RainbowHost
RAINBOWHOST LEGAL / 02

Privacy Policy

This policy explains what RainbowHost collects, why it is used, and the choices available to people who use the service.

Effective August 14, 2026

1. Scope

This Privacy Policy applies to RainbowHost websites, the RainbowHost Discord bot, GDPS hosting dashboard, hosted project infrastructure, and phpMyAdmin access at RainbowHost domains. GlowHost and other products may have separate privacy policies.

2. Information we collect

Account and Discord data

When you claim or use a key, we process your Discord user ID, Discord username, key assignment, redemption state, and related bot command activity. We do not receive your Discord password.

Project and hosted content

We process GDPS names, descriptions, random project codes, database credentials, uploaded dashboard icons, core configuration, database records, and files you or your GDPS users submit.

Technical data

Our servers may record IP address, request time, requested path, response status, browser or client information, security events, and diagnostic logs. We also store session tokens in hashed form.

3. How we use information

  • Authenticate users and connect Discord keys to RainbowHost accounts.
  • Create, operate, display, secure, support, and delete GDPS projects.
  • Detect abuse, enforce limits, investigate incidents, and protect users.
  • Diagnose failures, maintain availability, and improve product features.
  • Comply with legal obligations and respond to valid requests.

We do not use your GDPS database password to advertise to you.

4. When information is shared

We may share information with infrastructure, security, DNS, email, and authentication providers only as needed to operate RainbowHost. Data may also be disclosed when required by law, to protect rights and safety, during a business transfer, or with your direction.

RainbowHost does not sell personal information. Public GDPS names, descriptions, icons, and content may be visible to anyone when you publish a project.

Third-party services such as Discord, GitHub, and linked download providers process data under their own policies.

5. Cookies and sessions

RainbowHost uses a secure, HTTP-only session cookie to keep you signed in. phpMyAdmin uses its own authentication cookie. These cookies are necessary for account and database access; RainbowHost does not require advertising cookies.

6. Retention and deletion

We keep account and project information while needed to provide the service, meet security and legal needs, and resolve disputes. Deleting a GDPS removes its managed project files, database, and database user from active hosting. Limited logs or backups may remain temporarily until routine rotation.

7. Security

RainbowHost uses measures such as isolated database users, generated passwords, hashed session tokens, upload validation, TLS, access controls, and restricted private paths. No system is perfectly secure, so keep your key and credentials private and report suspected exposure promptly.

8. Your choices

You can update project information, replace an uploaded icon, delete a GDPS, log out, or stop using RainbowHost. To request access to, correction of, or deletion of account-level information, contact us. We may need to verify your identity before fulfilling a request.

9. Children

RainbowHost is not intended for children under 13. If you believe a child under 13 provided personal information, contact us so we can review and remove it where appropriate.

10. Changes to this policy

We may update this policy to reflect product, security, or legal changes. We will update the effective date and may provide additional notice for significant changes.

11. Contact

Privacy questions and requests can be sent to [email protected] with "RainbowHost privacy" in the subject line.