What we collect, why we collect it, and what we do with it.
Last updated: July 28, 2026 · Effective: August 11, 2026
Plain English summary. We collect what we need to give you the service, understand how it is used, prevent fraud, and bill you. We don't sell your data. We don't read what you store on your virtual machines. We use a small number of well-known sub-processors, including Stripe, Cloudflare, and MaxMind, and list them below. You can ask us to delete your data at any time.
ServersCamp is operated by ServersCamp S.R.L., a company registered in Romania. When this policy says "we", "us", or "ServersCamp", it means that company. When it says "you", it means the person or organisation using our services or visiting this website.
Contact for any privacy question: [email protected].
We do not currently run a centralised log collector. Application processes write to standard output inside their containers, but those streams are not aggregated, archived, or queryable. Once a container restarts, those lines are gone.
HTTP request metadata is observed by our reverse proxy provider, Cloudflare. We also temporarily store first-party product analytics such as your IP address, browser and device information, pages visited, referrer, campaign parameters, clicks, form submissions (form names and actions, not entered values), scroll depth, and session activity. If you sign in, these events may be associated with your user and organisation.
Traffic leaving our network passes sensors that look for known attack patterns: contact with cryptocurrency mining pools, port scans, brute-force attempts, high-rate automated crawling, outbound spam, and traffic floods. This is pattern matching on network behaviour, not reading your data. Nothing at all is recorded for traffic that matches nothing, which is almost all of it.
When a pattern does match, we record:
We record these because a rule number on its own cannot be checked or argued with. When we act on a match, you get the same lines we did, so you can compare them against your own logs and tell us we are wrong. Request bodies, payloads, headers beyond the ones listed, credentials and cookies are never captured.
We use these records to stop attacks that originate on our platform, to answer abuse complaints, and to enforce the acceptable use rules in our terms of service. On trial accounts a match can suspend the account automatically, or open a support ticket asking you to explain the traffic, depending on how conclusive the pattern is: see section 4.1 of the terms. The records are kept for 14 days and then deleted.
We do not inspect the contents of your virtual machines, databases, or object storage. Block storage volumes are encrypted at rest. Object storage data is private by default. The only time we would access workload contents is if compelled by valid legal order, or if we have an active abuse complaint and need to verify it (e.g., to confirm reported phishing content). Even then, only authorised staff with audit logging.
When you contact us by email or chat, we keep the messages and any attachments you send. We use them to help you and to improve our docs.
We operate our own first-party analytics on the marketing site and Cloud Panel. It helps us understand traffic sources, navigation, conversion, errors, and feature use. We use MaxMind GeoIP and minFraud to derive location, network, proxy or VPN indicators, device intelligence, and a fraud-risk score from login and signup traffic. MaxMind's fraud-prevention device tracking can recognise the same device across network changes and participating sites. We do not use this data for advertising.
This site uses a small number of cookies. None of them are used for advertising or cross-site tracking.
sc_vid) - recognises repeat visits across our website and panel. Lasts up to 1 year.sc_sid) - groups activity into a visit. Lasts 30 minutes and is extended while you are active.__mmapiwsid) - first- and third-party cookies plus local storage used to recognise devices for fraud prevention, including when an IP address changes. Lasts up to 2 years.To run the service we share specific data with the following companies. We've picked them because they are widely used, EU-friendly, and have their own published privacy commitments.
| Company | What it's used for | What it sees | Location |
|---|---|---|---|
| Stripe | Payment processing for cards | Card details, billing address, transaction amount | Ireland (EU) |
| Oblio | Romanian-compliant invoice generation | Billing name, address, VAT ID, line items | Romania (EU) |
| BCR (Banca Comercială Română) | Bank account for SEPA transfers | Standard bank-transfer metadata | Romania (EU) |
| Cloudflare | CDN, DDoS protection, reverse proxy | Public IP, request URL, headers, bytes transferred (kept on their systems for ~30 days) | Global edge network |
| MaxMind | IP geolocation, device intelligence, and fraud prevention | IP address, browser and device signals, language, account identifier, and login or signup context | United States (SCCs) |
We also run our own internal tooling (Grafana for metrics, OpenSearch for logs) on infrastructure we control. These are not third parties - your data does not leave our systems for those.
If we add or replace a sub-processor we'll update this list. For material changes we will notify you by email at least 14 days in advance so you can object.
If GDPR applies to you, we process your data on the following legal bases:
Under GDPR (and similar laws in many other countries) you have the right to:
Email [email protected] with any of these requests. We'll respond within 30 days.
Your data is hosted in EU datacenters by default. Some of our sub-processors (notably Cloudflare) operate global edge networks, which means request metadata (your IP, the URL you visited) may pass through servers outside the EU. Where data leaves the EU, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission.
We take security seriously. Some of what we do:
If you discover a security issue, please email [email protected] with the subject line "SECURITY". We will respond promptly.
ServersCamp is not directed at children. We don't knowingly collect data from anyone under 16. If you believe a child has signed up, contact us and we'll delete the account.
If we make material changes we will notify you by email and post a banner on the site at least 14 days before the change takes effect. Minor edits (typos, clarifications, new sub-processors that don't change how we use your data) we'll update silently with a new "Last updated" date at the top of this page.
ServersCamp S.R.L.
Șos. Colentina 16, Bl. A5, Ap. B44
Sector 2, Bucharest 021177, Romania
CUI: 50730737
Nr. Reg. Com.: J2024032843002
EUID: ROONRC.J2024032843002
Email: [email protected]