Legal

Privacy Policy

Last updated: August 30, 2026

At checkout

These documents are the agreement you accept when you order: the order page asks you to tick "I agree to the Terms of Service and the Refund Policy" before you pay, and the Terms of Service incorporate every other document listed here.

In plain language. We collect what we need to run your account and your servers: who you are, what you bought, what you paid, the addresses you connect from, the technical data of your Services, and the tickets you send us. Card numbers never reach us — the payment processor handles them. We do not sell personal data and we do not run advertising trackers. Server data disappears when the Service is deleted; billing records stay as long as tax law requires. You can see, correct, export and delete your data, and there is a section below for California and one for the EU and the UK. This box is a summary; the numbered sections below are the policy.

This policy is part of the terms you accept at checkout. The Terms of Service, accepted on the order page, incorporate it. It applies to tridentsky.net, to the client area at billing.tridentsky.net, to the game panel we operate, and to the emails and tickets we exchange with you.

1. Who Is Responsible

TridentSky is the controller of the personal data described here. Write to [email protected], with "Privacy" in the subject line, or to 5501 Hildebrand Boulevard a340, Kennewick, WA 99338, United States.

2. What We Collect and Why

2.1. Account data

Name, email address, password (stored only as a hash), country, language and theme preference, and, if you enable it, two-factor authentication data and backup codes. If you sign in with an external provider, we receive from it your name, email address and account identifier. We use this to create and secure your Account and to identify you when you contact us. Basis: performance of the contract with you.

2.2. Billing data

Billing name and address, invoices, orders, payments, credits, refunds, disputes, billing periods and products purchased. The payment processor tells us the type of payment method, its brand, its last four digits and an expiry date, plus a token that lets us charge it again for renewals. We never receive or store full card numbers, security codes or bank credentials. We use this to bill you, honour renewals, comply with tax and accounting rules and answer disputes. Basis: contract and legal obligation.

2.3. Service data

The configuration of each Service — name, node, location, resources, allocated IP address and ports, panel users you add — and the files, worlds, databases and configuration you place on your server. We store your server content only to provide the Service, and staff access it only when you ask for support, when we investigate an abuse report, or when the law requires it. Basis: contract, and legitimate interest in keeping the platform safe.

2.4. Logs and technical data

IP addresses, user agent, dates and times of sign-ins and of actions in the client area and the panel, session records, payment and provisioning events, node and network telemetry, security events, and the results of anti-bot challenges on our forms. We use this to operate the platform, investigate incidents, prevent fraud and abuse, answer payment disputes and defend claims. Basis: legitimate interest and legal obligation.

2.5. Support and email data

Tickets and their attachments, emails you send us and emails we send you, and the delivery status our email provider reports (delivered, bounced, opened where the provider reports it). We use this to answer you and to prove that notices such as invoices and suspension warnings were sent. Basis: contract and legitimate interest.

2.6. Website data

Pages visited, referrer, approximate location derived from your IP address at country or city level, and latency measurements your browser reports when you use our network test. We use this to run the site, measure demand and pick locations. We do not run advertising or cross-site tracking.

We do not ask for special categories of data (health, biometrics, political or religious views) and you should not send them to us.

3. Payments

Payments are processed by Stripe, Inc., which acts as an independent controller for the payment data it collects and processes it under its own privacy policy at stripe.com/privacy. When you pay or save a card, the details go from your browser to the processor; we receive only the tokenised reference and the metadata in Section 2.2. Fraud checks, 3-D Secure and dispute handling are carried out by the processor with the data it holds.

4. Who Else Processes Your Data

We do not sell personal data and we do not share it for cross-context behavioural advertising. We use a small number of service providers, bound by contract to process data only on our instructions:

  • Payment processing — the processor named in Section 3, for payments, saved payment methods, refunds, fraud checks and disputes.
  • Email delivery — the provider that sends and tracks the delivery of transactional email: your address, your name and the message content.
  • Infrastructure — the data centres and the operator of the physical hosts where the nodes and the portal run, in the United States.
  • CDN, DNS, edge network and anti-bot challenge — the provider that fronts our sites, terminates TLS, serves static assets and runs the challenge on our sign-in, registration and contact forms: your IP address, request metadata and the challenge result.
  • Network protection — the providers that filter denial-of-service traffic at the edge of our network see the IP addresses and traffic metadata directed at our addresses.

We also disclose data:

  • To law enforcement, courts or authorities where the law requires it or a valid legal request is made, and to report child sexual abuse material, which we always report.
  • To a payment processor, card issuer or fraud-prevention network to answer a dispute or a fraud investigation, including the evidence listed in the Chargeback and Dispute Policy.
  • To a rights holder or affected party to the extent needed to handle an abuse or copyright complaint, as described in the DMCA and Copyright Policy.
  • To a professional adviser under confidentiality, and to a successor in a merger, acquisition or sale of the business, in which case this policy continues to apply until it is replaced with notice to you.

5. International Transfers

Our infrastructure and our portal are in the United States, and our service providers may process data in the United States and other countries. If you use the Services from outside the United States, your data is transferred there, where data protection law differs from the law where you live. Where we transfer personal data from the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission's Standard Contractual Clauses, or the UK Addendum to them, together with the technical measures in Section 8. You can ask us for details of the safeguards that apply to a specific transfer.

6. Cookies and Local Storage

We use the minimum needed to make the sites work. We do not use advertising cookies, and there is no third-party tracking on our pages.

