1. The operating principle
Data that does not exist cannot be breached, subpoenaed, sold, or leaked by a departing employee. Our privacy design therefore starts from collection rather than protection: the strongest control over a field is not creating it.
What follows is an enumerated list rather than a statement of intent, because a specific list is falsifiable and a statement of intent is not.
2. What we collect
Data you provide:
- Email address. Required. Used to send credentials, renewal notices, service announcements and abuse correspondence. Never used for marketing without a separate opt-in, and never shared.
- Server configuration. Specification, location, operating system, hostname and SSH public key if supplied. Required to build what you bought.
- Support correspondence. Retained for 12 months so we can reference an earlier ticket, then deleted.
Data generated by operating the service:
- Payment transaction references. Produced by self-custodial wallets. We receive a transaction identifier and an amount. We do not receive wallet addresses, balances or any identity information.
- Resource and network counters. Aggregate CPU, memory, disk and port-level traffic totals, for capacity planning, billing accuracy and DDoS detection. No payload, no per-destination data.
- Control panel access logs. 0-day retention — they are written and discarded, not stored.
Data we never collect: legal name, postal address, identity documents, phone number, date of birth, payment card details, tax identifiers, company registration, browsing history, and the content of your server's traffic.
3. What we do not log
Explicitly, and as a matter of technical configuration rather than policy alone:
- No deep packet inspection on customer traffic.
- No traffic mirroring or capture.
- No NetFlow or sFlow records linked to customer identity.
- No DNS query logging on our resolvers.
- No inspection of customer disk contents.
- No third-party analytics, advertising pixels or session recording on this website.
nimbusvps.com runs no third-party JavaScript at all. There is no Google Analytics, no Meta pixel, no session replay tool and no advertising tag. The site sets no tracking cookies, which is why you have never seen a cookie banner here.
4. Retention
| Data | Retention |
|---|---|
| Email address | While you have an active service, then 90 days |
| Invoices and transaction references | 7 years, where required by accounting law |
| Server configuration | Until 7 days after service ends |
| Server disk contents | Securely erased 7 days after service ends |
| Control panel access logs | 0 days (not kept) |
| Support tickets | 12 months |
| Aggregate traffic counters | 90 days, not linked to identity |
5. Who we share with
We do not sell, rent or trade customer data. We have no advertising relationships. We do not participate in data cooperatives.
Data reaches third parties in exactly three circumstances:
- self-custodial wallets receives the invoice amount and reference in order to process payment. It does not receive your server configuration.
- Datacenter operators know that a rack contains our equipment. They do not have customer-level data.
- Courts with jurisdiction over the relevant facility, on receipt of a valid order — see below.
6. Legal requests
We respond only to legally valid orders issued by a court with jurisdiction over the datacenter holding the server in question.
We refuse, and log: informal requests by email or telephone; requests from agencies of countries other than the hosting jurisdiction that have not gone through mutual legal assistance; civil demands unaccompanied by a court order; and any request whose scope exceeds what the order actually compels.
Where we receive a valid order we notify the affected customer unless the order itself prohibits notification, and where it does we seek permission to notify once any gag period expires.
In practice the answer to most requests is that the requested data does not exist. Counts are published in the transparency report once a reporting quarter has closed; none has yet, so that page currently carries the method and an empty table.
7. Your rights
You may at any time request a copy of the data we hold about you, request its correction, or request its deletion. Email [email protected] from the address on the account. We respond within 30 days and there is no charge.
The realistic scope of such a request is small: an email address, a list of invoices, and a server configuration. Deletion of the email address while a service is active means we can no longer contact you and cannot verify future requests, so it takes effect at the end of your term rather than immediately.
8. Security
Data at rest in our billing systems is encrypted. Access to production systems requires hardware security keys and is limited to named engineers. Off-site snapshot storage is encrypted at rest and stored in a different jurisdiction from the server it protects.
Security issues can be reported to [email protected]. We have not published an OpenPGP key yet, so ask on that address for a confidential channel rather than assuming one. We do not pursue researchers acting in good faith.