Privacy Policy
Effective Date: August 30, 2026 · Version 1.2
1. Overview & Commitment
hostnetvps.com ("we", "us", "our") is committed to safeguarding your privacy and protecting the security of your account, billing data, and server credentials. This Privacy Policy details the types of information we collect, how it is handled, and the strict security practices we enforce to prevent unauthorized access.
We do not sell, rent, or trade your personal or operational data to third parties under any circumstances.
2. Information We Collect
We collect information strictly necessary to provide done-for-you compute services:
- Account Identification: Email address, encrypted authentication hashes, and user profile information.
- Billing & Payment Data: Stripe customer tokens, subscription status, and billing invoice history. We do not store raw credit card numbers on our servers.
- Server & Infrastructure Metadata: Server hostname, IP address, provisioned specifications, and status logs.
- Security Audit Logs: Timestamped records of credential reveal requests (including user ID, IP address, and server ID accessed) and authentication events.
- Support Ticket Communications: Messages, technical logs, and timestamps submitted through our in-dashboard ticketing system.
3. Encryption & Credential Vault Architecture
Server root credentials, temporary passwords, and private SSH keys are never stored in plain text. All secrets are encrypted at rest using AES-256-GCM authenticated encryption.
Database security is enforced via strict Row Level Security (RLS) policies with default-deny permissions. Credentials can only be decrypted through server-side authenticated routines requiring user password re-authentication. Every credential reveal writes an immutable record to our audit log.
4. Use of Information
We use the collected information exclusively to:
- Hand-provision, configure, and maintain your compute instances and DGX Spark memory attachments.
- Process subscription payments and generate accurate billing records via Stripe.
- Verify your identity and authenticate session access to the customer portal and credential vault.
- Respond to support tickets and coordinate hardware change requests.
- Calculate and enforce our 99.9% Uptime SLA and apply pro-rata service credits.
5. Third-Party Service Providers (Sub-Processors)
We partner with select infrastructure and billing vendors that meet rigorous security and privacy standards:
- Stripe: Payment processing, card validation, and subscription management.
- Supabase (PostgreSQL): Encrypted database storage, user authentication, and row-level access control.
- Resend: Transactional email delivery for account verification and critical service alerts.
6. Data Retention & Customer Rights
Account data is retained for the duration of your active subscription. Following account termination, server instances and associated credential vaults are purged. In accordance with GDPR and international data protection laws, customers have the right to request access to, rectification of, or deletion of their personal data by opening a support ticket in their dashboard.
7. Cookies & Session Tokens
We use secure, HTTP-only authentication cookies strictly necessary to maintain authenticated sessions in the customer portal and admin interface. We do not employ third-party tracking pixels or behavioral advertising cookies.
8. Contacting the Privacy Team
If you have questions regarding this Privacy Policy or wish to exercise data rights, please submit an authenticated ticket via /dashboard/support.