Skip to content

Legal

Privacy Policy

Last updated: September 26, 2026

VPSORA exists to make MTA:SA server hosting fast, free and worry-free. This policy explains what we collect, why we collect it, and the control you keep over your data.

What we collect

Account identifiers. When you sign up with GitHub or Google, we receive the identifiers and public profile fields you approve — never your password. On paid plans, our payment provider receives your billing details; we never store full card numbers on our servers.

Server data. The servers you create — mode, region, resources, player activity and console output — are stored so we can run your server, take backups and keep communities safe.

Usage and technical data. Basic analytics such as page visits, feature usage and error reports help us improve the product. We do not build advertising profiles and we never sell your data.

How we use your data

We use collected data to provide and operate the platform, to take backups and offer one-click restore, to prevent abuse and protect the network, to improve features and reliability, and to comply with legal obligations. Data is processed only for those purposes.

Who we share it with

We share data only with the subprocessors we rely on to run the service — cloud infrastructure, storage and the payment processor — and only the minimum each one needs. We never sell personal data, and we never hand it to advertisers.

Authorities: we may disclose data where required by law or in good faith to protect the rights, safety or security of our users, the platform or the public.

How long we keep it

Server data stays for as long as your workspace exists. Free servers pause after 1 hour idle but their data is kept. Backups are retained for 90 days on paid plans unless extended. Console and access logs are kept for 30 days. When you delete your account, we erase associated data within 30 days. Deleting your account also removes your servers; backups that predate deletion are purged within their retention window.

Your rights

Depending on your location (including under the GDPR and the DPA we publish), you may access, correct, export or delete your data, and object to certain processing. Write to legal@vpsora.dev and we will act on verified requests within 30 days. You can also delete your workspace yourself at any time from the dashboard.

Security

All traffic is encrypted in transit (TLS 1.2+), data at rest is encrypted, access is limited on a need-to-know basis and our team follows least-privilege through roles. We run DDoS protection on every server. For the full picture, see our Security page.

Cookies and local storage

We use localStorage for the theme preference and a cookie for language selection — both strictly functional. We use no advertising or cross-site tracking cookies. Even without cookies the entire site works.

Contact us

Questions about this document? Email legal@vpsora.dev — we aim to answer within two business days. legal@vpsora.dev