Privacy Policy

Last updated: August 17, 2026

TL;DR: We Collect Nothing

VMFrost was built on a simple principle: we can't leak, sell, or misuse data we don't have. We collect no personal information, no tracking cookies, no analytics. Your privacy is protected by design, not policy.

1. Information We Do NOT Collect

Unlike traditional hosting providers, we deliberately avoid collecting:

  • No names - We don't ask for or store your real name
  • No email addresses - No email required for registration or communication
  • No phone numbers - Never requested at any point
  • No physical addresses - We don't need to know where you live
  • No payment information - Cryptocurrency transactions don't reveal identity
  • No IP address logs - Access logs are anonymized and deleted after 24 hours
  • No tracking cookies - Only essential session cookies for functionality
  • No analytics or telemetry - We don't use Google Analytics or similar services
  • No social media integrations - No Facebook pixels, Twitter tracking, etc.

2. Information We Do Collect

To provide our service, we collect only the absolute minimum:

Authentication Token

A randomly generated token (e.g., FB-XXXXX...) that identifies your account. This token is hashed before storage and cannot be reverse-engineered to reveal any personal information.

Server Configuration Data

Technical information about your servers: OS, resources, location preferences. This data is necessary to provide the service and is not linked to any personally identifiable information.

Payment Records

Cryptocurrency transaction hashes for accounting purposes. These are public blockchain records that don't reveal your identity unless you choose to link them yourself.

Temporary Access Logs

Anonymized connection logs kept for 24 hours for security and debugging. These logs have IP addresses stripped and are permanently deleted after 24 hours.

3. How We Use Data

The minimal data we collect is used exclusively for:

  • Authenticating you when you log in
  • Provisioning and managing your servers
  • Processing payments and maintaining billing records
  • Detecting and preventing abuse (DDoS, spam, illegal content)
  • Debugging technical issues when you report them

We never: Sell data, share with advertisers, use for marketing, or profile user behavior.

4. Data Storage and Security

All data is stored in encrypted databases within our German data centers. We implement:

  • AES-256 encryption at rest
  • TLS 1.3 encryption in transit
  • Regular security audits and penetration testing
  • Strict access controls (only essential staff)
  • Automated data deletion policies

Despite our security measures, no system is 100% secure. Use your own encryption for sensitive data.

5. Third-Party Services

We use minimal third-party services:

  • Cryptocurrency payment processors: To accept crypto payments. They see transaction details but no personal information.
  • Infrastructure providers: Our servers are hosted in Germany. They have physical access to hardware but no access to encrypted data.

We do NOT use: Google Analytics, Facebook Pixel, advertising networks, email marketing platforms, CRM systems, or any tracking/analytics services. The only tracking available is for the referral system, which keeps no logs, only allows the inviter to see how many people he has invited aswell as how much commission he has made.

6. Cookies

We use only essential cookies required for the website to function:

  • Session cookies: To keep you logged in (expires when you close browser)
  • Authentication tokens: Stored locally in your browser

No tracking cookies, no advertising cookies, no third-party cookies.

7. Data Retention

We retain data only as long as necessary:

  • Active accounts: Data retained while account is active
  • Access logs: Automatically deleted after 24 hours

8. Law Enforcement and Legal Requests

We comply with valid legal requests from German authorities. However:

  • We can only provide data we actually have (which is minimal)
  • We cannot provide personal information because we don't collect it
  • We cannot decrypt your server data (you control encryption keys)

We will not: Voluntarily cooperate with mass surveillance, provide data without proper legal process, or install backdoors.

9. Your Rights (GDPR)

Under GDPR, you have the right to:

  • Access: Request what data we have about you (spoiler: almost nothing)
  • Rectification: Correct inaccurate data
  • Erasure: Delete your account and all associated data anytime
  • Portability: Export your server data
  • Object: Object to data processing (though we do minimal processing)

However, since we don't collect personal data, most GDPR rights are moot. You're private by default.

10. Children's Privacy

Our services are not directed at children under 16. We don't knowingly collect data from minors. Since we don't collect age information, we can't prevent children from using the service. Parents/guardians are responsible for monitoring their children's internet usage.

11. International Data Transfers

All data stays within the European Union (Germany). We do not transfer data to countries outside the EU. Your data benefits from German and EU privacy laws, which are among the strongest in the world.

12. Changes to This Policy

We may update this policy occasionally. Significant changes will be announced on our homepage. Continued use after changes constitutes acceptance. Check the "Last updated" date at the top.

13. Contact

Questions about privacy? Contact us through your account dashboard. We don't provide email support to avoid collecting your email address.

Remember: The best privacy policy is the one that says "we don't have your data." That's VMFrost.