Privacy Policy
The personal data HourlyVPS collects, why, how long we keep it and your rights under GDPR, UK GDPR and CCPA/CPRA.
Last updated
In plain English
- White Label Services, LLC, the company behind HourlyVPS, is the controller of the personal data described here. Contact: [email protected].
- We collect what we need to run your account and servers: account details, billing records, server metadata, logs and support messages.
- We do not sell personal information or share it for advertising, and this website uses no analytics or advertising trackers.
- Service providers process data for us: CDN and security, payment processing, email delivery and data-center operations. Ask us for the current list.
- You can access, correct, delete or export your data and object to some uses. Email us to do so.
- We do not look inside your servers. For data you store on them, you are the controller and we act as your processor.
This summary is here to help you read the document. If it differs from the numbered sections, the numbered sections apply.
1. Who we are
The controller of your personal data is White Label Services, LLC, 1308 Coffeen Ave, Sheridan, WY 82801, USA (“we”, “us”), which operates HourlyVPS, the website hourlyvps.com and the customer portal at portal.hourlyvps.com (the “Portal”).
For anything about privacy, including requests to exercise your rights, write to [email protected]. Residents of the European Economic Area, the United Kingdom and Switzerland can contact us at the same address.
2. What this policy covers
This policy covers personal data we handle when you visit hourlyvps.com, create or use an account in the Portal, order or use our Services, contact us or send us an abuse report.
It does not cover the data you store or process on your own servers (“Customer Content”). For Customer Content, you are the controller and we process it only to provide the Services; we do not access it except as described in section 11 of the Terms of Service. Business customers who need a data processing agreement under Article 28 GDPR can request one at [email protected].
3. Personal data we collect
| Category | Examples | Where it comes from |
|---|---|---|
| Account data | Name, email address, company name, postal address, country, phone number if you give one, tax ID, password (stored as a hash), security settings | You |
| Verification data | Information you give us when we ask you to verify your identity or payment method, and the result of the check | You, payment processors |
| Billing and payment data | Top-ups, charges, invoices, account-credit balance, payment method type, limited card details such as brand, last four digits, expiry date and country, cryptocurrency transaction IDs and sending addresses, payment status and fraud signals from processors | You, payment processors |
| Server metadata | Servers you create, plan, location, assigned IP addresses, hostnames, reverse-DNS records, operating-system image, metered hours and resource usage, creation, power and deletion events | Our systems |
| Logs and security data | Portal and API access logs (IP address, time, browser user agent, action), website request logs, and network data such as traffic volumes and flow records used for billing, attack mitigation and abuse detection | Our systems, our CDN and security provider |
| Support and communications | Tickets, emails, contact-form messages and the information in them | You |
| Abuse reports | Name and contact details of the reporter, the report and its evidence, details of the customer concerned | Reporters, our systems |
| Marketing preference | Whether you agreed to receive product news by email | You |
Card numbers are entered on, or sent directly to, our payment processor; we receive only the limited card details listed above. We do not ask for special categories of data, such as health or religious beliefs. Please do not include them in tickets.
4. How we use personal data and our legal bases
Under the EU and UK General Data Protection Regulation (GDPR), we need a legal basis for each use of personal data. These are ours:
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and run your account; provide, meter and bill the Services; give support | Account, billing, server metadata, support | Performance of our contract with you (Art. 6(1)(b)) |
| Process payments, prevent payment fraud and handle chargebacks | Billing, verification, logs | Contract; our legitimate interest in preventing fraud (Art. 6(1)(f)) |
| Verify identity where needed and screen against sanctions lists | Account, verification | Legal obligation (Art. 6(1)(c)); legitimate interest in preventing fraud and abuse |
| Protect the website, the Portal and our network; detect and mitigate attacks; handle abuse reports | Logs and security data, abuse reports, server metadata | Legitimate interest in the security of our Services, our customers and the wider internet; legal obligation where it applies |
| Keep accounting and tax records; answer lawful requests from authorities | Billing, account | Legal obligation |
| Send service notices about maintenance, incidents, billing and changes to our terms | Account | Contract; legitimate interest in keeping customers informed |
| Send product news by email, only if you opted in | Email address | Consent (Art. 6(1)(a)), which you can withdraw at any time |
| Plan capacity and improve the Services using aggregated usage figures | Server metadata | Legitimate interest in running and improving the Services |
| Establish, exercise or defend legal claims | The data relevant to the claim | Legitimate interest |
We need your account and billing data to provide the Services. Without it, we cannot open an account for you.
