What we store, why, and for how long — in plain language.
This policy covers data GhostArch holds about you, our customer. It also explains what we hold about visitors to the blogs we host, since that is data you are responsible for as the publisher.
| Data | Why we have it |
|---|---|
| Email address, and your name if you give one | To identify your account and contact you about it |
| A one-way hash of your password | To sign you in. We cannot read your password, only check it |
| Your sites: domain names, plan, resource limits, status | To run them |
| Subscriptions, invoices, credit ledger | To bill you and to keep the financial records we are required to keep |
| Support tickets and their messages | To answer you, and to have a record of what was agreed |
| A session cookie, and server-side session records | To keep you signed in |
We do not hold any card or bank details. Invoices on this platform are settled manually, so no payment instrument is ever entered into the panel.
Some optional features need a token from another service — a Cloudflare API token for DNS, or a GitHub token for theme sync. When you provide one it is encrypted before it is stored and it is never sent anywhere except to the service it belongs to. You can remove it at any time from the panel.
We produce traffic statistics for each site. This is worth reading carefully, because it is designed to answer "how many people read this" without building a profile of who they are.
| Cookie | Purpose | Life |
|---|---|---|
ghostpanel.sid | Keeps you signed in. Strictly necessary. | 7 days |
Your light/dark preference is stored in your browser's local storage, not in a cookie, and never leaves your device. We use no advertising, profiling or cross-site cookies, which is why this site shows you no cookie consent banner — there is nothing to consent to.
We do not sell your data, and we do not share it for advertising. We disclose data to authorities only where we are legally required to, and we will tell you unless we are forbidden from doing so.
Your sites run on our hosts in the regions listed on our locations page. Your account and billing records live in the same infrastructure. Using this service means your data is processed there.
You can ask us to:
Depending on where you live you may also have the right to object to processing or to complain to a data protection authority.
Passwords are hashed, tokens are encrypted at rest, and every site runs in its own container rather than sharing a filesystem with other customers. Traffic to the panel and to hosted sites is encrypted with TLS. Administrative access to the panel is restricted and the panel itself runs without root privileges.
No system is perfectly secure. If we discover a breach affecting your data, we will tell you what happened, what was affected and what we did about it.
The service is not intended for children, and we do not knowingly collect data from them.
If this policy changes materially we will announce it in the panel before it takes effect, and update the date above.
To exercise any of the rights above, or to ask a question about this policy, sign in and open a support ticket from the Support section of the panel. We answer there rather than by email.
Your blog, your domain, your database — running in about a minute.