Privacy Policy

This document is legally binding in English only. The rest of RollerHoster is available in your language.

Version 2026-07-09

1. Who is responsible (controller)

Operator: [legal name] · [postal address] · [contact email]. This block must be completed by the operator before production launch; everything below describes what the RollerHoster software actually does.

2. What we store and why

DataPurposeLegal basis (GDPR Art. 6(1))
Username, email, password hash (argon2id) or Google account idYour account and sign-in(b) contract
TOS/privacy acceptance (timestamp, policy version, method)Proving your agreement(c) legal obligation / (f) legitimate interest
Session records incl. IP address and browser user-agentKeeping you signed in; abuse prevention(b) contract, (f) legitimate interest
Server configuration, team memberships, activity feed entriesOperating your game servers(b) contract
Payment transactions and credit ledgerBilling; tax and accounting law(b) contract, (c) legal obligation
Support ticketsHelping you(b) contract
Administrative audit entries incl. the acting admin's IPSecurity and accountability of privileged actions(f) legitimate interest
Optional: your linked Hytale account (account/profile UUID, username, an encrypted refresh token)Authenticating your server against Hytale under your own account(b) contract — only if you link it
Waitlist email (pre-launch signup)One launch notification(a) consent

Passwords are never stored in plaintext. Hytale tokens and server credentials are encrypted at rest. We do not use advertising trackers or analytics cookies; the dashboard keeps your session token in your browser's localStorage only.

3. How long we keep it

DataRetention
Account dataUntil you delete your account
Sign-in sessionsExpire automatically (30 days of inactivity by default) and are removed at expiry or logout
Activity and admin audit entries90 days, then deleted automatically
Server performance metricsRaw: ~25 hours · hourly rollups: 60 days · alerts: 30 days
Payment transactionsKept for statutory accounting periods; on account deletion they are irreversibly de-identified (your user id is replaced by a keyed one-way reference that cannot be recomputed without the operator's secret key)
Backups of your serversRotated by your keep-count. Deleting a backup or the server immediately triggers deletion of the archive and its off-site copy; if a storage node is unreachable at that moment, the failure is logged and the operator removes the remaining copy as soon as possible
Support ticketsDeleted with your account
Waitlist emailUntil you unsubscribe (see §7) or delete an account registered with the same email, and in any case no longer than 24 months from signup, after which it is deleted automatically. We also store the date and the version of the wording you consented to, so we can show what you agreed to.

4. Who receives data (processors and recipients)

The operator must list the concrete SMTP and backup-host providers (and their locations / transfer safeguards, e.g. SCCs for non-EEA providers) here.

5. Your game servers and other people's data

Worlds, logs and backups of your server can contain personal data of the players who join it (names, UUIDs, chat). For that data you are the controller and we act as your processor: we store and back it up on your instructions and delete it with your server. See the Terms of Service for the processing terms.

6. Age

RollerHoster is not intended for children. You must be 16 or older to create an account; we ask you to confirm this at sign-up and record that confirmation. We do not knowingly collect data from anyone younger, and we do not seek parental consent (GDPR Art. 8) — if we learn that an account belongs to someone under 16, we delete it. If you believe a child has given us their data, contact the operator and we will erase it.

7. Your rights

8. Changes

Material changes bump the version date above and are announced on the dashboard before they take effect.

« Back