1. Who We Are
Summit Nodes (“Summit Nodes,” “we,” “us,” or “our”) operates summitnodes.com, related Summit Nodes websites and subdomains, the Client Area at clients.summitnodes.com, and hosting-related services. For privacy requests, contact support@summitnodes.com.
Depending on the context, Summit Nodes may act as a controller (for example, for our marketing site, accounts, and billing) or as a processor / service provider (for example, when we host personal data contained in your websites, email, or databases on your instructions).
2. Scope of This Policy
This Policy applies to personal information we process in connection with:
- Visiting or interacting with summitnodes.com and related pages;
- Creating or using a Summit Nodes Account or Client Area;
- Purchasing, renewing, or managing web hosting, reseller hosting, VPS, dedicated servers, domains, or add-ons;
- Contacting support via email, tickets, Discord, or other channels we designate;
- Receiving invoices, service notices, security alerts, or marketing communications (where permitted).
This Policy does not govern third-party websites, apps, or services that we do not control, including payment processors, domain registries/registrars, Discord, or analytics providers, except to the extent we receive data from them in connection with our Services.
3. Information We Collect
3.1 Information you provide
- Identity and contact data: name, email address, phone number (if provided), company name, billing/shipping address, and support correspondence.
- Account data: username, password hashes or authentication tokens (we do not store plaintext passwords), security settings, and preferences.
- Transaction data: plan selections, invoices, payment status, tax information where required, order history, and payment-method metadata returned by our processor (for example, card brand and last four digits). Full card numbers are handled by Stripe, not stored as complete PANs on Summit Nodes servers.
- Communications: ticket contents, email contents to support, Discord messages when you engage our staff/community in support contexts, and feedback.
- Verification data: information reasonably needed to verify identity, prevent fraud, or process ownership/access disputes.
3.2 Information collected automatically
- Device and log data: IP address, browser type/version, device type, operating system, referring URLs, pages viewed, timestamps, and diagnostic logs.
- Hosting/telemetry data: server resource metrics for web, reseller, VPS, and dedicated services; security/abuse signals; authentication logs; DNS queries related to our platforms; malware/spam detection indicators; network edge telemetry; and uptime/error telemetry.
- Cookie and similar technologies: session identifiers, preference cookies, and similar technologies described in Section 6.
3.3 Information from third parties
- Stripe and related payment infrastructure (payment confirmation, decline codes, fraud signals, and saved-payment-method tokens);
- Domain registrars/registries (registration status, WHOIS-related operational data where applicable);
- Security/fraud vendors and public abuse databases;
- Publicly available sources when investigating abuse or verifying business information.
3.4 Customer Content
If you use hosting Services, you and your end users may upload websites, databases, files, emails, and other content (“Customer Content”), which may include personal data of third parties. Summit Nodes processes Customer Content to provide the Services. You are responsible for having a lawful basis to collect and process that data and for providing required notices to your end users.
4. How We Use Information
We use personal information to:
- Provide, provision, operate, maintain, and improve the Services;
- Create and secure Accounts, authenticate users, and prevent unauthorized access;
- Process orders, renewals, refunds, invoices, and collections;
- Provide customer support and service communications;
- Monitor for abuse, fraud, spam, malware, attacks, and Terms violations (including subdomain misuse);
- Protect the security, integrity, and availability of our networks and customers;
- Comply with legal obligations, enforce agreements, and respond to lawful requests;
- Send transactional notices (renewals, outages, security incidents, policy updates);
- Send marketing communications where permitted by law (you may opt out);
- Analyze aggregated usage to improve performance, UX, and capacity planning;
- Establish, exercise, or defend legal claims.
5. Legal Bases for Processing (EEA/UK and Similar Laws)
Where required, we rely on one or more of the following bases:
- Contract: processing necessary to provide Services you request and administer your Account;
- Legitimate interests: securing our platform, preventing abuse/fraud, improving Services, and communicating about related products, balanced against your rights;
- Consent: where required for certain cookies or marketing (you may withdraw consent);
- Legal obligation: tax, accounting, law-enforcement response, and similar duties;
- Vital interests: rare cases involving threats to personal safety or critical security events.
6. Cookies and Similar Technologies
We and our service providers may use cookies, local storage, pixels, and similar technologies to:
- Keep you logged in and maintain session security;
- Remember preferences;
- Measure traffic and performance;
- Detect fraud and abuse;
- Support billing/client portal functionality.
You can control cookies through browser settings. Blocking certain cookies may break login, checkout, or Client Area features. Where consent tools are presented, we will honor those choices for non-essential cookies as required by law.
7. How We Share Information
We do not sell personal information. We may share information with:
- Service providers / processors that help us operate hosting, billing, email delivery, security, DNS, domain services, analytics, and customer support infrastructure, under confidentiality and data-protection obligations;
- Stripe (and related payment infrastructure) to complete transactions, store payment methods you save, and help prevent fraud;
- Professional advisors such as lawyers, auditors, or insurers when needed;
- Authorities and rights holders when required by law, legal process, or to protect rights, safety, and security (including responding to valid copyright/abuse notices);
- Business transfers in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to appropriate confidentiality protections;
- With your direction when you authorize integrations or ask us to share information.
