1. What we collect
Account: email address, display name, optional company name, language preference, and a hash of your password. We never store the password itself.
Billing: invoices, balance ledger entries, and the transaction reference and status returned by the payment provider. We never see or store your full card number; card details are handled by the payment provider.
Service: the machine model and region you rent, its address and ports, traffic usage, and the power and reinstall requests you submit.
Technical: the IP address and browser identifier used at sign-in, to spot unusual logins and to throttle brute-force attempts. Ticket contents and anything you describe in them.
2. Why we need it
To perform the contract: without an email we cannot hand over credentials, without invoices we cannot reconcile payments, without machine records we cannot provision anything.
For security: IP and sign-in records drive rate limiting and account-theft investigations. Balance adjustments and impersonation by staff are written to an audit log, which constrains us as much as it protects you.
For legal obligations: transaction records are kept as long as applicable tax and accounting rules require.
We do not sell your information and we do not use it for third-party advertising.
3. Who we share it with
Upstream facilities and hardware suppliers: the technical details needed to provision and repair a machine. Not your payment details.
Payment providers: invoice amount and reference, so they can collect.
Email provider: your address and the message contents, to send verification, invoice and renewal mail.
Law enforcement: only on a legally founded formal request. Unless we are forbidden to, we will try to tell you first.
4. How long we keep it
Account information is kept while the account exists. After you close it we delete or anonymise that information within 30 days, except transaction records we are required to retain.
Sign-in and rate-limit records are kept 90 days. Audit logs are kept three years, because they record privileged actions.
Data on a machine is wiped with the machine when the service ends; we keep no separate copy.
5. Your rights
You can view and change your account information in the portal, export your invoices, and switch off marketing email. Transactional email — verification, invoices, renewal reminders, handover notices — cannot be switched off, because it is how we perform the contract.
You can ask us to correct information, delete your account, or send you a copy of what we hold about you. Write to support@fucker.sh; we reply within 30 days.
If you think we have handled your information improperly, you can complain to the data protection authority where we are registered.
6. Cookies and local storage
We set only what the service needs to run: a session identifier, a CSRF token, and your language preference. Without them you cannot stay signed in.
There are no third-party analytics or advertising trackers on this site.
7. Contact
Privacy questions go to support@fucker.sh, or by post to FUCKER NETWORKS LIMITED.
Material changes to this policy are emailed 30 days in advance.