RareSRV is operated by AntNetwork, L.L.C., based in New York, United States. In this policy, “RareSRV,” “we,” and “us” refer to that operator. Contact privacy@raresrv.pro about this policy or your personal information.
This policy explains how we handle information about visitors, prospective customers, customers, and authorized account users when they use our website, client portal, billing, support, and hosting services. It also describes information shared for domain registration and third-party services purchased through RareSRV.
We determine how account, billing, security, and business records are used. For personal information that a customer uploads to their hosted website, database, or email service, we generally act on that customer's instructions as a service provider or processor. The customer is responsible for their own privacy notices and lawful use of that information. Where required, a separate data processing agreement governs that relationship.
Account and contact information includes names, email addresses, business details, telephone numbers, billing addresses, account permissions, and information you provide when registering or updating your account.
Orders and payments generate records such as the products you select, service configuration, domain names, quotes, invoices, billing terms, payment status, transaction references, credits, refunds, and disputes. Payment providers collect payment credentials through their checkout services. RareSRV's payment flow does not ask our application to receive or store a full card number or card security code. Do not send those details in chat, tickets, or email.
Support and sales information includes messages, attachments, contact details supplied in guest chat, quotes, troubleshooting information, and the history of our conversations. A chat can be associated with your customer account when you become a customer or identify yourself through an authorized process. Staff can see conversation history and delivery or read status where available.
Service information includes hosting account identifiers, domains, DNS settings, server selections, operating systems, provisioning results, resource usage, service logs, and files or other content stored using our services. Domain registration may require a registrant's name, organization, postal address, email, and telephone number.
Security and technical information can include IP addresses, browser and device information, request timestamps, server logs, login events, account changes, and evidence relevant to fraud or abuse. We store password hashes rather than readable account passwords. If you enable an authenticator, we process enrollment and verification information and recovery-code records.
If you choose a connected sign-in service, we receive the verified identity information and identifiers needed to link and authenticate your account. Depending on the enabled integration, this may include your name, email, Google account identifier, or Microsoft tenant and account identifiers. We do not receive your Google or Microsoft password.
We obtain information directly from you, from people you authorize to manage your account, from your use of the services, and from payment, identity, registrar, hosting, email, and security providers that support the requested service. We can also receive reports from people alleging abuse, fraud, or infringement. We assess those reports rather than treating every allegation as an established fact.
We use information to create accounts; prepare quotes; maintain carts; process and reconcile orders, payments, renewals, and refunds; register and manage domains; provision and support services; communicate about your account; investigate abuse and security incidents; meet legal and accounting obligations; and resolve disputes.
We also use service and transaction records to understand operational performance, such as failed payments, support workload, and service demand. This does not itself require advertising trackers on your browser.
We also measure public website activity using first-party aggregate counters for page views and selected navigation clicks. These counters use an allowlisted public page name, a broad referral-source category, a broad device category, and the UTC day. They do not store visitor or account identifiers, IP addresses, full browser identifiers, query strings, searched domains, or individual browsing histories. The collection endpoint necessarily receives ordinary network request information; it uses a short-lived in-memory hash for rate limiting, not a persistent analytics identifier. Separate hosting and security logs may retain technical request information as described in this policy. Traffic counters are not linked to payment or customer records and do not measure unique visitors.
Where a law requires a legal basis for processing, our bases are performing or preparing a contract with you, complying with legal obligations, pursuing legitimate interests such as securing and operating the service where those interests do not override your rights, and consent where required. We do not treat acceptance of the Terms of Service as blanket consent to every use of personal information. You can withdraw consent for a consent-based activity without changing the lawfulness of earlier processing.
We share information as needed with the providers supporting the service you use. These include hosting and infrastructure providers; domain registrars and registries; payment processors and banks; email delivery and support services; identity providers; and backup, security, accounting, and professional advisers. Authorized staff access information for their work and support responsibilities.
Stripe processes card payments and, where offered, Cash App Pay. We send the information needed to prepare and reconcile checkout, including the amount, currency, invoice or payment reference, and relevant customer details. Payment confirmation, refund, and dispute information is returned to RareBilling. See Stripe’s Privacy Policy.
Namecheap processes domain availability, registration, renewal, transfer, and management requests when it is the registrar for your order. Registrant contact details and domain instructions are supplied as needed for that transaction. See Namecheap’s Privacy Policy.
Our hosting infrastructure runs the RareSRV site and billing application. For hosting purchases, account and domain details and the selected package are sent to the hosting provider operating the relevant control panel, including DirectAdmin where selected. Transactional email is sent through our configured mail server and then through the recipient’s mail provider. Your email address, message content, and delivery information are involved in that delivery.
If you choose Google sign-in, Google authenticates you and supplies the verified identity information used to sign in or link your RareSRV account. See Google’s Privacy Policy. Connecting a sign-in service is optional. It does not give RareSRV your provider password.
A dedicated server or additional product may be fulfilled by the supplier identified for that offer. A payment or identity provider offered later will be identified when you choose it. We send the information needed for the selected service; having an integration available does not send every customer’s data to every potential supplier.
Providers may process some information under their own privacy notices, particularly payment providers, identity providers, and domain registrars. Domain registration details must be transmitted to the registrar and relevant registry. Applicable registration rules can require disclosure to authorized parties or inclusion in registration-data services. A domain privacy service does not guarantee that all registration details can remain confidential.
We may disclose information when legally required, to address an imminent safety or security threat, to establish or defend legal rights, or to investigate misuse within the law. We limit these disclosures to what is appropriate for the purpose. Copyright notices and counter-notices may be shared with the parties involved as described in our DMCA Policy.
If our business is sold, reorganized, or merged, relevant records may be transferred subject to appropriate safeguards and applicable notice requirements.
