Privacy Policy

Effective Date: January 1, 2025 · Last Updated: September 24, 2026

1. Introduction

Tools.BD ("we," "us," or "our") operates the website https://tools.bd (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our free network intelligence tools, including DNS lookup, WHOIS/RDAP lookup, ASN lookup, IP address lookup, and network prefix analysis.

By accessing or using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this Privacy Policy, please do not access the Service.

We are committed to protecting your privacy and being transparent about the data we process. Our tools are designed to be used without requiring user accounts, registration, or the submission of personal information.

2. Information We Collect

2.1 Information You Provide

When you use our tools, you voluntarily submit the following types of data for analysis:

  • Domain names — You enter domain names (e.g., example.com) to perform DNS health checks, WHOIS lookups, and email security analysis.
  • ASN numbers — You enter Autonomous System Numbers (e.g., AS17644) to retrieve network intelligence data including prefixes, peers, upstreams, and downstreams.
  • IP addresses — You enter IP addresses (e.g., 8.8.8.8) to perform ASN lookups, geolocation, and reverse DNS checks.
  • Network prefixes — You enter CIDR prefixes (e.g., 103.14.23.0/24) to analyze network blocks and RPKI validation status.
  • Contact information — If you contact us via email, we may receive your email address and any information you choose to provide in your message.

2.2 Information Collected Automatically

When you access the Service, we automatically collect certain information:

  • IP address — Your IP address is used for rate limiting (20 requests per minute) to prevent abuse and ensure fair usage for all visitors. It is stored temporarily in Redis cache for up to 1 minute and is not permanently logged with personal identifiers.
  • Usage data — We log the type of tool used (domain scan, ASN lookup, IP lookup, prefix lookup), the query entered, your country (derived from IP), and the timestamp. This data is used for aggregate statistics and is not linked to your identity.
  • Browser and device information — Standard HTTP headers including user agent string are processed by our web server for security and compatibility purposes.

2.3 Cookies and Tracking Technologies

We use the following cookies and tracking technologies:

  • Theme preference cookie — A local storage value remembers your dark/light mode preference. This is stored entirely on your device and is not transmitted to our servers.
  • Google Analytics — We use Google Analytics (measurement ID: G-7YJK6FWYLE) to understand how visitors use our site. Google Analytics uses cookies to collect information such as visit frequency, pages viewed, and referring websites. This data is anonymized and does not personally identify you. Google Analytics data is retained for 26 months.

We do not use advertising cookies, social media tracking pixels, or any other third-party tracking technologies beyond Google Analytics.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • To provide our services — Processing your domain, ASN, IP, and prefix queries to deliver analysis results.
  • To prevent abuse — Using IP-based rate limiting to protect the Service from automated abuse and ensure availability for all users.
  • To improve our services — Analyzing aggregate usage patterns to understand which tools are most popular and how we can improve them.
  • To display public content — Showing recent public domain scans on our homepage and maintaining an index of scanned ASNs for community benefit.
  • To enable sharing — Generating shareable report links when you explicitly request them (only when you click "Share Report").
  • To communicate with you — Responding to your inquiries if you contact us via email.
  • To comply with legal obligations — We may use or disclose information where required by law or to protect our rights.

We do not sell, rent, or trade your personal information to third parties.

4. Data Storage and Retention

4.1 Domain Scan Results

  • Public scans — Domain scan results are stored in our PostgreSQL database for up to 30 days, after which they are automatically deleted. Public scans may appear in search results, on our homepage, and in our sitemap.
  • Private scans — When you use the "Private scan" option, results are not stored in our database. They are returned to you immediately and then discarded.
  • Shared reports — If you generate a share link, the scan data associated with that token is retained for 30 days. After expiration, the share link becomes invalid.

4.2 ASN Data

  • ASN intelligence data (organization name, country, prefixes, peers, upstreams, downstreams, WHOIS, RPKI) is stored permanently in our database to enable fast lookups.
  • This data is automatically refreshed every 24 hours to ensure accuracy.
  • ASN data is sourced from public registries (RIPE Stat, Regional Internet Registries, PeeringDB) and does not contain personal information.

4.3 IP and Prefix Lookups

  • IP address and prefix lookup results are cached in Redis for 30 minutes for performance, then automatically discarded.
  • No permanent records of individual IP or prefix lookups are maintained.

