Privacy Policy
How Spaceflare collects, uses, shares, and protects personal data across the Console, the firewall agents, the managed edge, tunnels, and server tooling.
On this page
- 1. Who we are and scope
- 2. Data we collect
- 2.1. Account data
- 2.2. Technical and telemetry data
- 2.3. Usage data
- 2.4. Support data
- 2.5. Payment data
- 3. How we use data
- 4. Legal bases (GDPR and India DPDP)
- 5. Cookies and similar technologies
- 6. How we share data
- 7. International transfers
- 8. Retention
- 9. Security measures
- 10. Your rights
- 11. Grievance officer (India)
- 12. Children
- 13. Changes to this policy
- 14. Contact us
This Privacy Policy explains what personal data Spaceflare ("we", "us") collects when you use our services, why we collect it, how long we keep it, and the rights you have over it. Spaceflare is a PingLess Studios product, managed and operated by ALTIS TECH SOLUTIONS, GST 27EVKPG7066M1ZV.
This policy applies to the Services: the OpenShield-XDP and LiteShield-XDP firewall agents, the PingLess WAF managed edge, L4 tunnels, Health Monitor, Server Optimization, Game Panel Setup, the Cloudflare integration products, the Console (the Spaceflare dashboard), and our APIs. It applies to you as the Customer, the account holder, and covers personal data processed in connection with your Protected Infrastructure: the servers, game servers, sites, and APIs you enroll in the Services.
Please read this policy together with our Terms of Service, Data Processing Addendum, and Cookie Policy.
1. Who we are and scope
The data controller for the personal data described in this policy is:
ALTIS TECH SOLUTIONS (PingLess Studios) Room 110 Krishna Galaxy, First Floor, Mharal Pada Road, Near Tharwani, Varap, Shahad 421103, Dist: Thane, Maharashtra, India GST: 27EVKPG7066M1ZV Privacy contact: support@spaceflare.org
This policy covers three main processing contexts:
- Console accounts: the data we hold about you as a registered user of the Console.
- Protected Infrastructure telemetry: the network and system metadata we necessarily process to detect and mitigate attacks and to operate the products. Firewall agents run on your own servers and the Console polls their metrics APIs; the managed WAF processes logs at our edge; the fleet daemon reports host vitals.
- Support and billing: the data generated when you contact us or pay for the Services.
Where we process personal data contained in your traffic strictly on your behalf and on your instructions, our Data Processing Addendum applies and forms part of our agreement with you.
2. Data we collect
2.1. Account data
When you register for the Console we collect:
- your name and email address;
- your password, stored only as a cryptographic hash (we never store plaintext passwords);
- your product entitlements: the licenses, credit unlocks, and subscription periods attached to your account;
- your organization memberships and sharing grants, where you use them;
- the per-server API keys and connection details used to link your servers to the Console. Keys and other secrets you entrust to us (for example TLS certificates for your sites) are stored server-side, encrypted at rest with AES-256-GCM.
2.2. Technical and telemetry data
To provide attack mitigation and monitoring we necessarily process traffic and system metadata of your Protected Infrastructure. This is inherent to how the Services work: we cannot distinguish an attack from legitimate traffic without observing the traffic itself. Concretely, per product:
- Firewall agents (OpenShield-XDP, LiteShield-XDP): server IP addresses and hostnames; source IP addresses of inbound traffic; packet and byte rates and protocol distributions; attack records (type, peak rates, country attribution); ban lists; agent diagnostics (version, interface, kernel).
- PingLess WAF (managed edge): edge logs for traffic passing through our edge, including requested hosts and paths, client IP addresses, user agents, and WAF rule matches.
- L4 tunnels: tunnel endpoints, port mappings, and per-tunnel traffic rates.
- Health Monitor and fleet tooling: host vitals (CPU, memory, disk, network counters), process lists, VM inventories on hypervisors, system events (for example out-of-memory kills or failed services), and benchmark results you choose to run.
- Server Optimization and Game Panel Setup: the actions and output of the installer or tuning agent while it runs on your server.
- Cloudflare products: the zones, DNS records, and analytics of the Cloudflare accounts you connect, read or changed through Cloudflare's API strictly as you direct.
2.3. Usage data
When you use the Console we automatically collect standard usage data: Console logs (such as sign-in times, IP addresses, and actions taken), device and browser type, and your approximate location derived from your IP address.
2.4. Support data
When you contact support we keep the tickets, messages, and any attachments you choose to upload. When you grant support access to a service or link a ticket to it, we log every support action taken on that service for your transparency feed. Please avoid including unnecessary personal data, especially other people's, in attachments.
2.5. Payment data
Payments are processed by Cashfree. We never see or store full card numbers. We receive only what we need to administer your purchase: a transaction reference, payment status, billing country, and the product purchased. Manual payments (for example bank transfers) are recorded with the reference details you or our administrators supply.
