Skip to content
Legal

Privacy Policy

Exactly what data NimbusVPS collects, why, how long it is kept, and what happens when someone asks for it — as an enumerated list, not a statement of intent.

The short version
We store your email address, the transaction reference for each invoice, and the technical configuration of your server. That is the complete list. Access logs have 0-day retention — they are not kept. We do not sell, share or profile.

1. The operating principle

Data that does not exist cannot be breached, subpoenaed, sold, or leaked by a departing employee. Our privacy design therefore starts from collection rather than protection: the strongest control over a field is not creating it.

What follows is an enumerated list rather than a statement of intent, because a specific list is falsifiable and a statement of intent is not.

2. What we collect

Data you provide:

  • Email address. Required. Used to send credentials, renewal notices, service announcements and abuse correspondence. Never used for marketing without a separate opt-in, and never shared.
  • Server configuration. Specification, location, operating system, hostname and SSH public key if supplied. Required to build what you bought.
  • Support correspondence. Retained for 12 months so we can reference an earlier ticket, then deleted.

Data generated by operating the service:

  • Payment transaction references. Produced by self-custodial wallets. We receive a transaction identifier and an amount. We do not receive wallet addresses, balances or any identity information.
  • Resource and network counters. Aggregate CPU, memory, disk and port-level traffic totals, for capacity planning, billing accuracy and DDoS detection. No payload, no per-destination data.
  • Control panel access logs. 0-day retention — they are written and discarded, not stored.

Data we never collect: legal name, postal address, identity documents, phone number, date of birth, payment card details, tax identifiers, company registration, browsing history, and the content of your server's traffic.

3. What we do not log

Explicitly, and as a matter of technical configuration rather than policy alone:

  • No deep packet inspection on customer traffic.
  • No traffic mirroring or capture.
  • No NetFlow or sFlow records linked to customer identity.
  • No DNS query logging on our resolvers.
  • No inspection of customer disk contents.
  • No third-party analytics, advertising pixels or session recording on this website.

nimbusvps.com runs no third-party JavaScript at all. There is no Google Analytics, no Meta pixel, no session replay tool and no advertising tag. The site sets no tracking cookies, which is why you have never seen a cookie banner here.

4. Retention

DataRetention
Email addressWhile you have an active service, then 90 days
Invoices and transaction references7 years, where required by accounting law
Server configurationUntil 7 days after service ends
Server disk contentsSecurely erased 7 days after service ends
Control panel access logs0 days (not kept)
Support tickets12 months
Aggregate traffic counters90 days, not linked to identity

5. Who we share with

We do not sell, rent or trade customer data. We have no advertising relationships. We do not participate in data cooperatives.

Data reaches third parties in exactly three circumstances:

  • self-custodial wallets receives the invoice amount and reference in order to process payment. It does not receive your server configuration.
  • Datacenter operators know that a rack contains our equipment. They do not have customer-level data.
  • Courts with jurisdiction over the relevant facility, on receipt of a valid order — see below.

We respond only to legally valid orders issued by a court with jurisdiction over the datacenter holding the server in question.

We refuse, and log: informal requests by email or telephone; requests from agencies of countries other than the hosting jurisdiction that have not gone through mutual legal assistance; civil demands unaccompanied by a court order; and any request whose scope exceeds what the order actually compels.

Where we receive a valid order we notify the affected customer unless the order itself prohibits notification, and where it does we seek permission to notify once any gag period expires.

In practice the answer to most requests is that the requested data does not exist. Counts are published in the transparency report once a reporting quarter has closed; none has yet, so that page currently carries the method and an empty table.

7. Your rights

You may at any time request a copy of the data we hold about you, request its correction, or request its deletion. Email [email protected] from the address on the account. We respond within 30 days and there is no charge.

The realistic scope of such a request is small: an email address, a list of invoices, and a server configuration. Deletion of the email address while a service is active means we can no longer contact you and cannot verify future requests, so it takes effect at the end of your term rather than immediately.

8. Security

Data at rest in our billing systems is encrypted. Access to production systems requires hardware security keys and is limited to named engineers. Off-site snapshot storage is encrypted at rest and stored in a different jurisdiction from the server it protects.

Security issues can be reported to [email protected]. We have not published an OpenPGP key yet, so ask on that address for a confidential channel rather than assuming one. We do not pursue researchers acting in good faith.

Questions about this document?

Email [email protected]. We would rather answer a question before you buy than argue about a clause afterwards.

NimbusVPS · Registered as an International Business Company. The registered company name is not published here yet. The name previously shown could not be reconciled with the jurisdiction and form of incorporation stated elsewhere on this site, so it was withdrawn, and it goes back only from the incorporation record.