# legal

Privacy Policy

Last updated: 2026-09-02

1. Scope and Roles

This Policy explains how bashrack handles personal data when you visit our website, create or use an account, purchase Services, contact support, or use our APIs. bashrack is the controller for account, billing, security, and service-administration data. Contact [email protected] for privacy requests.

When a customer uses our infrastructure to process personal data in its own workloads, the customer determines the purposes and means of that processing and bashrack acts as a processor or service provider. Customers remain responsible for their notices, instructions, and lawful basis for that data.

2. Data We Collect

We collect account and profile data such as name, username, email, company, billing address, preferences, and verification status; authentication data such as password hashes, sessions, connected identity providers, two-factor credentials, and security events; and billing data such as wallet transactions, invoices, payment status, currency, provider references, and limited payment metadata. Payment providers process full card, bank, or cryptocurrency details; bashrack does not store full card numbers.

We also collect service configuration and usage, including orders, resource identifiers, IP addresses, traffic and resource consumption, support messages and attachments, API and webhook settings, audit events, access times, request metadata, device/browser details, errors, and fraud or abuse signals. We may receive verified identity data from an OAuth provider you choose and transaction status from a payment provider.

3. Purposes and Legal Bases

We process data to create and administer accounts, provide infrastructure and support, authenticate users, process payments, calculate usage and billing, send transactional messages, and enforce the Terms. The legal basis is performance of a contract or steps you request before entering one.

We process data to secure the Services, prevent fraud and abuse, maintain audit records, improve reliability, understand aggregate usage, and establish or defend claims based on our legitimate interests balanced against your rights. We also process data for tax, accounting, sanctions, law-enforcement, and other legal obligations. Optional analytics or marketing processing is based on consent, which you may withdraw without affecting earlier processing.

4. Sharing and Service Providers

We do not sell personal data. We disclose only data reasonably necessary to providers supporting a function, which may include payment processors such as PayPal and NOWPayments; infrastructure, storage, database, networking, monitoring, security, CAPTCHA, email, and support providers; and an OAuth provider you select, such as GitHub, Google, Discord, GitLab, Microsoft, Slack, or X. Google Analytics or Google Tag Manager receives analytics data only when configured and permitted by your consent.

We may disclose relevant data to authorities or affected parties when required by law or reasonably necessary to protect rights, safety, and the Services; to professional advisers under confidentiality; or with a merger, reorganization, financing, or sale. We require service providers to process data for authorized purposes under appropriate contractual and security obligations.

5. Cookies and Analytics

Strictly necessary cookies and similar storage support authentication, security, preferences, and core operation and do not depend on analytics consent. Optional analytics and advertising storage is denied by default and enabled only if you choose "Accept all" in the consent banner. Choosing "Necessary only" does not prevent use of the core Services.

You can reopen "Cookie settings" in the site footer at any time to change or withdraw your choice. Browser controls may also block cookies, although core features may then fail. The consent choice itself is stored locally under br-cookie-consent.

6. Retention and Deletion

We retain account and service records while the account or Services are active. Session data normally expires after 7 days of inactivity or a configured shorter limit. Operational server logs may be retained for up to 90 days. Raw public-status samples are retained for 7 days and aggregated status history for 90 days. Security, fraud, support, billing, invoice, tax, and audit records remain only for the period reasonably necessary for their purpose and applicable legal or limitation periods.

Deleted data may remain in access-restricted backups until rotation completes and may be retained longer for security investigation, legal compliance, disputes, or claims. Customers should delete or export workload data before terminating a resource; deleting an account does not replace deletion of independently controlled customer workloads.

7. Security

We use safeguards appropriate to the data, including access controls, encryption of selected account fields, hashed passwords, protected sessions, audit logging, and abuse-detection measures. No system is completely secure. You remain responsible for securing your workloads, applications, credentials, backups, and access configuration and should report suspected compromise promptly.

8. International Transfers

bashrack and its providers may process data in countries other than your own. Where applicable law requires transfer safeguards, we use recognized mechanisms such as adequacy decisions, standard contractual clauses, or another lawful mechanism, with supplementary measures where appropriate.

9. Your Rights

Depending on applicable law, you may request access, correction, deletion, restriction, or portability and may object to processing based on legitimate interests. You may withdraw consent and may complain to the data-protection authority where you live, work, or believe a violation occurred. Lawful exceptions may apply for record-keeping, security, fraud prevention, and claims.

Submit requests to [email protected]. We may verify identity and authority before acting. We will respond within the period required by law and explain any lawful refusal or extension. We do not use solely automated decisions producing legal or similarly significant effects unless disclosed at the relevant time and lawfully supported.

10. Required Data and Third Parties

Account, authentication, service-configuration, and billing data marked as required is necessary to provide the relevant Service. Without it, we may be unable to create an account, process payment, or deliver the Service. Optional profile and analytics data is not required. Third-party websites and services have their own privacy practices.

11. Children's Privacy

The Services are not directed to individuals under 18, and we do not knowingly permit them to create accounts. Contact us if you believe a minor provided personal data so we can investigate and take appropriate action.

12. Changes and Contact

We may update this Policy for legal, security, operational, or product changes. Material changes will carry a revised date and, where appropriate, notice through the Service or email. Where consent is required for a new purpose, we will seek it before that processing begins.

For questions or requests, email [email protected] or use our contact page.