Legal
Privacy Policy
Last updated: 19 July 2026
1. Who we are and scope
This Privacy Policy explains how Scalewithus (“Scalewithus”, “we”, “us”) collects, uses, discloses, and protects personal information when you use our websites, console, APIs, documentation, and VPS hosting services (the “Services”). It should be read with our Terms of Use.
Contact for privacy requests:
contact@scalewithus.com · +91 8878870188 · Contact page
By creating an account, topping up a wallet, deploying a VPS, or otherwise using the Services, you acknowledge this Policy. If you do not agree, do not use the Services.
2. Roles: account data vs content on your VPS
- Account and billing data. For personal information in your Scalewithus account, billing profile, support tickets, and control-plane logs, we act as the organization determining how that data is processed (sometimes called a “data fiduciary” / controller under applicable law).
- Customer content on your VPS. Files, databases, applications, logs, and other data you store or process inside a virtual machine (“Customer Content”) are controlled by you. We process Customer Content only as needed to provide hosting, migration, backups (where offered), abuse/security response, and legal compliance — not to use it for advertising or to build unrelated profiles.
- You are responsible for providing any required notices and obtaining any required consents from your end users whose data you put on a VPS. Your end users should not contact us as their primary privacy contact for data you control.
3. Information we collect
Account, identity, and authentication
- Name, email address, username
- Password (stored hashed) and/or passkey / WebAuthn credential metadata
- KYC or verification data you submit when we request it (for example government ID, address proof, business documents) and related review outcomes
- Team/member invitations and role metadata, if you use shared access features
Billing and payments
- Billing contact details, company name, tax identifiers (if provided)
- Wallet balance, top-ups, usage charges, invoices/transactions, and payment status
- Payment metadata from payment providers (for example last-four digits, transaction IDs, failure codes). Full card numbers are typically handled by the payment processor, not stored by us
Service and console use
- Console activity, deploy/power/rebuild actions, project and server configuration metadata
- SSH public keys you store, hostname/labels, package and network assignments
- Login history, IP addresses, device/browser/user-agent information, approximate location derived from IP
- Support communications (email, phone, WhatsApp, tickets) and attachments you send
Technical, security, and abuse signals
- Host, network, and control-plane telemetry for operations, capacity, troubleshooting, and abuse prevention
- Security logs, rate-limit events, fraud signals, and complaint/abuse reports relating to your services
- Cookies or similar technologies for sessions and limited analytics (see Cookies)
Customer Content (on-VPS data)
We do not routinely inspect Customer Content. It may nonetheless be processed mechanically when disks are stored, migrated, snapshotted, backed up, restored, or when we take emergency action for security, abuse, or legal process (for example isolating a host or preserving evidence). Backup systems, where offered, may copy disk images or related data on a best-effort basis as described in the Terms.
Information from others
- Payment processors, fraud-prevention tools, and identity providers
- Abuse reporters, blocklist operators, upstream networks, or law enforcement
- Publicly available sources where relevant to fraud or sanctions screening
4. How we use information
- Provide, operate, maintain, migrate, and improve the Services
- Create and manage accounts; authenticate users (including passkeys); reset access
- Process wallet top-ups, usage metering, invoicing, tax collection, and collections
- Provide support and respond to requests
- Monitor for abuse, fraud, security threats, spam, and Terms violations; investigate and remediate incidents
- Enforce our Terms of Use; protect the platform, our rights, customers, and the public
- Comply with law, regulation, court orders, and lawful requests
- Send service, security, and account notices (these are not optional marketing if needed to operate the account)
- Send product or marketing messages only where permitted by law (you may opt out of non-essential marketing)
- Perform analytics on aggregated or de-identified data to improve the Services
We do not sell your personal information, and we do not use Customer Content to train public AI models or to advertise to third parties.
5. Legal bases and India DPDP
Depending on your location and applicable law (including India’s Digital Personal Data Protection Act, 2023, where it applies), we process personal data based on one or more of:
- Contract / service delivery — to provide the account, VPS, billing, and support you request
- Legitimate use / legitimate interests — security, fraud and abuse prevention, service improvement, network integrity (balanced against your rights)
- Consent — where we ask for it (for example certain cookies or optional marketing)
- Legal obligation — tax, accounting, sanctions, law-enforcement, and similar duties
- Employment / business context — if your employer or organization provides your details for an account
Where consent is the basis, you may withdraw it as described below; withdrawal does not affect processing already performed or processing required to run a paid service you still use.
6. Sharing and disclosure
We may share information with:
- Service providers / subprocessors — hosting, storage, email, monitoring, analytics, KYC, and payment providers who process data on our instructions under confidentiality and security obligations
- Professional advisors — lawyers, accountants, insurers, auditors, when needed
- Business transfers — in connection with a merger, acquisition, financing, reorganization, or sale of assets; successors may continue to use information as described in this Policy
- Abuse and security partners — upstream networks, hosting partners, or abuse desks when needed to mitigate attacks, spam, or illegal activity involving your services
- Authorities and legal process — when we reasonably believe disclosure is required by law, court order, or government request, or to protect rights, safety, property, or the integrity of the Services
- With your direction — for example when you authorize a team member or integrate a third-party tool
We may disclose limited account or technical information in good faith to respond to valid legal process or urgent threats. Where legally permitted and practicable, we may notify you of a request — but we are not obligated to do so if notice would be unlawful, futile, or would increase risk.
