First draft — v0.1, not yet legally reviewed, not published. Every document on this site must be reviewed by a solicitor before it is relied on. See the status note on the home page.

Privacy Policy

Last updated: [PUBLISH DATE] · Version: 0.1 (first draft — not yet legally reviewed, not yet published)

This is a first draft. It must be reviewed by a solicitor qualified in England & Wales (and, if Hostable ever specifically targets EU or US customers at scale, a lawyer in the relevant EU member state / US state) before it is published or relied on. Facts used throughout (entity name, address, ICO number, contacts) are placeholders pending TODO.md items — see _facts.md for the single source of truth.

1. Who we are

Hostable (hostable.games) is operated by [LEGAL ENTITY NAME — PENDING INCORPORATION], of [REGISTERED ADDRESS — PLACEHOLDER] ("Hostable", "we", "us"). We are the data controller for the personal data described in this policy.

ICO registration number: [ICO REGISTRATION NUMBER — PENDING].

Contact us about your data at privacy@hostable.games.

2. What Hostable is, in plain terms

Hostable gives you a free, lightweight Minecraft server. You can boost it (more RAM, more uptime, extra features) by watching ads, completing a survey, or paying. This policy explains what we collect to run that service, why, and what rights you have over it.

3. Who this policy is for — read this if you are under 18

You must be at least 16 years old to create a Hostable account. We ask for your date of birth at signup and will not create an account for anyone who tells us they are under 16.

We do not knowingly collect personal data from anyone under 13. If we learn that someone under 13 has given us personal data, we will delete their account and associated data as soon as reasonably practicable. A parent or guardian who believes their child (under 16) has created a Hostable account can contact privacy@hostable.games to have the account and data removed.

If you are 16 or 17, you can use Hostable, but we recommend a parent or guardian is aware, particularly before you make any payment.

4. What we collect, and why

CategoryExamplesPurposeLawful basis (UK/EU GDPR)
Account dataEmail, username, hashed password, date of birth (age-gate only, not stored beyond the check unless needed for a support dispute)Create and secure your accountContract (Art 6(1)(b))
Server dataServer name/ID, status, RAM/uptime tier, configurationOperate the Minecraft server you asked forContract
Billing dataPurchased boosts, transaction reference (card details never touch our servers — see §7)Process payment, tax recordsContract; legal obligation (HMRC, 6-year retention)
Support dataTicket contents, whatever you tell us in a support requestResolve your issueContract; legitimate interest in providing support
Ad/survey interactionWhich ad or survey network delivered your boost, completion status, advertising identifiers set by that networkGrant the boost you earned; the ad network's own processing is described in §8Contract (granting the boost); the ad network's own processing runs on consent, obtained through the cookie banner — see the Cookie Policy
Technical/security dataIP address, device/browser metadata, access logsKeep the service secure, detect abuse, rate-limitLegitimate interest (security)
CommunicationsEmails we send you (password resets, service notices, marketing if you opt in)Operational and (opt-in only) marketing emailContract (operational); consent (marketing)
Legal agreement recordsA record of your agreement to our EULA, Terms of Service, Privacy Policy, and the cookie/storage notice — timestamp, IP address, and (where available) a copy of the exact document text you agreed toProve what was agreed to and when, if it's ever disputedLegal obligation / legitimate interest (accountability, UK GDPR Art 5(2))

We do not use automated decision-making that produces legal or similarly significant effects on you. Boost eligibility and server limits are applied by simple rule (e.g. "watched N ads this period"), not profiling.

5. Where your data is processed, and international transfers

Your account, server, and session data is held on infrastructure we operate ourselves — a mixture of Linode and other self-hosted infrastructure. The exact split and datacenter location(s) are not yet finalized — see the Hostable repo's TODO.md, which tracks this as an open decision (a prior host was retired; the final topology is still being confirmed) — so this section cannot yet commit to a single country or a blanket "no international transfer" claim for that data. This will be updated with the confirmed provider mix and location(s), and the transfer table below corrected accordingly, before this policy is published. A small number of other providers already process data outside the UK/EEA regardless of where our own infrastructure ends up. Where that happens, we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, and/or the EU–US Data Privacy Framework and its UK Extension, as the applicable safeguard. You can request a copy of the relevant safeguard by writing to privacy@hostable.games.

