Last updated: 15 July 2026

Privacy Policy

This Privacy Policy explains what information GrowVPS ("GrowVPS", "we", "us") collects, how we use and share it, and the choices and rights you have. It applies to the GrowVPS marketing site and to the dedicated server ("box") we provision for you.

The short version: We collect the minimum we need to bill you and run your box. Payments go through PayPal — we never store your card number. Your business data and any social-media access tokens live sealed on your own box, not pooled with other customers. You can export or delete your data. We use a small number of infrastructure sub-processors, listed below.

1. What we collect

Account & contact information

When you sign up, we collect your email address and basic account details needed to create and manage your subscription and to send you service and lifecycle messages (for example, your build-status link and sign-in details).

Payment information

Payments are processed by PayPal. We receive limited billing metadata from PayPal (such as subscription status, the last four digits and brand of your card, and billing country) so we can manage your subscription. We never receive or store your full card number, CVC, or full payment credentials — those are handled entirely by PayPal under its own security and compliance program.

Box telemetry & operational data

To keep your box healthy, we collect operational telemetry such as provisioning and lifecycle events, uptime and health checks, resource usage, and error logs. This is used for monitoring, support, security, and billing integrity — not for advertising.

Data on your box

Your box stores the business data you put on it, which may include personal information about your own contacts or customers ("Customer Data"), and — if you connect them — access tokens for social-media or other third-party accounts you authorize. These social tokens are stored sealed (encrypted) on your own dedicated box, are used only to perform the actions you configure, and are not pooled into a shared multi-tenant store. As the operator of your box, you are the controller of the Customer Data on it; we act as your processor for that data.

Backups

We take daily encrypted backups of your box so your data can be restored and exported. Backups are encrypted and scoped so that one customer's backups are isolated from another's.

2. How we use it

  • To create, provision, operate, secure, and maintain your dedicated box;
  • To process payments, manage your subscription, and prevent fraud (via PayPal);
  • To send you service, transactional, and lifecycle communications (build status, sign-in, billing notices, security and policy updates);
  • To provide support and respond to your requests;
  • To monitor performance, diagnose problems, and improve reliability and security; and
  • To comply with legal obligations and enforce our Terms of Service.

We do not sell your personal information, and we do not use your Customer Data or your social tokens for advertising.

Where the GDPR or similar laws apply, we process personal data on the bases of performing our contract with you (providing the service and billing), our legitimate interests (securing and improving the service, preventing fraud), your consent (where required, for example certain communications), and compliance with legal obligations.

4. Sub-processors & sharing

We share limited data with a small number of infrastructure providers that help us run the service. Each processes data only as needed to provide its function:

  • PayPal — payment processing and subscription billing.
  • Hetzner — server/compute hosting for your dedicated box.
  • Cloudflare — DNS, network, and related edge services, and encrypted backup storage.
  • Amazon Web Services (AWS SES) — delivery of transactional and lifecycle email.
  • Our social-publishing provider — the engine that performs the social/marketing publishing actions you configure. (We describe this provider generically; it operates on your behalf using the access you authorize.)

We may also disclose information if required by law, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets (in which case we will seek to ensure continued protection of your data). Aside from the operational sharing described here, we do not sell or rent your personal information.

5. Where data is stored

Your dedicated box and its daily backups are hosted with the infrastructure providers listed above. Depending on the provider and region, data may be stored and processed in the European Union, the United States, or other regions where our sub-processors operate. Where personal data is transferred across borders, we rely on appropriate safeguards (such as the sub-processors' standard contractual clauses and compliance programs).

6. Data retention

We keep account and billing records for as long as your subscription is active and thereafter as needed to meet legal, tax, and accounting obligations. Customer Data on your box is retained while your subscription is active. After cancellation or termination, we complete an export and take a final snapshot, then retain backups and snapshots only for a limited wind-down window before securely deleting them. Operational logs and telemetry are retained for a limited period for security and reliability purposes.

7. Export & deletion rights

Built, Not Rented — no lock-in. You can request a full export of your Customer Data at any time, and export is part of the cancellation flow. You may also request access to, correction of, or deletion of your personal information, and depending on your location you may have additional rights (for example, under the GDPR or CCPA) such as objecting to or restricting certain processing. To exercise any of these, email [email protected]. We take a snapshot before we destroy anything, so a deletion request is honored deliberately and verifiably. Note that some records (such as billing history) may be retained where required by law.

8. Cookies

Our marketing site uses minimal cookies and does not use third-party advertising or cross-site tracking cookies. Where we use cookies or similar technologies for essential functionality (for example, a session/authentication cookie on account or status pages), they are limited to operating the service. Any status links we email are handled so that access tokens are kept out of referrer headers.

9. Security

We use technical and organizational measures designed to protect your information, including encryption of backups, sealed (encrypted) storage of sensitive tokens on your own box, isolation between customers' boxes and backups, and least-privilege access to infrastructure. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. Please tell us promptly at [email protected] if you believe your account or data has been compromised.

10. Children

GrowVPS is a business service and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.

11. Changes

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you. Your continued use of the service after changes take effect constitutes acceptance of the updated policy.

12. Contact

Questions, requests, or privacy concerns? Email [email protected]. See also our Terms of Service.

← Back to GrowVPS