Privacy Policy
Last updated: 6 October 2026
1. Who is responsible
The data controller is Bytewave OÜ (Estonia), the company operating GHosting. To exercise any of your rights or ask questions, see contact.
2. What we collect and why
- Account data — your email address and a hashed password (never the password itself). Needed to run your account and reach you about your servers. Legal basis: performance of contract.
- Orders and invoices — what you bought and when. Legal bases: performance of contract and our legal accounting obligations.
- Payment data — handled entirely by Stripe. We receive confirmation of payment and the last digits of your card for reference; we never see or store full card numbers.
- Support messages — the content of tickets you open, so we can help you. Legal basis: performance of contract.
- Server data — the game files, configuration and logs of your rented server, processed only to provide the hosting service.
- Usage analytics — cookieless page views and allowlisted browser actions, including the page path, referrer host, campaign tags and an approximate device category (desktop, mobile, tablet or unknown) derived from browser request headers. We retain a daily rotating salted visitor hash and, when a visitor is signed in, an account link so we can exclude internal traffic. We do not retain IP addresses or full browser headers for analytics. A separate aggregate report groups this data by device category. Legal basis: legitimate interest in understanding site usage.
- Order context — a coarse device category for the request that created an order or trial, and for a real Checkout session when one is successfully issued. We retain the session start time and category with the order to report aggregate checkout and confirmed-purchase counts. Simulated and automatic renewal payments are recorded separately and are not assigned a current purchaser device. Campaign tags may be retained with the original order and carried onto renewals for the same container. These records are account-linked and are kept with the order and accounting records.
- Trial abuse prevention — a salted, one-way hash of the claimant network is retained for up to 30 days to enforce the rolling trial allowance. The raw network address is not stored. Legal basis: legitimate interest in keeping limited trial capacity available to genuine users.
- Affiliate data — referral codes, accepted program terms, attributed purchases, commission records and payout history. This is needed to operate the program, prevent fraud and meet accounting obligations. Affiliates never receive a referred customer's identity or contact details.
- Customer feedback: an optional star rating, comment, the server it concerns and the hosting credit granted for it. We use this to improve the service and respond to problems. With your separate permission, an anonymous version may be published on GHosting. Legal bases: legitimate interest for internal feedback and consent for public use.
3. Cookies and local storage
We use no third-party tracking or advertising cookies. When you log in, a session token is stored in your browser so you stay signed in. Campaign attribution is retained for the current tab. If you follow an affiliate link, the referral code and capture time may be stored in first-party browser storage for up to 30 days so the correct affiliate can be credited if you purchase. Dismissing a customer feedback prompt stores a first-party reminder time for up to 7 days. These values are not used to follow you across other websites.
4. Who we share data with
Only processors necessary to run the service: Stripe (payments), our transactional email provider (delivery of account and billing emails), and European infrastructure providers that physically host our servers. We never sell your data. Feedback is displayed publicly only when you give separate permission, and public reviews do not include your email address, server name or server address.
5. How long we keep it
- Account data: for as long as your account exists. You may ask us to delete it at any time.
- Invoices and order records: 7 years, as required by Estonian accounting law.
- Server files: paid-plan files are deleted no earlier than 7 days after the term ends; free-trial files are deleted after a 3-day post-trial grace period.
- Page-view and browser-action analytics, including daily visitor hashes, account links and coarse device categories: 90 days, after which the event rows are deleted. Order-linked device and campaign context is retained with order records for 7 years.
- Raw affiliate click hashes: up to 90 days. Financial commission and payout records are retained with the associated accounting records.
- Customer feedback: while your account exists or until you ask us to delete it. Withdrawing publication permission removes it from public display without reversing hosting credit already granted.
6. Your rights
Under the GDPR you can request access to, correction of, deletion of, or a portable copy of your personal data, and you can object to processing based on legitimate interest. Write to us via the contact page and we will respond within 30 days. You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or your local supervisory authority.
7. Changes
If we change this policy in a way that affects you materially, we will email account holders before the change takes effect.