We may disclose aggregated or de-identified information that does not reasonably identify you.
8. Billing, Stripe, and Saved Payment Methods
Summit Nodes uses Stripe to process payments securely in the Client Area (clients.summitnodes.com). When you place an order or make a payment, card details are submitted through Stripe’s secure checkout/payment flows. Summit Nodes receives transaction results and limited payment-method metadata (such as brand and last four digits) needed for invoices, receipts, support, fraud prevention, and Account administration. We do not store full primary account numbers on Summit Nodes application servers.
8.1 Automatic card saving
When you place an order or make a payment in the Client Area, your card is automatically saved (via Stripe) so future invoices and renewals can be paid more easily. Saved-card records are associated with your Account and processed under this Policy and our Terms of Service.
8.2 Removing a saved card
You can remove a saved card at any time in the Client Area under the Saved Cards tab by choosing Remove Card. Removing a card stops that method from remaining on file. If no saved card remains, each payment that becomes due must be entered manually at the time it is due. We may retain limited historical billing records (for example, invoice history and last-four metadata on past charges) as described in our retention practices, even after a card is removed from active saved methods.
8.3 Stripe as a third party
Stripe acts as an independent payment processor. Stripe’s collection and use of personal and payment data are also governed by Stripe’s own terms and privacy policy. We share with Stripe the information needed to process payments, maintain saved payment methods you authorize through checkout, and manage disputes or fraud reviews related to your Account.
9. Hosting Customer Data and Subprocessors
When we process Customer Content as a processor/service provider, we do so on your documented instructions as reflected in your use of the Services and our Terms. You are responsible for configuring Services appropriately, securing credentials, and handling end-user requests that should be directed to you as the site/service operator.
We may use infrastructure and software subprocessors (for example, data center/network providers, control panel vendors, backup tooling, anti-abuse systems, and email filtering). We remain responsible for subprocessors we engage to process personal data on our behalf for the Services, subject to our agreements with them.
Summit Nodes Subdomains and hostnames under summitnodes.com are platform resources. Logs and telemetry associated with those hostnames may be processed for security, abuse prevention, brand protection, and service delivery as described in our Terms.
10. VPS Hosting Privacy
When VPS Services are available and you use a VPS, the following additional privacy details apply. Until a VPS is provisioned to your Account, this section is informational only.
10.1 Roles and Customer Content on VPS
On a VPS, you typically have root or administrator-level access. Content, applications, databases, email, and other data you place on the VPS (“VPS Customer Content”) are processed by Summit Nodes as a processor/service provider to host the instance and related network connectivity. You remain the controller (or equivalent) for personal data in VPS Customer Content and for notices/rights requests from your end users, except where Summit Nodes acts as controller for Account, billing, and platform operations data.
10.2 Data Summit Nodes may process for VPS
- Provisioning and access data: instance identifiers, IP assignments, OS/template selections, initial credentials delivery metadata, and Client Area service records;
- Network and security telemetry: traffic volume/patterns, DDoS or abuse signals, authentication attempts visible at the network edge, and null-route or filter events;
- Support and incident data: information you share in tickets or that we observe while responding to abuse, legal process, or infrastructure incidents;
- Optional management tooling: if you use panel, backup, monitoring, or reinstall features we provide, related logs and job metadata.
Summit Nodes does not routinely access files inside your VPS. We may access or inspect instance-level data when reasonably necessary for security, abuse prevention, legal process, service restoration you request, or as otherwise described in our Terms and this Policy.
10.3 Your responsibilities
You are responsible for securing the VPS OS and applications, controlling who has credentials, configuring encryption, and handling end-user privacy compliance for services you run on the VPS. Independent backups of VPS Customer Content remain your responsibility unless a separate backup product expressly covers them.
11. Dedicated Server Privacy
When you use a Dedicated Server (including AMD EPYC 9015, AMD EPYC 9175F, AMD EPYC 9255, Intel Xeon configurations when offered, or other dedicated configurations), the following additional privacy details apply.
11.1 Roles and Customer Content on dedicated hardware
Dedicated Servers typically include root or administrator-level access to bare-metal (or equivalent) hardware. Content and personal data you store or process on the server (“Dedicated Customer Content”) are hosted on infrastructure we operate or procure. Summit Nodes generally acts as a processor/service provider for Dedicated Customer Content and as a controller for Account, billing, IP assignment, inventory, provisioning, and platform security data.
11.2 Data Summit Nodes may process for dedicated servers
- Order and inventory data: plan/SKU, CPU/RAM/storage class, platform (for example AMD EPYC or Intel), location (such as Grand Rapids, MI), included IP counts, and availability/reservation status;
- Network identifiers: assigned IPv4/IPv6 addresses, switch/port metadata needed to deliver connectivity, and reverse DNS records you or we configure;
- Hardware and facility operations data: hardware serials or asset tags, replacement/maintenance events, power/network alarms, and data-center provider tickets related to your server;
- Security and abuse telemetry: edge traffic metrics, attack signatures, abuse complaints, and actions such as null-routing;
- Out-of-band / management interfaces: where Summit Nodes retains IPMI or similar management access for hardware support, related access logs and credentials under our control (you must not attempt unauthorized use of management networks).
