and retains only the name and last four digits rather than full credit-card details.source | Proton may request Proton Captcha, email, or SMS verification for some sensitive operations besides account creation, and temporarily saves provided IP addresses, email addresses, and phone numbers to send a code and for anti-spam purposes.source |
Source: 5 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.
Field definitions
- Signup identifiers
- Identifiers, requiredness, collecting actor, plan, region, and platform stated for signup or initial use.
- Payment identifiers
- Trigger, identifier type, requiredness, collecting actor, retained-by field, plan, region, and exceptions stated by the current cell.
- Later verification
- A later trigger, requested identifier, requesting actor, and scope stated by the current cell.
Who operates the path and what its documents say about retention and deletion
Operating jurisdiction, retention, and deletion are separate fields, so an account-deletion statement does not establish that every registration, billing, legal, registry, or mail record is erased.
The operating-entity column identifies the legal name and the jurisdictional details supported by the current cell. Incorporation, governing law, hosting location, customer location, registry location, and top-level-domain policy are not treated as synonyms. If the source establishes one and not another, the table prints the supported field and preserves the other as unknown.
Retention is reported at the grain the cell supplies: data category, controller, trigger, stated duration, and exception. A duration tied to one category is not generalized to every record associated with the path. An exception stays connected to the rule it qualifies. When a document uses a relative or non-numeric period, the table preserves that wording instead of estimating a date or converting it into a universal schedule.
Deletion is also narrower than erasure of an entire domain history. The deletion column reports the initiation path, completed-erasure statement, exceptions, timeframe, and controller that the cell supports. A documented way to close an account does not answer whether a registry, billing provider, legal archive, mail system, or other actor retains a separate record. The matrix does not combine those actors unless the captured source does so.
A missing retention period or completion statement remains an evidence gap or verified absence under the stored marker. It is never rendered as immediate deletion, zero retention, or proof that a record does not exist. The result is a scoped reading of published terms rather than a promise about all data connected to a domain path.
| Jurisdiction | Operating entity | Retention | Deletion |
|---|---|---|---|
| Cloudflare RegistrarCloudflare Registrar says its agreement is governed by California law, without regard to conflict-of-law principles.source | Cloudflare Registrar says its agreement is governed by California law, without regard to conflict-of-law principles.source | Cloudflare Registrar says it stores personal information consistently with its stated business purposes or as long as needed to fulfill and comply with legal obligations, with retention varying by several factors.source | Cloudflare Registrar says people may email [email protected] to request access, correction, update, portability, deletion, restriction, or objection regarding their personal information, and says it will respond within 30 days.source |
| GandiGandi's domain-registration terms identify Gandi SAS as the French registrar and describe it as a simplified joint stock company.source | Gandi's domain-registration terms identify Gandi SAS as the French registrar and describe it as a simplified joint stock company.source | Gandi says Personal Data is kept no longer than necessary for its collection and processing purposes, with a maximum retention period defined for each processing purpose.source | Gandi says account deletion can be requested through its customer support form.source |
| NamecheapNamecheap's terms identify Namecheap, Inc., its subsidiaries, and its sister companies collectively as Namecheap.source | Namecheap's terms identify Namecheap, Inc., its subsidiaries, and its sister companies collectively as Namecheap.source | Namecheap says ICANN requires registrars to retain mandated Whois information for two years after a domain expires or the registrant relationship ends, whether or not a privacy service protects it.source | Namecheap instructs users seeking account closure to email [email protected] with the account username, Support PIN, and reason for closure.source |
| PorkbunPorkbun says Porkbun LLC's Domain Name Registration Agreement governs domain-registration and related services obtained from it.source | Porkbun says Porkbun LLC's Domain Name Registration Agreement governs domain-registration and related services obtained from it.source | Porkbun says it retains information while an account is active, as needed to provide services, or for other purposes in its Privacy Policy, and ceases retaining or associating personal data as soon as it is reasonable to assume retention no longer serves its collected purpose or legal or business needs.source | Porkbun says confirming account deletion with the account password submits the account to its deletion queue, logs the user out, and redirects to the Porkbun homepage.source |
| Proton MailProton AG operates the services and, being domiciled in Switzerland, is governed by the laws and regulations of Switzerland.source | Proton AG operates the services and, being domiciled in Switzerland, is governed by the laws and regulations of Switzerland.source | Proton temporarily saves provided IP addresses, email addresses, and phone numbers for verification-code delivery and anti-spam purposes; if saved permanently, the data is stored only as a cryptographic hash.source | Proton says deleting a Proton Account permanently deletes the account and all its data from Proton's systems with no recovery path.source |
Source: 5 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.
