Privacy Policy
1. Controller and Definitions
MineXHost LLC, a limited liability company organized in the Commonwealth of Pennsylvania, United States ("MineXHost," "we," "us," or "our"), is the data controller of the Personal Information processed through our website and our control panel (the "panel"). You may contact us at [email protected].
In this Privacy Policy (this "Policy"), "Services" means our website, the panel, and the Minecraft server hosting services we provide through them; "you" and "your" refer to any individual who uses the Services, including a visitor to our website; and "Personal Information" means any information that relates to an identified or identifiable individual.
2. Information We Collect
We collect only the information we need to provide the Services, as described in this Section 2.
2.1 Account Information. We collect your email address, the username you choose, your password in hashed form (we never store passwords in plaintext), your email-verification status, and your account role.
2.2 Technical and Security Logs. For fraud prevention and account security, we record IP addresses and timestamps in our security and activity audit log. The log covers sign-ins (including failed attempts), changes to passwords and two-factor authentication settings, API key actions, and significant administrative actions.
We do not collect or store the IP addresses of players who join your game server. For those players, the panel records only player names, UUIDs, and session times. Player IP addresses are seen transiently at the upstream DDoS-protection layer and are not retained by us. Your server's own log may record a player's IP address, because Minecraft does so by default; that log is your server's data and is under your control. On Minecraft 1.20.2 and later, setting log-ips=false in server.properties turns this logging off.
2.3 Website Analytics. We measure use of our own website with a first-party, self-hosted analytics tool (umami) that runs entirely on our own servers. No third-party analytics or advertising service receives this data, and we do not conduct cross-site tracking of any kind. The tool does not set cookies or store anything on your device. It records only aggregate usage information: the page path (with any query string removed, except standard ad-campaign tags such as utm_source and utm_campaign, which tell us which advertisement or link brought you to the site), the domain of the referring website, screen size, browser language, page title, performance metrics, and basic interaction events, such as button clicks.
We do not store your IP address. We use it only transiently, together with a randomly generated salt that we create each day and then delete, to derive an anonymized one-way hash for counting visits within the same day, and we then discard your IP address. Because each day's salt is random and is deleted within 48 hours, hashes from different days cannot be linked to one another, and once a day's salt has been deleted, no one, including us, can trace that day's hashes back to an IP address.
2.4 Billing Information. We keep records of your orders, subscriptions, invoices, and payments. Card payments are processed by Stripe. We receive a payment token and an opaque Stripe customer reference; we never receive your full card number or card security code (CVC).
2.5 Server Data. We store the server names and configuration you provide, and the worlds, mods, and other files you upload to your servers.
2.6 Consent Records. When you accept our policies at registration or at checkout, we record the time, the policy version, and the source IP address so that we can demonstrate your acceptance.
2.7 Affiliate Referral Cookie. If you arrive at our website through an affiliate's referral link (a web address containing ?ref=), we set one first-party cookie named mx_rp so that we can credit the correct affiliate if you later purchase a server. The cookie contains only a random identifier. It does not contain your name, email address, affiliate code, or any other information about you. The cookie lasts 14 days, after which it expires and no longer credits any affiliate. The cookie carries the HttpOnly attribute, which prevents scripts on the website from reading it, and the SameSite=Lax attribute. On our HTTPS site, it also carries the Secure attribute.
Together with the cookie, we store a record of the visit that contains only a one-way, salted hash of your IP address and browser user-agent, and never the values themselves. We do not use this cookie for advertising, profiling, or cross-site tracking, and we do not share it with anyone. If your browser sends a Global Privacy Control signal (Sec-GPC), we do not set the cookie. You may also delete the cookie at any time in your browser settings; doing so affects only which affiliate receives credit.
2.8 Communications. We keep the support tickets and other messages you send us.
2.9 No Sale of Personal Information. We do not sell your Personal Information, and we do not use it for third-party advertising.
2.10 Discord. If you join our Discord server or link your Discord account to the panel, we collect the information described in Section 10.
