Legal
Privacy Policy
Last updated: July 2, 2026
GhostRDP ("we," "our," or "us") is committed to your privacy. We collect only what is necessary to provide and improve our Services, and we never sell or rent your personal information to third parties. This Privacy Policy explains how we handle your data.
1. Information We Collect
- Account information: Email address, name (optional), and account credentials you provide during registration.
- Payment information: Billing name, email, and payment method details processed by our third-party payment processors. We do not store full credit card numbers.
- Usage data: Server resource usage (CPU, RAM, disk, bandwidth), IP addresses assigned to your servers, and connection timestamps.
- Communication data: Support tickets, live chat transcripts, and any other communications you send us.
- Device & access logs: Browser type, operating system, IP address, and pages accessed when visiting our website. Collected via cookies and server logs.
2. How We Use Your Information
- To provision, maintain, and improve our Services.
- To process payments and send billing-related communications.
- To respond to your support requests and communicate about your account.
- To send product updates, security notices, and administrative messages.
- To detect and prevent fraud, abuse, and violations of our Terms of Service.
- To comply with legal obligations and respond to lawful government requests.
3. Data Retention
We retain your personal information only as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required by law. Specifically:
- Account data: Retained for the duration of your account plus 90 days after termination.
- Usage logs: Retained for up to 12 months.
- Payment records: Retained for a minimum of 5 years per applicable financial regulations.
- Support communications: Retained for up to 2 years.
4. Data Protection & Security
We implement industry-standard technical and organizational measures to protect your data, including:
- Encrypted connections (TLS 1.2+) for all website and control panel traffic.
- Encrypted storage for sensitive data at rest.
- Role-based access controls and least-privilege principles for staff.
- Regular security reviews and penetration testing.
- Network-level DDoS protection and firewall rules.
No method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. If you suspect a data breach, contact us immediately at [email protected].
5. Third-Party Services
We use trusted third-party services to operate our business. These providers are contractually bound to handle your data only for the purpose of providing their services to us:
- Payment processors: Stripe, PayPal, CoinGate, and other payment providers. Their privacy policies govern their data handling.
- Cloud infrastructure: Our servers are hosted with vetted upstream providers. Server-side data processing occurs on infrastructure we manage.
- Support & communications: Crisp.im for live chat, helpdesk software for ticket management.
- Analytics: We use minimal, privacy-respecting analytics. We do not use advertising or tracking networks.
6. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Right to access: Request a copy of the personal data we hold about you.
- Right to rectification: Request correction of inaccurate or incomplete data.
- Right to erasure: Request deletion of your personal data, subject to legal retention requirements.
- Right to data portability: Receive your data in a structured, commonly used format.
- Right to object: Opt out of processing for direct marketing purposes.
To exercise any of these rights, contact us at [email protected]. We will respond to all verified requests within 30 days. California residents (CCPA) and EU residents (GDPR) have additional rights as provided under applicable law.
7. Cookies
We use cookies and similar technologies to operate our website and control panel:
- Essential cookies: Required for authentication, session management, and security. Cannot be disabled.
- Analytics cookies: Used to understand how visitors interact with our website. Privacy-respecting and non-intrusive.
- Marketing cookies: We do not use marketing or advertising cookies.
You can manage or disable cookies through your browser settings. Disabling essential cookies may impair your ability to use the control panel.
8. Children's Privacy
Our Services are not directed to or intended for individuals under the age of 18. We do not knowingly collect personal information from minors. If we become aware that we have collected data from a minor without verified parental consent, we will take steps to delete that information promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. When we make material changes, we will update the "Last updated" date at the top of this page and, for significant changes, notify you via email or a prominent notice on our website. Your continued use of our Services after any changes indicates your acceptance of the updated policy.
10. Contact
If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us at [email protected]. For security-related concerns, contact [email protected].