Privacy Policy
Effective: 07 Oct 2025
We collect the minimum needed to run our services—nothing creepy. We use privacy‑friendly Cloudflare Web Analytics.
What we collect
- Account & contact: name, email, organization, and messages you send us.
- Billing: transaction IDs and status from our processors (we never see full card data).
- Service data (hosting): IPs, ports, DNS records, instance IDs, usage events, resource metrics, and crash logs.
- Operational logs: security/uptime logs (rotated regularly).
- Email (POP/SMTP, routing): sender/recipient, timestamps, message size, delivery status. We do not read message content unless you explicitly ask for troubleshooting.
- Website analytics: anonymous, aggregate metrics via Cloudflare (no cross‑site tracking).
What we don’t do
- No selling data. Ever.
- No ad pixels or creepy cross‑site tracking.
- No reading your email unless you ask us to help debug.
Why we collect it (legal bases/purposes)
- Provide services (set up/operate hosting, game servers, mail, DNS, monitoring).
- Secure & maintain (prevent abuse, DDoS, fraud; fix bugs; capacity planning).
- Support & communications (respond to tickets, outages, invoices).
- Legal (tax/audit, enforce terms).
If your local law requires a legal basis: contract, legitimate interests, and compliance.
Retention
- Account & billing: while you’re a customer + up to 7 years for tax/audit.
- Operational logs/metrics: typically 30–180 days (shorter for high‑volume logs).
- Backups: rolling windows (commonly 7–30 days).
- Delete requests: we delete or irreversibly anonymize unless we must keep data for legal reasons.
Who processes your data (sub‑processors)
- Cloudflare (DNS, CDN, SSL, DDoS, Web Analytics).
- Payment (e.g., Stripe/PayPal/Paymenter gateway) – tokenized payments only.
- Email (e.g., Brevo/SMTP relay) – transactional mail and routing.
- Monitoring (Prometheus/Grafana stack) – service metrics/alerts.
- Support (email/ticketing) – messages you send us.
We only share what’s necessary for them to perform the service, under agreements.
International transfers
Our infrastructure operates in Pakistan and the United States. Data may move to where we (or our processors) run. We use standard safeguards offered by our providers.
Security
- Network isolation and firewalls by default; DDoS protection.
- TLS in transit; encrypted volumes where supported for sensitive stores.
- Principle of least privilege; audit logging; key rotation.
- Regular updates and vulnerability patching.
No system is perfectly secure, but we work to minimize risk and impact.
Your choices & rights
- Access/Export/Correct/Delete: email us; we’ll help within a reasonable time.
- Opt‑out of non‑essential communications: unsubscribe links or ask us.
- Cookies: we avoid non‑essential cookies; Cloudflare may set strictly necessary ones.
Rights vary by region; if your law grants specific rights (e.g., EEA/UK/California), we honor valid requests.
Email & content on our platform
You control what you upload/host.
For abuse handling (spam, malware, DDoS, illegal content), we may scan metadata and automated signals. We only inspect content when required by law or to resolve a problem you asked us to fix.
Children
Our services are for individuals 13+ (or your country’s digital consent age). We don’t knowingly collect children’s data.
Third‑party links
If you follow links to other sites, their policies apply.
Changes to this policy
We’ll update this page for material changes and, when appropriate, notify you by email or dashboard.
Contact
Questions or data requests? hello@manoversa.host