0xHost
Se connecter

Politique de confidentialité

Nous collectons le moins possible. Cette page explique exactement quoi, pourquoi et pour combien de temps.

Ce document n'est disponible qu'en anglais. C'est la version anglaise qui fait foi.

1 Who we are

This policy explains how 0xHost ("we", "us") handles personal data when you visit our website or use our services: VPS and dedicated servers, domains, web hosting, IP networks and add-ons. It applies to 0xhost.com, its Tor mirror and our Telegram bot.

Questions or requests about your data: open a support ticket from your panel, write to [email protected], or message @HostAgent_Bot on Telegram.

2 What we do not ask for

We are built to need as little about you as possible:

  • We do not ask for your real name, postal address, phone number or any identity document.
  • An email address is optional when you sign up with Telegram, and you can use a generated username.
  • You pay with cryptocurrency or account balance. We never receive card or bank details.
  • We do not use advertising, analytics or tracking scripts, and we do not sell or rent data to anyone.

3 What we collect

Account: your username, a hashed password (we cannot read it), your email address if you give one, your Telegram ID and username if you connect Telegram, your two-factor authentication settings, your alert preferences and your account balance.

Services: what you order and its configuration, such as server names, IP addresses, operating system, domain names, expiry dates and renewal settings. For servers we keep the initial login shown in your panel.

Billing: orders, invoices and balance movements. For crypto payments: the amount, the coin and network, the payment address and the transaction hash. These are public on the blockchain by nature.

Support: the tickets you open, their messages and attachments, and live chat conversations.

Messages we send you: a record of each email or Telegram notification (type, recipient, date and delivery status), with passwords and similar secrets removed.

4 Logs and IP addresses

  • Web server logs record the IP address, page and browser of each request. They are deleted automatically after 14 days.
  • API keys: we store the IP address and route of the last request made with each key, so you can see it in your panel.
  • Sign in with Telegram: while a login is waiting for your approval we store the requesting IP address and browser, so the bot can show you which device is asking.
  • Payments and orders do not record your IP address. Payments made before September 2025 did; ask us and we will remove it.

Our network filters traffic to protect our services and yours against attacks. This filtering looks at traffic patterns, not at the content of your data.

5 How we use your data

Only to run the services you ask for:

  • to create, run, renew and support your services;
  • to take payments and keep your balance and invoices correct;
  • to send the alerts you choose, such as renewals, suspensions and security notices;
  • to protect our infrastructure and customers from fraud and abuse, and to handle abuse reports as described in our Terms.

We do not send marketing email.

6 Who else sees data

We share the minimum each partner needs to do its job:

  • Payment processor: the amount, currency, order number and a short description. Not your email or account details.
  • Domain registrations: domains are registered with our own contact details, so your name and email do not appear in public domain records (WHOIS).
  • hCaptcha checks the sign-up, login and password recovery forms for bots. It receives your IP address and browser data under its own privacy policy.
  • Telegram, only if you use our bot or sign in with Telegram.
  • Fonts and icons on our pages are loaded from Google Fonts and cdnjs, which see your IP address when your browser downloads them.

7 The content of your servers

The data you store on your servers is yours. We do not inspect it, index it or make copies of it.

When a VPS is terminated it is deleted together with its disks, and its data cannot be recovered.

For extra protection you can encrypt your data yourself. Our knowledge base explains how to do it with LUKS2.

8 Cookies and local storage

We use only what the site needs to work. There are no advertising or tracking cookies.

  • PHPSESSID: keeps you logged in, for up to 30 days. It is set when you open the login or sign-up page or use the panel, not when you only browse our public pages.
  • rd_lang: remembers the language you chose.
  • rd_ui: remembers whether you prefer the classic or the new design.
  • Local storage in your browser keeps small preferences such as the light or dark theme and the compact sidebar. It never leaves your device.

9 How long we keep data

  • Web server logs: 14 days.
  • Account data: while your account exists.
  • Orders, invoices, payments and balance movements: for as long as we are required to keep accounting records, also after a service ends, so your history and any refund stay possible.
  • Records of terminated services (name, dates, IP address, invoices) stay in your account history.

When you ask us to delete your account, we delete or anonymise your personal data, except what we must keep by law.

10 Security

The whole site is served over HTTPS and is also reachable through a Tor onion address. Passwords are stored as one-way hashes. You can protect your account with two-factor authentication, and API keys can be limited in time and revoked at any moment. Access to customer data inside 0xHost is limited to the staff who need it to provide support.

11 Your rights

Wherever you live, you can ask us to:

  • tell you what personal data we hold about you and give you a copy;
  • correct data that is wrong;
  • delete your account and personal data;
  • stop a particular use of your data, for example notifications.

Send your request from your panel (support ticket) or to [email protected]. We may ask you to confirm the request from your account so no one else can make it in your name. We answer within 30 days. If you are in the European Union you can also complain to your data protection authority.

12 Changes to this policy

When we change how we handle data we update this page and the date at the top. Important changes are also announced in the panel.

Retour en haut