frost

Legal

Privacy Policy

This policy explains what personal data Frost Hosting Ltd. collects, why we collect it, who we share it with and the choices you have. We collect only what we need to run your servers and bill for them.

Last updated

01Who is responsible

Frost Hosting Ltd. is the data controller for the personal data described here. You can reach our privacy team at privacy@frost.gg.

02What we collect

We collect the following data:

  • Account details: your name, email address, password hash and two-factor settings.
  • Billing details: your billing address, tax ID and payment history. Card numbers are handled by our payment processor, and we never see or store them.
  • Service data: server names, IP addresses, resource usage, logs and support tickets.
  • Technical data: IP address, browser type and pages visited when you use our website or control panel.

03Files on your servers

The files, worlds, databases and applications stored on your servers belong to you. We do not look through them, except when you ask us to in a support ticket, when an abuse report requires it, or when the law requires it.

04How we use your data

We use your data to:

  • provide, run and secure the services you ordered;
  • take payments, send invoices and prevent fraud;
  • answer support tickets and send important service notices;
  • improve performance and plan capacity, using aggregated data; and
  • send product news, but only if you opt in. You can unsubscribe at any time.

06Who we share it with

We never sell personal data. We share it only with providers that help us deliver the service, under contracts that protect it:

Provider typePurposeData shared
Payment processorsTaking payments and fighting fraudName, email, billing address
Datacenter partnersHosting your serversService data only
Email deliveryInvoices and service noticesName, email
Support deskManaging support ticketsName, email, ticket contents

07International transfers

Your servers run in the region you choose. Account and billing data is stored in the European Union. When a provider processes data outside the UK or EEA, we rely on adequacy decisions or standard contractual clauses.

08How long we keep it

Server data is deleted 7 days after a service ends. Account data is kept while your account is open and for 12 months after it is closed. Invoices are kept for 6 years because tax law requires it.

09Your rights

You can ask to access, correct, export or delete your personal data, or object to or restrict how we use it. Most of this can be done from your account settings. For anything else, email privacy@frost.gg and we will reply within 30 days. You also have the right to complain to your local data protection authority.

10Security

We encrypt data in transit with TLS, hash passwords with a modern algorithm, limit staff access to what each role needs and log administrative actions. If a breach affects your data, we will tell you without undue delay.

Questions about this policy?

A real person reads every message, usually within a day.