Privacy Policy
1. Scope
ArtstationX ("we", "us") provides subscription-based rental of servers located in the United States. This Privacy Policy explains what personal information we collect, how we use and share it, and what rights you have when you visit our site, create an account, purchase a plan, or use the subscription service.
This policy covers the ArtstationX website, user panel, and official clients. It does not cover third-party websites or services you may reach through links on our site; those are governed by their own privacy policies.
By using the service you confirm that you have read and understood this policy. If you disagree with any part of it, please stop using the service.
2. Information We Collect
We follow the principle of data minimization and collect only what is necessary to provide and maintain the service.
2.1 Account information
- Email address (for sign-in, password recovery, order and expiry notices);
- Your password, stored only as a salted one-way hash (we cannot read your plaintext password);
- Optional invitation codes, referral relationships, and details you choose to submit.
2.2 Order and payment information
- Order number, plan name, amount, currency, coupon, payment status and timestamp;
- Transaction reference numbers returned by the payment provider.
We do not collect or store full card numbers, CVV codes, or third-party wallet passwords. Payment data is handled by licensed payment providers in their own environment.
2.3 Service operation data
- Subscription tokens and device/client identifiers used to recognize an active subscription;
- Aggregate upload and download byte counts with their measurement window, used for billing, quotas and fair use;
- Concurrent device count and last connection time, used to enforce per-plan device limits.
2.4 Technical and log information
- IP address, timestamp, browser user agent, operating system and language when you access the panel;
- Sign-in records (successful and failed) and security events, used for fraud prevention and account protection;
- Server error logs generated for troubleshooting and abuse prevention.
2.5 Support information
- Problem descriptions, screenshots and contact details you provide in tickets, email or messaging channels.
3. What We Do Not Collect
While delivering the connectivity service we commit to the following:
- We do not log the destination websites, page contents, or communications you access through the service;
- We do not retain a plaintext history of your DNS queries, nor use it for profiling or sale;
- We do not decrypt, inject into, or inspect the content of encrypted traffic;
- We do not sell your personal information or use it for third-party ad targeting.
To keep the service available, bill accurately, and defend against abuse (DDoS, spam, credential stuffing), the system still retains the connection metadata it needs — byte counts, connection times, node identifiers — plus security logs. These records do not include the content you access.
4. How We Use Information
- To create and maintain your account, verify identity, and secure sign-in;
- To activate, renew, change and terminate subscriptions, and to calculate quota and expiry;
- To process payments, issue order records, and handle payment disputes;
- To provide technical support and respond to tickets and enquiries;
- To monitor service quality, diagnose faults, and plan node capacity;
- To detect and prevent fraud, chargeback abuse, account sharing abuse, and breaches of the Terms of Service;
- To comply with law or protect the legitimate rights of us and our users.
We will not use this information for purposes unrelated to providing the service without your separate consent.
5. Legal Bases
If you are located in the EEA, the UK, or a jurisdiction with comparable law, we rely on the following legal bases:
- Performance of a contract — to deliver the subscription you purchased;
- Legitimate interests — to secure our network and accounts, prevent abuse, and improve service quality;
- Legal obligation — to meet tax, accounting and other applicable requirements;
- Consent — for example marketing email, which you may withdraw at any time.
7. Third-Party Sign-In
You may sign in or link your account using Google, Apple, Telegram and similar providers. When you do:
- We receive only the fields needed to identify the account — typically the provider's unique user identifier, your email address, and a public display name or avatar;
- We never receive your password for that provider, and we do not request access to your contacts, messages, cloud files, or posting permissions;
- We never post anything on your behalf.
You can unlink a provider at any time under Profile → Linked accounts. Once unlinked, we delete or anonymize the provider identifier. If that provider is your only sign-in method, set an email and password first so you do not lose access. You may also revoke our application's authorization from within your account settings on that platform.
8. Cookies and Local Storage
We use cookies, localStorage and sessionStorage for:
- Strictly necessary — keeping your sign-in token and session so you stay logged in across pages;
- Preferences — remembering language, light/dark theme, and list filters;
- Security — detecting unusual sign-ins and automated requests.
We do not serve third-party advertising cookies or cross-site tracking pixels. You may clear or block cookies in your browser, but sign-in and other features will not work correctly.
9. Data Retention
| Data | Retention |
|---|---|
| Account information | For the life of the account; cleared after deletion subject to legal requirements |
| Orders and transactions | As required by tax and accounting rules, typically no less than 3 years |
| Traffic statistics | Current and recent billing cycles, for billing and dispute review |
| Sign-in and security logs | Normally no more than 90 days, for risk control and incident investigation |
| Support tickets | A reasonable period after closure for follow-up reference |
After the retention period we delete the data or irreversibly anonymize it.
10. Data Security
- HTTPS/TLS enforced across the site;
- Passwords stored as salted one-way hashes, never in plaintext or reversible form;
- Least-privilege access control for administrative systems, with audit trails on key actions;
- Regular patching of systems and dependencies against known vulnerabilities.
No method of transmission or storage over the internet is completely secure. Please use a strong, unique password and avoid reusing it on other sites.
If a breach occurs that may affect your rights, we will notify you by email or site announcement within the time limits set by applicable law, describing the impact and recommended steps.
11. International Transfers
Our servers and providers are located in multiple countries and regions. By using the service you understand that your information may be transferred to, stored, and processed outside your own country. We apply appropriate safeguards, such as contractual protections, so that transferred data remains protected consistently with this policy.
12. Your Rights
Subject to applicable law, you have the right to:
- Access the information we hold about you;
- Correct inaccurate or incomplete information;
- Delete your account and associated data, where no legal retention duty applies;
- Restrict or object to certain processing in specific circumstances;
- Port the data you provided to us in a common machine-readable format;
- Withdraw consent where processing is based on it (without affecting prior lawful processing);
- Complain to your local data protection authority.
You can delete your account yourself in the app under Settings → About → Delete Account, confirming with your password or a verification code sent to your email address. To exercise the other rights, contact us using Section 15. We may need to verify your identity first, and we normally respond to valid requests within 30 days. Deleting your account also terminates any active subscription; under Section 5 of the Terms of Service, amounts already paid are not refunded.
13. Children
The service is offered to adults and is not directed to anyone under 18 (or the age of majority in your jurisdiction). We do not knowingly collect personal information from minors. If you are a parent or guardian and believe a minor has provided us with information, contact us and we will delete the data and close the account.
14. Changes to This Policy
We may update this policy to reflect legal, technical or service changes. The updated version will be posted on this page with a new effective date. If a change materially affects your rights, we will also notify you by email or site announcement. Continuing to use the service after a change takes effect means you accept the updated policy.
15. Contact Us
For questions, requests or complaints about this policy or your personal data:
- Email: arteasx@duck.com
- User panel: sign in and open a support ticket
Marking your email subject as "Privacy request" helps us route it faster.