I paid for WHOIS privacy on a domain registered through GreenCloudVPS (the "protected" tier, not the free one). Six months later, a colleague mentioned my home address was visible in some "historical WHOIS archive."
Turns out GreenCloudVPS's privacy service—run by a third party called VelaShield—had a six-month exposure window. When I verified my identity for a UDRP defense (which I won. Long story), they temporarily removed privacy protection. The "temporary" flag failed. My real data sat exposed for 187 days. It was scraped by multiple archive services.
I discovered this when someone mailed a printed photo of my house to my house. With a note about the domain.
VelaShield offered me free credit monitoring. I asked about their data retention policy. They cited "internal procedures." I asked about the six-month window. They stopped responding.
Has anyone else seen this specific failure mode? (I am particularly interested in whether GDPR article 17 erasure requests would apply to historical WHOIS scrapers. I suspect not, but one tries.)
I have since transferred everything to KnownHost with double privacy layers. Not sure it helps.