WhereWhat's processed thereSafeguard
Linode + other self-hosted infrastructure — [TBC — exact split/location(s) not yet finalized]Account data, server records, sessions, backups[TBC — depends on final locations]
United StatesTransactional email (Resend, AWS US by default)UK IDTA / EU SCCs and/or EU–US DPF (UK Extension)
Ireland / US (Stripe)Payment processing (implemented; live once production Stripe keys are configured — see §7)Stripe's own SCCs / DPF certification
US by default, EU option available (Cloudflare)Traffic passing through the tunnel/edge (TLS termination)Cloudflare DPA, DPF certification

See suppliers.md for the full list with roles.

6. Cookies and similar technologies

Handled in full in the Cookie Policy, including the separate UK/EU consent-based model and the US "opt-out"/Global Privacy Control model for AdSense once it's live. This policy covers the personal data behind those cookies; the Cookie Policy covers the mechanism.

7. Payments

Card payments are handled entirely by Stripe (the integration is built and live in the product — see the Hostable repo's TODO.md for the current status of production API keys). Your card details go directly to Stripe and never touch Hostable's servers. Stripe acts as an independent controller for fraud prevention and anti-money-laundering checks, not purely as our processor — see Stripe's own privacy policy for that processing.

8. Advertising and surveys

No ad or survey network is integrated into Hostable yet. Earning a boost by watching an ad or completing a survey is a planned feature, not a live one — the current product has no ad-network script loaded anywhere (see suppliers.md). Once a network is chosen (currently under consideration: Google AdSense; a survey network is not yet chosen) and actually wired in, it will set its own cookies/identifiers and process data under its own privacy policy, which we'll link to at the point you interact with it, and this section will be updated to describe what's actually live rather than what's planned. We would only ever receive confirmation that the ad/survey was completed, not the network's own analytics about you.

We will not enable an ad or survey network without a signed data processing term from that network, and — because Hostable's userbase may include 16–17 year olds — we require any network we use to support non-personalized / non-behavioral ad delivery for under-18 accounts at minimum. [This is a product requirement to build, not yet implemented — see TODO.md.]

9. Who we share data with

We share data only with the sub-processors listed in suppliers.md, each under a written data processing agreement, and:

10. How long we keep your data

DataRetentionWhy
Account + server dataDuration of account + up to 30 days after you request deletion (an automated daily sweep completes erasure once that window passes)Contract; short window to reverse an accidental/malicious deletion request
Billing/invoice records6 years after the end of the tax yearHMRC statutory requirement
Support tickets24 months after closureLegitimate interest — support history
Security/access logs90 daysLegitimate interest — security
Marketing consent recordsUntil withdrawn, plus 24 monthsEvidence of consent (PECR)
Legal agreement records (EULA, Terms of Service, Privacy Policy, cookie/storage notice)6 years after account closureAccountability (UK GDPR Art 5(2)); matches our billing-record retention as the same "may need it for a future dispute" reasoning — kept independently of your account record, identified by the email address you used rather than a live account link, once the account itself is erased
Backups35 days rollingService availability

11. Your rights

Under UK GDPR (and EU GDPR if it applies to you), you have the right to:

To exercise any of these, email privacy@hostable.games. See our internal DSAR procedure for how we handle and time-box these requests.

If you are in the United States

Hostable does not sell your personal data for money. Depending on your state of residence and applicable state privacy law (e.g. California's CCPA/CPRA), you may have rights to know, delete, correct, opt out of the "sale or sharing" of personal information (which under CCPA's broad definition can include some advertising-cookie data even without a cash sale), and to non-discrimination for exercising these rights. We recognize the Global Privacy Control (GPC) signal as a valid opt-out request. See the Cookie Policy §"Your US privacy rights" for the mechanism. [Other state-specific variations (Virginia, Colorado, Connecticut, Utah, Texas, Oregon, etc.) need a state-by-state legal review before Hostable claims compliance with each by name — flagged, not yet done.]

12. Security

See our public Security page for how we protect your data, and our internal Information Security Policy (available to enterprise/insurer requests) for the underlying controls.

13. Changes to this policy

We'll post the new version here with an updated date, and keep prior versions archived so you can see what changed. For a material change (e.g. a new category of data, a new international transfer, a new sub-processor) we'll email you or show an in-app notice the next time you sign in, summarizing what changed — not just a silent date bump. See Terms of Service §8 for the same commitment applied to pricing and plan changes specifically.

14. Contact

privacy@hostable.games · [REGISTERED ADDRESS — PLACEHOLDER]

↑ Back to top