5. Cookies and similar technologies
This website uses no analytics, advertising or social-media trackers. It relies only on strictly necessary technologies, and on a theme preference stored in your own browser if you choose one. The Portal uses a session cookie so you can log in and place orders. Our Cookie Policy lists them all.
6. Who we share personal data with
We share personal data only as described here.
Service providers process personal data on our behalf, under contract and on our instructions:
- CDN, DNS and security: Cloudflare, Inc., which delivers and protects hourlyvps.com and the Portal and processes request data such as IP addresses and request headers;
- payment processing: card and cryptocurrency payment processors, which also act as independent controllers for their own fraud-prevention and legal obligations;
- email delivery: the provider that sends our account, billing and service emails;
- infrastructure and data-center operations: the infrastructure partner that operates our hardware and network with us, and the data-center facilities in Istanbul and New York that house it;
- professional advisers, such as lawyers and accountants, who are bound by confidentiality.
The current list of service providers is available on request at [email protected].
Authorities. We disclose data when the law requires or allows it, for example in response to valid legal process or to protect someone from death or serious injury. Our Transparency page explains how we handle these requests.
Abuse handling. When we forward an abuse report to the customer concerned, we remove the reporter’s personal details unless the reporter agrees or the law requires otherwise. Copyright notices are usually forwarded in full, because the customer needs them to respond; see our Report abuse page.
Business transfers. If we are involved in a merger, acquisition or sale of assets, personal data may pass to the successor, which must continue to protect it as this policy describes or tell you about any change.
We do not sell personal data and do not share it for cross-context behavioral advertising.
7. International transfers
We are based in the United States, our servers are in Türkiye and the United States, and our service providers may process data in other countries. Your data may therefore be processed outside your own country, including in countries that the EU or the UK does not consider to offer adequate protection.
When we transfer personal data from the European Economic Area, the United Kingdom or Switzerland, we use a lawful transfer mechanism, such as the European Commission’s Standard Contractual Clauses (with the UK Addendum where it applies), or the recipient’s certification under the EU-US Data Privacy Framework where available. You can ask for a copy of the relevant safeguards at [email protected].
8. How long we keep personal data
| Data | How long |
|---|---|
| Account data | While your account is open, then up to 3 years after it is closed, to handle questions, disputes and legal claims |
| Billing, payment and metered-usage records | 7 years after the transaction, for tax and accounting law |
| Verification documents you upload | Up to 90 days after the verification is finished; the result is kept with your account data |
| Server disks, snapshots and their contents | Deleted when you delete the server, or 7 days after a Service ends for another reason, as described in the Terms of Service |
| IP address assignment records (which account used which address, and when) | 2 years, for abuse handling and for legal obligations that may apply to hosting providers where our servers are located |
| Portal and API access logs | 12 months |
| Website request and security logs | Up to 30 days |
| Network flow and attack-mitigation data | Up to 90 days |
| Support tickets and emails | 3 years after the ticket is closed |
| Abuse reports and enforcement records | 3 years after the case is closed |
| Marketing consent | Until you withdraw it, plus a record of the consent and withdrawal for 3 years |
Backups of our own systems, such as the Portal database, may hold copies for up to 30 days longer before they are overwritten. We keep data longer only when the law requires it or when it is needed for a legal claim, and then delete or de-identify it.
9. Security
We protect personal data with technical and organizational measures, including encryption in transit for the website and the Portal, access limited to people who need it, password hashing, logging and network-level attack protection. No system is perfectly secure. If a breach affects your personal data and the law requires us to tell you or a regulator, we will. Our Security page has more detail.
