Privacy Policy
Last updated: August 21, 2026 • Compliant with GDPR, CCPA & Global Data Privacy Laws
Policy Sections
At API Hosting, we respect your privacy. We never sell your personal information, server contents, or gaming telemetry data to third-party ad networks. We store data strictly to provision hosting infrastructure, deliver customer support, and safeguard our network against malicious activity.
1. Information We Collect
We collect personal information directly provided by you when registering an account, placing an order, or communicating with technical support:
- Account Details: Full name, email address, password hash, billing address, phone number, and Discord username (if linked).
- Financial & Payment Data: Credit card details, PayPal tokens, and billing transaction histories (processed securely via PCI-DSS compliant third-party payment gateways).
- Technical & Log Data: IP addresses, browser user agent, login timestamps, server configuration metadata, and bandwidth usage statistics.
2. How We Use Your Information
Your data is processed strictly for the following operational and security purposes:
- Automated provisioning and ongoing operation of your game servers, VPS instances, and dedicated nodes.
- Processing invoice payments, renewals, and fraud detection checks.
- Delivering 24/7 customer support responses and critical maintenance notifications.
- Mitigating DDoS attacks, network intrusions, and illegal account access.
- Complying with statutory accounting and tax regulations.
3. Data Storage & Security
We employ defense-in-depth security measures to protect your sensitive personal data and server files:
All website, client portal, and control panel connections use TLS 1.3 encryption. Backups and billing databases are encrypted using AES-256.
Game server instances run in sandboxed containers with strict file system isolation, preventing unauthorized cross-tenant data inspection.
5. Third-Party Services
We partner with trusted third-party service providers to facilitate infrastructure, billing, and communication. All partners are bound by strict Data Processing Agreements (DPAs):
- Payment Gateways: Stripe, PayPal, and Paysafecard for secure checkout processing.
- Infrastructure & Datacenters: Equinix, Digital Realty, and Path.net for physical server hosting and volumetric DDoS mitigation.
- Support & Communications: Zendesk and SendGrid for automated ticket dispatch and billing email notices.
6. Your Rights (GDPR & CCPA)
Under global data privacy laws, you possess the following rights regarding your personal information:
- Right of Access: Request a copy of all personal data held about you in a structured format.
- Right to Erasure ("Right to Be Forgotten"): Request permanent deletion of your account and personal details (subject to statutory tax retention requirements).
- Right to Rectification: Request correction of inaccurate or outdated contact information via the client portal.
7. Data Retention
We retain active customer data for the duration of your active subscription plus 30 days following service cancellation.
Tax, invoicing, and accounting records are retained for up to 7 years in accordance with federal financial compliance obligations. Server access logs and threat security telemetry are purged after 90 days.
8. Contact Us
If you have questions, privacy concerns, or wish to submit a data subject access request (DSAR), please contact our Data Protection Officer (DPO):