Privacy Policy
This explains what MossMC collects about you, why, who else sees it, and what you can ask us to do with it. It is written to be read, not to be impressive.
1. What we collect
Because you gave it to us
- Account: username, email address, and a hashed password. We never store your password itself.
- If you sign in with Discord or Google: your identifier on that service, your email address, and your display name or avatar. We do not receive your password for those accounts.
- If you link Minecraft: your Minecraft UUID and username. You choose to link this; it is not required to use the hosting side.
- Support and contact messages you send us.
Because you used the service
- Servers: names, plans, configuration and the files you upload.
- Transactions: what you bought, when, how many tokens, and Stripe's reference for the payment. We never see or store your card number.
- Technical logs: IP addresses, browser type, timestamps, and error traces. These exist so we can debug failures and detect abuse.
- In-game: which servers you visit through the network, your friends list, your cosmetics, and adverts you post. This is stored against your Minecraft UUID.
We do not use advertising trackers, we do not run third-party analytics that profile you across other sites, and we do not sell your data to anyone. There is no data broker in this picture.
2. Why we hold it
- To run your account and your servers — the thing you asked us to do.
- To take payment and keep the records tax law requires.
- To keep the platform working and secure, and to detect fraud and abuse.
- To reply when you contact us.
If you are in the UK or EU: our lawful bases are performance of a contract (running the service), legal obligation (financial records), and legitimate interests (security, fraud prevention, and keeping the thing online).
3. Cookies
We use a session cookie to keep you signed in, and a CSRF token cookie that protects your account from actions triggered by other websites. Both are necessary for the site to work and neither tracks you anywhere else. We do not use advertising or analytics cookies.
4. Who else sees it
| Who | What they get | Why |
|---|---|---|
| Stripe | Email, payment details you enter with them | To take payment. They are the card processor; we are not. |
| Our hosting provider | Everything stored on the servers, as the operator of the hardware | The machines the service runs on. |
| Discord / Google | Only what you authorise at sign-in | Optional sign-in methods you chose. |
| Mojang | A username you ask us to look up | To resolve a Minecraft account when you link or are whitelisted. |
We will disclose information if we are legally required to. If that happens and we are permitted to tell you, we will.
If MossMC is ever sold or transferred, account data would move with it, and we would tell you before that happened.
5. How long we keep it
- Account data: while your account is open, and deleted when you close it.
- Server files: deleted when the server is deleted. Backups are cleared on our normal backup cycle after that.
- Payment records: kept as long as tax and accounting rules require, typically several years, even after an account closes.
- Technical logs: a short rolling window, then overwritten.
6. Your rights
Whoever and wherever you are, you can ask us to:
- tell you what we hold about you;
- give you a copy of it;
- correct anything wrong;
- delete your account and its data;
- stop using it for something specific.
For a copy of your data you do not need to wait for us: sign in and use Request My Data on your account page to download it immediately. For anything else, email [email protected] and we will respond within 30 days. We may ask you to confirm you are the account holder first — that check protects you.
UK and EU users also have the right to complain to their data protection authority. California residents have rights under the CCPA to know, delete, and not be discriminated against for exercising them; we do not sell personal information as that law defines it.
7. Children
MossMC is not for children under 13, and we do not knowingly collect their information. If you are a parent and believe your child under 13 has an account, email [email protected] and we will delete it.
Between 13 and 18, an account is fine with a parent or guardian involved, and any payment must be authorised by them.
8. Security
Passwords are hashed. Traffic to the site is encrypted in transit. Access to production systems is limited to people who need it. Payment card details never touch our servers.
No system is perfectly secure, and we will not pretend otherwise. If a breach affects your data, we will tell you what happened, what was involved, and what to do about it — promptly, and without waiting to have a tidy story.
9. Where your data lives
Our servers are in Germany. If you are outside the EU, your data is transferred there to be processed. Stripe processes payment data in accordance with its own privacy policy and international transfer safeguards.
10. Changes
If we change this policy materially, we will tell account holders by email or an in-dashboard notice before it takes effect. The version and date at the top of this page always reflect the current text.
Questions: [email protected].