Legal
Privacy Policy
We need some information. We don’t need your entire life story.
Effective Date: [DATE]
Not yet reviewed by counsel, and still has real placeholders below ([DATE], [LEGAL ENTITY NAME], [PRIVACY EMAIL],[BUSINESS ADDRESS]) that need actual values before this is binding — replace before this site takes real orders.
The Packet Mill provides virtual servers and related hosting services from Portland, Oregon.
Running servers requires some information about customers.
Running servers does not require us to know everything about customers.
Our general philosophy is simple:
Collect what we need.
Protect it.
Don’t sell it.
Don’t turn it into an advertising profile.
Don’t keep it forever just because storage is cheap.
1. The Short Version
We collect information needed to:
- create your account;
- provision your VM;
- bill you;
- communicate with you;
- keep the network secure;
- troubleshoot problems;
- and comply with legal obligations.
We do not sell your personal information.
We don’t use the contents of your VM to advertise to you.
We don’t routinely inspect your files.
Your payment card is handled by our payment processor rather than stored on Packet Mill infrastructure.
That’s the gist.
The rest exists because lawyers are apparently uncomfortable with privacy policies containing only six sentences.
2. Information We Collect
Depending on how you use Packet Mill, we may collect things like:
- your name;
- email address;
- company or organization name;
- billing address when necessary;
- account identifier;
- services ordered;
- invoices;
- payment status;
- transaction IDs;
- support messages;
- login records;
- IP addresses;
- VM identifiers;
- network assignments;
- bandwidth usage;
- resource consumption;
- system events;
- security events;
- and abuse reports.
We try to limit collection to information we reasonably need.
We do not need to know what coffee you ordered this morning.
Unless you email support about it.
Then technically it may be in the ticket.
3. Payment Information
Payments are handled by a third-party payment processor.
Our goal is for sensitive financial information to remain firmly in the payment processor’s world.
Packet Mill does not intend to store:
- complete credit-card numbers;
- card security codes;
- or other complete card credentials.
We send the payment processor the amount.
They attempt the transaction.
They send us information about the result.
Packet Mill may retain:
- payment status;
- transaction ID;
- amount;
- date;
- refund status;
- dispute information;
- and limited payment-method information provided by the processor.
Think of us as the person at the cash register who knows you paid but does not take your credit card home afterward.
4. What’s Inside Your VM
Your virtual machine belongs to your workload.
We do not routinely inspect:
- your files;
- databases;
- websites;
- source code;
- private applications;
- communications;
- or other content stored inside your VM.
We don’t mine your VM for advertising data.
We don’t sell information about what you’re running.
We don’t have a room where somebody watches customer terminals scroll by in green text.
Although admittedly that would look extremely 1994.
5. When We May Access a VM
There are limited circumstances where we may need to access a customer’s VM or related information.
These can include:
- support you specifically requested;
- troubleshooting;
- infrastructure failure;
- security incidents;
- credible abuse reports;
- protecting other customers;
- or legal requirements.
We try to limit access to what is reasonably necessary for the situation.
If you ask us to troubleshoot something inside your VM, for example, we may need to look inside your VM.
Computers remain stubbornly resistant to telepathy.
6. Logs
Servers generate logs.
Lots of logs.
Logs about logs.
Occasionally logs explaining why another log failed.
Packet Mill may maintain operational information such as:
- account logins;
- timestamps;
- source IP addresses;
- administrative actions;
- VM starts and stops;
- network usage;
- bandwidth;
- resource utilization;
- system errors;
- authentication events;
- and security alerts.
We use this information to operate, protect, troubleshoot, and improve the service.
7. Network Traffic
Your network packets necessarily pass through our network.
That is somewhat central to the whole business model.
We do not routinely inspect the contents of customer traffic.
Automated systems may analyze technical characteristics of traffic for things such as:
- routing;
- capacity management;
- DDoS protection;
- abuse detection;
- troubleshooting;
- and network security.
During an incident, we may temporarily capture or inspect network information when reasonably necessary to diagnose or resolve the problem.
We are interested in whether the network works.
We are not interested in reading your SSH session.
8. How We Use Your Information
We may use customer information to:
- create your account;
- provision services;
- generate invoices;
- process billing;
- send service notices;
- provide support;
- prevent abuse;
- investigate security incidents;
- troubleshoot problems;
- comply with tax and accounting requirements;
- comply with applicable law;
- and improve Packet Mill.
We do not sell your personal information.
We do not rent it.
We do not trade it for artisanal coffee beans.
9. Other Companies We Work With
No hosting company exists entirely by itself.
Packet Mill may use other companies for things such as:
- payment processing;
- email;
- DNS;
- domain services;
- hosting and colocation;
- Internet transit;
- monitoring;
- support tools;
- accounting;
- and infrastructure.
