Skip to content
All plans

Cloud

VPS Hosting Soon
Discord Bot Hosting Soon
Support

Legal

Privacy Policy

Last updated August 2026

This policy covers the personal data GhostNode Ltd holds about you, our customer — your account, your payments, your sign-ins. It is written to be read rather than to be defensible, and everything in it describes what the software actually does. Where it names a retention period or a category of data, that is what is in the database, not an estimate.

It does not cover the data your own server collects about the people who play on it. For that you are the controller and we act on your instructions — see Data on your own server and the Data Processing Agreement.

Who is responsible

GhostNode Ltd, registered in England and Wales under number 17414337, of 66 Paul Street, London, EC2A 4NA, United Kingdom, is the controller of the personal data described here.

Write to dpo@ghostnode.gg about anything in this policy, including a request to see, correct or delete your data. It is a separate address from support on purpose: these requests have statutory deadlines and are handled by a person rather than a queue.

What we collect

What you give us

  • Your name and email address, when you register.
  • Your password, stored only as a one-way hash. We cannot read it, and neither can anybody who takes a copy of the database.
  • Two-step sign in details, if you turn it on: a secret and a set of recovery codes, both encrypted.
  • What you name things — your server names, and anything you type into the panel.
  • What you write to us, in an email or on Discord, and our reply.
  • Your marketing preference, and the moment you gave or withdrew it.

What we record as you use the service

  • Sign-ins — the time, the IP address, the browser and operating system, and the country the IP resolves to. Successful sign-ins only. This is the list you can see yourself on your account page, and it exists so that you can spot somebody else in your account.
  • An audit trail of actions taken on your account and servers, with who did it, when and from what IP. Every state change is written down and attributed — to you, or to the sub-user who actually did it, never anonymously.
  • Emails we sent you — the address, the subject, the time and whether it was delivered. Never the body. A password reset link sitting in a log is an account takeover waiting for a leak, so we do not keep one.
  • Technical logs from the web servers and the application, which include IP addresses. Secrets are stripped before anything is written.

What we get from other people

  • Payment records from Stripe — the amount, the tax, the invoice number, the outcome, and the card's brand and last four digits. We never receive or store a card number. Your card details go from your browser to Stripe and we are told only whether it worked.
  • Fraud signals, where the affiliate programme is involved: a card fingerprint from Stripe that lets us see one card being used across several accounts, without ever holding the card itself.

Under the UK and EU GDPR we have to have a lawful basis for each purpose. Ours are:

  • To provide the service you bought — your account, your servers, billing, support. Basis: performance of a contract.
  • To keep accounts and pay tax — invoices, VAT records, payment history. Basis: legal obligation.
  • To keep the service secure — sign-in records, audit logs, rate limiting, investigating abuse. Basis: legitimate interests, being our interest and yours in an account nobody else can get into and a network nobody is attacking from.
  • To prevent fraud in the affiliate programme — the checks described under Automated decisions. Basis: legitimate interests, in not paying commission on referrals that are somebody referring themselves.
  • To send you service email — provisioning, invoices, suspension warnings, alerts you configured. Basis: performance of a contract. You cannot opt out of these while you have an active account, because they are the service.
  • To send you marketing, if you asked for it. Basis: consent, which you can withdraw at any time from your account page or by clicking unsubscribe. We do not buy lists and we do not email people who have not asked.
  • To respond to a legal request or defend a legal claim. Basis: legal obligation or legitimate interests.

Where we rely on legitimate interests we have weighed them against your rights, and you may object — see Your rights.

What we never do

  • We do not sell your personal data. Not to a data broker, not to an advertiser, not to anybody. There is nothing to opt out of because it does not happen.
  • We do not share it for cross-context behavioural advertising — the thing California's law calls “sharing”. We run no advertising trackers and no analytics that follow you off this site.
  • We do not read your server files except where we need to in order to run the service, act on a report, or help you with something you asked about.
  • We do not store your card number and never see it.

Who else sees it

Only the companies that make the service work, each of them under a contract that limits what they may do with it. Every one is named, with what it does and where it is, on the Sub-processors page — which is the list we keep current rather than a paragraph that goes stale.

