Privacy Policy
BITFOO LLC · Version 1.0 · Effective
Guide to the document
In Plain Language
A short summary of what follows. It is here to help you understand this policy, not to replace it.
- We collect what we need to run your account — your contact and billing details, your support conversations, and technical records like server logs and IP addresses. Not much more.
- We never see your card number. Payment details go straight from your browser to our payment processor. We hold a token and the last four digits.
- We don't sell your data. Not to anyone, for any purpose. We don't share it for advertising either.
- We don't look inside your hosting. What you put on your server is yours. We access it only to investigate a specific problem, keep the platform safe, or where the law requires it — and that's governed separately.
- Some of our suppliers are outside the United States. Our domain registrar is in Europe and part of our technical support team is in India. We tell you the categories below, and we'll name every one of them if you ask.
- Our analytics don't use cookies and don't track you across other websites. Our live chat, when it's running, is a third-party tool that sets its own.
- You have rights over your data — see it, correct it, delete it, take it elsewhere. Email privacy@bit.foo and we'll deal with it.
- Marketing is opt-in. You'll only hear from us about products and offers if you asked to.
This summary is not part of the policy and has no legal effect. The numbered sections below are the actual policy and govern in full.
The policy
1. About This Policy
1.1 This policy explains how BITFOO LLC (“Bitfoo,” “we,” “us”) handles personal information. We are a Pennsylvania limited liability company at 146 East King St, Unit #1283, Lancaster, PA 17602, United States.
1.2 It applies to our website, our client portal, and the accounts and services we provide.
2. Two Different Roles
2.1 We handle two very different kinds of information, and this matters for what this policy covers.
2.2 Information about you as our client. Your name, contact details, billing records, support conversations, and the technical records generated by your use of our services. We decide how this is handled, and this policy governs it.
2.3 Information inside your services. Whatever you store on your hosting or servers — your website, your databases, your email, and any personal information about your customers that they contain. We do not decide what you keep there or why. We hold it to provide the service, and we access it only in the narrow circumstances set out in Section 11 of our Acceptable Use Policy.
2.4 If you need a written data processing agreement covering the information described in 2.3, contact privacy@bit.foo and we will provide one.
3. What We Collect
3.1 When you register. First and last name; company or organisation and job title; postal address; country, state or province, and postal code; telephone and fax number; email address; tax or VAT identification number; your chosen username and password; and an optional recovery email address.
3.2 When you pay. Card details are entered directly into our payment processor and never reach our systems. We receive and store a payment token, the card brand, the last four digits, and the expiry date, together with a record of the transaction. For bank transfers we hold the payment reference and result.
3.3 When you contact us. The content of support tickets, and our replies, including anything you choose to include in them. Where we offer live chat, the transcript of that conversation.
3.4 When you use our services. Technical records generated automatically, including IP addresses, timestamps, control panel and portal login records, resource usage, and server, network, and mail logs.
3.5 When we need to verify you. Some services require identity or business verification before we activate them, and we may need to verify you before acting on a request under Section 9. What we ask for depends on the situation and we ask for as little as will do the job — for example a business registration number, a licence reference, or confirmation of a detail already on your account. We only request identity documents where nothing lighter will work.
3.6 When we screen for fraud. We use a third-party fraud-screening service when orders are placed. It receives your IP address and order details and returns a risk assessment. We do this to prevent fraudulent orders and the account takeovers that follow them.
3.7 On our website. We use analytics that do not set cookies and do not track visitors across other websites. We collect aggregate information about how our site is used. Our site content is served from our own infrastructure; where a third-party tool such as live chat is running, it loads from that provider — see Section 10.
3.8 If you subscribe. Your email address and preferences for product news and offers, if you asked to receive them.
3.9 We do not deliberately collect special categories of personal information such as health, biometric, or political data, and ask that you do not send them to us.
4. Why We Use It, and Our Legal Basis
Where the GDPR or UK GDPR applies to you, these are our legal bases.
| What we do | Why | Legal basis |
|---|---|---|
| Create and run your account, provide services, take payment | To deliver what you bought | Performance of a contract |
| Support you | To answer your questions and fix problems | Performance of a contract |
| Protect our network, investigate abuse, prevent fraud | To keep the platform and our clients safe | Legitimate interests |
| Keep records of transactions and tax | Because we are required to | Legal obligation |
| Respond to lawful requests from authorities | Because we are required to | Legal obligation |
| Send product news and offers | Because you asked | Consent |
| Understand how our website is used | To improve it | Legitimate interests |
4.1 Where we rely on legitimate interests, we have considered whether our interest is outweighed by your rights and concluded it is not. You may object — see Section 9.
