Hexacraft — Last Updated: September 2026
Hexacraft ("Company", "we", "our", "us") is committed to protecting your privacy and ensuring that your personal data is handled in a secure, transparent, and lawful manner. This Privacy Policy explains how we collect, use, process, store, disclose, and safeguard your information when you access or use our website, billing panel, control panels, APIs, servers, and related hosting services (collectively, the "Services").
By registering an account or using our Services, you acknowledge and agree to the practices described in this Privacy Policy.
1. Scope of This Policy
1.1 This Privacy Policy applies to:
- Visitors of our website
- Registered customers and account holders
- Users of Minecraft hosting and VPS services
- Individuals contacting support or interacting with our systems
1.2 This policy does not apply to third-party services, platforms, or websites not owned or controlled by Hexacraft.
2. Information We Collect
We collect only the information necessary to operate secure, reliable hosting infrastructure.
2.1 Information You Provide Directly
When you create an account or purchase services, we may collect:
- Full name
- Email address
- Billing address
- Payment-related details (processed via third-party providers)
- Support tickets and communication records
You are responsible for ensuring that all provided information is accurate and up to date.
2.2 Automatically Collected Information
When you access our Services, we may automatically collect:
- IP address
- Login timestamps
- Browser type and version
- Device and operating system
- Referring URLs and pages visited
- Bandwidth usage and session logs
This information is used for security, analytics, and service optimization.
2.3 Service-Related Data (Hosting Data)
For infrastructure services, we may collect:
- Server resource usage (CPU, RAM, storage, bandwidth)
- Network traffic metadata (not content inspection unless required)
- Firewall logs and intrusion detection alerts
- Authentication attempts and access logs
We do not access or monitor private server content unless required for abuse investigation, security enforcement, or legal compliance.
3. Legal Basis for Processing (GDPR Compliance)
Where applicable, we process personal data under the following legal bases:
- Contractual Necessity – to provide hosting services
- Legal Obligations – compliance with tax, fraud, or law enforcement requirements
- Legitimate Interests – maintaining infrastructure security, preventing abuse, and improving services
- Consent – where explicitly required
4. How We Use Your Information
We use collected information to:
- Create and manage user accounts
- Process payments and generate invoices
- Provide hosting services and maintain infrastructure
- Detect, prevent, and investigate abuse or fraud
- Enforce our Terms of Service and policies
- Provide technical support
- Send service-related notifications (billing, outages, security alerts)
- Improve performance, reliability, and user experience
We do not sell, rent, or trade personal data.
5. Payment Processing
5.1 Payments are processed through trusted third-party providers.
5.2 Hexacraft does not store full payment card details on its servers.
5.3 Payment providers are responsible for handling sensitive financial data under their own compliance frameworks.
6. Data Retention Policy
6.1 We retain data only as long as necessary for operational, security, and legal purposes:
- Active accounts → retained while services are active
- Inactive accounts → may be deleted after extended inactivity
- Billing records → retained as required by law
- Abuse logs → may be retained indefinitely for security
6.2 Data may be securely deleted once retention requirements expire.
7. Data Sharing and Disclosure
We may share limited data with:
- Payment processors
- Data center and infrastructure providers
- Security and anti-DDoS providers
- Legal authorities when required
We only share data necessary for service delivery or legal compliance.
8. Law Enforcement Requests
We may disclose user data when required by court orders, government authorities, or law enforcement investigations. We reserve the right to comply with valid legal requests.
9. Data Security Measures
We implement industry-standard security measures, including:
- Encryption (SSL/TLS)
- Firewalls and intrusion detection systems
- Access control and authentication systems
- Role-based staff permissions
- Continuous monitoring and logging
Despite these measures, no system can guarantee absolute security.
10. User Responsibilities
You are responsible for:
- Securing your account credentials and maintaining strong passwords
- Keeping your email address active
- Implementing security measures on VPS servers
- Maintaining backups of your data
We are not responsible for account compromise caused by user negligence.
11. Cookies and Tracking Technologies
We use cookies to maintain login sessions, store user preferences, and analyze traffic patterns. Disabling cookies may impact functionality.
12. International Data Transfers
Your data may be stored or processed in different countries depending on infrastructure location. By using our Services, you consent to such transfers.
13. Your Data Rights
Depending on jurisdiction, you may request access to your data, request correction, request deletion, object to processing, or request data portability. Requests may require identity verification.
14. Account Deletion
Upon request active services will be terminated. Data may be permanently deleted, though billing records may be retained for legal reasons. Deletion does not cancel outstanding payment obligations.
15. Third-Party Services
Our platform may integrate third-party tools such as billing systems, control panels, and payment gateways. We are not responsible for third-party privacy practices.
16. Children's Privacy
Services are not intended for users under 14 years of age. We do not knowingly collect data from minors.
17. Business Transfers
In case of merger, acquisition, or asset sale, user data may be transferred as part of business operations.
18. Limitation of Liability
We are not liable for unauthorized access beyond our control, user misconfiguration, third-party failures, or security breaches despite reasonable safeguards.
19. Policy Updates
We may update this Privacy Policy periodically. Continued use of Services constitutes acceptance of updates.