1. Who we are
This Privacy Policy explains how CoAI Host ("CoAI Host", "we", "us") handles personal data when you visit host.coaiwork.com, create an account, order or use our cloud VPS services (the "Services"), or contact us. It should be read together with our Terms of Service and Acceptable Use Policy. Questions can be sent to support@coaiwork.com.
2. Data we collect
- Account and contact details: your name, company name (optional), email address, postal address, phone number, account password (stored only as a one-way hash), language and currency preference, marketing-email preference, and security settings such as two-factor authentication.
- Billing details: orders, invoices, payments, refunds and credit notes, the payment method type and, for saved cards, the card brand, last four digits and expiry date that Stripe returns to us, and Stripe's customer and payment references. We do not receive or store full card numbers or security codes (see section 4).
- Service details: for each server, its plan, hostname, operating system, assigned IP address, the SSH public keys you give us, the initial root (Linux) or Administrator (Windows) password (see section 9), resource and traffic usage statistics, and a history of actions such as start, stop, reboot, reinstall and upgrades.
- Communications: support tickets, emails and other messages you send us, and copies of the service and billing emails we send you (shown under Email History in the client area).
- Technical data: the IP address, browser type and the pages or API routes requested when you use the website, client area or server console, login times and failed login attempts.
3. How we use it
- To create and manage your account, provision and operate your servers, and provide the console and control-panel features.
- To bill you, collect payments (including automatic renewals with a saved card), and keep the accounting records we are required to keep.
- To send service emails you need, such as order confirmations, server details, invoices, payment reminders, overdue and suspension notices, and security or maintenance notices.
- To provide support, investigate abuse reports and keep our network, our customers and the Services secure, including fraud prevention.
- To send marketing emails, but only if you have opted in; you can opt out at any time in the client area or through the link in the email.
- To comply with the law and respond to valid legal requests.
We do not sell your personal data, and we do not use it for third-party advertising.
4. Card payments (Stripe)
Card payments are processed by Stripe. Card details are entered in Stripe's secure payment form and go directly to Stripe; they never pass through or are stored on our servers. When you pay by card, Stripe stores the card as a token so that renewals can be charged automatically, and gives us only the card brand, last four digits and expiry date. You can remove a saved card at any time in the client area under Payment Methods. Stripe processes payment data under its own privacy policy: https://stripe.com/privacy.
5. Email (SendGrid)
Our service and billing emails are sent through SendGrid (Twilio), which processes your email address, the email content and delivery information (for example whether a message was delivered or bounced and, where enabled, whether it was opened or a link was clicked) on our behalf. SendGrid's privacy policy: https://www.twilio.com/en-us/legal/privacy.
6. Your server's content
The data you store on or process with your server is yours. We do not access it except where needed to investigate abuse or a security incident, to protect our network, to provide support you have asked for, or to comply with the law. If you process other people's personal data on your server, you are responsible for doing so lawfully. We do not back up customer servers; when a server is terminated or cancelled, its disks and all data on them are permanently deleted.
7. Logs and cookies
Our web servers and security systems log technical data (section 2) to operate the Services, detect abuse and troubleshoot problems. The website and client area use cookies that are needed for them to work: a session cookie that keeps you logged in and holds your cart, security cookies that protect forms, and preference cookies for language and currency. Opening the browser console of a server sets a login cookie for our console host (pve.coaiwork.com). Stripe sets its own cookies on the checkout and payment pages to prevent fraud. We do not use advertising or third-party analytics cookies.
8. Who we share data with
- Service providers that process data for us: Stripe (payments), SendGrid (email), the data-centre and network providers that host our servers in Utah, United States, and Hetzner Online GmbH, which stores our encrypted off-site backups in Germany (European Union). Backups are encrypted on our servers before they are sent, so Hetzner cannot read their contents.
- Authorities or other parties where we are required to by law or valid legal process, or where needed to protect our rights, our customers or the public (for example in abuse or fraud cases).
We do not share your data with anyone else without your permission.
9. How long we keep data
- Account, billing and support records: for as long as you have an account, and after that for as long as we need them for accounting, tax, fraud-prevention or legal purposes.
- Server data: kept only while the server exists. It is permanently deleted when the server is terminated or cancelled, or when you reinstall it.
- Root passwords: a daily clean-up (at about 03:00 JST) removes root passwords from what we store, as follows. (1) Stored email copies: the password is removed from our stored copy of the "server is ready" email and of the reinstall email at the first daily clean-up after the email is 3 days old, so at the latest 4 days after it was sent; the rest of the email is kept. You can still reveal the current password in the client area. (2) Task queue: the password you enter for a reinstall is removed from the completed reinstall task at the first daily clean-up after the task has been completed for 1 day, so at the latest 2 days after it completed. A task that has not completed (for example one that failed) keeps the password until it completes or our staff remove it. (3) Backups: backups of our billing system that were made before a removal still contain these passwords until the backups themselves are deleted: backups kept on our server after at most about 5 weeks, and encrypted off-site copies after at most about 3 months (see "Backups" below).
- Backups: our billing system (including account, billing and support records) is backed up daily on our server, where copies are kept for up to about 5 weeks, and in encrypted form to off-site storage in Germany (Hetzner), where database copies are kept for up to about 3 months and full system copies for up to about 3 months. The contents of customer servers are not backed up by us.
- Emails we sent you: copies are kept in your account's email history for as long as the account exists.
- Logs: kept for a limited period for security and troubleshooting.
10. Security
We protect data with encrypted connections (HTTPS), access controls, hashed account passwords, and encrypted storage of the server passwords that our billing system keeps for your services (the plain-text copies in stored emails and in the task queue are removed as described in section 9). No system is completely secure; if we become aware of a security incident that affects your personal data, we will notify you where required.
11. Your choices and requests
- You can view and update your account details, change your password and marketing-email preference, and remove saved cards in the client area.
- You can ask us for a copy of the personal data we hold about you, ask us to correct it, or ask us to close your account and delete your data. We will do so unless we have to keep certain records (for example invoices) for legal reasons.
- Send requests to support@coaiwork.com from the email address on your account, or open a support ticket.
The Services are intended for businesses and adults and are not directed at children.
12. Changes to this policy
We may update this Privacy Policy from time to time. The current version is always published on this page with its "Last updated" date. We will notify you by email of material changes.
13. Contact
Questions or requests about privacy can be sent to support@coaiwork.com or submitted as a support ticket in the client area.