Controller. The public name is NodeKVM. The site is nodekvm.com. Until a legal name and registered address are published, “we” means the operator of this site. The purpose is to rent a server, take payment, provision it, support it, and keep the books. The purpose is not to sell a list to a third party.
What this policy covers
This policy covers the English pages, the sign-in window, the public order page, the return from payment, the console, tickets, and invoices. It does not cover software you install inside the rented server’s operating system. You run that environment. We do not read the business data in it as a rule, unless you authorize a fault investigation or the law requires it.
Using the site means you understand the processing described here. If you do not agree, do not register or order, and do not submit an email in the signed-out flow.
What we collect
What you give us
- An email address, and a name if you choose to enter one.
- A password or an email code. The code is for registration, sign-in, or reset. We keep what is needed to check it. The page does not show the full password back to you.
- Ticket subject, body, attachments, and later replies.
- The model, disks, bandwidth, extra IPv4, operating system, and billing term you choose on the order page.
What an order and a running server need
- Order number, invoice number, payment status, amount due, and term.
- Instance id, public IPv4, SSH or RDP access details, and provisioning status.
- The request and the handling record for a power ticket: on, off, or restart.
What is produced automatically
- A browser guest id, so an order paid while signed out can be tied to the account you sign in with later.
- A sign-in session and local storage such as language preference.
- Basic access logs: time, path, referrer, and device type, for security and troubleshooting.
- Site actions you start yourself, such as opening the sign-in window or submitting a configuration, so we can see whether the flow works. A separate analytics backend may not be connected yet. If it is connected later, collection still stays inside this page.
Card numbers and wallet keys are collected by the payment gateway. We receive the payment result, an invoice hash, and the fields needed to reconcile. We do not store a full card number.
Why it is used
- To recognize an account, complete registration and sign-in, and reset a password.
- To create an order, take payment, provision an instance, and show access details in the console.
- To handle tickets, power actions, and abuse complaints.
- To issue invoices and to spot a repeated payment or an unpaid order.
- To protect the site, for example by limiting unusual sign-in or bulk registration.
- To provide records the law requires, or that a lawful request from an authority requires.
We do not sell your email or orders to a list broker, and we do not build an advertising profile from business content on the server. Prices and specs on the product pages are the same for every visitor. They are not set per person.
Cookies and local storage
This site uses browser local storage. The session is not kept only in a third-party advertising cookie. The main items are:
- Guest id: so a signed-out order can still match an invoice after you register.
- Sign-in token and user cache: so the console stays signed in.
- A cache of the payment-gateway list: so the channel list is not fetched again every time.
Clearing site data can drop a signed-out cart or session. It does not delete an order that has already been paid and attached to an account. You can clear this site’s data in the browser. You will need to sign in again. These identifiers are not used to track browsing on other sites that has nothing to do with the rental.
Sharing and disclosure
Necessary fields are shared only in the cases below. They are not sold:
- Payment gateway: invoice amount, order id, and the parameters the return needs, so payment can finish.
- Provisioning and facility systems: the configuration, the image choice, the address count, and other details needed to hand over the machine you bought.
- Ticket handling: the fault description you wrote may be seen by support staff, so they can handle power or hardware.
- Legal process: when a court, a regulator, or law enforcement requests records under the law.
- Protecting rights: investigating fraud, abuse, or an attack, and only with the parties who need it.
If a provider changes, we require them to process data only for the purposes in this policy. A change of legal entity or brand name is not, by itself, a sale to an unrelated third party.
Where data is stored, and cross-border access
The server you rent is in Tokyo, Japan. Business data you place on it sits in Tokyo. Account, order, and console records may sit on servers or suppliers we use to run this site. That place is not necessarily Tokyo.
If you visit from another country or region, the path of that visit crosses a border. We use access controls that match a rental service. We do not claim a particular adequacy decision. If the law later requires a separate consent or an extra clause, this page will be updated.
How long it is kept
- Account details: for as long as the account exists. After you ask to close it and no invoice is open, login credentials are deleted or anonymized, except accounting records the law requires us to keep.
- Orders and paid invoices: at least until that term ends, and longer for the fields bookkeeping, tax, or fraud prevention still needs.
- Tickets: may be kept for a period after they are closed, so a power action or a complaint can be traced.
- Guest id and session: they lapse when the session ends or you clear browser data. An order already tied to an account is unaffected.
- Access logs: kept for a short security period, then deleted or rolled into statistics that do not contain an email address.
Data on the machine’s disks may be erased after the service ends. See backup responsibility in the terms of service. That content is what you put on the server, not the account file on this site. Erasure follows the terms of service.
Security
Sign-in and console requests use the HTTPS the site’s environment provides. Passwords are not shown in clear text. Console access details are shown only to a signed-in account that is allowed to see that instance. Staff access to orders and support records is limited by role.
No website can promise it will never be broken into. You still need a strong password, a protected mailbox, and care about opening the console in public. If you think credentials have leaked, change the password and open a ticket at once.
Your choices
- Access: sign in to the console to see the account email, instances, invoices, and tickets.
- Correction: the display name and password can be changed in the console. An email change goes through a ticket, so an order is not attached to the wrong address.
- Deletion: you can ask to close the account. An unfinished payment dispute, or an invoice the law requires us to keep, may delay deletion.
- Stopping a signed-out flow: close the page, clear this site’s local data, and do not continue the order. A paid order is not cancelled by that. It follows the terms of service.
- Optional statistics: if a switchable analytics tool is added later, this page will say how to opt out. There is no separate advertising-tracking switch today.
To use these choices, sign in and open a ticket that names the request. We may ask you to show that you hold the account. The same request can go to support@nodekvm.com.
Minors
This service is not for anyone under 18. We do not knowingly collect a child’s personal information. If you find that a minor has registered, open a ticket. We will close the account and handle leftover records under section 7.
Other sites
During payment you may leave this site for a gateway page. That page follows the gateway’s own privacy rules. An outside link in a note or on the help page is collected by that other site, not by us. Read their notice before you submit a payment or personal information.
Updates to this policy
If the range of collection, the purposes, or the contact details change, we update the date at the top of this page. A material change will be pointed out after sign-in or in a ticket when we can. Continuing to use the site means you have seen the updated notice. If you do not accept it, stop using the site and ask to close the account.
A change to a product spec, such as memory size, the Tokyo facility, or the monthly price, is written on the pricing page. That is not an expansion of personal-information collection. An order already paid follows the rule in the terms of service.
Contact
For a privacy request, including access or deletion: sign in, open a console ticket, and put “Privacy request” in the subject. Or write to support@nodekvm.com.
Use rules, prohibited conduct, and backup responsibility are in the terms of service. Order and access steps are in the help center.