Skip to content
Hostwolf APPS
Product Pricing Blog Contact Get Started

Privacy Policy

Last updated: October 9, 2026

1. Who we are

Hostwolf ("we") is the data controller for personal data processed to run the Service. You can reach us at [email protected].

2. What we collect

  • Account data — email address, name, password (hashed), and your region and plan choices.
  • Billing data — handled by our payment processor; we store only customer references, invoices and the last four digits of payment methods where the processor exposes them. We never store full card numbers.
  • Apps, servers and databases — when you connect a GitHub repository, we receive the account and repository access needed to clone your code and run builds. Your code, environment variables, databases and files are processed to build and run your apps, serve traffic, and take scheduled backups. They stay on your server, in the city you chose.
  • Technical logs — IP addresses, authentication events, console actions, deploy and build logs, resource metrics, and abuse/security logs.
  • Support conversations — email threads, so we can help with your requests.
  • Website analytics — the website and console use Cloudflare Web Analytics, which is cookieless and reports only aggregated statistics such as page views, referrers and page-load performance. It does not track you across sites.

Cookies — we set only strictly necessary and preference cookies on hostwolf.net, never for advertising or tracking:

  • hw-language — the language you chose, shared by the website, blog and console; kept for 1 year.
  • hw-currency — the display currency you chose, set only if you pick one; kept for 1 year.
  • Console session and security cookies — keep your console session working and protect forms against cross-site request forgery; kept for up to 12 hours, or up to 400 days if you choose to stay signed in.

The console also keeps a few interface settings, such as dismissed notices, in your browser's local storage. Checkout pages are run by our payment processor, which sets its own cookies under its privacy policy.

3. Why we process it (legal bases)

  • Performance of contract — running your account, apps, servers and databases, billing, and support.
  • Legitimate interest — keeping logs to prevent abuse and attacks, securing our infrastructure, and improving the Service.
  • Legal obligation — tax and accounting records.
  • Consent — if you ever opt in to product emails, you can opt out at any time.

4. Payments

Card and other payment data are processed by our payment processor under their privacy policy as a data processor for us. We receive only the identifiers needed to manage your subscription.

5. Hosting and subprocessors

We run app servers and VPS on infrastructure from the providers below, and use standard tooling for email and payments:

  • Hetzner (Germany, Finland, the US and more) — cloud infrastructure;
  • Vultr (regions across North America, Europe, Asia and Australia) — cloud infrastructure;
  • Cloudflare, Inc. (global) — website and console delivery, security, and cookieless web analytics;
  • Our payment processor — payments;
  • GitHub (Microsoft) — the repository connection you authorise, used to clone code and run builds;
  • Transactional email provider — service and account email.

Where personal data leaves the EU/EEA, we rely on adequacy decisions or Standard Contractual Clauses.

6. How long we keep it

  • Account and billing data: for the life of the account, then up to 90 days (longer where tax law requires).
  • Server, security and build logs: up to 30 days, longer only for open abuse cases.
  • Server files, apps, databases and their backups: deleted within 14 days after your server is deleted at the end of a cancelled period.
  • Support conversations: up to 12 months.

7. Your rights

Depending on where you live, you have the right to access, correct, delete, restrict or object to processing of your personal data, and to receive a machine-readable copy of it (portability). Where processing is based on consent, you can withdraw it any time. To use any of these rights, email [email protected] — we respond within 30 days. You can also complain to your local data protection authority.

8. Security

We encrypt traffic with TLS, hash passwords, restrict infrastructure access to staff who need it, and monitor for abuse. No system is perfect, so we also keep the blast radius small: card data never touches our servers, and server instances are isolated from each other.

9. No ad networks, no selling

We do not sell personal data. The website does not run advertising or cross-site tracking; our only analytics is the cookieless, aggregated Cloudflare Web Analytics described above.

10. Changes and contact

If this policy changes materially we will notify account holders by email at least 14 days in advance. Questions: [email protected].

Hostwolf APPS
Product Pricing VPS Blog Contact Terms Privacy Refunds Acceptable use Games ↗
© 2026 Hostwolf
[email protected]