Privacy Policy
Last updated: August 2026
1. Introduction
1.1. NodeHarbor (“we,” “us,” “our”) respects your privacy and is committed to protecting the personal information you share with us. This Privacy Policy explains what information we collect, why we collect it, how we use and protect it, and the rights you have regarding your data.
1.2. This policy applies to all visitors, registered users, and customers of our website, panel, and associated services (collectively, the “Services”). By using our Services, you consent to the practices described in this policy.
1.3. We may update this policy from time to time. Material changes will be announced via email or a notice on our website. The “Last updated” date at the top of this page reflects the most recent revision.
2. Information We Collect
2.1. Information you provide directly:
- Account details — your name, email address, and password (stored only as a secure hash).
- Billing information — invoice details, payment method references, and order history. Full payment card numbers are processed by our payment providers and are never stored on our servers.
- Support and communications — messages you send to our support team, including any information you choose to include.
- Profile and configuration data — server names, settings, and preferences you configure within your account.
2.2. Information collected automatically:
- IP addresses — we record the IP address used to log in and access your account, which we use for security monitoring and to detect suspicious activity.
- Device and browser data — operating system, browser type, and user-agent information, used to provide an optimized experience and to describe session activity.
- Usage data — pages visited, features used, and general interaction patterns, used to improve our Services.
- Session records — we maintain session logs (including timestamps and associated IP addresses) to keep your account secure.
2.3. Where you interact with third-party services (such as payment gateways or our NodeHarbor management panel), those providers may collect information in accordance with their own privacy policies.
3. How We Use Your Information
3.1. We use the information we collect to:
- Create and manage your account, authenticate logins, and keep your sessions secure;
- Provision, operate, and support the hosting Services you purchase;
- Process payments, generate invoices, and manage billing and refunds;
- Send service-related communications, including account verification, password resets, security alerts, and important notices;
- Send marketing communications where you have opted in (you may opt out at any time);
- Prevent fraud, abuse, and unauthorized access, and investigate security incidents;
- Analyze and improve the performance, reliability, and user experience of our Services;
- Comply with applicable legal and regulatory obligations.
3.2. We do not sell your personal information to third parties.
4. Legal Basis for Processing
4.1. We process personal information on the following bases (in particular for users in the European Economic Area and similar jurisdictions):
- Performance of a contract — to provide and operate the Services you have requested;
- Legitimate interests — to secure our platform, prevent fraud, and improve our Services;
- Legal obligation — where we are required to process data by applicable law;
- Consent — for marketing communications and other activities where you have given explicit consent, which you may withdraw at any time.
5. Cookies & Similar Technologies
5.1. We use cookies and similar technologies to keep you logged in, remember your preferences, and understand how our Services are used.
5.2. The primary cookie we set is a session identifier that authenticates you while you are logged into the control panel. Session tokens are stored in hashed form on our servers.
5.3. You can configure your browser to refuse cookies or to alert you when a cookie is being set. Please note that some features of our Services may not function correctly without cookies.
5.4. We do not currently use cookies to serve targeted advertising.
6. Sharing & Third-Party Processors
6.1. We do not sell, rent, or trade your personal information. We share data only with service providers who help us deliver the Services, under strict confidentiality obligations:
- Payment processors — to process payments and handle billing transactions. They may collect your card details directly and are governed by their own policies (e.g., PCI DSS requirements).
- Infrastructure and game panel providers — our own NodeHarbor management infrastructure used to deliver your game and VPS hosting. Account and server details are shared only as necessary to provision and manage your resources.
- Email providers — used to deliver account verification, notifications, and support messages.
- Cloud and analytics services — used for hosting our platform, security, and performance measurement.
6.2. We may disclose information where required by law, regulation, or legal process, or where necessary to protect the rights, property, or safety of NodeHarbor, our customers, or the public.
6.3. If NodeHarbor is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your data is subject to a different privacy policy.
7. Data Security
7.1. We implement administrative, technical, and physical safeguards to protect your information, including:
- Encryption of sensitive data in transit (TLS) and hashing of passwords and session tokens;
- Role-based access controls so only authorized personnel can access customer data;
- Security monitoring, fraud detection, and session activity logging (including IP-based login alerts);
- Regular review of our infrastructure and provider security practices.
7.2. No method of transmission or storage is completely secure. While we strive to protect your data, we cannot guarantee absolute security, and you are responsible for safeguarding your account credentials and enabling available security features.
8. Data Retention
8.1. We retain personal information only as long as necessary to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements.
8.2. Specifically:
- Account data is retained while your account is active and for a reasonable period after closure;
- Billing and transaction records are retained as required by tax and accounting law;
- Session and security logs are retained for a limited period to support fraud prevention and incident investigation;
- Server data (files and configurations) is deleted shortly after service termination, as described in our Terms of Service. You are responsible for backing up data you wish to keep.
9. Your Rights
9.1. Depending on your jurisdiction, you may have the following rights regarding your personal information:
- Access — request a copy of the personal information we hold about you;
- Correction — update or correct inaccurate information (much of this can be done in your account settings);
- Deletion — request deletion of your account and personal data, subject to legal retention obligations;
- Restriction — request that we limit how we process your data in certain circumstances;
- Portability — request a machine-readable copy of data you provided to us;
- Objection — object to processing based on legitimate interests or for direct marketing;
- Withdraw consent — withdraw any consent you have given at any time.
9.2. To exercise any of these rights, contact us using the details in Section 13. We will respond within the timeframe required by applicable law. We may ask you to verify your identity before fulfilling a request.
9.3. If you are in the European Economic Area (EEA), you also have the right to lodge a complaint with your local data protection supervisory authority.
10. International Data Transfers
10.1. NodeHarbor is based in Pakistan, and our infrastructure and providers are located in multiple countries. By using our Services, you acknowledge that your information may be processed and stored outside your country of residence.
10.2. Where we transfer personal data of individuals in the EEA or similar jurisdictions to countries that may not provide an equivalent level of protection, we rely on appropriate safeguards (such as standard contractual clauses) to protect your information.
11. Children's Privacy
11.1. Our Services are intended for individuals who are at least 18 years old (or the age of majority in their jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can delete it.
12. Changes to This Policy
12.1. We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes via email or a prominent notice on our website.
12.2. Your continued use of the Services after changes take effect constitutes acceptance of the updated policy.
13. Contact Us
13.1. If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
- Through the contact form on our website (/contact);
- By email at the address listed on our contact page; or
- By mail to our registered address in Pakistan.
13.2. We will acknowledge your request promptly and aim to resolve it within thirty (30) days.