These companies may receive the information reasonably necessary to perform their role.
We try to avoid giving vendors information they don’t need.
10. Cookies
Our website and customer portal may use cookies or similar technologies for things like:
- staying logged in;
- maintaining your session;
- account security;
- remembering preferences;
- and basic analytics.
We don’t need seventeen advertising networks following you around the Internet because you looked at a $12 VPS.
If we materially change how we use tracking or analytics technologies, we’ll update this policy.
11. Information We Don’t Sell
Let’s make this particularly clear.
Packet Mill does not sell customer personal information.
Your account is not a marketing asset.
Your VM is not an advertising profile.
Your browsing history is not our business.
Your data is not being traded behind a curtain at Saturday Market.
12. Sharing Information
We may share information when reasonably necessary:
- at your direction;
- with vendors providing Packet Mill services;
- to investigate fraud;
- to respond to serious security incidents;
- to protect our infrastructure;
- to protect customers;
- as part of a legitimate business transaction;
- or when required by applicable law.
We don’t casually hand customer information to unrelated third parties.
13. Law Enforcement
If law enforcement or another government agency asks us for customer information, we require appropriate legal process when the law requires it.
A request does not become legally binding just because it has a government logo at the top.
Depending on the circumstances, valid process may include things like:
- subpoenas;
- warrants;
- court orders;
- or other lawful demands.
Where legally allowed and reasonably practical, we may notify affected customers.
We may challenge requests we believe are invalid, overly broad, or legally deficient.
14. Retention
We keep different kinds of information for different lengths of time.
For example:
Billing and accounting records may need to remain for tax and legal reasons.
Security information may need to remain while an incident is being investigated.
Operational logs may be kept for shorter periods.
We do not intend to keep every log generated since the dawn of UNIX.
Information is generally retained only as long as reasonably necessary for legitimate business, security, accounting, dispute-resolution, or legal purposes.
15. What Happens When a VM Is Deleted
When you delete a VM, or when a terminated VM reaches its deletion date, we remove its active storage through our normal systems.
However, storage systems are complicated.
Residual data may temporarily remain in:
- snapshots;
- backups;
- storage replicas;
- logs;
- or other technical systems
until those systems naturally rotate, expire, or overwrite it.
We don’t promise instant forensic erasure unless we specifically agree to provide such a service.
If your VM contains exceptionally sensitive information, you should consider securely deleting it before canceling the service.
16. Security
We use reasonable technical and organizational measures to protect customer information.
That may include things like:
- access controls;
- network segmentation;
- authentication;
- monitoring;
- encryption where appropriate;
- and limiting administrative access.
No system is perfectly secure.
Not ours.
Not Google’s.
Not the machine under someone’s desk that’s been running FreeBSD since 2003.
Customers are responsible for securing their own VMs and credentials.
17. Passwords and Credentials
Please use good passwords.
Even better, use SSH keys and multifactor authentication where available.
Do not use:
password
password1
portland
or the name of your dog followed by 123.
If someone gains access to your account because you reused credentials from another breached service, we will help where we reasonably can, but good security begins with your account.
18. Security Incidents
If Packet Mill discovers a security incident involving customer personal information, we will investigate it.
We may take steps to:
- contain the incident;
- protect affected systems;
- preserve evidence;
- determine what occurred;
- and prevent recurrence.
If applicable law requires customer notification, we will provide notification as required.
19. Your Privacy Requests
You may contact us to ask reasonable questions about personal information associated with your Packet Mill account.
Depending on applicable law and the circumstances, you may request things such as:
- access;
- correction;
- or deletion.
We may need to verify your identity first.
We may also need to retain certain information for reasons such as:
- billing;
- tax records;
- fraud prevention;
- security;
- disputes;
- or legal obligations.
Deleting an account does not mean the IRS lets us delete the accounting records too.
We checked.
20. Children
Packet Mill is not intended for children under 13.
We do not knowingly collect personal information from children under 13 through our normal account-registration process.
If you believe such information has been provided to us, contact us.
21. Changes to This Policy
Technology changes.
Our services may change.
Privacy laws may change.
Portland will continue debating the best coffee shop.
If we materially change this Privacy Policy, we’ll provide reasonable notice through our website, customer portal, or email.
The date at the top identifies the current version.
22. Questions About Privacy
You can contact us about privacy at:
The Packet MillPortland, Oregon
[LEGAL ENTITY NAME]
[PRIVACY EMAIL]
[BUSINESS ADDRESS]
We’d rather answer a privacy question than make you interpret a 42-page corporate policy written entirely in legal fog.
Your packets belong to you.
We’re just milling them.