4.2 Where we rely on consent, you may withdraw it at any time and it is as easy to withdraw as it was to give.
5. Who We Share It With
5.1 We do not sell personal information. We do not share it for cross-context behavioural advertising. We do not trade, rent, or otherwise make it available for anyone else’s marketing.
5.2 Categories of recipients. We share information with service providers who help us deliver our services, limited to what each needs:
-
Infrastructure and datacenter providers, who host the servers your services run on — United States
-
A white-label hosting platform partner, whose infrastructure delivers our shared hosting, including web, database, and mail services and the anti-spam filtering applied to them — locations vary, see Section 6
-
A wholesale domain registrar, where you register or transfer a domain — European Union
-
Certificate authorities and certificate distributors, where you order an SSL/TLS certificate — United States and elsewhere
-
Our payment processor, who handles your payment details — United States
-
A technical support partner, whose engineers assist with support and server work — India, contracting through a United States entity
-
A fraud screening provider, at the point of order — United States
-
Email delivery, for account, billing, and service notices
5.3 We will name them. We do not publish the specific companies here, but we will tell you exactly who they are on request. Email privacy@bit.foo. Business clients who need a named subprocessor list for their own compliance can have one.
5.4 We also disclose information where we are required to by law or valid legal process, where necessary to investigate abuse or protect our network and clients, to professional advisers under confidentiality, and to a buyer if our business is sold — in which case we will tell you.
5.5 Every provider we use is bound by confidentiality and may only use the information to provide services to us.
6. Information That Leaves the United States
6.1 Where your service is hosted is largely your choice. Several of our services are available in more than one region, and you select the region when you order. Where you choose a location outside the United States, your service and the data in it are stored there. The regions available for each service are shown at the point of order.
6.2 Separately from where your service is hosted, some of the providers we rely on operate outside the United States:
-
Domain registration is handled by a provider in the European Union.
-
Part of our technical support is provided from India. Engineers there may access support tickets and, where necessary to resolve a problem, the services they relate to. Our support partner holds ISO 9001 and ISO 27001 certification, the recognised international standards for quality management and information security management.
-
Our shared hosting platform partner operates infrastructure in multiple regions, including within and outside the United States.
6.3 Where personal information covered by the GDPR or UK GDPR is transferred to a country without an adequacy decision, we put appropriate contractual safeguards in place with the provider concerned, requiring them to protect that information to standards consistent with this policy. You can ask us about the safeguards applying to a particular transfer at privacy@bit.foo.
6.4 We contract with providers who commit to protecting information to standards consistent with this policy, regardless of where they operate.
7. How Long We Keep It
7.1 We keep personal information only as long as we need it.
| Information | Kept for |
|---|---|
| Account and contact details | While your account is open, then 12 months |
| Billing, invoice, and tax records | 7 years, as required for tax and accounting |
| Support tickets and chat transcripts | 3 years after your account closes or the conversation ends, whichever is later |
| Operational server, network, and access logs | 90 days |
| Security, fraud, and abuse investigation records | 12 months, longer where an investigation or legal obligation requires |
| Identity and business verification documents | Deleted once verification is complete, and in any event within 90 days, unless we are required to keep them |
| Marketing preferences | Until you unsubscribe, then a minimal record so we do not contact you again |
7.2 We may keep information longer where we are required to by law, where it relates to an unresolved dispute or investigation, or where we are legally obliged to preserve it.
7.3 Content inside your services is deleted on the timeline in our Terms of Service, not under this Section. Where you have purchased a backup service, backups are held on our own offsite infrastructure in the location you selected, and are deleted on the timeline in our Service Terms.
8. Security
8.1 We protect personal information with measures appropriate to the risk, including encryption of data in transit, access controls limiting who can reach what, multi-factor authentication on administrative access, named individual accounts rather than shared credentials, logging and review of administrative access, and prompt revocation of access when someone no longer needs it.
