Privacy policy
What we collect when you buy and run a VPS, why we need it, how long we keep it, and the rights you have over it.
Last updated 17 September 2026
This policy explains how Rogue Wave Hosting handles personal information when you visit this website, create an account, buy a virtual private server, and use the client portal. It is written to be read, not to be skimmed past, so it says what we actually hold rather than listing every category a hosting company could conceivably collect.
1. Scope of this policy
This policy covers the marketing website, the checkout and client portal, and the account and operational records we keep in order to provision and run your servers.
It does not cover the content of your virtual private server. You have full root or administrator access to your instance, you install and configure the software on it, and whatever personal data you choose to process there is governed by your own privacy notice, not this one. Section 6 explains the split.
2. Who is responsible for which data
There are two distinct relationships, and it matters which one applies:
- Your relationship with us. For your account, billing and support records, and for the operational logs described in section 5, Rogue Wave Hosting decides what is collected and why. In data protection terms we are the controller for that information.
- Your relationship with your own users. For anything you store or process inside your VPS, you decide what is collected and why. You are the controller for that data and we process it only as an incident of hosting the machine it sits on.
3. Information we collect
Account and billing information
- The name, email address and any organisation details you give us when you register.
- The billing information needed to charge for the service, including the billing address and country required for tax purposes. Card details are entered with our payment provider and are handled by that provider; we hold only the limited reference data needed to identify a payment, such as the card type, the last digits and the expiry, together with the record of what was charged.
- Your invoices, payments, credits and the plan and term you selected, including whether you are billed monthly or on a quarterly, semi-annual or annual prepaid term.
- Authentication data for the client portal, held in a form that lets us verify a sign in without storing your password in readable text.
Server metadata
To provision and operate an instance we necessarily hold the configuration of that instance: the region you chose, the memory and disk you bought, the operating system image, the dedicated IPv4 address assigned to it, hostname, power state, the initial credentials issued at setup until you change them, and the record of upgrades, reinstalls and cancellations. Setup is automated and a server is ready within seconds of checkout, which means this metadata is created as part of checkout itself.
Support correspondence
Tickets and email you send to us, our replies, and any diagnostic detail you choose to include. Please do not paste passwords or private keys into a ticket.
Website and portal usage
Standard request data when you load a page: IP address, timestamp, the page or endpoint requested, the referring page, and browser and operating system information from the user agent string. We use it to keep the site working and to detect abuse of the site itself.
4. Why we use it
- To provide the service. Creating your account, provisioning the instance you bought, assigning its address, making it reachable, applying upgrades, and answering your support requests. This use is necessary to perform our contract with you.
- To bill you. Calculating the charge from the memory on your plan, applying the term discount where one applies, issuing invoices, taking payment and chasing non-payment. This is also contractual, and in part a legal obligation where tax and accounting records are concerned.
- To keep the platform safe and available. Investigating abuse reports, tracing the source of network attacks, spam and intrusion attempts, operating DDoS protection, and protecting other customers on shared disk and network capacity. We rely on our legitimate interest in running a secure network, and on yours in not sharing that network with an attacker.
- To meet legal obligations. Responding to lawful requests from competent authorities, retaining records we are required to retain, and dealing with legal claims.
- To tell you about the service. Operational notices such as maintenance windows, security advisories, billing reminders and changes to these policies. These are part of running the account and are not marketing. If we ever send genuine marketing email it will be on the basis of your consent and every message will carry an unsubscribe link.
We do not sell personal information, and we do not use your data to build advertising profiles or share it with advertising networks.
5. Connection and security logs
Running a network that carries other people's traffic means keeping enough record of that traffic to answer the question "where did this come from". We log platform-level connection and flow data associated with your instance and its address, authentication events on the client portal, and the actions taken through the portal such as a rebuild or a power cycle. Where DDoS mitigation triggers, the mitigation event is recorded too.
These logs exist for security, abuse handling and fault diagnosis. They are not used to analyse what you host or to profile you, and access to them is limited to the people who need it for those purposes.
We do not inspect the content of traffic inside your instance as a matter of course. Where an abuse report or a security incident makes it necessary, we may examine traffic characteristics at the network level to identify and stop the activity, and we keep that examination as narrow as the problem allows.
