1. What this policy covers
This policy explains how Cloud RDP VPS (“we”, “us”) handles personal information when you visit our website, create an account, place an order or use a server. We collect only what we need to run the service.
2. What we collect
- Account details — your name, email address and password (stored as a one-way hash by our authentication provider), plus optional details you add such as a phone number, billing country, company name, Telegram or WhatsApp.
- Orders and payments — the plans you order, amounts, the payment method you chose, the transaction reference, and the proof of payment you upload (an image or PDF).
- Server details — the login details we set up for your server. The password is encrypted before it is stored.
- Support — messages and attachments you send in tickets or through the contact form.
- Technical data — your IP address, browser type and timestamps, used for security, rate limiting and an audit log of important actions.
3. How we use it
- to create and secure your account;
- to take orders, verify payments and deliver and manage your servers;
- to answer support requests;
- to send service emails — order and payment updates, delivery, expiry reminders and ticket replies;
- to prevent fraud and abuse, and to meet our legal and accounting obligations.
We do not sell your personal information and we do not use it for advertising.
6. How we protect it
Server passwords are encrypted before they are stored and are revealed only to you, on request, in your dashboard. Payment proofs are kept in private storage. Access to data is restricted by role, and important actions are written to an audit log. No system is perfectly secure, but we take care to keep yours safe.
7. How long we keep it
We keep your information while your account is active and for as long as we need it to provide the service, resolve disputes, prevent fraud and meet legal and accounting requirements.
8. Your choices
You can ask us to show you the information we hold about you, correct it, or delete it. We can't delete records we are required to keep, and an account with active servers can't be closed until they have expired. To make a request, open a ticket from your dashboard or use our contact page.
9. Where data is processed
Our providers may process data in countries other than the one you live in. We choose providers that protect data appropriately.
10. Children
The service is not intended for anyone under 18, and we do not knowingly collect their information.
11. Changes and contact
We may update this policy; the “Last updated” date above shows the current version. If you have questions, reach us through the contact page.