1. Data Controller
Eternodes is the data controller for personal data collected through the eternodes.com platform.
Privacy contact: privacy@eternodes.com
2. Data We Collect
2.1 Account and Registration Data
- Full name
- Email address
- Password (stored hashed with bcrypt — never in plain text)
- Account creation and last update timestamps
2.2 Billing and Payment Data
- Purchase and subscription history
- Payment amounts and statuses
- Stripe / PayPal transaction identifiers
- No banking details are stored on our servers — payment processing is delegated to Stripe and PayPal (PCI-DSS certified)
2.3 Service Usage Data
- Information about created servers (name, status, allocated resources)
- Pterodactyl identifier linked to your account
- Activity logs (logins, actions performed on servers)
2.4 Technical Data
- IP address (used for rate limiting and security)
- Session tokens (stored server-side, expire after 24 hours)
- Browser information (User-Agent) for security purposes
3. Purposes of Processing
| Purpose | Legal basis |
| Providing and managing the services | Contract performance |
| Billing and payment processing | Contract performance / Legal obligation |
| Account-related communications (expiry, alerts) | Contract performance |
| Security, abuse and fraud prevention | Legitimate interest |
| Compliance with legal and tax obligations | Legal obligation |
| Service improvement (anonymous statistics) | Legitimate interest |
4. Data Recipients
Your data may be shared with the following sub-processors, solely for service delivery purposes:
- Stripe, Inc. – card payment processing (privacy policy: stripe.com/privacy)
- PayPal Holdings, Inc. – PayPal payment processing (privacy policy: paypal.com/privacy)
- Pterodactyl / Pelican Panel – server hosting infrastructure
- Cloudflare, Inc. – bot protection via Turnstile (if enabled) and CDN (privacy policy: cloudflare.com/privacypolicy)
Eternodes never sells, rents, or transfers your personal data to third parties for commercial purposes.
5. Data Retention
- Active account data: retained for the duration of the subscription + 30 days after account deletion
- Billing data: 7 years (legal accounting obligation)
- Password reset tokens: 1 hour (automatic expiry)
- Security logs: 90 days
- Deleted server data: 7 days after suspension
6. International Transfers
Your data may be transferred to third countries (including the United States) via our sub-processors Stripe, PayPal, and Cloudflare. Such transfers are subject to appropriate safeguards (e.g. Standard Contractual Clauses approved by relevant data protection authorities, or equivalent frameworks).
7. Your Rights
You have the following rights regarding your personal data:
- Right of access: obtain a copy of your personal data
- Right of rectification: correct inaccurate or incomplete data
- Right to erasure ("right to be forgotten"): request deletion of your data
- Right to data portability: receive your data in a structured, machine-readable format
- Right to object: object to processing based on legitimate interest
- Right to restriction of processing: request temporary suspension of processing
To exercise your rights, contact: privacy@eternodes.com. We will respond within 30 days.
8. Data Security
Eternodes implements appropriate technical and organisational measures to protect your data:
- Passwords hashed with bcrypt (cost factor 12)
- Encrypted communications via HTTPS/TLS
- JWT tokens for authentication (24-hour lifespan)
- SQL injection protection via prepared statements
- Login attempt rate limiting
- Bot protection via Cloudflare Turnstile (if enabled)
- HTTP security headers (Helmet, CSP, HSTS in production)
- HttpOnly + Secure session cookies (in production)
9. Cookies and Similar Technologies
Eternodes uses only strictly necessary cookies for service operation:
- Session cookie: keeps you signed in on the platform (HttpOnly, lasts 24 hours)
- JWT authentication token: stored in localStorage for the dashboard
We do not use tracking, behavioural analytics, or advertising cookies.
10. Minors
Our services are not directed at persons under the age of 16. We do not knowingly collect personal data from children under 16. If you believe a minor has provided their data on our platform, please contact us immediately.
11. Policy Updates
We reserve the right to update this policy at any time. The "Last updated" date at the top of this page will be revised accordingly. In the event of a material change, you will be notified by email.
12. Contact
For any privacy-related questions or data protection requests:
Email: privacy@eternodes.com