Privacy Policy
Effective September 27, 2026 ยท TidalVPS
This policy explains what personal information TidalVPS ("we", "us") collects, why, and what choices you have. It applies to our website, control panel and services.
What we collect
- Account information: your name, email address, and optionally company and country, plus a securely hashed password (we cannot see your password).
- Billing information: invoices, payment history and a customer reference from our payment processor. Card details are entered directly with Stripe and never touch our servers; we only see things like the card brand and last four digits in Stripe's dashboard.
- Service information: the servers you order, their hostnames, IP addresses, operating systems, SSH public keys you add, and actions you take in the control panel (for example power actions and reinstalls).
- Security and activity logs: the IP address you sign up and log in from, and a log of account activity, used to protect your account and to prevent fraud and abuse.
- Support messages: the contents of tickets and emails you send us.
- Server usage metrics: servers include the TidalVPS metrics agent, which every minute reports CPU, memory and disk usage percentages and network throughput (bytes per second). It never reads or sends files, processes or traffic contents. We use these numbers for your usage graphs and to spot abuse patterns such as crypto mining or outgoing attacks. You can remove the agent at any time (
systemctl disable --now tidalvps-agent.timer); your graphs will stop. - IP reputation: we check our servers' IP addresses against public spam and malware blocklists.
- Abuse reports that other people send us about activity from your server's IP addresses.
- Abuse and network signals: reports from our infrastructure providers about spam, attacks, DDoS mitigation or other activity involving your server's IP addresses.
We do not look through the files or data stored on your server as part of normal operations.
Cookies
We use a single essential cookie to keep you logged in and protect forms from forgery. We do not use advertising or cross-site tracking cookies.
How we use it
- To create and manage your account and deliver, bill for and support your servers.
- To send service emails such as invoices, delivery notices, DDoS alerts and security notices.
- To detect, investigate and prevent fraud, payment disputes, abuse and violations of our Terms and Acceptable Use Rules.
- To comply with legal obligations and respond to lawful requests.
- To improve our services. We may send occasional product updates; you can unsubscribe at any time.
Who we share it with
We do not sell your personal information. We share it only with:
- Stripe, to process payments and prevent fraud.
- Our infrastructure providers (data center and network operators), to the extent needed to run your servers, for example your server's hostname and technical configuration.
- Our email provider, to deliver service emails.
- Authorities or other parties when required by law, to respond to valid legal process, or to protect the rights, property and safety of our customers, our providers, the public or us, including in response to abuse reports.
- A successor business, if we are involved in a merger, acquisition or sale of assets.
How long we keep it
We keep account and billing records while your account is open and afterwards as long as needed for tax, accounting, dispute and legal purposes (typically up to 7 years for billing records). Server data is deleted when a service is terminated. Security logs are kept for as long as they are useful for fraud and abuse prevention.
Security
We use industry-standard measures including encrypted connections, hashed passwords, encryption of stored server credentials and restricted staff access. No system is perfectly secure, so please use a strong, unique password and keep your servers updated.
Your rights
You can view and update your profile in the control panel. You can ask us to provide a copy of your personal information, correct it, or delete it by contacting [email protected]. Depending on where you live (for example California, under the CCPA/CPRA, or the EU/UK, under the GDPR), you may have additional rights, including to know what we collect and to not be discriminated against for exercising your rights. We may need to keep some information to meet legal obligations, resolve disputes or prevent abuse, and we will verify your identity before acting on a request.
Children
Our services are not intended for anyone under 18, and we do not knowingly collect information from children.
International users
We are based in the United States and process information there. By using the services you understand your information will be processed in the U.S. and in the countries where our providers operate.
Changes
We may update this policy. For material changes we will notify you by email or in the control panel before they take effect.
Contact
TidalVPS
[email protected]