Privacy Policy
Torchbyte (“Torchbyte”, “we”, “us”, or “our”) provides hosting and infrastructure services, including VPS, dedicated servers, DDoS protection, and game server hosting. We respect your privacy and are committed to protecting personal data. This Policy explains what we collect, how we use it, your choices, and your rights.
This Policy applies to: (i) visitors to torchbyte.com and related sites (the “Sites”); (ii) customers and prospective customers; and (iii) end users who interact with our services through our customers.
1) Who we are & how to contact us
Controller: All Things IT SRL.
Email: [email protected]. If you are in the EEA or UK, you may also contact our EU/UK representative (if appointed) or lodge a complaint with your local authority.
2) Personal data we collect
Data you provide (via WHMCS): name, email, phone, company, billing addresses, service selections, support tickets/communications, authentication data, preferences.
Payments: we do not store full payment instrument details on Torchbyte servers. Payments are processed by PayPal and Stripe. We receive limited metadata (e.g., transaction IDs, status, timestamps, last four digits).
Support & communications: ticket contents, emails, chat logs, and any attachments.
Automatically collected: IP addresses, timestamps, device and browser info, referrer/exit pages, configuration data when using our Sites or WHMCS portal.
Network telemetry (sFlow): sampled flow records (e.g., source/destination IPs and ports, protocols, interface identifiers, packet/byte counts) from our network equipment to monitor bandwidth, improve performance, and detect/prevent abuse and attacks. sFlow is sampling-based and does not capture all traffic or full payload contents.
Cookies & similar tech: used for session management, security, preferences, and analytics.
From third parties: payment confirmations/fraud signals from PayPal/Stripe; aggregated or de-identified usage metrics from Google Analytics 4 and Matomo.
3) How we use personal data
• Provide and operate services (provision servers, manage accounts, process orders and payments, client portal, support).
• Security and abuse prevention (including DDoS mitigation and sFlow-based monitoring).
• Billing and account administration (invoicing, collections, fraud prevention).
• Improve and develop services (troubleshooting, performance optimization, capacity planning).
• Communications (service/transactional notices, invoices, disruptions; marketing where permitted).
• Legal compliance (meet obligations, establish/defend claims, cooperate with authorities).
EEA/UK legal bases: contract; legitimate interests (security, fraud prevention, analytics, improvement); legal obligation; consent (for certain cookies/marketing where required).
5) Payments
Payments are processed by PayPal and Stripe under their terms and privacy notices. Torchbyte receives limited transaction metadata for reconciliation, anti-fraud, and support.
7) International data transfers
We operate in the US and EU and may transfer data across borders. Where required, we use appropriate safeguards such as Standard Contractual Clauses (SCCs), DPAs, and supplementary measures.
8) Data retention
We retain personal data only as long as necessary for the purposes described, including service delivery, legal obligations (tax/accounting/fraud), dispute resolution, and enforcement. When no longer needed, data is deleted or anonymized.
9) Security
We maintain administrative, technical, and organizational measures: access controls, encryption in transit where appropriate, hardened infrastructure, network monitoring (including sFlow collectors), and periodic reviews. No system is fully secure; safeguard your credentials and systems.
10) Your rights and choices
Depending on your location, you may have rights to access, rectify, erase, restrict, port, object, and withdraw consent. Contact [email protected]. You may also complain to your local authority. For California residents, CCPA rights may apply; we do not knowingly sell or share data of consumers under 16.
11) End-user / customer data
For data our customers store or process via our services (“Customer Data”), Torchbyte acts as a processor and processes such data only under customer instructions. Customers are responsible for their own privacy notices and responding to end-user requests.
12) Children’s privacy
Our services are not intended for children under 16, and we do not knowingly collect their data.
13) How we respond to requests for information
We assess legal requests (e.g., subpoenas, court orders) for validity and scope, require appropriate process, and notify affected customers where legally permitted.
14) Changes to this Policy
We may update this Policy from time to time. The effective date above shows the latest revision. Material changes will be communicated on the Sites, by email, or in the client portal.
15) Additional disclosures
Do Not Track: our Sites do not respond to DNT signals.
Third-party links: external sites/services are governed by their own policies.
16) Service-specific details
WHMCS client area: manages accounts, billing, tickets, and authentication; may set essential cookies.
Payments (PayPal & Stripe): Torchbyte does not store full card/bank details; see their privacy notices.
Analytics (GA4 & Matomo): GA4 configured without IP storage; Matomo configured to minimize personal data.
Network telemetry via sFlow: we collect sampled flow data for bandwidth monitoring, capacity planning, network optimization, and abuse detection/prevention. sFlow is sampling-based and retained for a limited period, after which it is aggregated or deleted.
17) Region-specific terms
EEA/UK: Torchbyte is a controller for site/account data and a processor for Customer Data. Lawful bases include contract, legitimate interests, legal obligations, and consent (where required). International transfers are safeguarded as above.
United States (including California): see Section 10 for CCPA-related disclosures.
18) Contact & complaints
Questions or concerns: [email protected]. EEA/UK users may lodge a complaint with a local data protection authority.