Legal · Privacy policy

How we handle your personal data

This page covers what we collect when you browse, configure, pay, sign in, and use the console. List prices and hardware specs are product facts, not personal data. Contact email is support@sfpcloud.com. Publishing a legal name later will not widen the collection already described.

Last updated: 20 September 2026 Read together with the terms of service We do not sell personal data

Controller. The public name is SFP Cloud. This site is sfpcloud.com. Until a legal name and registered office are published, “we” means the operator of this site. We process data to take orders, collect payment, provision machines, support you, and keep accounts — not to sell mailing lists.

Scope

This policy covers the English pages on this site, the sign-in dialog, the configurator, payment return, the console, tickets, and invoices. It does not cover software you install inside the operating system you rent. You administer that environment. We do not read business data stored there unless you authorize troubleshooting or the law requires it.

Using this site means you understand the processing described here. If you do not agree, stop registering and ordering, and do not submit an email in the guest checkout flow.

What we collect

What you provide

  • Email, and a name if you choose to enter one.
  • A password or an email verification code (codes are used to register, sign in, or reset; we store what we need to verify them and never echo a full password on the page).
  • Ticket subjects, bodies, attachments, and later replies.
  • The server, disks, bandwidth, extra IPv4, OS, and billing term you pick on the configurator.

What we need to fulfill an order

  • Order numbers, invoice numbers, payment status, amount due, and term.
  • Instance identifiers, public IPv4, SSH or RDP access details, and provisioning status.
  • Power-action tickets (on, off, reboot) and how they were handled.

What is generated automatically

  • A browser guest identifier so an unpaid or just-paid order can attach to the account you sign in with later.
  • Sign-in session and language preference in local storage.
  • Basic access logs: time, path, referrer, device type, used for security and debugging.
  • Interactions you start (for example opening the sign-in dialog or submitting a configuration), so we can tell whether the flow works. The analytics endpoint may not yet be wired to a separate dashboard. If it is, collection still stays within this page.

Card numbers and wallet secrets are collected by the payment gateway. We receive payment results, invoice hashes, and the fields needed to reconcile. We do not store a full card number.

Why we use it

  • Identify an account, complete registration and sign-in, and reset a password.
  • Create orders, collect payment, provision instances, and show access details in the console.
  • Handle tickets, power actions, and abuse reports.
  • Issue invoices and distinguish paid orders from unpaid ones.
  • Protect the site, including limiting unusual sign-ins or bulk registration.
  • Produce records when the law or a lawful request requires them.

We do not sell your email or orders to list brokers, and we do not build advertising profiles from the contents of your server. Prices and specs on the product pages are the same for every visitor. We do not personalize list prices.

Cookies and local storage

This site uses browser local storage. Sessions are not written only into third-party advertising cookies. The main items are:

  • Guest identifier: so a guest order can still match an invoice after you register.
  • Sign-in token and user cache: to keep the console signed in.
  • Payment-gateway list cache: to avoid fetching channels on every visit.

Clearing site data drops a guest cart or session. It does not delete an order that has already been paid and attached to an account. You can clear this site’s data in the browser; you will need to sign in again. We do not use these identifiers to track browsing that is unrelated to the rental.

Sharing and disclosure

We share only the fields needed in the cases below. We do not sell data:

  • Payment gateways: invoice amount, order identifiers, and return parameters so payment can complete.
  • Provisioning and site systems: configuration results, image choice, and address counts so we can deliver the machine you bought.
  • Ticket work: the fault description you write may be read by support staff handling power or hardware issues.
  • Legal requirement: when a court, regulator, or law-enforcement body lawfully requests records.
  • Protecting rights: investigating fraud, abuse, or attacks, limited to people who need those fields.

If a vendor changes, we require them to process data only for the purposes in this policy. A later change of legal entity or brand name is not, by itself, a sale to an unrelated third party.

Where data is stored and cross-border transfer

The server you rent sits in Tokyo. Business data you place on that machine stays in Tokyo under your control. Account, order, and console records may live on servers or vendors we use to run this site, which may not be in Tokyo.

Visiting from another country means the request path crosses a border. We apply access controls that match a rental service. We do not claim a specific adequacy decision. If the law later requires a separate consent or extra terms, this page will be updated.

How long we keep it

  • Account details: for as long as the account exists. After you ask us to close it and there are no open invoices, we delete or anonymize sign-in credentials, except records the law requires us to keep.
  • Orders and paid invoices: at least until that term ends, and then as long as bookkeeping, tax, or anti-fraud rules require the necessary fields.
  • Tickets: may be kept for a period after they are closed so power actions and complaints can be traced.
  • Guest identifiers and sessions: expire when the session ends or you clear browser data. Orders already attached to an account are not affected.
  • Access logs: kept briefly for security, then deleted or rolled into statistics that do not include email.

Data on the machine disks may be wiped after the service ends. See backup responsibility in the terms. That is content you placed on the server, not account data on this site. Wipe rules follow the terms.

Security

Sign-in and console requests use the HTTPS provided by the environment that hosts this site. Passwords are not shown in clear text. Access details appear only to a signed-in account that is allowed to see that instance. Internal access to orders and support records is limited by role.

No website can promise it will never be breached. Use a strong password, protect the mailbox, and do not open the console in public. If you think credentials leaked, change the password and open a ticket immediately.

Your rights and choices

  • Access: sign in to the console to see the account email, instances, invoices, and tickets.
  • Correction: name and password can be changed in the console. Email changes go through a ticket so orders are not attached to the wrong account.
  • Deletion: you can ask us to close the account. An unfinished payment dispute or invoices we must keep by law may delay deletion.
  • Withdrawing from the guest flow: close the page and clear this site’s local data, then stop ordering. A paid order is not canceled that way; it follows the terms.
  • Optional analytics: if we later add an analytics tool you can turn off, we will explain how on this page. There is no separate advertising-tracking switch today.

To exercise these rights, sign in and open a ticket that states the request type. We may ask you to prove you hold the account. You may also send the same request to support@sfpcloud.com.

Children

This service is not offered to people under 18. We do not knowingly collect a child’s personal data. If you find that a minor registered, open a ticket. We will close the account and handle leftover records under section 7.

Third-party pages

Payment may take you off this site onto a gateway page. Those pages follow the gateway’s own privacy rules. Outbound links in notes or help, if they point elsewhere, collect under that site’s rules, not ours. Read the other party’s notice before you submit payment or personal data.

Updates

When collection, purposes, or contact details change, we update the date at the top of this page. Material changes will be flagged after sign-in or in a ticket where we can. Continued use means you have seen the updated text. If you do not accept it, stop using the service and ask us to close the account.

Changes to product specs (memory size, the Tokyo site, monthly prices) belong on the pricing page. They are not “expanded personal-data collection.” Those changes follow the rules for already-paid orders in the terms.

Contact

For privacy, access, or deletion requests: sign in, open a console ticket, and put “Privacy request” in the subject, or write to support@sfpcloud.com.

Use rules, prohibited activity, and backup responsibility are in the terms of service. Ordering and access steps are in Help.

Sections

Scope What we collect Why we use it Cookies and local storage Sharing and disclosure Storage and borders Retention Security Your rights Children Third-party pages Updates Contact