3. How We Use Information
We use Personal Information for the following purposes:
- Creating and operating your account, and provisioning, operating, and supporting your servers.
- Processing payments, sending receipts and invoices, and managing subscriptions.
- Securing the Services, including detecting and preventing fraud, abuse, and unauthorized access.
- Sending service and transactional emails, such as email verification, password reset, receipts, and important notices. We send marketing email, if any, only with your consent, and you may opt out at any time.
- Complying with legal obligations, such as tax and accounting recordkeeping.
- Crediting the correct affiliate when a person the affiliate referred purchases a server, using the
mx_rpcookie described in Section 2.7.
4. Legal Bases for Processing (GDPR)
4.1 Legal Bases. Where the General Data Protection Regulation (the "GDPR") applies, we rely on the following legal bases:
- Performance of a contract, for operating your account and your servers.
- Legitimate interests, for security, fraud prevention, and service improvement.
- Legal obligation, for maintaining financial records.
- Consent, for optional marketing. You may withdraw your consent at any time.
4.2 Affiliate Referral Cookie. The affiliate referral cookie (mx_rp, described in Section 2.7) is not required to deliver the Services, so we do not rely on legitimate interests for it. We honor a Global Privacy Control signal from your browser by not setting the cookie, and you may remove the cookie at any time. Removing it does not affect your account, your servers, or anything you have purchased. If you are located in a jurisdiction whose law requires prior opt-in consent for a cookie of this kind, you may contact us at [email protected] and we will exclude you from its use.
5. Disclosure of Information
We share Personal Information only with processors that help us operate the Services, under contract and only to the extent necessary. These are our payment processor (Stripe), our email delivery providers, and our infrastructure and hosting providers. We may also disclose Personal Information where required by law or to protect our rights, our users, or the Services. Our website analytics tool (umami) is self-hosted on our own infrastructure, so we do not share analytics data with any third-party analytics provider. If you use our Discord features, we also send Discord the information needed to operate them, as described in Section 10.
6. Retention
6.1 Account and Financial Records. We retain account and server data for as long as your account is active. When you delete your account, or when we erase it at your request, we promptly anonymize your Personal Information. We retain invoices and financial records for the period required by tax and accounting law, in an anonymized form that is no longer linked to your identifying details.
6.2 Server Data. We retain your server's world, files, and backups for as long as the server exists. Suspending a server, for example for non-payment or when a free trial ends, stops the server but does not delete anything. When a server is removed, we hold it in a recycle bin for 30 days from the moment of removal, during which it can be restored in full. When the 30-day period ends, the server's storage volume and backups are permanently destroyed. If you erase your account, your servers are destroyed immediately together with the account (see Section 7), and the 30-day period does not apply. If you receive a refund under the money-back guarantee described in the Refund Policy, we delete the server and its world data immediately, and the 30-day period does not apply. Section 9 of the Terms of Service states the same period.
6.3 Security and Activity Logs. We maintain an audit log of security-relevant actions, with the source IP address and the time of each action. The log covers sign-ins (including failed attempts), changes to passwords and two-factor authentication settings, API key actions, and administrative actions. We retain these entries for 2 years, after which they are deleted automatically.
If you erase your account before that period ends, we do not delete these entries. An audit log must remain a reliable record of security incidents, and some entries describe actions you took on another person's server and form part of that person's records. Instead, we remove the information that identifies you, namely the IP address, your username, and your device details, and retain only a record of what action occurred, what it affected, and when. Website analytics records are kept separately from this log and have never contained your IP address or any identifier that refers to you (see Section 2.3).
6.4 Consent Records. We keep records of the consents you give us. Different consent records are retained in different ways because they serve different purposes:
- Your acceptance of our policies (the checkboxes at registration and at checkout) is stored with the date, the version of the wording you were shown, and the IP address from which you submitted it. Because this record contains an IP address, it is deleted when you erase your account. After erasure, we retain only the invoice and audit trail, which does not identify you.