4.4 Rate Limiting Data

  • IP-based rate limit counters are stored in Redis for 1 minute, then automatically cleared.
  • No permanent record of rate limit events is maintained.

4.5 Request Logs

  • Aggregate usage statistics (tool type, query, country, timestamp) are stored for analytics purposes.
  • Individual request logs are retained for a limited period and do not contain personally identifiable information beyond IP addresses.

5. Third-Party Services

We use the following third-party services to operate and improve the Service:

  • Google Analytics — Website traffic analysis. Google Analytics collects anonymized usage data. You can opt out by installing the Google Analytics Opt-Out Browser Add-on. Google's Privacy Policy.
  • RIPE Stat — We query RIPE Network Coordination Centre's API for ASN, prefix, and routing data. RIPE Stat.
  • Regional Internet Registries (RIRs) — We query ARIN, RIPE NCC, APNIC, AFRINIC, and LACNIC WHOIS/RDAP servers for domain and ASN registration data.
  • PeeringDB — We query PeeringDB for network peering and exchange point data. PeeringDB Privacy Policy.
  • Routinator — We query rpki.zorn.ltd (powered by Routinator) for RPKI/ROA validation data.
  • DNS resolvers — We query public DNS resolvers (Google, Cloudflare, Quad9, OpenDNS, etc.) for DNS propagation testing. These queries do not contain your personal information.
  • Let's Encrypt — Provides SSL/TLS certificates for HTTPS encryption. Let's Encrypt Privacy Policy.
  • OpenStreetMap — Used on ASN detail pages to display geographic maps. Map tiles are loaded from OpenStreetMap servers. OSMF Privacy Policy.

These third-party services have their own privacy policies. We encourage you to review their policies independently.

6. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • Encryption — All data transmitted between your browser and our servers is encrypted using TLS/SSL (HTTPS). We use automatic HTTPS provided by Caddy with Let's Encrypt certificates.
  • Security headers — We enforce strict security headers including X-Content-Type-Options, X-Frame-Options, X-XSS-Protection, Referrer-Policy, and Permissions-Policy.
  • Rate limiting — IP-based rate limiting prevents automated abuse and brute-force attacks.
  • Input validation — All user input is validated, sanitized, and escaped before processing or storage.
  • Access control — Our database and server infrastructure are protected by firewalls and access controls. Only authorized personnel have server access.
  • Regular updates — We keep our software dependencies and server operating system updated with the latest security patches.

While we strive to protect your information, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security.

7. Your Rights and Choices

You have the following rights regarding your data:

  • Private scans — Use the "Private scan" option to prevent your domain scan results from being stored in our database.
  • Data deletion — You may request deletion of any scan data associated with your queries by contacting us at info@tools.bd. We will process deletion requests within 30 days.
  • Opt out of analytics — You can disable Google Analytics by installing the Google Analytics Opt-Out Browser Add-on or by enabling "Do Not Track" in your browser settings.
  • Cookie control — You can control cookies through your browser settings. Disabling cookies may affect the theme preference feature but will not impact core functionality.
  • Access and portability — You may request a copy of any data we hold about you by contacting us.
  • Right to object — You may object to our processing of your data by contacting us, and we will cease processing unless we have compelling legitimate grounds.

To exercise any of these rights, please contact us at info@tools.bd.

8. Children's Privacy

Our Service is not directed to individuals under the age of 13 (or the applicable age of consent in your jurisdiction). We do not knowingly collect personal information from children. If you are a parent or guardian and you become aware that your child has provided us with personal information, please contact us at info@tools.bd. If we become aware that we have collected personal information from a child without verification of parental consent, we will take steps to remove that information from our servers.

In the United States, we comply with the Children's Online Privacy Protection Act (COPPA). We do not knowingly collect personal information from children under 13. In the EU/EEA and UK, the minimum age varies by member state (typically between 13 and 16).

9. International Data Transfers

Our servers are located in the European Union. If you access the Service from outside the EU, your information may be transferred to, stored, and processed in the EU. By using the Service, you consent to the transfer of your information to the EU, which may have different data protection laws than your country of residence.

For transfers from the EEA/UK, we rely on adequacy decisions, Standard Contractual Clauses (SCCs), or other approved transfer mechanisms where required by applicable law.

10. Regional Privacy Rights

10.1 European Union & EEA (GDPR)

If you are located in the European Economic Area (EEA), the General Data Protection Regulation (EU) 2016/679 ("GDPR") applies to our processing of your personal data.

