VPS

PRIVACY

Privacy policy.

Last updated: September 28, 2026

1. What this policy covers

This policy explains what Tovahub processes when you visit the site, sign in, fund an account, order a VPS, or manage a server. It describes the current application behavior and does not apply to the separate policies of Google, X, Servury, Arc, or other third-party services.

2. Information you provide

Depending on how you use the service, we may process your wallet address, signed wallet-login messages, social identity provider, provider subject identifier, name, and email address when the identity provider returns one. We may also process your selected plan, operating system, server hostname, order details, renewal choice, and requests for server actions.

We do not ask for or store your wallet private key. Wallet transactions are signed by your wallet. We do not ask for or store your Google or X password.

3. Operational and transaction data

To operate the marketplace, we process account balances, immutable ledger entries, order and payment status, blockchain transaction data, configured deposit addresses, provider server identifiers, server status, IP address, port, operating system, expiration time, and normalized usage information requested for an owned server.

Operational records may include security, reconciliation, audit, provider-task, and maintenance information. Provider error details are reduced before they are shown in customer or operator views.

4. Cookies and sessions

The service uses essential HttpOnly session cookies to keep you signed in. Wallet sessions expire after a limited period. Social sign-in uses a short-lived HttpOnly OAuth state cookie to protect the authorization flow, and that cookie is removed after the callback. The current application does not use advertising cookies or an analytics profile.

5. How information is used

6. Services we use

Social sign-in may use Google and X. VPS provisioning uses the configured infrastructure provider, currently Servury by default. Blockchain reads and confirmations use the configured Arc network and RPC service. Account and operational records are stored in the configured MongoDB database. These services receive only the information needed for the relevant sign-in, infrastructure, blockchain, or database operation and have their own terms and privacy policies.

7. What we do not do

We do not sell account information for advertising. We do not store wallet private keys, social-account passwords, or provider credentials in the browser. Server-side secrets and provider credentials are kept in the production secret runtime and are not returned by customer API responses.

8. Retention and security

We retain account, payment, operational, security, reconciliation, and audit records for as long as they are needed to provide the service, resolve disputes, complete financial reconciliation, investigate abuse, maintain security, or meet legal and provider obligations. Session and OAuth state data expire automatically according to their configured lifetime.

We use signed sessions, one-time wallet nonces, OAuth state and PKCE checks, owner-only server routes, bounded provider responses, and server-side secret handling. No internet service can guarantee absolute security, so protect your wallet, social account, and server credentials.

9. Your choices

You can stop using a social sign-in session by signing out. You can choose not to connect a wallet or use social sign-in, but account features that require authentication will not be available. A request to correct or remove information may be limited by transaction integrity, fraud prevention, abuse investigation, provider requirements, or legal obligations.

10. Changes to this policy

We may update this policy when the service, providers, data practices, or legal requirements change. The version published on this page applies from its stated update date.