Legal
Privacy Policy
Privacy Policy
Company details: Legal entity name, company number, registered office, VAT number, and ICO registration (if applicable) are configured by administrators and shown when available. Until configured, treat references to the controller identity as incomplete placeholders — not invented registrations.
1. Who we are
This Privacy Policy explains how Rackstead Hosting ("Rackstead", "we", "us") processes personal data when you visit our websites, create an account, order hosting, or use the control panel and related services (the "Services").
Where company legal details are configured in Admin → Legal & Compliance → Company Details, that entity is the data controller for account and billing data. Contact for privacy enquiries: the privacy email published in Company Details (default intent: [email protected]) or via the control panel support channel.
If a dedicated Data Protection Officer (DPO) is appointed, contact details will be published in Company Details. No DPO details are invented here.
2. Scope
This policy covers personal data processed by Rackstead as controller for our platform. Where you host customer or end-user content on a VPS or related service, you typically act as controller of that content and Rackstead may act as a processor under our Data Processing Addendum (DPA) where that relationship applies.
3. Personal data we collect
Depending on how you use the Services, we may process:
Account and profile
- Name, email address, password hash (we do not store plaintext passwords)
- Optional company name, phone, billing address, country, VAT number
- Preferred currency and locale
- Email verification status
- Role and admin permission assignments (staff accounts)
Authentication and security
- Login history (IP address, user agent, success/failure)
- Two-factor authentication status (TOTP secrets are stored encrypted/protected and are never exported in privacy downloads)
- OAuth provider account identifiers when you choose Google, GitHub, or Discord sign-in/linking (only if those integrations are configured)
- Discord user id and username if you link Discord
- API key metadata (name, prefix, scopes, last used) — full key secrets are not recoverable for export
- SSH public key fingerprints and names you upload (private keys are never accepted or stored)
Billing and commerce
- Orders, plan selections, regions, OS choices, billing cycle
- Invoices and payment status
- Wallet balance and wallet transactions
- Payment provider references (e.g. Stripe/PayPal ids) when those providers are configured — card numbers are handled by the payment provider, not stored by Rackstead
- Affiliate/referral codes and related commission metadata if you use affiliate features
- Promo redemptions
Service metadata
- VPS and game server metadata (names, hostnames, status, region, assigned IPs when allocated, resource usage metrics)
- Domains and DNS records you manage through the platform
- Support tickets and messages
- Notifications and notification preferences
- Activity and audit logs of control-panel actions
- Abuse reports you submit or that relate to your services
- Dedicated server quote requests you submit
Technical data
- IP addresses and browser user agents for security, rate limiting, and fraud monitoring
- Cookie and similar technology data as described in our Cookie Policy
Communications
- Service, security, and billing emails
- Marketing emails only where you have opted in (never pre-ticked)
We do not invent analytics, advertising pixels, or chat widgets that are not present in the product. If those are added later, this policy and the Cookie Policy will be updated.
4. Purposes and lawful bases
| Purpose | Examples | Typical lawful basis | | --- | --- | --- | | Provide the Services | Account, provisioning, control panel | Contract | | Billing and tax records | Invoices, payments, wallet | Contract / Legal obligation | | Security and fraud prevention | Login logs, rate limits, fraud alerts | Legitimate interests / Legal obligation | | Support | Tickets, abuse handling | Contract / Legitimate interests | | Service communications | Verification, invoices, security alerts | Contract / Legitimate interests | | Marketing | Product news (opt-in) | Consent (PECR/UK GDPR as applicable) | | Legal compliance | Responding to lawful requests | Legal obligation |
You may object to processing based on legitimate interests where applicable. Essential service and security messages cannot be disabled via marketing preferences.
5. Recipients and processors
We share data with subprocessors needed to operate the platform (payments, email, OAuth providers, domain registrar, infrastructure). See /legal/subprocessors for the register of providers that are actually configured or clearly integrated. We do not sell personal data.
Staff/administrators with appropriate permissions may access customer data to operate support, billing, abuse, and security functions. Access is logged where the platform records audit events.
6. International transfers
If personal data is transferred outside the UK, we will use appropriate safeguards required by UK data protection law. Specific transfer mechanisms for each subprocessor must be confirmed during supplier/legal review and recorded in the subprocessor register.
7. Retention
We retain categories of data for different periods. Account and billing records are kept while your account is active and for a further period needed for legal, tax, and dispute purposes. Exact day counts are not invented here — see Admin retention metadata and /legal/privacy updates after business/accountant review. Consent, legal acceptance, invoice, and abuse records may need longer retention than general profile data.
8. Your rights
Under UK GDPR you may have rights to: access, rectification, erasure (where applicable), restriction, objection, portability (where applicable), and withdrawal of consent. You may complain to the Information Commissioner's Office (ICO).
Use Settings → Privacy & Data to export data, manage marketing/cookie preferences, and submit privacy requests. We will not delete records we are legally required to keep (for example certain invoices) solely because an erasure request is filed; such requests enter a review workflow.
9. Cookies
See our Cookie Policy.
10. Children
The Services are intended for adults and businesses capable of entering a contract. We do not knowingly collect data from children.
11. Changes
Material changes will be published as a new document version. Where re-acceptance is required, the control panel will prompt you.
12. Contact
Privacy contact: as configured in Company Details, or via control panel support.