8.2 Our technical support partner holds ISO 27001 certification, and their personnel access our systems under named accounts subject to the same controls.
8.3 No system is perfectly secure. We cannot guarantee that information will never be accessed improperly, and you are responsible for keeping your own credentials safe.
8.4 If a breach happens. Where a security incident affects your personal information, we will notify you and the relevant authorities as and when the law requires, and will tell you what happened, what we are doing about it, and what you can do. We would rather tell you early and update you than wait until we know everything.
9. Your Rights
9.1 Depending on where you live, you may have the right to:
-
Know what personal information we hold about you and get a copy
-
Correct information that is wrong or incomplete
-
Delete information, where we are not required to keep it
-
Port your information to another provider in a usable format
-
Object to processing based on legitimate interests
-
Restrict processing while a dispute is resolved
-
Withdraw consent at any time
-
Not be discriminated against for exercising any of these rights
9.2 We do not use automated decision-making that produces legal or similarly significant effects about you. Fraud screening informs our review of an order; it does not decide it on its own.
9.3 How to ask. Email privacy@bit.foo. Tell us what you want and enough for us to find your records.
9.4 How we check it’s you. The simplest way is to contact us from the email address on your account, or to open a ticket while logged in — that is usually all we need. Where a request is unusual, or would give access to sensitive information, we may ask you to confirm details we already hold. We will not ask for identity documents unless nothing else will do, and anything we do ask for is used only to verify you and deleted afterwards.
9.5 If we cannot verify a request, we will tell you and explain what would help. We will not act on a request we cannot verify — refusing is safer for you than acting for an impostor.
9.6 How quickly. Within 30 days. If a request is complex we may need longer, and we will tell you before the 30 days are up.
9.7 Free of charge, unless a request is manifestly unfounded or excessive, in which case we will explain before charging anything.
9.8 Authorised agents. Where someone makes a request on your behalf, we will need proof they are entitled to.
9.9 Complaints. If you are unhappy with how we have handled your information, please tell us first at privacy@bit.foo. If you are in the EEA or the UK you also have the right to complain to your national data protection authority.
10. Cookies and Tracking
10.1 Our analytics do not use cookies and do not track you across other websites. We see aggregate information about how our site is used, not a profile of you.
10.2 Our client portal uses strictly necessary cookies — keeping you logged in, maintaining your session, and protecting against cross-site request forgery. These cannot be turned off without breaking the portal.
10.3 Live chat. We use a third-party live chat service on our website. When it loads it sets its own cookies and receives your IP address, the pages you are viewing, and anything you type into it. It is not present on every page or at all times, and where it does not load, none of this applies.
10.4 We do not use advertising cookies, conversion pixels, retargeting, or any tracking that follows you to other websites.
10.5 Consent. Where the law of your country requires your consent before non-essential cookies are set, we will ask for it before loading anything that sets them, and you can decline without losing access to our services.
10.6 Global Privacy Control. We make a good-faith effort to honour recognised browser privacy signals. Since we do not sell or share personal information, there is little for such a signal to opt you out of.
11. Marketing
11.1 We send product news and offers only if you asked for them, either by ticking the box at registration or subscribing later.
11.2 Unsubscribe at any time using the link in any marketing email, or by emailing privacy@bit.foo. We will act promptly.
11.3 Unsubscribing from marketing does not stop service messages — invoices, renewal reminders, security notices, and messages about your account. Those are part of providing the service and you cannot opt out of them while you hold an account.
12. Children
12.1 Our services are for adults and are not directed to children. You must be at least 18, or the age of majority where you live, to hold an account.
12.2 We do not knowingly collect personal information from children. If you believe a child has given us information, contact privacy@bit.foo and we will delete it.
13. Changes
13.1 We may update this policy. For material changes we will give at least 30 days’ notice by email and publish the updated policy with a new version number and effective date.
13.2 Corrections and clarifications take effect on publication. Each version carries a version number and effective date, with a change log.
14. Contact Us
Privacy questions and requests: privacy@bit.foo
BITFOO LLC 146 East King St, Unit #1283 Lancaster, PA 17602 United States
General support: support@bit.foo · Legal: legal@bit.foo · Abuse: abuse@bit.foo