Privacy Policy
Last Updated: 13 November 2025
1. Introduction
Welcome to VPSPioneer. We are committed to protecting and respecting your privacy. This Privacy Policy outlines how VPSPioneer Ltd. ("VPSPioneer," "we," "us," or "our") collects, uses, processes, and safeguards your personal data when you use our website (vpspioneer.com), purchase our services (collectively, the "Services"), or interact with us.
This policy is prepared in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
For the purpose of this data protection legislation, the Data Controller is:
VPSPioneer Ltd.
The Almere, 353 Avebury Boulevard
Milton Keynes, MK9 2HH
United Kingdom
Email: hello@vpspioneer.com
2. What Information We Collect
We may collect, use, and store the following types of personal data:
- Personal Identification Data: Full name, billing address, email address, and phone number. This is collected when you register for an account or purchase Services.
- Financial Data: Payment card details are not stored by us. They are collected and processed directly by our third-party payment processors (e.g., Stripe, PayPal). We only store a token or a record of the transaction.
- Technical & Usage Data: Your IP address, browser type and version, operating system, device type, cookie information, and pages you visited on our website. This is collected automatically when you browse our site.
- Service Data: Information you provide to us when you submit a support ticket, including the content of your communications with our team.
- Domain Registration Data (WHOIS): When you register a domain name, we are required by ICANN to collect data for the public WHOIS database, including your name, address, email, and phone number.
- Client Content (Your Data): This is the data you upload to your hosting account, VPS, or dedicated server (e.g., your website files, databases, emails). We do not access, view, or manage your Client Content except where you explicitly request us to do so (e.g., for a support ticket, a migration, or our Malware Removal service) or where required by law.
3. How We Collect Your Data
We collect data in the following ways:
- Directly: When you fill out our order forms, create an account, submit a support ticket, or contact us via email.
- Automatically: When you use our website, we automatically collect Technical & Usage Data via server logs and cookies. We also use fraud detection services (like MaxMind) which check your IP address during checkout.
- From Third Parties: We receive transaction confirmations from our payment processors (Stripe, PayPal) and may receive information from our domain registrars (e.g., OVH, Enom) or service providers.
4. Our Lawful Basis for Processing Data
Under UK GDPR, we must have a valid reason (lawful basis) to process your data. Our lawful bases are:
- Contractual Necessity: We process your data to fulfill the contract we have with you. This includes creating your account, provisioning your hosting/VPS, registering your domain, and taking payment.
- Legal Obligation: We must process certain data to comply with UK law (e.g., keeping financial records for HMRC tax purposes for at least 6 years).
- Legitimate Interest: We process data for our legitimate interests, such as:
- Preventing fraud and securing our network (e.g., using MaxMind).
- Sending you essential service announcements (e.g., planned maintenance).
- Analyzing website usage to improve our Services.
- Consent: Where required (e.g., for setting non-essential marketing cookies or sending you marketing newsletters), we will ask for your explicit consent.
5. How We Use Your Data
Your data is used for the following purposes:
- To create and maintain your account.
- To process your orders and provide the Services you purchased.
- To process payments and prevent fraudulent transactions.
- To register or transfer domain names on your behalf.
- To respond to your support tickets and provide customer service.
- To perform services you have explicitly requested (e.g., Website Malware Cleaning).
- To send critical service-related communications (e.g., outage notifications, billing reminders, security alerts).
6. Who We Share Your Data With (Third Parties)
VPSPioneer does not sell your personal data. We only share it with trusted third-party partners who are essential to providing our Services:
- Domain Registrars: To register your domain, we must send your WHOIS data (Name, Address, Email) to our upstream registrar partners (e.g., OVH, Enom, or other ICANN-accredited registrars).
- VPS & Dedicated Server Providers: When you order a VPS or Dedicated Server (which we resell), we must pass necessary account details to our upstream provider to provision the server.
- Payment Processors: We share payment information with Stripe, PayPal, or other processors to handle transactions.
- Fraud Detection Services: We pass your IP address and order details to MaxMind to screen for fraudulent orders.
- Email Service Providers: We use external providers (e.g., Hostinger/Titan, SendGrid) to send transactional and marketing emails.
- Legal Authorities: If required by a valid UK court order or law enforcement request.
7. International Data Transfers
Your data may be processed in countries outside the UK. For example, our domain registrars, payment processors (Stripe), or VPS providers may be located in the EU or the USA.
We ensure your data is protected by:
- Only transferring data to countries deemed "adequate" by the UK government (e.g., the EU).
- Using legally-binding Standard Contractual Clauses (SCCs) or other approved safeguards for transfers to other countries (e.g., the USA).
8. Data Security
We take the security of your data very seriously. We implement robust technical and organizational measures to protect it, including:
- SSL/TLS encryption (HTTPS) on all our websites and client areas.
- Secure firewalls on our servers (Proxmox, Hestia).
- Strict access controls (e.g., 2FA for staff).
- Regular security audits and malware scanning.
9. Data Retention
We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for.
- Active Accounts: We retain your data for as long as you have an active account with us.
- Inactive Accounts: After you cancel all services, we are legally required (for UK tax law) to retain your billing information (invoices, name, address) for six (6) years.
- Client Content (Your Data): When you terminate a hosting/VPS service, your data (website files, databases) is permanently deleted from our servers within 30 days.
10. Your UK Data Protection Rights
Under UK GDPR, you are a "Data Subject" and have significant rights. You have the right to:
- Request Access to your personal data.
- Request Rectification of incorrect data.
- Request Erasure of your personal data (the "right to be forgotten"), subject to our legal obligations (see Section 9).
- Object to Processing of your data (e.g., for direct marketing).
- Request Restriction of Processing your data.
- Request Data Portability (to receive your data in a machine-readable format).
- Withdraw Consent at any time (if we are processing based on consent).
To exercise any of these rights, please contact us at hello@vpspioneer.com.
You also have the right to lodge a complaint with the UK's data protection regulator, the Information Commissioner's Office (ICO), at www.ico.org.uk if you are unhappy with how we have handled your data.
11. Cookie Policy
Our website uses cookies (small text files) to function. We use:
- Strictly Necessary Cookies: To run our shopping cart (WHMCS) and client area. These cannot be disabled.
- Performance/Analytical Cookies: (e.g., Google Analytics) To help us understand how visitors use our site so we can improve it.
- Functional Cookies: To remember your preferences (e.g., language or currency).
We will ask for your consent to use non-essential cookies via a cookie banner on your first visit.
12. Changes to This Privacy Policy
We may update this policy from time to time. We will notify you of any significant changes by posting the new policy on this page and, where appropriate, by emailing you.