1. What we collect
Account and billing data: name, email address, phone number, username, password (stored only as a salted, one-way hash), company name, billing address, tax identifier.
Payment data: payments are processed by Razorpay, PayPal, a hosted card checkout and BTCPay. We receive a transaction reference, the amount, the method and, for cards, the last four digits and brand. We never receive or store full card numbers.
Security and usage data: IP addresses, user-agent strings, login history and device fingerprints (for new-device alerts and session binding), API request logs (method, path, status, IP, duration) and actions taken in the console.
Service telemetry: hypervisor metrics for your servers (CPU, memory, disk and network counters, power state) collected by the regional collector to show live graphs and detect failures.
Network data: flow records (source, destination, ports, byte counts) from our traffic analysis for DDoS detection and traffic engineering, kept for 30 days.
Support data: tickets, emails, attachments and staff notes.
Website data: server logs and a small number of first-party cookies: a session cookie when you log in, a currency preference, and a theme preference stored in your browser.
2. Why we use it
- To provide the service you ordered — performance of a contract
- To bill you and keep accounts — contract and legal obligation (tax law)
- To prevent fraud and abuse and keep the network secure — legitimate interest and legal obligation
- To send transactional email (invoices, renewals, security alerts, ticket replies) — contract
- To send product updates — consent, which you can withdraw at any time
- To comply with law, including lawful requests from authorities
3. Who sees it
Joy staff who need it to do their jobs, under confidentiality obligations and with access logged. Processors who act on our instructions: payment providers (listed above), email delivery providers for transactional mail, and datacenter operators for physical hosting. Authorities where we are legally required to disclose.
We do not sell personal data and do not share it with advertisers.
4. Where it is stored
Account, billing and support data is stored on Joy infrastructure in India with encrypted backups in Singapore. Server telemetry is stored in the region of the server.
5. How long we keep it
| Data | Retention |
|---|---|
| Invoices, payments, tax records | 8 years (tax law) |
| Account profile | While the account exists; deleted within 30 days of closure |
| Login and API logs | 90 days |
| Server telemetry | Live data 5 minutes; series 15 minutes; daily aggregates 13 months |
| Flow records | 30 days |
| Support tickets | 3 years after closure |
| Server disks and snapshots | Deleted within 30 days of termination |
| 1tbShare metadata | 30 days after link expiry |
6. Security
Passwords are stored as salted one-way hashes; two-factor authentication (TOTP) is available and recommended; sessions are bound to device and network and rotate automatically; server credentials and node secrets are encrypted at rest with authenticated encryption; all web traffic uses TLS 1.3 with a strict Content-Security-Policy; staff actions are audited.
7. Your rights
You can access, correct, export or delete your personal data, object to or restrict certain processing, and withdraw consent for marketing. Most of this is self-service in the console (Account → Profile, Notifications, Security); for everything else open a ticket or email privacy@joycloud.services. We answer within 30 days.
Deleting your account deletes your servers and data; invoices are kept as required by tax law. You may also complain to your local data-protection authority.
8. Cookies
We set a session cookie when you log in (essential), a currency cookie when you change currency (functional) and store a theme preference in your browser's local storage (functional). We do not set analytics or advertising cookies.
9. Children
Our services are for people 18 and over. We do not knowingly collect data from children; if you believe a child has created an account, contact us and we will delete it.
10. Changes
We will announce material changes to this policy in the Updates feed and by email 30 days before they take effect.