Privacy Policy
Last Updated: July 1, 2026
1. Data Collection & Input Arrays
NetBay Hosting operates a privacy-centric Virtual Private Server marketplace. We collect and process user data strictly to maintain authentication sessions, handle secure payments, and route compute commands to our hypervisor fleet.
We capture the following categories of data during your utilization of the platform:
- Registration Data: Name, email address, password (stored solely as bcrypt hashes), billing address (including state and postal code for GST calculations), and business credentials (GSTIN).
- Support Data: Support tickets, embedded message payloads, and category assignments (Technical support requests carry VM service mapping references).
- System Audit logs: Access logs, request latencies, client IP addresses (resolved through reverse proxies), browser User Agents, and Approximate GeoIP location mappings (City, Region, Country).
2. How We Use Your Personal Information
Your personal data is strictly used for the following operational workflows:
- Compute Provisioning: Mapping IP addresses and resources on physical hosts, writing virtualization configurations, and setting user tags on VM nodes.
- Communications: Delivering signup OTP verification emails, account balance notification alerts, security warnings, login notifications, and system announcement updates.
- Tenant Branding: Retaining white-label reseller configuration settings (logo URLs, custom domains, primary/accent colors) to apply custom stylesheet settings.
3. Zero-Knowledge VM Policy
NetBay Hosting operates a strict zero-knowledge logical policy regarding your compute nodes. While we monitor hardware performance metrics (such as CPU load, memory exhaustion, network input/output rates, and hypervisor statuses) to guarantee uptime and cluster health:
We absolutely NEVER monitor, inspect, read, or duplicate any files, databases, operating system configurations, or logical network traffic inside your virtual machines. The root credentials and file storage of your VPS remain entirely in your private custody.
4. Data Retention & Auto-Deletion Schedules
We implement automatic deletion schedules to keep our persistent storage footprints light and respect user privacy:
- Developer API Logs: Request telemetry (IP address, latency, endpoint path, and status code distributions) are retained for exactly 7 days before permanent destruction.
- Signup OTPs: Temporary verification records expire and delete automatically within 10 minutes (using MongoDB TTL indexes). Wiped immediately on successful verification.
- Terminated VM History: Action records linked to terminated VMs are held for exactly 3 months before permanent deletion to assist with customer billing disputes.
- Login Events: Retained indefinitely as a security audit trail to prevent unauthorized access and trace intrusion attempts.
5. Payment Security & Subprocessors
NetBay Hosting does not collect or retain payment card details, bank credentials, or UPI PINs.
All payment transactions are handled through PhonePe's secure checkout gateway. PhonePe collects your payment instruments directly. NetBay Hosting only receives webhook callbacks containing payment status, convenience fee breakdowns, and transaction IDs (stored under the `payments` and `transactions` tables).
6. Cookies & Local Storage Configurations
We utilize cookies and localStorage options to power session persistence:
- Session Cookies: A secure cookie (`netbay_session`) is used to maintain Single Sign-On (SSO) configurations across dashboard views and reseller custom domains.
- Local Storage: Reseller configurations, API doc preferences, token secrets, and interface theme selections (glassmorphic vs solid cards) are stored locally in your browser.
7. Your Rights & Access Controls
Under Indian digital laws and general data protection standards, users have the right to inspect their stored account profiles, download transaction histories, request password resets, or close their accounts. To completely wipe your data and delete your account, you must terminate all active VM compute instances, withdraw or spend remaining wallet balances, and contact our support administrators.