6. Data you store inside your VPS
Your instance is yours. We do not routinely read the contents of your disk, your databases or your application logs. Because you hold root or administrator access, you are responsible for the software you install, the accounts you create, the ports you open through your firewall, and the security of anything you process there.
Two consequences follow, and both are worth stating plainly:
- If you process other people's personal data inside your instance, you are the controller for it. You need your own lawful basis, your own privacy notice, and your own answer for data subject requests about it. We cannot answer those requests for you, because we do not have visibility into your data model.
- Rogue Wave Hosting does not provide a backup or snapshot service, so there is no copy of your instance data held by us for you to restore from. Keeping your own copies, and keeping them somewhere other than the instance itself, is part of your responsibility as controller.
We may access an instance where it is genuinely necessary: to investigate a confirmed abuse report, to respond to a security incident affecting the platform, to comply with a lawful order, or because you have asked us to look at something in a support ticket. Access of that kind is limited to what the purpose requires.
When an instance is cancelled or terminated, its storage is released back to the platform and the data on it is no longer retrievable by us or by you. Take what you need off the machine before it goes.
7. How long we keep information
We keep each category of information for as long as the purpose that justified collecting it still applies, and then we stop. Rather than quote a retention period we cannot honour for every record type, here is the purpose that governs each one:
- Account and server metadata
- Kept while the account is open, because it is what makes the service work. After closure, only what is needed for the purposes below is retained.
- Invoices, payments and tax records
- Kept for the period the applicable accounting and tax rules require, which is longer than the life of the account.
- Connection and security logs
- Kept for the period needed to investigate abuse, security incidents and faults, and rotated out on a routine cycle once that window has passed. Where a specific log is part of an open investigation, a legal claim or a request from a competent authority, it is preserved until that matter closes.
- Support correspondence
- Kept while it remains useful context for your account and for any related dispute, then deleted.
- Abuse records
- Kept for as long as needed to enforce the acceptable use policy consistently, including the record of a prior notice or suspension, since the enforcement ladder depends on knowing whether something has happened before.
Where we no longer need information but cannot delete it immediately, for example because it sits in a routine system record, we restrict its use to storage until it is removed.
8. Where information is processed
We operate in four regions and you choose the one your instance runs in:
- Toronto, Ontario, Canada
- Washington, D.C., United States
- Brussels, Belgium, in the Digital Realty BRU1 facility
Server metadata and operational logs for an instance are handled in connection with the region that instance runs in. Account, billing and support records are part of a single customer relationship and may be processed in connection with any of these regions, which means information about you can move between Canada, the United States and the European Union.
If you are in the European Economic Area and your personal data is transferred out of the EEA, that transfer is made under a mechanism the GDPR permits for the destination in question. For Canada this includes the adequacy decision in place for commercial organisations there. For the United States, where no adequacy route applies to the transfer, we rely on the European Commission's standard contractual clauses together with the technical and organisational measures described in section 12. You can ask us for information about the mechanism applied to a specific transfer using the contact details in section 14.
If the region you run in matters to you for data protection reasons, choose it at checkout. Brussels keeps the instance and its operational data inside the European Union.
9. Cookies and local storage
This site is static and is not instrumented for advertising. We use only what the site and the client portal need to function:
- Session and authentication. A cookie that keeps you signed in to the client portal and protects form submissions against cross-site request forgery. Without it you cannot stay logged in.
- Preferences. A small amount of local storage for choices you make in the interface, such as your colour scheme, so the page does not reset itself on every visit.
- Checkout state. Short-lived storage that remembers the configuration you were building so that moving between steps does not lose it.
These are strictly necessary or set at your own instruction, so we do not ask for consent to them. We do not set advertising or cross-site tracking cookies. You can clear or block cookies in your browser, but the client portal will not be able to keep you signed in if you block its session cookie.
10. Who we share information with
We disclose personal information only in these situations:
- Service providers acting on our instructions. Payment processing, invoicing, email delivery, and the facilities that house our hardware. They may use the data only to provide their service to us. You can ask for information about the providers involved in your account by writing to privacy@roguewavehosting.com.
