Privacy policy
What the ZoPanel website and license server collect, why, how long we keep it, and what the panel on your server never sends us.
Draft — to be reviewed by legal counsel before publication.
This policy explains what personal data [COMPANY LEGAL NAME], [ADDRESS] ("we") collects through the ZoPanel website, the customer account, the store and the license server, and what the ZoPanel software installed on your server sends to us.
The short version
- The website and license server keep what we need to sell, deliver and protect licenses: your account details, orders, licenses and the servers they are activated on.
- The panel on your server does not send us your customers' websites, files, databases, mailboxes or visitor data.
- The website sets one session cookie when you sign in. No advertising or tracking cookies.
What we collect on the website
| Data | When | Why |
|---|---|---|
| E-mail address, name, company, preferred language | When you create an account or edit your profile | To identify you, deliver licenses and contact you about your orders |
| Password | When you create or change it | Stored only as a one-way hash, used to sign you in |
| Sign-in sessions: time and IP address | When you sign in | To keep you signed in and detect misuse of your account |
| Account activity: action, time and IP address (for example a license transfer) | When you act in your account | Security and dispute handling |
| Support tickets and messages | When you contact us | To answer you and keep a history of the case |
| E-mail verification and password reset tokens | When you request them | Stored hashed, valid for a limited time |
Our web servers may also keep standard technical logs (IP address, requested page, time, browser user agent) to run and protect the service.
What we collect for orders
When you buy a license we record the plan, the amount and currency, your e-mail address, the server ID the license is for (if given), the payment method, the payment provider's reference and result, and the order status.
Payments are processed by OnePay (cards, Apple Pay, Google Pay) or PayPal. You enter your card or PayPal details on their pages, not ours; we never receive your full card number. When you pay through OnePay, your browser's IP address is passed to OnePay for fraud checks. These providers handle your data under their own privacy policies.
What the license server collects
A license is tied to one server. To activate it and keep it valid, the panel contacts our license server and sends:
- the license key or the signed license token;
- the server ID, a hash derived from the server's machine ID (not the machine ID itself);
- the server's hostname;
- the ZoPanel version and a SHA-256 checksum of the running panel program, so we can detect modified copies;
- the IP address the request comes from, which we see as part of the connection.
Online licenses are refreshed once a day. For each activation, refresh, transfer or deactivation we keep an event with the server ID, IP address, hostname, version, checksum and time. You can see recent events for each license in your customer account. We use this data to deliver the license, enforce the one-license-per-server rule, detect copied or cloned licenses, and help you when you contact support.
If you buy a license from inside the panel, the panel also sends the chosen plan, your e-mail address, the server ID and your browser's IP address to start the order.
What the panel does not send
The ZoPanel software runs on your server, under your control. Apart from the license calls above, and the checks for new versions, it does not send us:
- your websites, files, databases or e-mail;
- names, e-mail addresses or other data of your customers or their visitors;
- usage statistics or analytics.
Alerts, backups to S3 storage, webhooks and similar features send data only to destinations you configure. With no license installed (Free plan), the panel contacts the license server only when an administrator opens the upgrade page to see the plans, or buys a license.
Cookies
The website uses one session cookie (__Host-zps), set only when you sign in. It is limited to our domain, sent only over HTTPS, not readable by scripts, and expires after 30 days or when you sign out. It is strictly necessary for the account to work, so no consent banner is needed for it.
We do not use advertising or tracking cookies. If we enable a web analytics service in the future, we will name it in this policy, describe what it collects and, where the law requires it, ask for your consent first.
Who receives your data
- Payment providers (OnePay, PayPal), for payments.
- The provider we use to send e-mail, to deliver licenses and notifications.
- Our hosting providers, who store the website and license server data on our behalf.
- Authorities, when we are legally required to disclose it.
We do not sell personal data and do not share it for advertising.
How long we keep it
- Account data: while your account exists. When you ask us to delete it, we delete or anonymise it, except what we must keep below.
- Orders and licenses: for as long as the license can be used and afterwards for the period required by accounting and tax law.
- License events: for as long as the license exists, to detect misuse and answer support questions.
- Sessions: until they expire (30 days at most) or you sign out.
- Support tickets: while your account exists, unless you ask us to delete them sooner.
- Technical logs: for a short period needed for security and troubleshooting.
Legal bases
Where data-protection law such as the GDPR applies, we process data to perform our contract with you (account, orders, licenses, support), to meet legal obligations (accounting records), and for our legitimate interests (security, fraud prevention, detecting copied licenses). Where we rely on consent, you can withdraw it at any time.
Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to its processing, receive it in a portable format, and complain to a data-protection authority. You can change your name, company and language in your account at any time. For anything else, open a ticket on the support page; we may ask you to confirm your identity first.
Security
Passwords and tokens are stored hashed, the website is served only over HTTPS, and access to customer data is limited to the staff who need it. See our Security policy to report a vulnerability.
Children
The website and the store are intended for businesses and professionals and are not directed to children.
Changes
We may update this policy. The date at the top shows the latest version; material changes are announced on the website or by e-mail.
Contact
[COMPANY LEGAL NAME], [ADDRESS]. Open a ticket on the support page or write to us through the contact page.