- Your consent at checkout to our starting your service immediately (see the Refund Policy) is stored with your order, together with the date, the version, and the exact wording you were shown. This record contains no IP address. It is retained for as long as the order record itself, which is the period required by tax and accounting law.
- When you approve a change to your modpack, we keep a record of what our software did to your server. We store this record separately, outside your server's own storage, so that it cannot be altered from within the server it describes. The record contains the server's identifier, the name you gave the server, and what was changed. We retain it while the server exists and for 7 years after the server is deleted, which is long enough to address a dispute about what you agreed to, after which it is deleted automatically. If you ask us to erase your account, we will continue to hold this record for that period, because it is evidence of an instruction you gave us. You may ask us to review it by contacting [email protected].
7. Your Rights, Including Erasure
7.1 Your Rights. Subject to applicable law, you have the right to access, correct, and export (data portability) your Personal Information, to restrict or object to its processing, and to have it erased (the "right to be forgotten").
7.2 Deleting Your Account. You may delete your account yourself from the Security page in the Account section of the panel. Deletion requires you to re-enter your password. It then anonymizes your email address, username, and stored IP addresses; removes the identifying details from your entries in our security audit log (see Section 6.3); unlinks your Discord account, if you linked one (see Section 10.8); destroys your servers; and cancels your subscriptions. We retain anonymized financial records as required by law.
7.3 Requests and Complaints. You may also exercise any of these rights by emailing [email protected], and you may lodge a complaint with your local data protection authority.
8. Security
We hash passwords using bcrypt, encrypt secrets at rest, and grant access on a least-privilege basis. The panel supports two-factor authentication. No system is completely secure, but we take commercially reasonable measures to protect your data.
9. International Transfers
Your Personal Information may be processed in countries other than your own. Where required, we use appropriate safeguards, such as Standard Contractual Clauses, for international transfers.
10. Discord
MineXHost runs a community server on Discord, where our bot is called MineXBot. Using Discord with us is optional. This Section applies to you only if you join our Discord server or link your Discord account to the panel. Our staff turn individual bot features on and off, so not every feature described below may be in use at a given time.
10.1 Discord Is a Separate Service. Discord is an independent service that we do not operate. Your Discord account, the messages you post on Discord, and the records Discord keeps are processed by Discord under its own Privacy Policy. This Section describes only what MineXHost receives and keeps. Deleting data from the panel does not delete anything that Discord holds.
10.2 Linking Your Discord Account. You may link your Discord account from the Profile page in the Account section of the panel. Linking uses Discord sign-in with the identify permission only, which does not give us your email address. We store your Discord user ID (the number Discord assigns to your account), the time you linked, and which of the Customer and Early Access roles we have given you. We do not store your Discord username, avatar, or email address. During linking, Discord gives us sign-in tokens. We use them once to read your Discord user ID, then ask Discord to cancel them, and we do not store them.
10.3 Customer and Early Access Roles. While your account is linked, we give your Discord account the Customer role while you have a subscription in effect, and the Early Access role while a subscription bought with the Early Access code is in effect. We use your Discord user ID to add and remove these roles. While a role change is waiting to be made, we keep a record of the change and your Discord user ID. That record is deleted when Discord accepts the change, or after 30 days if Discord keeps refusing it.
10.4 Support Tickets From Discord. If your account is linked, you can turn a post in our #support forum into a private support ticket in the panel, or open a ticket from a ticket button in our Discord. Tickets opened from Discord can be general or technical; billing questions go through the panel. We copy only what you type into the ticket form: a subject, which starts as your post's title, and your message. We do not copy the rest of your post, other people's replies to it, or attachments. Replies you send through the Discord reply form are added to the ticket in the same way. The form refuses text that looks like a payment card number. Once created, the ticket is an ordinary panel ticket (Section 2.8), and we keep a record connecting it to the forum post. In the forum post, the bot posts only short notices, such as that a private ticket was opened, that staff replied, or that the ticket was closed. It does not post the contents of the ticket or of staff replies.