Legal basis for processing:

  • Legitimate interests (Article 6(1)(f) GDPR) — We process data for rate limiting, abuse prevention, and service improvement based on our legitimate interest in maintaining a secure and functional service.
  • Consent (Article 6(1)(a) GDPR) — Google Analytics tracking is based on your consent. You can withdraw consent at any time.
  • Performance of a contract (Article 6(1)(b) GDPR) — Processing your queries is necessary to provide the Service you requested.

Your rights under the GDPR:

  • Right of access (Article 15) — request a copy of your personal data
  • Right to rectification (Article 16) — request correction of inaccurate data
  • Right to erasure (Article 17) — request deletion of your personal data ("right to be forgotten")
  • Right to restriction of processing (Article 18) — request restriction of processing
  • Right to data portability (Article 20) — request transfer of your data in a structured, machine-readable format
  • Right to object (Article 21) — object to processing based on legitimate interests
  • Right to withdraw consent (Article 7(3)) — withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal
  • Right to lodge a complaint (Article 77) — file a complaint with your local Data Protection Authority (DPA)

To exercise these rights, contact our Data Protection Contact at info@tools.bd. We will respond within 30 days as required by Article 12(3) GDPR.

10.2 United Kingdom (UK GDPR)

If you are located in the United Kingdom, the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018 ("DPA 2018") apply to our processing of your personal data.

The UK GDPR retains the same core principles and individual rights as the EU GDPR. Your rights under the UK GDPR include all the rights listed in Section 10.1 above.

Key differences:

  • The UK GDPR is governed by the laws of England and Wales.
  • The supervisory authority is the Information Commissioner's Office (ICO). You have the right to lodge a complaint with the ICO.
  • International data transfers from the UK rely on UK International Data Transfer Agreements (IDTAs) or adequacy decisions made by the UK Secretary of State.

We also comply with the Privacy and Electronic Communications Regulations 2003 (PECR) regarding cookies and electronic communications.

10.3 United States

If you are a resident of the United States, the following federal and state privacy laws may apply:

Federal Law:

  • Children's Online Privacy Protection Act (COPPA) — We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will delete it promptly.
  • CAN-SPAM Act — If we send commercial emails (which we currently do not), we will comply with the CAN-SPAM Act requirements including opt-out mechanisms.

State Privacy Laws:

  • California (CCPA/CPRA) — The California Consumer Privacy Act, as amended by the California Privacy Rights Act, grants California residents rights including: the right to know what personal information is collected; the right to delete personal information; the right to opt-out of the sale or sharing of personal information; the right to correct inaccurate personal information; the right to limit use of sensitive personal information; and the right to non-discrimination. We do not sell or share personal information.
  • Virginia (VCDPA) — The Virginia Consumer Data Protection Act grants Virginia residents rights including: access, correction, deletion, data portability, and the right to opt out of targeted advertising and data sales. We do not sell personal data or process data for targeted advertising.
  • Colorado (CPA) — The Colorado Privacy Act grants Colorado residents similar rights including access, correction, deletion, portability, and opt-out of targeted advertising and data sales. We honor universal opt-out mechanisms recognized under Colorado law.
  • Connecticut (CTDPA) — The Connecticut Data Privacy Act provides comparable rights to those under the Virginia VCDPA, including access, correction, deletion, and opt-out rights.
  • Utah (UCPA) — The Utah Consumer Privacy Act grants Utah residents rights to access, delete, and port personal data, and to opt out of targeted advertising and data sales.
  • Texas (TDPSA) — The Texas Data Privacy and Security Act grants Texas residents rights including access, correction, deletion, data portability, and opt-out of targeted advertising and data sales.
  • Oregon (OCPA) — The Oregon Consumer Privacy Act provides Oregon residents with rights to access, correct, delete, and port personal data, and to opt out of targeted advertising and data sales.
  • Montana (MCDPA) — The Montana Consumer Data Privacy Act provides similar rights to those under the Virginia VCDPA.

We do not sell personal information, process data for targeted advertising, or profile users for automated decision-making. To exercise your state privacy rights, contact us at info@tools.bd. We will respond within 45 days as required by applicable state law.

10.4 Bangladesh

Tools.BD operates under the .bd country code top-level domain (ccTLD), which is administered by the Bangladesh Telecommunications Company Limited (BTCL) under the authority of the Ministry of Posts, Telecommunications and Information Technology (MoPTIT) and the Bangladesh Telecommunication Regulatory Commission (BTRC).

