This policy explains how LiteVPS collects and uses personal data when you visit litevps.dev, use the LiteVPS web portal or REST API, or operate virtual infrastructure provided by LiteVPS (together, the Service).

1. Who is responsible for your data

LiteVPS is the data controller for account, billing, support, security, and Service-usage data. Contact us about privacy or data-protection requests at privacy@litevps.dev.

When customers upload or create personal data inside their virtual machines, snapshots, files, or command workloads, the customer determines why and how that data is used. For that data, LiteVPS acts as a processor or service provider on the customer's behalf.

2. Data we collect

  • Account and identity data: email address, password hash, account identifiers, email-verification and password-reset records, and Google or Apple sign-in identifiers if you use social login.
  • Billing data: balance and transaction history, billing preferences, Stripe customer and payment-method references, and payment status. LiteVPS does not store complete payment-card numbers.
  • Infrastructure data: VM and project names, plans, templates, IP addresses, domains, proxy rules, SSH public keys, API-token labels and hashes, cloud-init data, snapshots, and resource usage.
  • Workload content: files transferred through the Service and commands submitted through managed execution, including command output and errors. VM disks and snapshots contain content you choose to store.
  • Communications: support messages, notification addresses, limit-increase requests, and other messages you send us.
  • Technical and security data: IP address, user agent, request path, response status, timestamps, latency, authentication and security events, transfer sizes, execution duration, and infrastructure logs.

3. How and why we use data

  • Provide accounts, authentication, virtual machines, networking, file transfer, managed execution, support, and other requested Service features.
  • Meter usage, process payments, maintain balances and transaction records, and prevent billing abuse.
  • Secure the Service, detect fraud and prohibited activity, troubleshoot failures, enforce the Acceptable Use Policy, and protect users and infrastructure.
  • Send transactional messages about verification, security, billing, support, and material Service changes.
  • Measure reliability, capacity, and feature usage and improve Service performance.
  • Comply with legal obligations and establish, exercise, or defend legal claims.

Where European data-protection law applies, we rely on performance of our contract to provide the Service; our legitimate interests in securing, operating, and improving it; compliance with legal obligations; and consent where the law specifically requires it. You may withdraw consent at any time without affecting earlier lawful processing.

4. When we share data

We share data only as needed with:

  • Stripe for payments and payment-method management.
  • Mailgun for transactional and support email delivery.
  • Cloudflare for Turnstile anti-abuse checks during registration.
  • Google and Apple when you choose their sign-in services.
  • Hosting, network, DNS, and content-delivery providers that operate infrastructure or deliver software required by the Service.
  • Professional advisers, authorities, or other parties when required by law, needed to protect rights and safety, or involved in a business reorganization.

We do not sell personal data or share it for cross-context behavioral advertising.

5. Cookies and browser storage

LiteVPS uses strictly necessary cookies for authentication, administrative access, and temporary OAuth security state. The main authentication cookie may remain for up to 30 days; OAuth state cookies expire after about 10 minutes. These cookies are used to provide and secure the Service, not for advertising. We do not use third-party advertising analytics.

6. Retention

We retain data only for as long as needed for the purposes above. In particular:

  • Account and infrastructure records are generally kept while the account or resource remains active and afterward where needed for security, disputes, or legal obligations.
  • Asynchronous command jobs and detailed product telemetry are generally retained for up to 30 days. Some execution audit history may remain until older records are displaced by newer activity.
  • Central infrastructure logs are generally rotated after approximately 14 days.
  • Encrypted database backups are generally retained for seven days, so deleted database records may remain in backups until those backups expire.
  • VM disks and snapshots remain until they or the related resource are deleted, subject to operational deletion and backup cycles.
  • Billing, fraud, support, and legal records may be retained longer where reasonably necessary or legally required.

7. International transfers

LiteVPS and its providers may process data in countries other than yours. Where required, we use appropriate safeguards for international transfers, such as adequacy decisions or standard contractual clauses. Provider-specific details may also be available in each provider's privacy notice.

8. Security

We use technical and organizational measures intended to protect personal data, including access controls, encrypted transport, restricted credentials, isolation, monitoring, and encrypted backups. No system is completely secure, and customers remain responsible for securing their accounts, credentials, applications, and data inside their virtual machines.

9. Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a portable copy of personal data, and to object to certain processing. You may also withdraw consent and complain to your local data-protection authority.

Send requests to privacy@litevps.dev. We may need to verify your identity before completing a request. Some data may be retained where an exception applies, including billing, security, fraud-prevention, and legal-record requirements.

10. Customer responsibilities

If you process another person's personal data through LiteVPS, you are responsible for providing required notices, having a lawful basis, honoring that person's rights, and configuring your workload securely. Do not submit sensitive data in commands, paths, support messages, or other fields unless necessary and appropriately protected.

11. Children

The Service is intended for business and developer use and is not directed to children. If you believe a child has provided personal data without appropriate authorization, contact us so we can investigate.

12. Changes to this policy

We may update this policy to reflect changes to the Service, providers, or law. We will post the revised policy here and update the date above. We will provide additional notice when required by law.