Field definitions
- Operating entity
- The legal operating entity and jurisdictional details stated by the current cell.
- Retention
- Data category, controller, trigger, duration, and exceptions stated by the captured source.
- Deletion
- Initiation path, completed-erasure statement, exceptions, timeframe, and controller stated by the cell.
What WHOIS redaction, a privacy proxy, and RDAP each mean in the captured documents
WHOIS redaction, privacy or proxy identity, and RDAP treatment are different documented fields, and a value in one column does not determine either of the others.
The WHOIS-redaction column records the default treatment, protected fields, eligibility, top-level-domain scope, plan, included cost, and exceptions supported by the exact cell. It does not mean the registrar failed to collect the underlying registrant data. It also does not state what a registry, payment actor, dispute process, lawful request, or other access channel can obtain.
The privacy-proxy column records the service name, provider legal name, documented role, contact or forwarding fields, eligibility, top-level-domain scope, and terms locator supported by the captured evidence. Redacted output and substituted proxy data are not merged into one label. If the document does not establish a proxy actor or field, the comparison leaves that element unknown.
The RDAP column remains separate because it records whether RDAP is documented, displayed fields, redacted fields, eligibility, top-level-domain scope, the stated WHOIS distinction, and the documentation locator. The page does not assume that an RDAP response duplicates a WHOIS display. It reports the statement stored for each path and leaves an unsupported relationship between the two systems unresolved.
Registrar-only fields for the custom-domain mail path remain documented as not applicable because that path uses a separately obtained domain and an external registrar. The not-applicable label is a boundary, not a missing-research shortcut and not a claim about whichever registrar the reader may choose. Across all rows, a verified absence means the declared documents did not disclose the field under the capture method; it does not prove that no feature, artifact, disclosure route, or capability exists.
| Jurisdiction | WHOIS redaction | Privacy or proxy identity | RDAP treatment |
|---|---|---|---|
| Cloudflare RegistrarCloudflare Registrar says its agreement is governed by California law, without regard to conflict-of-law principles.source | Cloudflare Registrar provides personal-data redaction for WHOIS information when the registry permits it.source | Cloudflare Registrar says WHOIS redaction removes most contact information categorized as personal data, including registrant name, email address, and postal address, and displays “Data Redacted” in those fields.source | Cloudflare Registrar describes RDAP as a standard for querying domain contact and nameserver information for all registered domains.source |
| GandiGandi's domain-registration terms identify Gandi SAS as the French registrar and describe it as a simplified joint stock company.source | Gandi says its default option hides personal data in public WHOIS, while state, country, an anonymized email address, and company name where applicable remain visible and all other information displays “redacted for privacy”.source | Gandi says its default option replaces the user's email address in public WHOIS and, where possible, at the registry with an anonymized email address.source | Gandi says the Whois service will eventually be replaced by RDAP, which implements differentiated access according to the quality of the requesters.source |
| NamecheapNamecheap's terms identify Namecheap, Inc., its subsidiaries, and its sister companies collectively as Namecheap.source | Namecheap says it provides privacy protection by default for the full set of WHOIS information, including registrant, administrative, and technical contacts.source | Namecheap says it selected WithHeldForPrivacy as its third-party provider of WHOIS Privacy Services.source | Namecheap says its database query returns publicly available information, including RDAP Terms of Service and ICANN-required data, for a Namecheap-registered domain.source |
| PorkbunPorkbun says Porkbun LLC's Domain Name Registration Agreement governs domain-registration and related services obtained from it.source | Porkbun says its free WHOIS Privacy service is enabled by default and does not show actual contact information in a WHOIS query or send it to the registry.source | Porkbun says that, for domains that support it, it publishes Private By Design, LLC as the registrant in the public WHOIS database instead of the customer's real information, while important communications related to the domain name are forwarded to the customer through Private By Design.source | Except for TLDs that do not support it, such as country-code top-level domains, Porkbun says it does not publish personal data to RDAP unless the customer permits it or a registry policy requires it, with notice at purchase when disclosure is required.source |
| Proton MailProton AG operates the services and, being domiciled in Switzerland, is governed by the laws and regulations of Switzerland.source | To use a custom domain with Proton Mail, you must have a custom domain, such as yourdomain.com, which can be purchased from a domain name registrar, and a paid Proton plan; all paid plans support adding custom domains.source | To use a custom domain with Proton Mail, you must have a custom domain, such as yourdomain.com, which can be purchased from a domain name registrar, and a paid Proton plan; all paid plans support adding custom domains.source | To use a custom domain with Proton Mail, you must have a custom domain, such as yourdomain.com, which can be purchased from a domain name registrar, and a paid Proton plan; all paid plans support adding custom domains.source |
Source: 5 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.