7. International and cross-border processing
Our VPS infrastructure is operated primarily for customers in India. Account, billing, support, email, payment, and analytics systems may be processed in India and/or other countries where we or our providers operate. By using the Services, you understand that your information may be transferred to and processed in those locations, subject to applicable law and appropriate safeguards for the nature of the data.
8. Retention and deletion
- Account and billing records are retained while your account is active and thereafter as needed for tax, accounting, dispute, fraud-prevention, and legal retention periods.
- Operational and security logs are retained for a limited period for diagnostics, abuse investigation, and security, then deleted or aggregated.
- KYC documents may be retained as required for compliance and risk management.
- After account closure or VPS deletion, disks, snapshots, and backups may be deleted according to our operational schedules. Deletion from active systems may be prompt; residual copies in backups or disaster-recovery media may persist until those media cycle — backup retention is best-effort and not a guarantee that data remains available for you to retrieve.
- We may retain information needed for legal holds, ongoing disputes, chargebacks, or abuse investigations even after a deletion request.
- We are not required to retain Customer Content for your future use after suspension, termination, or non-payment; see the Terms.
9. Security
We use administrative, technical, and organizational measures designed to protect personal information and infrastructure (access controls, least privilege where practicable, encrypted transport where appropriate, monitoring). Absolute security cannot be guaranteed.
- You must protect credentials, passkeys, API tokens, and SSH keys.
- You are responsible for securing Customer Content and guest systems (patching, firewalls, application security, encryption at rest inside the guest if required for your use case).
- Host, disk, or node failures can cause data loss; platform backups (if any) are best-effort. This Policy does not create a durability, uptime, or breach-notification SLA beyond what mandatory law requires.
- If we become aware of a personal-data breach affecting account data we control, we will take steps required by applicable law, which may include notifying you and/or authorities when legally required.
10. Your choices and rights
Subject to applicable law (including DPDP rights where they apply), you may be able to:
- Access or update certain account and billing profile information in the console
- Request a copy, correction, or deletion of personal data we hold about you as fiduciary/controller
- Withdraw consent for processing that is solely consent-based (for example optional marketing)
- Opt out of non-essential marketing emails via unsubscribe links or by contacting us
- Raise a grievance with us at the contact above; if unresolved, you may have rights to approach the applicable regulatory authority under local law
Limits: We may refuse or limit requests that are unfounded, excessive, legally restricted, or that would compromise security, other users, ongoing investigations, or our legal obligations. Deleting account data may require closing the account and does not automatically erase Customer Content already deleted from hosts, nor information we must keep for law or dispute purposes. Requests about data inside your VPS should be handled by you as the party controlling that content.
Email contact@scalewithus.com to make a request. We may require identity verification and reasonable detail before acting. We aim to respond within the period required by applicable law.
11. Children
The Services are not directed to individuals under 18 (or the higher age of majority where you live). We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will take appropriate steps to delete it.
12. Cookies and similar technologies
- Essential cookies — authentication, session continuity, security, and load balancing. Required for the console to function.
- Preferences — remember UI settings where used.
- Analytics — limited measurement of how the marketing site or console is used, where enabled.
You can control cookies through browser settings. Blocking essential cookies may break login or console features. Where required by law, we will present additional cookie choices.
13. Third-party sites and services
The Services may link to third-party sites or payment pages. Their privacy practices are governed by their own policies. We are not responsible for third-party content or practices.
14. Organization / employer accounts
If you use the Services on behalf of a company, your organization may control access and may receive account activity related to your user. Direct privacy requests about workplace accounts may need to be coordinated with your organization.
15. Automated processing
We may use automated systems for fraud scoring, abuse detection, rate limiting, and capacity management. These systems may affect access to the Services (for example challenging a login or suspending a high-risk deploy). You may contact us to request human review of an automated decision that significantly affects you, where required by law.
16. No extra warranties
This Privacy Policy describes privacy practices. It does not create warranties about service uptime, backup success, data durability, or security beyond what is stated here and in the Terms. Marketing descriptions of “daily backups” or similar features are best-effort convenience features as defined in the Terms.
17. Changes
We may update this Privacy Policy from time to time by posting a revised version. The “Last updated” date will change when we do. Material changes may also be communicated by email or console notice when practicable. Continued use after the effective date constitutes acknowledgment of the updated Policy. If you do not agree, stop using the Services and close your account.
18. Contact and grievance
Privacy and grievance contact:
Scalewithus
contact@scalewithus.com
+91 8878870188
Contact page
Questions? Contact us or email contact@scalewithus.com .