The RareSRV website and RareBilling application do not include third-party advertising pixels or advertising-data sales integrations. Their business reporting uses our own account, order, payment, and support records. We do not use that reporting to follow you across unrelated websites for advertising. This does not prevent the operational disclosures described above or change the independent notices of a payment or sign-in provider you choose.
Retention depends on why a record is needed. A browser-cookie expiry, hidden order, closed ticket, cancelled service, or removed record in a panel is not a promise that all related information has been erased.
Public-site traffic counters are retained as daily aggregates for up to 395 days of reporting history. Older aggregates are removed when collection or report access next runs. These counters have no per-visitor record to retrieve or delete. Backups follow the separate recovery-archive retention described below.
- Account and customer records are kept while needed to operate the relationship, establish account ownership, support existing services, handle requests, and meet continuing legal obligations. We assess deletion requests against those needs.
- Invoices, payments, refunds, credits, disputes, and domain transaction records are retained for accounting, tax, reconciliation, registrar, fraud-prevention, and legal requirements. Retention can extend beyond account closure. We restrict or remove information when those purposes and any applicable preservation requirements no longer justify keeping it.
- Support tickets, chat messages, attachments, sales enquiries, quotes, and customer history are kept while needed to resolve the enquiry, continue the customer relationship, establish what was agreed, or address a complaint or dispute. Closing a conversation does not automatically erase it.
- Saved carts and guest leads do not have an automatic 30-day server deletion rule. Their browser identifiers expire separately. Server records are reviewed or removed according to whether they remain needed for the requested transaction, enquiry, account relationship, or a legal purpose.
- Active login sessions and challenges stop being usable at their expiry or when revoked. Security-event, access, abuse, and audit records can remain longer for investigation, access accountability, fraud prevention, dispute resolution, or legal preservation. We do not apply a single automatic erasure deadline to every security record.
- Hosted files, databases, and email follow the purchased service’s cancellation and retention terms and any specific service notice. Where a routine hosting deletion is scheduled, the notice identifies the affected service and the earliest deletion date. Account and financial history may remain after the hosting provider removes the hosting account. Keep your own current copy of important content.
- Routine encrypted server recovery archives use a 14-day cleanup window, with the newest two archives retained even if they are older. Separately held recovery-verification, incident, or preservation copies can remain longer while needed for recovery assurance, an investigation, or a legal obligation. Operational billing backups are distinct from a customer’s purchased hosting-backup service. We do not promise immediate removal of an individual record from every backup.
A legal hold or an unresolved dispute can require information to be retained longer than the ordinary operational need. Where appropriate, retained information is restricted to that purpose. For a record-specific retention or deletion question, contact privacy@raresrv.pro.
You can update available account information in the client portal and contact privacy@raresrv.pro for access, correction, deletion, a portable copy, or a question about how we use your information. Depending on the law that applies, you may also have rights to restrict or object to processing, withdraw consent, opt out of certain processing, use an authorized agent, appeal a decision, or complain to a privacy regulator. We will verify requests proportionately and respond within applicable legal deadlines. We do not charge for an ordinary rights request unless the law permits it.
We explain any lawful reason for refusing or limiting a request and any available appeal route. We do not retaliate against a person for exercising a protected privacy right. Some information is required to provide a service, complete a domain registration, investigate fraud, or keep required records.
For personal information hosted by one of our customers, contact that customer first where possible. We assist the customer as required by our agreement and applicable law. We do not change or disclose a customer's hosted records to an unverified third party.
You can stop promotional email through its unsubscribe mechanism or by contacting us. Necessary account, billing, security, domain, and support messages can continue while relevant to your relationship with us. Optional marketing choices are separate from service registration.
RareSRV operates from the United States. Our hosting, payment, domain, identity, mail, and other service providers may process information in the United States and other countries, depending on the provider and the service you choose. A hosting location shown in an offer describes the purchased hosting service; it does not mean that every billing, payment, email, or support record stays in that location.
Privacy laws can differ between countries. Where a transfer requires contractual or other safeguards under applicable law, we will use the required arrangement for that processing. Contact privacy@raresrv.pro for information about the providers and transfer arrangements relevant to your service. This policy does not claim that RareSRV holds an international-transfer certification.
We use encrypted web connections, account and role-based access controls, sign-in limits, additional staff verification, and records of sensitive actions. Customer authenticator enrollment is optional. Account passwords use salted one-way hashing; they are not stored as readable passwords.
Selected sensitive fields, including customer address and notes, support and chat message bodies, attachments, and certain provisioning and integration secrets, are encrypted at rest. This is field-level protection, not a claim that every database column is encrypted. Some identifying and operational fields remain searchable. Encrypted recovery archives protect copies used for restoring the billing platform, with decryption controlled separately.
Payment credentials are entered on the payment provider’s checkout. RareBilling records payment references and outcomes for billing and reconciliation; it does not operate a card-number or card-security-code entry form. Do not send full card details, account passwords, or authenticator recovery codes through support messages.
No service or transmission method can guarantee absolute security. We investigate incidents and provide notifications when required by applicable law. Using a hosted payment checkout does not by itself certify RareSRV’s entire platform or company against a security or payment standard.
Our direct account and purchasing services are intended for adults who can enter a binding contract. They are not directed to children under 13. If you believe a child has provided personal information directly to RareSRV without appropriate authorization, contact us. Customers operating websites for children are responsible for the legal requirements applicable to their own services.
We will publish updates with an effective date and provide additional notice of material changes when required. Where consent or another legal step is required for a new use, a policy update alone will not substitute for it.
Privacy requests: privacy@raresrv.pro. Operator: AntNetwork, L.L.C., trading as RareSRV, New York, United States. For ordinary account help, use customer support.