What Purpose Life
Session cookie Keeps you signed in to the client area. Strictly necessary; the client area does not work without it. Until you sign out or the session expires
Language cookie Remembers whether you read the site in English or Spanish. 1 year
Theme and motion preference Stored in your browser's local storage, not sent to us, so the site opens in the light or dark theme you chose and respects reduced motion. Until you clear your browser data
Security challenge Set by our edge provider when you complete the anti-bot challenge on the sign-in, registration or contact forms, so you are not challenged repeatedly. Strictly necessary for security. Short-lived, set by the provider
Panel session The game panel sets its own session cookie when you open it. Until you sign out

Blocking these cookies in your browser is possible, but the client area and the panel cannot work without their session cookies.

7. Retention

Data How long
Account data While the Account exists, then deleted within 30 days of closure, except what Section 7 keeps below
Invoices, payments and tax records 7 years from the end of the tax year, as required by US tax and accounting rules
Server content and backups While the Service exists; deleted with the Service, including deletion 14 days after an unpaid due date, and not recoverable afterwards
Support tickets and email logs 3 years from the last message, then deleted
Sign-in, session and security logs 12 months
Network, node and provisioning logs 12 months, longer only for a specific incident under investigation
Fraud, chargeback and abuse records Up to 7 years, limited to what is needed to prevent repeat fraud and defend claims
Anti-bot challenge results Days, at the provider

Where we must keep a record for law or defence of a claim, we keep the minimum and stop using it for anything else.

8. Security

Traffic runs over HTTPS. Passwords are hashed with a modern memory-hard algorithm, and two-factor secrets and backup codes are stored encrypted. Sessions are cookie-based, bound to the host and revocable from the client area, where you can also see and close other sessions and enable two-factor authentication. Staff access is limited to the people who need it, administrative actions are recorded in an audit log, and customers' servers are isolated from each other on the node. No system is perfectly secure; if you find a vulnerability, write to [email protected] and we will work with you.

9. Breach Notification

If we become aware of a breach of personal data that is likely to result in a risk to you, we will notify the competent supervisory authority within 72 hours where that applies, and notify you without undue delay, by email to the address on your Account, with what happened, what data was involved, what we have done and what you should do. Where the law of your state or country sets a different deadline or channel, we follow it.

10. Your Rights

Wherever you live, you can:

  • Access the personal data we hold about you and get a copy.
  • Correct data that is wrong or out of date — most of it directly in the client area.
  • Delete your Account and your data, subject to the records we must keep.
  • Export your account and billing data in a portable, machine-readable format.
  • Object to or restrict processing based on legitimate interests, and withdraw consent where we asked for it, without affecting what was done before.
  • Complain to your data protection authority.

To exercise a right, write to [email protected] from the address on your Account, or open a ticket. We may ask you to confirm details only the Account holder would know, or to write from the address on the Account. We answer within 30 days and tell you if we need longer because the request is complex. We do not charge for a request unless it is manifestly excessive or repetitive, and we never treat you differently for making one.

To close your Account: cancel your Services, then ask us in writing. We delete the Account and its personal data within 30 days, keeping only the billing records the law requires and the minimum needed to prevent fraud and defend claims.

11. California Notice (CCPA/CPRA)

If you are a California resident:

  • In the last 12 months we collected the categories in Section 2: identifiers (name, email, IP address, account identifiers), customer records and commercial information (billing address, purchases, invoices, payments), internet or network activity (sign-ins, panel and site activity, logs), approximate geolocation derived from an IP address, and the content of your tickets and of the servers you host with us. Sources: you, your browser and device, our systems, and our payment processor.
  • We use them for the business purposes in Section 2, and disclose them to the service providers and in the situations in Section 4.
  • We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the last 12 months, including data of anyone under 16.
  • You have the right to know, to delete, to correct, to opt out of sale or sharing (there is nothing to opt out of), to limit the use of sensitive personal information (we do not use it for the purposes that trigger this right), and not to be discriminated against for exercising a right.
  • Submit a request at [email protected]. We verify it against the details on your Account. An authorised agent may act for you with written permission and a way for us to verify it with you.

12. Notice for the EU, the UK and Switzerland

If you are in the European Economic Area, the United Kingdom or Switzerland, our legal bases are the ones stated with each category in Section 2: performance of the contract, our legitimate interests in security, fraud prevention, defence of claims and improving the Services, compliance with legal obligations, and consent where we ask for it. You have the rights in Section 10, including the right to data portability and the right to lodge a complaint with your supervisory authority. Transfers are covered by Section 5. We do not take decisions producing legal effects about you by automated means alone; automated fraud checks by our payment processor can decline a payment, and you can ask us to look at it.

13. Children

The Services are for adults. A person under 18 may use them only under the supervision of a parent or legal guardian, who holds the Account. We do not knowingly collect personal data from children under 13, and we do not direct our Services to them. If you believe a child has given us personal data, write to [email protected] and we will delete it and close the Account.

14. Marketing

We send transactional messages — order confirmations, invoices, renewal reminders, suspension and deletion notices, security alerts, ticket replies, maintenance notices — because they are needed to run your Services, and they cannot be turned off while the Account is active. News and offers are sent only if you opt in, and every one of them has an unsubscribe link. Your notification preferences are in the client area.

15. Changes

We may update this policy. We will notify you by email or in the client area at least 14 days before a material change takes effect, unless the change is required by law. The "last updated" date at the top shows the current version.

16. Contact

TridentSky 5501 Hildebrand Boulevard a340, Kennewick, WA 99338, United States Email: [email protected] — subject "Privacy" Website: tridentsky.net Client area: billing.tridentsky.net

Questions about these documents? Write to [email protected].