Last updated August 18, 2026
This Privacy Policy explains how PowerupStack handles personal data when you visit our website, create an account, buy credits, or use our game-server hosting service.
Who is responsible for your data
PowerupStack is the controller responsible for the processing described in this policy.
PowerupStack, De Nieuwe Erven 3, unit 13863, 5431 NV Cuijk, the Netherlands. Chamber of Commerce (KvK): 98577794; VAT: NL005339099B42. Email: support@powerupstack.com
Data we use and why
We process only the data needed for the purposes below.
| Purpose | Typical data | Legal basis |
|---|---|---|
| Provide and secure your account | Name, email, password hash, sessions, verification state, registration, successful-login and session-refresh IP addresses with first- and last-seen times, security events | Contract and our legitimate interest in account and platform security |
| Host and operate game-server instances | Instance configuration, files, backups, usage, network and operational events | Contract |
| Billing, credits, refunds and fraud prevention | Orders, balances, transactions, payment references, billing usage, country and tax information | Contract, legal obligation and legitimate interests |
| Customer support | Tickets, messages, attachments, account and instance context | Contract and legitimate interests |
| Service messages | Email address, notifications and delivery status | Contract and legitimate interests |
| Website improvement | Temporary document ID or account ID, page-version assignment, page or event, locale, coarse country and device class | Our legitimate interest in understanding and improving how the website performs |
| Referral attribution | Referral code from the current URL or signup form, optional referral cookie and attribution record | Steps at your request and legitimate interests for a code used at signup; consent for optional cookie persistence; contract and legitimate interests after registration or purchase |
| Abuse prevention and legal claims | IP addresses, audit events, suspension and security records | Legitimate interests and legal obligations |
We do not use website-comparison results to make decisions that produce legal or similarly significant effects about you.
Children and optional cookies
The service is available from age 13, subject to the age and guardian requirements in our Terms of Service. Optional cookies are available only when the user confirms that they are 16 or older. We may still compare page versions without optional cookies by using an identifier held only for the current browser document, or the account ID of a signed-in user. A referral code supplied in the current URL or signup form can still be applied to the registration the user requests without storing a referral cookie.
We ask only for the age band “under 16” or “16 or older” when optional cookies are requested. We do not ask for a date of birth for this purpose. If the user is under 16 or does not answer, we use necessary cookies only and do not create optional persistent website-improvement identifiers or referral cookies.
A parent or legal guardian may contact us to exercise formal privacy rights for a user under 16.
Cookies and referral links
Strictly necessary cookies support authentication, security and your privacy preferences. They do not require consent where they are necessary for a service you requested.
powerupstack_cookie_consentstores your categories and coarse age band so we can respect your choice. It expires after 180 days.powerupstack_experiment_visitoris an optional pseudonymous identifier used to remember valid optional consent and keep page versions consistent across visits. It is created only after valid page-version persistence or referral consent and expires after no more than 180 days.powerupstack_pending_privacy_deletionis strictly necessary browser storage used only when a withdrawal request cannot yet be queued. It temporarily keeps the pseudonymous visitor ID so you can retry after a reload. It is removed as soon as the request is accepted and expires after no more than 7 days.powerupstack_affiliateis an optional first-party referral cookie. It is created only after valid affiliate consent and expires after 30 days.
The first privacy prompt offers Use necessary cookies only, Allow optional cookies, and Customize. Optional categories are off by default. You can change or withdraw your choice at any time through Privacy & cookie settings in the website footer. Withdrawal removes the relevant optional browser identifiers and queues deletion of data linked to the optional visitor ID. Page comparisons continue without an experiment cookie using a temporary ID held only for the current document, or the account ID when signed in. We do not store raw IP addresses or detailed browser information for this purpose.
A referral parameter already present in your browser address remains visible when optional cookies are unavailable or refused. We may retain the code temporarily in page memory and apply it when you submit the signup form, but we do not store it in the referral cookie without consent. Because it remains in the address bar, it can still appear in your local browser history or in a URL that you copy.