The following Bangladeshi laws and regulations are applicable to the Service and our data processing practices:

  • Digital Security Act 2018 (DSA) — We comply with the provisions of the Digital Security Act 2018 regarding data protection, unauthorized access, and digital offenses. We take reasonable measures to prevent unauthorized access to our systems and data. Under Section 32 of the DSA, unauthorized access to computer systems or data is a punishable offense, and we implement appropriate security measures to protect against such access.
  • Information and Communication Technology Act 2006 (ICT Act) — As amended, the ICT Act 2006 governs electronic transactions, data protection, and cyber offenses in Bangladesh. We comply with the relevant provisions regarding electronic data processing and storage.
  • Right to Information Act 2009 — We respect the spirit of transparency promoted by the Right to Information Act and endeavor to provide clear information about our data practices through this Privacy Policy.
  • BTCL Domain Registration Policies — As a holder of a .bd domain, we comply with BTCL's domain registration policies, terms, and conditions, including requirements for accurate registration information and acceptable use of the domain.
  • BTRC Regulations — We comply with applicable Bangladesh Telecommunication Regulatory Commission regulations regarding internet services and data handling.

Your rights as a user in Bangladesh:

  • You may request information about what data we collect and how it is processed.
  • You may request correction of inaccurate data or deletion of your data.
  • You may file a complaint with BTRC or the relevant authorities if you believe your data protection rights have been violated.
  • Under the Digital Security Act 2018, you have the right to report any misuse of your personal data to the law enforcement authorities.

If you are a Bangladeshi user and have concerns about data processing, please contact us first at info@tools.bd. If you are not satisfied with our response, you may escalate your complaint to:

  • Bangladesh Telecommunication Regulatory Commission (BTRC)btrc.gov.bd
  • Bangladesh Telecommunications Company Limited (BTCL)btcl.gov.bd

10.5 Other Jurisdictions

If you are located in a jurisdiction not specifically listed above, you may still have data protection rights under your local laws. We will honor any verifiable data access, correction, or deletion requests to the extent required by applicable law. Please contact us at info@tools.bd to exercise your rights.

11. Do Not Track Signals

Some browsers offer a "Do Not Track" (DNT) feature that signals to websites that you do not want to have your online activity tracked. We honor DNT signals and will disable Google Analytics tracking for users who have DNT enabled in their browser.

Some US states (including California, Colorado, and Connecticut) require businesses to honor universal opt-out mechanisms such as the Global Privacy Control (GPC). We recognize and honor GPC signals as a valid opt-out request.

12. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

  • EU/EEA: Notify the relevant supervisory authority within 72 hours and affected individuals without undue delay, as required by Articles 33 and 34 of the GDPR.
  • UK: Notify the Information Commissioner's Office (ICO) within 72 hours and affected individuals without undue delay, as required by the UK GDPR and DPA 2018.
  • Bangladesh: Notify the BTRC and affected users in accordance with the Digital Security Act 2018 and applicable BTRC regulations.
  • US states: Notify affected residents in the timeframe required by applicable state data breach notification laws (typically 30-60 days depending on the state).

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date at the top. You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

For significant changes, we may also display a notice on our homepage or send an email notification (if you have contacted us previously).

14. Open Source Status

This project is not open source. The source code is proprietary and not publicly available for use, modification, or redistribution. This Privacy Policy applies to the hosted service at tools.bd only.

15. Governing Law and Jurisdiction

This Privacy Policy shall be governed by and construed in accordance with the laws of the jurisdictions in which we operate, including:

  • Bangladesh — As the operator of a .bd ccTLD domain registered through BTCL, we are subject to Bangladeshi law, including the Digital Security Act 2018, the ICT Act 2006, and applicable BTRC regulations.
  • European Union — For users in the EEA, the GDPR applies to our processing of personal data. Any disputes may be referred to the relevant Data Protection Authority.
  • United Kingdom — For UK users, the UK GDPR and DPA 2018 apply. Disputes may be referred to the ICO.
  • United States — For US users, applicable federal and state privacy laws apply as described in Section 10.3.

Any disputes arising from or relating to this Privacy Policy shall be resolved through good-faith negotiation. If a resolution cannot be reached, disputes shall be submitted to the competent courts of the applicable jurisdiction.

16. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

We aim to respond to all privacy-related inquiries within 7 business days.