Privacy Policy
Last updated 16 August 2026.
We collect as little as running a hosting business allows. There is no advertising network here, no analytics script, no tracking pixel in our emails, and nothing on this site loads from a third-party domain.
What we hold about you
| What | Why | Kept for |
|---|---|---|
| Email address | Your login, invoices, server credentials, and anything urgent | While the account exists |
| Name, and company if you gave one | Putting a name on an invoice | While the account exists |
| Password | Signing in | Stored only as an Argon2id hash — we cannot read it |
| Invoices, payments, bitcoin addresses | Billing, and being able to explain what you paid | 7 years, as tax law requires |
| Support tickets | Answering you, and remembering what we said last time | 3 years after the ticket closes |
| Sign-in times and IP addresses | Detecting account compromise | 12 months |
| Web server logs | Diagnosing faults and handling abuse | 30 days |
What we do not collect
- No identity documents, no phone number, no date of birth.
- No card or bank details — bitcoin is the only payment method, so they never exist.
- No analytics, no advertising identifiers, no cross-site tracking.
- No open or click tracking in our emails.
- Nothing from inside your server. We do not inspect its contents or its traffic.
Cookies
One, called vlsess, set only after you sign in. It holds a session identifier and nothing else, and it is deleted when you sign out. There is no consent banner because there is nothing to consent to.
Bitcoin and privacy
We generate a fresh receiving address for every invoice and never reuse one, so nobody analysing the chain can total up what our customers pay simply by watching a single address.
Be aware of what this cannot do: bitcoin is a public ledger. If the coins you send are already linked to your identity somewhere else — a KYC exchange withdrawal, for instance — that link exists whatever we do at our end. We do not perform chain analysis on payments, and we do not use a processor that does.
Who we share with
We do not sell or rent your data. It is disclosed only:
- to our upstream datacentre, where an abuse or hardware matter requires it;
- where a valid legal order compels us — and we will tell you unless barred from doing so;
- to protect our network or another customer from an active attack.
We use no third-party analytics, no marketing platform, and no payment processor. Outbound email leaves through our own mail infrastructure.
Where it lives
Account and billing data is stored on our own server infrastructure in Europe. Backups are encrypted and held in object storage.
Your rights
Ask us and we will give you a copy of everything we hold about you, correct anything wrong, or delete what we are not legally required to keep. Invoices and payment records have to stay for the 7-year tax period; we will tell you exactly what that leaves behind rather than quietly keeping more.
Open a ticket or email support@vpslatch.net. We answer within 30 days and usually much sooner. If you are in the UK or EU and think we have got it wrong, you can complain to your national data protection authority.
Breaches
If customer data is exposed we will tell affected customers directly, and publish what happened, what was accessed, and what we changed. We would rather write an awkward disclosure than have you find out from someone else.