Beyond those, we disclose personal data only where we are legally required to, where it is necessary to establish or defend a legal claim, or to a buyer of our business if we are ever sold — in which case we will tell you before it happens. Requests from law enforcement are handled as described in the Abuse & Copyright policy: we check that the request is valid and its scope, and we tell you about it unless we are legally barred from doing so.

Where your data is

Your account, your invoices and your audit trail live on our application server in London, United Kingdom, whichever region your game server is in. Your game server — and therefore its files, its database and its backups — lives in the region you chose when you ordered:

  • London, United Kingdom
  • Amsterdam, Netherlands
  • US East Coast

Some of our suppliers are outside the UK and the EEA, principally in the United States. Where personal data is transferred there, we rely on the UK's International Data Transfer Addendum to the European Commission's Standard Contractual Clauses, or on the Clauses themselves for transfers out of the EEA, together with the additional safeguards those require. Where a supplier is covered by an adequacy decision, we rely on that. You can ask us for details of the mechanism used for any particular supplier and we will tell you.

How long we keep it

WhatHow longWhy
Your account record While your account is open It is the account
Invoices and payment records 6 years after the payment Tax and accounting law, and the limitation period for a claim
Audit trail 24 months Investigating disputes and security incidents
Sign-in records 12 months So you can spot an intrusion, and so we can
Record of emails sent 12 months Proving we told you something we were required to tell you
Server files and databases Until the server is terminated, then a short grace period It is your data and you may want it back
Snapshots taken before a destructive action 24 hours Undoing a mistake, which is only useful immediately

Closing your account

When you ask us to close your account we anonymise it rather than deleting the row. Your name, email address and personal details are emptied out; what remains is the money. Every payment on that account is a financial record we are required to keep for 6 years and it has to stay attached to something.

That is a limit on erasure that the law expressly allows, and we would rather explain it than claim to delete everything and quietly not. Everything that identifies you as a person goes; the invoice history survives without a person attached to it.

We cannot close an account while a server on it is still running, because that would leave you paying for something you can no longer reach. Cancel first, then ask.

Automated decisions

We run a small number of automated checks in the affiliate programme, and you are entitled to know about them rather than to discover them:

  • A referral is blocked automatically where it appears to be somebody referring themselves — the same person, household, card fingerprint or IP address within a short window.
  • Commission is capped automatically at a monthly ceiling, and held for a clearing period before it can be withdrawn.
  • Signups from throwaway email domains are refused at registration.

None of these produces a legal or similarly significant effect on you within the meaning of Article 22 — the worst outcome is a commission not paid — and none of them is profiling for marketing. If one of them has caught you wrongly, write to support@ghostnode.gg and a person will look at it and put it right.

Security

Passwords are hashed and never recoverable. Two-step sign in is available and we recommend it. Secrets such as your Discord webhook are encrypted in the database, described rather than displayed in the panel, and never written to a log. All traffic is over TLS. Access to production systems is limited to people who need it, staff actions are logged and attributed, and staff who sign in as you to help with a problem must give a reason, cannot make a purchase, and leave a record at both ends.

If a breach happens that is likely to risk your rights and freedoms, we will report it to the relevant supervisory authority within 72 hours of becoming aware, and tell you without undue delay where the risk to you is high. That obligation exists under the UK and EU GDPR, and the equivalent regimes in Australia, New Zealand, Singapore, South Korea and India each have their own notification duties which we will meet where they apply.

Your rights

Wherever you live, you can write to dpo@ghostnode.gg and we will handle your request under whichever regime gives you more. We will not charge you, and we will not treat you differently for asking.

United Kingdom and European Economic Area

Under the UK GDPR and the EU GDPR you have the right to: be told what we hold and why; get a copy of it; have it corrected; have it erased, subject to the accounting records described above; have its use restricted; object to processing we base on legitimate interests, including profiling; receive it in a portable, machine-readable format; and withdraw consent at any time where consent is what we relied on.