Field definitions
- WHOIS redaction
- Default treatment, protected fields, eligibility, TLD scope, plan, cost treatment, and exceptions stated by the cell.
- Privacy or proxy identity
- Service name, provider legal name, documented role, contact or forwarding fields, eligibility, TLD scope, and terms locator stated by the cell.
- RDAP treatment
- Whether RDAP is documented, displayed fields, redacted fields, eligibility, TLD scope, WHOIS distinction, and documentation locator stated by the cell.
Transfer locks are control mechanisms, not privacy verdicts
A transfer lock describes a documented control state and its activation or removal path; it does not establish how much identity data a provider collects or exposes.
The transfer-lock field keeps the documented mechanism, default state, activation path, removal path, duration, top-level-domain scope, plan, and transfer restrictions together. Those elements answer how the captured document describes a control around domain movement. They are not combined with WHOIS, RDAP, proxy, retention, or reporting fields to produce an overall quality judgment.
A lock can be described at more than one scope or stage, so the cell's qualifiers remain load-bearing. A statement about a default does not establish every later state. A removal path does not establish that removal is immediate, costless, available for every domain, or free of another restriction unless the same cell supplies those details. An unspecified duration or exception remains unknown rather than being filled from a general transfer rule.
The custom-domain mail path keeps a documented not-applicable value here because the external registrar, not the mail path, supplies the domain-transfer controls. The comparison does not select an external registrar for that row or import a lock from another row. That keeps the table useful for comparing complete paths without assigning registrar capabilities to a service that does not provide them.
This column is therefore read independently. It can help identify the control mechanics described for a path, but it does not answer whether a path minimizes collection, prevents lawful disclosure, changes registry obligations, or reduces account linkage. Those questions remain in their own sourced columns.
| Jurisdiction | Transfer lock |
|---|---|
| Cloudflare RegistrarCloudflare Registrar says its agreement is governed by California law, without regard to conflict-of-law principles.source | Cloudflare Registrar cautions that ICANN rules prohibit a domain transfer in specified circumstances.source |
| GandiGandi's domain-registration terms identify Gandi SAS as the French registrar and describe it as a simplified joint stock company.source | Gandi says most extensions have a transfer-protection lock and a domain cannot be transferred while the lock is enabled.source |
| NamecheapNamecheap's terms identify Namecheap, Inc., its subsidiaries, and its sister companies collectively as Namecheap.source | Namecheap says it may place a Registrar Lock that prevents domain-name services from being transferred without authorization, though it is not required to do so.source |
| PorkbunPorkbun says Porkbun LLC's Domain Name Registration Agreement governs domain-registration and related services obtained from it.source | Porkbun says a domain registration may not be transferred to another registrar during the first 60 days after its initial registration takes effect.source |
| Proton MailProton AG operates the services and, being domiciled in Switzerland, is governed by the laws and regulations of Switzerland.source | To use a custom domain with Proton Mail, you must have a custom domain, such as yourdomain.com, which can be purchased from a domain name registrar, and a paid Proton plan; all paid plans support adding custom domains.source |
Source: 5 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.
Field definitions
- Transfer lock
- Lock type, default state, activation and removal paths, duration, TLD scope, plan, and transfer restrictions stated by the cell.
Source availability, audit records, and request reporting answer different accountability questions
Public source artifacts, assessment records, and lawful-request reporting are three distinct evidence types, and none is an overall trust badge for a domain path.
Source availability records the component, repository or artifact locator, version or release locator, and license that the current cell establishes. A public repository for one component does not establish that every service component, registrar workflow, policy system, or infrastructure layer is public. The matrix preserves the named component and scope instead of broadening it into a product-wide claim.
The assessment-record column reports the assessment date, assessor, scope, access, and report locator stated in the captured evidence. A vendor-published assessment reference remains vendor-stated unless the cell carries a different admitted claim type. Its presence does not convert every product statement into an independently tested result, and its absence does not prove that no assessment exists.
Request reporting records the published period, jurisdiction, unit, scope, and counts only when the cell supplies them. Requests, orders, accounts, identifiers, disclosures, and challenged matters are not assumed to be interchangeable units. A process statement is not a count, and a count does not fully describe a process. When a report is not disclosed under the declared document search, the comparison preserves that verified absence instead of printing zero.