10.5 Server Commands. If your account is linked, you can use /server in our Discord to list your servers, check a server's status, or restart a server you have permission to restart. The answers are shown only to you. A restart goes through the same permission checks as a restart in the panel, and we record it in our audit log together with your Discord user ID and the result.
10.6 Community Features. The features below work from your Discord user ID. They do not require a linked panel account, and we do not connect them to one.
- Levels. Messages you post in our Discord can earn experience points. We store your Discord user ID, your points, your level, the number of messages that earned points, and when you last earned points. We count messages; we do not read or store their text for this feature. Other members can look up your level and rank with
/rankand/leaderboard. - Suggestions. When you submit a suggestion with
/suggest, we store its title, its text, and your Discord user ID, and we post it in our suggestions channel. When members vote on a suggestion, we store each voter's Discord user ID and vote, so that each member votes once. When staff approve or deny a suggestion, we store the decision, the reason given, and the staff member's Discord user ID. - Giveaways. Entry is free and requires no purchase. When you enter, we store your Discord user ID for that giveaway. When winners are drawn, we store their Discord user IDs and announce them in the giveaway's channel.
- Polls. When a poll is started with
/poll, we store the question, the answer choices, and the Discord user ID of the person who started it. Votes are held by Discord, not by us. - Role buttons. When you add or remove a role with one of our role buttons, we make the change on Discord and do not store it in our database.
10.7 Welcome Messages, Automatic Replies, and Moderation Logs. When you join our Discord, the bot may post a welcome message that mentions you, send you a welcome direct message, and give you starting roles. It does not store anything about you in our database to do this. If automatic replies are on, the bot reads the text of new messages to compare it with phrases our staff have set, and replies when one matches; it does not store the text. Our staff may also have the bot post a moderation log to a log channel in our Discord. The log can show when members join or leave, role and nickname changes, bans, and message edits and deletions. The text of an edited or deleted message is included only if staff turn that option on. In that case, the bot keeps the text of up to 5,000 recent messages in memory, never in our database, so that it can show what was changed; that copy is lost whenever the panel restarts. Log posts stay in that Discord channel until our staff delete them. We have not set an automatic deletion period for them.
10.8 Retention, Unlinking, and Deletion.
- Your link is kept until you unlink your Discord account or delete your panel account. You can unlink at any time with the Unlink button in the Discord card on the Profile page in the Account section of the panel. Unlinking deletes the stored link and removes your Customer and Early Access roles.
- If you delete your panel account (Section 7.2), we also unlink your Discord account, remove those roles, and delete the records connecting your tickets to forum posts.
- Our audit log records when you link or unlink, each Customer or Early Access role change, and each restart made from Discord, including your Discord user ID. These entries are kept for 2 years, as described in Section 6.3. If you delete your panel account, we remove your Discord user ID from the entries that record your own actions (linking, unlinking, and restarts). Entries that record a role change made by our system keep the Discord user ID until the 2-year period ends.
- Tickets opened from Discord are kept in the same way as any other ticket.
- Level, suggestion, vote, giveaway, and poll records are not connected to your panel account, so unlinking or deleting your panel account does not remove them. We do not currently delete them automatically. You may ask us to delete them.
- Messages you post in our Discord are held by Discord. You can delete your own messages on Discord, and you may ask us to remove them from our server.
To ask for a copy of, or the deletion of, your Discord-related data, email [email protected] and include your Discord user ID, so that we can find records that are not connected to your panel account. Your rights are described in Section 7.
11. Children
The Services are not directed to children under the age of 13 (or the minimum age under local law), and we do not knowingly collect their Personal Information. If you believe that a child has provided Personal Information to us, contact us and we will delete it.
12. Changes to This Policy
We may update this Policy. We will post material changes on this page with a new effective date and policy version, and we will notify you where required.
13. Contact
MineXHost LLC is the controller of the Personal Information described in this Policy. If you have privacy questions or requests, contact us at [email protected], or write to MineXHost LLC, 502 W 7th St, Ste 100, Erie, PA 16502.