We do not routinely browse disk contents of dedicated servers. Access may occur for hardware diagnostics you request, abuse or legal investigations, wipe/redeploy after termination, or other limited purposes in our Terms and this Policy.
11.3 Retention and reuse of hardware
After suspension or termination, disks may be wiped and hardware returned to inventory. Residual data risk is reduced through commercially reasonable wipe/redeploy practices, but you should assume that anything not exported before cancellation may become unrecoverable. IP addresses may be reassigned to other customers after your Service ends.
11.4 Your responsibilities
You are responsible for OS/application security, encryption of sensitive Dedicated Customer Content, access control for anyone you authorize, and privacy compliance for end users of systems you operate on the dedicated server. If Intel or other platforms are marked coming soon, no dedicated Service on that platform is active until provisioned.
12. International Data Transfers
Summit Nodes may process and store information in the United States and other countries where we or our providers operate. If you access Services from outside those locations, you consent to transfer of your information to those locations. Where required, we use appropriate transfer mechanisms (such as standard contractual clauses or equivalent safeguards) for cross-border transfers.
13. Data Retention
We retain personal information for as long as reasonably necessary for the purposes described above, including:
- Account and billing records for the life of the Account and a commercially reasonable period afterward for audits, disputes, and legal compliance;
- Support tickets and abuse records for security and dispute resolution;
- Server and security logs for a rolling period appropriate to operations and investigations;
- Customer Content for the duration of the Service and any brief post-termination retention window, after which it may be deleted or become unrecoverable;
- Marketing suppression lists as needed to honor opt-outs.
Retention periods may be extended when required to comply with law, preserve evidence, or establish/defend legal claims.
14. Security
We implement administrative, technical, and organizational measures designed to protect personal information against unauthorized access, loss, misuse, or alteration. Measures may include access controls, encryption in transit where appropriate, network monitoring, vulnerability management, and staff access limitations. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
You are responsible for safeguarding Account credentials, applying updates to your applications, and configuring your Services securely. Promptly notify us of suspected unauthorized Account access.
15. Your Privacy Rights (General)
Subject to applicable law, you may have rights to:
- Request access to personal information we hold about you;
- Request correction of inaccurate information;
- Request deletion of personal information;
- Object to or restrict certain processing;
- Request portability of certain information;
- Opt out of marketing emails (transactional/service messages may still be sent);
- Appeal a denied privacy request where required by law.
To exercise rights, email support@summitnodes.com with sufficient detail to verify your identity and process the request. We may decline requests where an exception applies (for example, legal retention, security, fraud prevention, or another person’s privacy).
16. California and Other U.S. State Privacy Rights
If you are a resident of California or another U.S. state with consumer privacy laws (such as the CCPA/CPRA and similar statutes), you may have rights to know/access, delete, correct, and opt out of certain sharing/targeted advertising practices, and not to be discriminated against for exercising rights.
Summit Nodes does not sell personal information as “sell” is commonly defined. If we engage in “sharing” for cross-context behavioral advertising as defined by applicable law, we will provide required opt-out mechanisms. We do not use or disclose sensitive personal information for purposes beyond those permitted by law for service delivery and security.
Authorized agents may submit requests where legally permitted, subject to verification. Metrics reporting will be provided if/when legally required.
17. EEA/UK Additional Information
If you are in the EEA/UK, you may lodge a complaint with your local supervisory authority. You may also contact us first so we can attempt to resolve your concern. Where we act as processor for Customer Content, please contact the relevant customer/controller first for end-user data requests.
18. Children’s Privacy
Services are not directed to children under 18, and we do not knowingly collect personal information from children under 13 (or under 16 where that is the applicable digital-consent age). If you believe a child has provided personal information, contact us and we will take appropriate steps to delete it.
19. Third-Party Links and Social Platforms
Our websites may link to third-party sites (including Discord and payment/client portals operated with third-party software). Their privacy practices are governed by their own policies. We encourage you to review those policies before providing information.
20. Do Not Track
Some browsers offer “Do Not Track” signals. Because there is no common industry standard for responding to such signals, our websites may not respond to DNT signals. We will honor legally required opt-out preference signals where applicable.
21. Automated Decision-Making
We may use automated tools to detect fraud, spam, malware, and abusive traffic patterns, which can result in automatic throttling, challenge pages, or suspension pending review. These measures are used for security and service integrity. You may contact support to request human review of an automated enforcement action affecting your Account.
22. Changes to This Privacy Policy
We may update this Policy from time to time. The “Last updated” date will change when we do. Material changes will be posted on this page and/or communicated through the Client Area or email when practicable. Continued use of the Services after an update means you acknowledge the revised Policy, except where applicable law requires a different form of consent.
23. Contact Us
Privacy questions or requests:
Summit Nodes
Email: support@summitnodes.com
Client Area: clients.summitnodes.com
Website: summitnodes.com
Also see our Terms of Service, including the strict Summit Nodes subdomain rules.