Recipients and international transfers
We disclose data only where needed to operate the service, complete transactions, meet legal obligations, or protect legal rights. Verified service recipients currently include:
- OVH Groupe SA / OVHcloud, for infrastructure, storage and hosted instances.
- Tebex, for supported checkout, payment and transaction services.
Banks, payment participants, professional advisers, and public authorities may receive limited data where a transaction or law requires it. We do not sell personal data.
Where a recipient processes data outside the European Economic Area, we use an applicable adequacy decision or contractual and technical safeguards required by Chapter V GDPR.
Retention
We delete or anonymize data when it is no longer needed, subject to the following maximum periods:
| Data | Retention period |
|---|---|
| Necessary privacy preference and coarse age band | 180 days |
| Pending withdrawal retry reference | Until the deletion request is accepted, maximum 7 days |
| Temporary/account page-version assignments and optional visitor ID | Maximum 180 days; optional visitor data is deleted earlier on withdrawal or expiry, and account data on erasure |
| Minimal positive consent and 16+ evidence | 5 years after withdrawal or expiry; pseudonymized on account erasure |
| Affiliate cookie | 30 days; deleted earlier on withdrawal |
| Unconverted referral qualification | Qualification period plus 30 days, capped at 180 days |
| Website-improvement analytics | 13 months; optional visitor records are deleted on withdrawal and account records on erasure |
| Routine HTTP and access logs | 90 days |
| Security, abuse, suspension and instance audit records | 2 years after the event or case closes |
| Active account and profile | Account lifetime plus the 7-day closure grace period; operational identifiers are erased within 24 hours afterward |
| Sessions | Expiry plus 30 days |
| Password recovery and email-change requests | 30 days after use or expiry |
| Registration IP | 180 days after registration |
| Account access IP history | 180 days after the address was last seen |
| Previous email history | 1 year |
| Notifications | Expiry plus 30 days |
| Instance content | Instance lifetime plus the 7-day deletion grace period |
| Backups | Rolling 30 days and inaccessible after account erasure |
| Closed support tickets, comments and attachments | 2 years |
| AI support knowledgebase search queries and result diagnostics | 90 days |
| Feedback | 2 years |
| Orders, invoices, balances, transactions, affiliate rewards and payouts | 7 years, or 10 years where the EU One Stop Shop record rule applies |
| Billing evidence derived from usage | 7 years, or 10 years where the One Stop Shop rule applies |
| Generated personal-data export ZIP | 7 days |
| Export request and delivery audit | 2 years |
Deletion from rolling backups occurs when the relevant backup expires. Until then, backup data is isolated from normal use and restored only for disaster recovery. A narrowly scoped legal hold may temporarily override a period where required for a dispute, investigation, or legal obligation.
Account closure
You can request account closure in account settings. There is a 7-day grace period during which you can cancel closure. After that period we invalidate sessions and remove or anonymize operational profile, security and optional-processing data. Financial records and other evidence that we must retain remain in minimized form for the periods above.
Your rights
Depending on the circumstances, you may have the right to:
- access your personal data and obtain a copy;
- correct inaccurate or incomplete data;
- delete data;
- restrict processing;
- object to processing based on legitimate interests;
- receive portable data in a structured, commonly used, machine-readable format;
- withdraw consent at any time without affecting earlier lawful processing; and
- complain to a supervisory authority.
A self-service ZIP export is available under Account settings → Privacy. It contains a README, structured JSON, and original support attachments. Large instance files remain downloadable through the instance file manager. The export excludes passwords, authentication secrets, internal security rules, privileged notes, and other people's personal data.
For any request the self-service tools cannot handle, email support@powerupstack.com. We may ask for information needed to verify identity and normally respond within one month.
You may complain to the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens, or to the supervisory authority where you live or work.
Security
We use access controls, password hashing, encrypted transport, private object storage, audit logging, backups and other organizational and technical safeguards appropriate to the risks. No system can guarantee absolute security. Please contact us promptly if you believe your account or data has been compromised.
Changes to this policy
We may update this policy when our services or legal obligations change. The current version and update date are always available on this page. Changes take effect when published here, unless applicable law requires otherwise.
Contact
Privacy questions and requests can be sent to support@powerupstack.com.