10. Your rights in the EEA, the UK and Switzerland
If the GDPR, the UK GDPR or the Swiss Federal Act on Data Protection applies to you, you have the right to:
- access the personal data we hold about you and get a copy of it;
- have inaccurate data corrected;
- have your data deleted, unless we must keep it, for example billing records under tax law;
- restrict how we use your data in certain cases;
- receive the data you gave us in a machine-readable format and have it sent to another provider (portability);
- object at any time to our use of your data based on legitimate interests, and to direct marketing;
- withdraw consent at any time, without affecting what we did before;
- not be subject to decisions based solely on automated processing that have legal or similarly significant effects (section 13);
- complain to a data-protection authority, in particular in the country where you live or work. In the UK, that is the Information Commissioner’s Office; in Switzerland, the Federal Data Protection and Information Commissioner. We would appreciate the chance to address your concern first.
We answer within one month. For complex or numerous requests, we may extend this by up to two further months, and we will tell you if we do.
11. Your rights under US state privacy laws
This section adds to the rest of this policy for California residents under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA). We handle requests from residents of other US states with comprehensive privacy laws in the same way.
Personal information we collected in the last 12 months
| CCPA category | Examples | Disclosed for a business purpose to |
|---|---|---|
| Identifiers | Name, email address, postal address, IP address, account ID | Service providers listed in section 6 |
| Customer records (Cal. Civ. Code § 1798.80(e)) | Name, address, phone number, limited payment-card details | Payment processors |
| Commercial information | Services ordered, top-ups, charges, usage | Payment processors, infrastructure partner |
| Internet or other network activity | Portal and website logs, network flow data | CDN and security provider |
| Approximate location | Location inferred from IP address (not precise geolocation) | CDN and security provider |
| Sensitive personal information | Account login: username and password | Nobody; used only to give you access to your account |
- Sources and purposes: as described in section 3 and section 4.
- No sale or sharing. We do not sell personal information or share it for cross-context behavioral advertising, and have not done so in the last 12 months. We have no actual knowledge of selling or sharing the personal information of anyone under 16. We honor Global Privacy Control signals as a request to opt out of sale and sharing.
- Sensitive personal information is used only to provide your account, so the right to limit its use does not apply.
- Retention: as described in section 8.
Your rights
- know what personal information we collect, use and disclose, and get a copy of it;
- have it deleted, subject to legal exceptions;
- have inaccurate information corrected;
- opt out of the sale or sharing of personal information (we do neither);
- not be discriminated against for exercising these rights.
You can use an authorized agent. We will ask for the agent’s signed permission and may confirm the request with you directly. We respond within 45 days and may extend this once by another 45 days if we tell you why. If we decline a request, you can appeal by replying to our answer with the word “Appeal”; we decide on appeals within 45 days.
12. How to exercise your rights
- Email [email protected] from the address on your account, or open a ticket in the Portal. Tell us which right you want to use and, if you can, which data it concerns.
- To protect your data, we confirm your identity before acting, usually by checking that you control the account’s email address. We do not ask for more information than we need.
- Requests are free. Where the law allows, we may charge a reasonable fee for, or refuse, requests that are clearly unfounded or excessive.
- You can view and update much of your data yourself in the Portal.
13. Automated checks
When you top up or order, our payment processors and our own systems may run automated checks, such as fraud scoring and sanctions-list matching. If an automated check stops an order or a top-up, you can ask for a person on our team to review it, explain your side and contest the result. We do not use personal data for profiling for marketing.
14. Children
Our Services are for adults aged 18 or over. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact [email protected] and we will delete it.
15. Changes to this policy
We may update this policy. If we make a material change, we will email account holders before it takes effect. The version number and effective date are at the top of this page.
16. Contact
Privacy questions and requests: [email protected]. Post: White Label Services, LLC, 1308 Coffeen Ave, Sheridan, WY 82801, USA. For other legal topics, see our legal documents.