What we collect. What we don't. No third version of the truth.
This page is written to match, word for word in substance, what our Terms of Service and our Anonymous VPS disclosure table already say. If you've read either of those, nothing here should surprise you.
- Effective September 3, 2026
- 9 min read
- No server content or traffic logging
1 Who This Policy Covers, and What It Doesn't
In shortthis covers the website and your account with us — not what you run on your own server.
This Privacy Policy explains what VPS For Life ("we", "us", "our") collects when you visit vpsforlife.com, contact us, or order and manage a VPS through our client area, and what we do with it. We are a VPS hosting provider headquartered at 55 Goswell Rd, Barbican, London EC1M 7AA, United Kingdom, and this policy is written with UK GDPR and the Privacy and Electronic Communications Regulations (PECR) in mind.
This policy is about our data practices — the website, the order process, billing, and support. It is not about what you install or run on the VPS itself once it's yours. Section 7 below draws that line explicitly, because for a hosting provider it's the distinction that actually matters.
This page works alongside, and does not replace, the "Data & Privacy" clause in our Terms of Service and the disclosure table on our Anonymous VPS Hosting page. Where this policy goes into more detail, it is expanding on those, not changing them.
2 Information We Collect
In shortan email address to run your account, plus whatever you choose to type elsewhere.
To order and provide a service, we collect:
- Email address — required. Your invoices, server credentials and password resets all go here. It does not have to be tied to your identity.
- Billing name and address — requested on the order form because the invoice template has fields for them. Not required to be real, and never checked against anything. See Anonymous VPS Hosting for the full disclosure.
- Payment confirmation — when you pay by card or PayPal, those processors handle your card/account details directly; we receive confirmation that an invoice was paid, not your full card number. Cryptocurrency payments (Bitcoin, USDT, Ethereum) are confirmed on-chain.
- Support content — anything you send us in a ticket, live chat message, or email, so we can help you.
When you use the website, we (and the tools listed in Section 5) may automatically collect:
- IP address, browser type, device type, and pages viewed — standard web server and analytics data.
- Approximate location inferred from IP address (country/city level, not GPS).
- Referring page and, briefly, marketing parameters (utm_*, gclid, fbclid) before our server strips them from the URL for that visit.
We do not collect, and never ask for: government ID, passport or driving licence, a phone number, or any identity-verification document, at any order value. See Section 7 and 8 for what we deliberately stay away from on the server side.
3 How We Use Your Information
In shortto run the service you paid for, keep it secure, and answer you when you write in.
We use the information above to:
- Provision, activate and maintain your VPS, and process payments and invoices.
- Respond to support tickets, live chat and contact-form messages.
- Screen orders for payment fraud (see Section 6 — this is a standard risk check, not an identity check).
- Send service-related email: invoices, renewal notices, maintenance windows, security notices about your account.
- Understand aggregate site usage (which pages are read, where visitors come from) so we can improve the site and knowledgebase.
- Meet legal obligations, such as responding to a valid legal request or investigating a confirmed Acceptable Use Policy violation.
We do not use your billing information for anything beyond running your account, and we do not send marketing email unless you separately opt in somewhere that says so.
4 Our Legal Basis for Processing
In shortmostly because we need to, to deliver what you ordered — the rest is consent or a real legitimate interest.
Under UK GDPR, each use above rests on one of these bases:
- Contract — provisioning your VPS, billing, and support exist because you ordered a service from us; we need this data to deliver it.
- Legitimate interest — fraud screening, basic site analytics, and keeping the network secure. We've weighed this against your right to privacy; where it doesn't hold up (non-essential cookies), we rely on consent instead — see Section 5.
- Consent — non-essential cookies, and any marketing communication, which we do not send unless you opt in.
- Legal obligation — UK tax and accounting record-keeping, and responding to valid legal process.
5 Cookies & Similar Technologies
In shortwe use a small number of cookies; here's exactly what each one is for.
We group the cookies and similar technologies this site uses into three categories:
- Strictly necessary — the client area's login and shopping-cart session cookies (WHMCS), and a short-lived session used by the contact-form CAPTCHA. The site cannot function without these; they are not tracking cookies and don't require consent under PECR.
- Analytics — Google Tag Manager and Google Analytics, which tell us in aggregate which pages get read and where visitors come from. We don't use this to identify you personally.
- Functional — the Tawk.to live-chat widget, which sets a cookie so a conversation can continue across page loads, and Google Fonts, which loads type files from Google's servers (your IP address is sent to Google to fetch the font, though modern Google Fonts serving does not itself set a tracking cookie).
A banner appears the first time you visit, before either the analytics or the functional category loads — nothing in those two categories runs until you choose Accept All, or individually switch a category on under Customize and save. Choosing Necessary Only, or simply leaving the banner alone, means neither loads. Your choice is remembered in your browser (not tied to your account) so you're not asked again on your next visit.