- Abuse complainants and network operators. When we act on an abuse report we may confirm to the reporter that the report was received and actioned. We may exchange technical detail, such as addresses and timestamps, with other network operators where that is needed to stop an attack.
- Competent authorities. Where we are legally required to disclose information, or where disclosure is necessary to protect someone from harm. We check that a request is valid before acting on it and we disclose no more than the request covers.
- Professional advisers and successors. Where necessary to establish or defend a legal claim, or in connection with a reorganisation or sale of the business, in which case the recipient remains bound by this policy until it is replaced with an equivalent one.
11. Your rights
If you are in the European Union or the wider European Economic Area, the GDPR gives you the following rights over the personal data we hold as controller. We honour them for every customer, wherever you are, except where a right is defined narrowly by a specific law.
- Access
- You can ask what personal data we hold about you and receive a copy of it, together with the purposes, the recipients and the retention approach.
- Rectification
- You can have inaccurate data corrected and incomplete data completed. Most account and billing details can be corrected by you directly in the client portal.
- Erasure
- You can ask us to delete personal data where we no longer need it for the purpose it was collected for. This right has limits: we cannot delete an invoice we are required to keep, and we cannot delete an abuse record while it is needed to enforce the acceptable use policy or to defend a claim. We will tell you which limit applies rather than simply refusing.
- Restriction
- You can ask us to stop using data while its accuracy or the basis for its use is in dispute. We will keep storing it but do nothing else with it until the point is resolved.
- Portability
- For the data you gave us and which we process to perform our contract with you, you can receive it in a structured, commonly used, machine readable format, or ask us to send it to another provider where that is technically feasible.
- Objection
- You can object to processing we carry out on the basis of our legitimate interests, including the security and abuse handling described in section 5. We will stop unless we can show compelling grounds that override your objection. You can object to direct marketing at any time and we will stop without any balancing exercise.
- Withdrawing consent
- Where we rely on your consent, you can withdraw it at any time. Withdrawal does not affect processing already carried out on that basis.
- Automated decisions
- We do not make decisions about you by automated means alone that have a legal or similarly significant effect. Automated fraud and abuse checks may flag an order or an instance for review, and a person makes the decision that follows.
To exercise any of these rights, write to privacy@roguewavehosting.com from the address on your account, or from another address together with enough detail for us to identify the account. We may ask you to confirm your identity before we act, because handing account data to the wrong person would be the worse failure. We respond within the period the applicable law allows and we will tell you if a request is complex enough to need an extension.
Requests about data held inside a customer's VPS have to go to that customer, not to us. If you have contacted a customer of ours and got nowhere, write to privacy@roguewavehosting.com and we will pass the request on to the account holder.
You also have the right to complain to a data protection supervisory authority. If you are in the EEA you can complain to the authority in the country where you live or work, or where the issue arose. We would rather hear from you first so we can try to put it right, but that is your choice and not a precondition.
12. Security
We take technical and organisational measures appropriate to the risk. In practical terms: our own hardware in the facilities listed in section 8, access to administrative systems limited to the people whose job requires it and protected by multi-factor authentication, encrypted transport for the website and the client portal, passwords stored only in hashed form, and DDoS protection on every plan at no extra cost.
Security inside your instance is your side of the line. You choose the operating system, you patch it, you decide which ports to open through the firewall, and you manage its credentials. A strong platform will not save a server with a password of "root" and port 22 open to the world.
If a personal data breach affecting data we control occurs and it is likely to result in a risk to your rights, we will notify the relevant supervisory authority and, where the law requires it, tell you directly and explain what happened and what to do.
13. Changes to this policy
We update this policy when the service or the law changes. The date at the top of the page shows when the current version took effect. Where a change materially affects how we use your personal data, we will tell account holders by email before it takes effect rather than relying on you noticing a new date.
14. How to contact us
- Privacy questions, data subject requests and questions about this policy: privacy@roguewavehosting.com
- Abuse reports, including reports about content hosted by a customer: abuse@roguewavehosting.com
- Everything else, including technical support and billing: support@roguewavehosting.com
Related pages: terms of service, acceptable use policy and service level.