Skip to content

Privacy Policy

Last updated 16 August 2026.

We collect as little as running a hosting business allows. There is no advertising network here, no analytics script, no tracking pixel in our emails, and nothing on this site loads from a third-party domain.

What we hold about you

WhatWhyKept for
Email address Your login, invoices, server credentials, and anything urgent While the account exists
Name, and company if you gave one Putting a name on an invoice While the account exists
Password Signing in Stored only as an Argon2id hash — we cannot read it
Invoices, payments, bitcoin addresses Billing, and being able to explain what you paid 7 years, as tax law requires
Support tickets Answering you, and remembering what we said last time 3 years after the ticket closes
Sign-in times and IP addresses Detecting account compromise 12 months
Web server logs Diagnosing faults and handling abuse 30 days

What we do not collect

  • No identity documents, no phone number, no date of birth.
  • No card or bank details — bitcoin is the only payment method, so they never exist.
  • No analytics, no advertising identifiers, no cross-site tracking.
  • No open or click tracking in our emails.
  • Nothing from inside your server. We do not inspect its contents or its traffic.

Cookies

One, called vlsess, set only after you sign in. It holds a session identifier and nothing else, and it is deleted when you sign out. There is no consent banner because there is nothing to consent to.

Bitcoin and privacy

We generate a fresh receiving address for every invoice and never reuse one, so nobody analysing the chain can total up what our customers pay simply by watching a single address.

Be aware of what this cannot do: bitcoin is a public ledger. If the coins you send are already linked to your identity somewhere else — a KYC exchange withdrawal, for instance — that link exists whatever we do at our end. We do not perform chain analysis on payments, and we do not use a processor that does.

Who we share with

We do not sell or rent your data. It is disclosed only:

  • to our upstream datacentre, where an abuse or hardware matter requires it;
  • where a valid legal order compels us — and we will tell you unless barred from doing so;
  • to protect our network or another customer from an active attack.

We use no third-party analytics, no marketing platform, and no payment processor. Outbound email leaves through our own mail infrastructure.

Where it lives

Account and billing data is stored on our own server infrastructure in Europe. Backups are encrypted and held in object storage.

Your rights

Ask us and we will give you a copy of everything we hold about you, correct anything wrong, or delete what we are not legally required to keep. Invoices and payment records have to stay for the 7-year tax period; we will tell you exactly what that leaves behind rather than quietly keeping more.

Open a ticket or email support@vpslatch.net. We answer within 30 days and usually much sooner. If you are in the UK or EU and think we have got it wrong, you can complain to your national data protection authority.

Breaches

If customer data is exposed we will tell affected customers directly, and publish what happened, what was accessed, and what we changed. We would rather write an awkward disclosure than have you find out from someone else.