Changed your mind? Open Cookie Preferences in the footer of any page, any time, to see and change what's switched on.
6 Who We Share Data With
In shortthe vendors that make the service work — never a data broker, never a sale.
We do not sell your data. We share it only with the following categories of recipient, only for the purpose stated:
- WHMCS — our billing and client-area platform. It stores your account, invoices and support history.
- Payment processors — PayPal, our card processor, and the cryptocurrency payment gateway for Bitcoin/USDT/Ethereum orders. They handle your payment method directly; we don't store full card numbers.
- Fraud-prevention services — used at checkout to screen for payment fraud using order-risk signals such as IP address. This is a risk check, not an identity check, and is unrelated to the "no ID" policy described on Anonymous VPS Hosting.
- Google — Tag Manager/Analytics (site usage) and Fonts (typefaces), as described in Section 5.
- Tawk.to — our live-chat provider, if you use the chat widget.
- Datacenter and network partners — the infrastructure providers in the country you choose at checkout host the physical server; they do not have a business reason to see your billing details, and we do not give them your account information beyond what's needed to operate the server you rent.
- Law enforcement or courts — only in response to a valid legal request, and only to the extent required.
7 Your Server Is Not Our Business
In shortwe don't look at what's on your VPS or what passes through it — full stop, with one exception.
Every plan includes full root or administrator access, and you retain ownership of everything you install or store. We do not access the contents of your server, except to investigate a confirmed Acceptable Use Policy violation or a valid legal request — the same standard set out in Terms §9.
We also do not hold a copy of your data as a matter of course. Backups, if you want them, are yours to set up — our knowledgebase has a guide for that.
8 International Data Transfers
In shortyour account data is handled from the UK/EU; your server itself lives wherever you choose.
Two different things move internationally, and they're worth separating:
- Your account and billing data (email, invoices, support history) is processed through our billing platform and the processors listed in Section 6. Where any of them operate outside the UK/EEA, we rely on their standard contractual clauses or equivalent safeguards.
- Your VPS itself is physically located in whichever of our datacenter countries you choose at checkout — see Datacenter Locations. That's a hosting choice you make, not personal data we transfer on your behalf.
9 How Long We Keep Data
In shortas long as your account is active, plus what UK law requires for financial records after that.
- Active accounts: account and billing data is kept for as long as your account is open, so your invoice and support history stay available to you.
- After closure: UK tax and accounting rules require us to retain invoicing records for a period after an account closes (typically several years). We retain the minimum needed to meet that obligation and delete the rest.
- Support tickets: kept for a reasonable period to maintain a service history, then periodically purged.
- Analytics data: retained in aggregate/anonymized form per the retention settings of the tools in Section 5, not indefinitely at the individual level.
10 Your Rights
In shortaccess, correct, delete, or export your data — just email us.
Under UK GDPR, you have the right to:
- Access the personal data we hold about you.
- Correct it if it's inaccurate — though as Section 2 explains, most billing fields are never checked against anything to begin with.
- Erase it, subject to what we're legally required to retain (Section 9).
- Restrict or object to certain processing.
- Port your data to another provider in a structured format.
- Withdraw consent at any time, for anything based on consent (Section 4).
To exercise any of these, email [email protected] with your account email and what you'd like us to do. We'll respond within the timeframe UK GDPR requires. If you believe we've mishandled your data, you can also complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
11 How We Protect Your Data
In shortencrypted in transit, access-controlled, and 2FA is available on your account.
- The website and client area are served over HTTPS with HSTS enabled.
- Two-factor authentication (authenticator app, Duo, or a hardware key) is available for your client-area account — we'd recommend turning it on.
- Payment card data is handled by our processors directly; we don't store full card numbers on our own systems.
- Internal access to billing and support systems is limited to staff who need it to do their job.
No system is perfectly secure, and we don't claim otherwise. If we ever become aware of a breach affecting your personal data, we'll notify affected customers and, where required, the ICO, without unnecessary delay.
12 Children's Privacy
In shortthis service is for businesses and adults — not aimed at children, and we don't knowingly collect their data.
VPS For Life's services are intended for use by businesses and individuals capable of entering a binding contract, and are not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us at [email protected] and we'll remove it.
13 Changes to This Policy
In shortwe may update this page — check the effective date above.
We may revise this Privacy Policy as our practices, the tools we use, or the law change. The current version is always the one published on this page, with the effective date shown at the top. If a change is significant — for example, a new category of data we collect, or a new type of third party we share it with — we'll make that clear here rather than letting it pass quietly.
14 Contact & Data Controller
In shortquestions, requests, or something looks wrong? Tell us directly.
VPS For Life, 55 Goswell Rd, Barbican, London EC1M 7AA, United Kingdom, is the data controller for the personal data described in this policy.
For anything covered here — a rights request, a question about a specific vendor, or to report something that looks wrong — email [email protected] or message us on WhatsApp. You can also use the form on our Contact page.