The two verified absences in these evidence fields retain their exact typed labels and explanations. They describe what the declared primary documents did not disclose under the capture method. They do not establish a closed source base, the nonexistence of an assessment, or the absence of lawful requests. The private phone-number comparison applies the same separation to another identifier layer.
| Jurisdiction | Source availability | Assessment record | Request reporting |
|---|---|---|---|
| Cloudflare RegistrarCloudflare Registrar says its agreement is governed by California law, without regard to conflict-of-law principles.source | Unknown Verified absenceNot disclosed in the captured primary source.source | Cloudflare Registrar describes SOC 2 Type II as a security-compliance attestation created by independent third-party auditors who validate and document Cloudflare's commitment to security.source | Cloudflare Registrar says it provides WHOIS records for its registrar customers in response to legitimate access seekers under ICANN's WHOIS data-disclosure requirements.source |
| GandiGandi's domain-registration terms identify Gandi SAS as the French registrar and describe it as a simplified joint stock company.source | Gandi describes gandi.cli as an archived command-line interface to Gandi.net products using the public API.source | Gandi says BSI certifies its management systems and provides downloads for ISO 22301:2019 and ISO 27001:2022 certificates and the associated ISO 27001:2022 Statement of Applicability.source | Gandi says its second transparency report covers February 18, 2025, through December 31, 2025.source |
| NamecheapNamecheap's terms identify Namecheap, Inc., its subsidiaries, and its sister companies collectively as Namecheap.source | Namecheap's terms prohibit reverse engineering, decompiling, or attempting to uncover source code and state that the source code and its organization are Namecheap's exclusive property.source | Namecheap says it works to protect customers with comprehensive domain and account security.source | Namecheap says law enforcement seeking customer identity or account information in a criminal matter must mail or serve Namecheap, Inc. with a valid U.S. subpoena.source |
| PorkbunPorkbun says Porkbun LLC's Domain Name Registration Agreement governs domain-registration and related services obtained from it.source | Porkbun says its API module is deprecated, provided as-is as an example for managing DNS records, and no longer maintained.source | Unknown Verified absenceNot disclosed in the captured primary source.source | Porkbun says it complies with lawful U.S. law-enforcement requests supported by a valid subpoena, warrant, or court order.source |
| Proton MailProton AG operates the services and, being domiciled in Switzerland, is governed by the laws and regulations of Switzerland.source | GitHub's record for the ProtonMail/WebClients repository gives its address as github.com/ProtonMail/WebClients.source | Proton custom-domain mail's account.protonmail.com, beta.protonmail.com, and calendar.protonmail.com web applications were subject to black-box and white-box penetration testing from April 22 through May 14, 2021.source | Proton Mail reports 9,301 legal orders received in 2025, including 988 contested orders and 8,313 orders complied with.source |
Source: 5 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.
Field definitions
- Source availability
- Named component, repository or artifact locator, version, release locator, and license stated by the cell.
- Assessment record
- Assessment date, assessor, scope, access, and report locator stated by the cell.
How to read this matrix without turning it into a ranking
Read each cell as a dated, scoped record of vendor-published or public-repository evidence, not as a score, rank, preferred path, product test, or prediction of current behavior.
The roster and thirteen attributes were fixed before the comparison was written. Rows appear in alphabetical order by the operating entity recorded in the cells. Inclusion, order, detail, or source availability does not express an endorsement. The page supplies no score, rank, best label, highlight, shortlist, or recommendation, and it carries no affiliate parameter.
Each cell should be read with its product, plan, region, platform, claim type, source class, source URL, capture date, and observation version. The capture date states when the document was collected; it does not promise that a policy, interface, product, or repository remains unchanged. A vendor-stated cell describes the captured vendor document. A public-repository cell describes the bounded artifact it names. Neither label silently becomes independent performance evidence.
Unknown and not-applicable values preserve different boundaries. A gap means the captured evidence did not settle the field. A verified absence means the declared primary documents did not disclose it under the capture method. Documented not applicable means the field does not belong to the described path at that scope. None of those labels should be rewritten as no, none, unsupported, zero, or proof that the underlying thing cannot exist.
The matrix does not establish that WHOIS redaction prevents registrar collection, registry processing, RDAP access, lawful disclosure, payment processing, or account linkage. It does not establish that closing an account erases every registration or billing record. It also does not treat the custom-domain mail path as a registrar; registrar-only controls remain with the external registrar a reader actually uses.
The privacy-tool comparison methodology and corrections hub is the canonical location for the evidence labels and correction channel. This matrix remains bounded to the five-row, sixty-five-cell evidence set described by this version.
How to read Unknown
- Unknown: Verified absence
- The captured authority was searched and shows no such rule or filing. No value is printed because the absence is the finding. The reason and the authority are printed beside the badge.
- Unknown: Not yet verified
- The captured sources did not settle this field yet. No value is printed, not even an earlier one. The reason is printed beside the badge, and an authority is linked only when one was supplied.