We respond within one month. If your request is complex we may extend that by two further months and will tell you why within the first month.

You can complain to the UK Information Commissioner's Office at ico.org.uk, or to the supervisory authority in your own EEA country. We would rather you came to us first, but it is your right either way.

United States

If you live in California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another state with a comprehensive privacy law, you have the right to know what we have collected about you and why, to get a copy, to have it corrected, and to have it deleted subject to the records we are required to keep.

You also have the right to opt out of the sale or sharing of personal information and of profiling for decisions with significant effects. We do none of those things, so there is nothing to opt out of — and we honour a Global Privacy Control signal for the same reason: it costs us nothing to respect a preference we already follow.

We do not collect sensitive personal information as those laws define it. We will not discriminate against you for exercising a right. You may appoint an authorised agent to make a request; we will need to verify that they act for you. If we refuse a request you may appeal by replying to our decision, and we will respond to the appeal in writing.

California residents may also request the information required by the “Shine the Light” law; the answer is that we disclosed no personal information to third parties for their own direct marketing purposes.

Australia

We handle personal information in line with the Australian Privacy Principles. You may request access to what we hold and ask for it to be corrected, and we will respond within a reasonable period — ordinarily 30 days. If you are unhappy with how we handled it, write to us first; if that does not resolve it you may complain to the Office of the Australian Information Commissioner. Where a data breach is likely to cause serious harm we will notify you and the OAIC under the Notifiable Data Breaches scheme.

New Zealand

We handle personal information in line with the Information Privacy Principles of the Privacy Act 2020. You may ask for access and correction, and complain to the Office of the Privacy Commissioner. We will notify the Commissioner and you of any privacy breach likely to cause serious harm.

Singapore, Japan, South Korea, India and elsewhere in Asia

If Singapore's Personal Data Protection Act applies to you, you may withdraw consent, request access and request correction, and dpo@ghostnode.gg is the address of the person responsible for our compliance with it.

If Japan's Act on the Protection of Personal Information applies, you may request disclosure, correction, addition, deletion, and the cessation of use or of provision to third parties.

If South Korea's Personal Information Protection Act applies, you may request access, correction, deletion, and suspension of processing, and you may take a dispute to the Personal Information Dispute Mediation Committee.

If India's Digital Personal Data Protection Act 2023 applies, you may request a summary of the data we process and its processing, correction, completion, updating and erasure, and you may nominate somebody to exercise those rights if you cannot. dpo@ghostnode.gg is also the address of our grievance officer for that Act.

Where a comparable law applies elsewhere in Asia or Oceania and gives you a right not listed here, write to us and we will honour it rather than argue about whether we had to.

Data on your own server

If your server records anything about your players — a character table, a ban list, chat logs, connection IPs — that is personal data too, and it is yours. You decide what is collected and why, which makes you the controller. We hold it and act on your instructions, which makes us your processor.

The Data Processing Agreement sets out what each of us must do about it. It applies automatically to every customer, with no signature required.

Two things follow that are easy to miss. Telling your players what you collect — and answering them when they ask for it or ask you to delete it — is your job, not ours; we have no relationship with them. And if a player writes to us directly, we will tell them to speak to you and pass the request on rather than acting on it ourselves.

Cookies

Named individually, with what each one does, on the Cookies Policy. There is no consent banner because there is nothing on this site that needs consent — no advertising, no analytics that follow you, no third-party trackers.

Children

This service is not for children. You must be 16 to hold an account, or 13 with a parent or guardian agreeing and taking responsibility. We do not knowingly collect data from anyone younger, and if we find out we have, we delete it. If you believe a child has given us personal data, write to dpo@ghostnode.gg and we will deal with it.

Changes to this policy

When we change it we update the date at the top. If a change materially affects how we use your data, we email you before it takes effect rather than relying on you noticing a date.


GhostNode Ltd is a company registered in England and Wales, company number 17414337. Registered office: 66 Paul Street, London, EC2A 4NA, United Kingdom. General enquiries support@ghostnode.gg; anything about personal data dpo@ghostnode.gg.

More policies

All policies