3. How we use data
We use the data described above to:
- Deliver the Services: operate the Console, connect your servers, run detection and mitigation, enforce rate limits and rule sets, and display your traffic and attack statistics;
- Secure the Services: detect abuse, fraud, and attacks against Spaceflare itself, and enforce our Acceptable Use Policy;
- Provide support: respond to tickets and troubleshoot issues with your Protected Infrastructure;
- Improve the Services: analyse aggregated or de-identified telemetry (for example, global attack trends) to tune detection models and plan capacity. We do not use identifiable Customer traffic data for advertising;
- Billing and account administration: process purchases, manage credits and entitlements, and send service-related notices;
- Comply with the law: meet tax, accounting, and regulatory obligations and respond to lawful requests.
4. Legal bases (GDPR and India DPDP)
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
| Purpose | Typical data | Legal basis |
|---|---|---|
| Provide the Services and mitigation | Account, telemetry, usage | Performance of a contract (Art. 6(1)(b)) |
| Secure the Services and prevent abuse | Telemetry, usage, Console logs | Legitimate interest (Art. 6(1)(f)) |
| Improve the Services | Aggregated / de-identified telemetry | Legitimate interest (Art. 6(1)(f)) |
| Provide support | Support tickets, account data | Performance of a contract (Art. 6(1)(b)) |
| Billing, tax, and accounting | Payment and invoice records | Legal obligation (Art. 6(1)(c)) |
| Optional analytics cookies | Cookie identifiers | Consent (Art. 6(1)(a)) |
For users in India, processing is carried out in accordance with the Digital Personal Data Protection Act, 2023, on the grounds of legitimate use (services you request) and, where required, your consent. Where we rely on legitimate interest, we have balanced our interest against your rights and freedoms; you may ask us for details of that assessment. Where we rely on consent, you may withdraw it at any time; withdrawal does not affect processing already carried out.
5. Cookies and similar technologies
The Console uses strictly necessary cookies to keep you signed in and protect the Service, plus optional analytics cookies that only load with your consent. The full list of cookies, their purposes, their lifetimes, and how to change your choices is in our Cookie Policy.
6. How we share data
We share personal data only in the following circumstances.
Subprocessors. We use a small number of service providers to operate the Services. Each is bound by a data processing agreement and may process personal data only on our instructions.
| Subprocessor | Purpose | Location |
|---|---|---|
| Vercel, Supabase, and platform-operated edge servers | Infrastructure and hosting | India / global edge |
| Transactional email provider (SMTP) | Transactional and service email | India |
| Cashfree | Payment processing | India |
| Sentry | Error and crash monitoring | EU/US |
Legal requests. We may disclose personal data where we are required to do so by law, regulation, or a valid request from a public authority, or where disclosure is necessary to protect our rights, your rights, or the safety of others. Where the law allows, we will tell you before we disclose.
Business transfers. If Spaceflare is involved in a merger, acquisition, or sale of assets, personal data may be transferred as part of that transaction, subject to this policy. We will notify you of any change of control.
We do not sell personal data. We do not rent it, trade it, or share it with third parties for their own marketing.
7. International transfers
Some of our subprocessors process data outside India, the European Economic Area, or the United Kingdom. Where we transfer personal data internationally, we rely on an adequacy decision or on appropriate safeguards, such as the European Commission's Standard Contractual Clauses, together with supplementary measures where required. You may request a copy of the relevant safeguards via the contact details below.
8. Retention
We keep personal data only as long as we need it for the purposes described in this policy.
| Data type | Retention period |
|---|---|
| Account data | Life of the account, plus 30 days after closure |
| Telemetry and attack records | 40 days |
| Edge logs (managed WAF) | 48 hours live, 30 days aggregated |
| Support tickets | 24 months |
| Billing and tax records | 8 years (statutory, India) |
| Backups | 30 days |
| Server API keys and connection details | Until the server is removed from the Console |
When retention ends, we delete or irreversibly anonymise the data. We may retain limited records longer where the law requires it or where necessary to establish or defend legal claims.
9. Security measures
We protect personal data with measures appropriate to the risk, including:
- encryption in transit (TLS) for the Console, APIs, and edge traffic;
- encryption at rest (AES-256-GCM) for the secrets you entrust to us (API keys, certificates, license material);
- server-side storage of your per-server API keys, never on your server image or in our client code;
- access controls on a least-privilege basis, so staff can only reach the data their role requires;
- logging and monitoring of administrative and support access, with support actions on your services visible to you in the Console.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we suffer a personal data breach that is likely to result in a risk to your rights, we will notify you and the relevant authority as the law requires.
10. Your rights
Where the GDPR or UK GDPR applies, you have the right to:
- Access: obtain a copy of the personal data we hold about you;
- Rectification: correct inaccurate or incomplete data;
- Erasure: ask us to delete your data, subject to legal retention duties;
- Restriction: limit how we process your data in certain circumstances;
- Portability: receive the data you provided to us in a structured, machine-readable format;
- Objection: object to processing based on legitimate interest, including any profiling;
- Withdraw consent: where processing is based on consent, withdraw it at any time;
- Complain: lodge a complaint with your local supervisory authority or, in India, the Data Protection Board of India.
Users in India have equivalent rights of access, correction, erasure, and grievance redressal under the Digital Personal Data Protection Act, 2023.
To exercise any of these rights, contact support@spaceflare.org. We respond within 30 days. We may need to verify your identity before acting on a request.
11. Grievance officer (India)
For grievances under Indian data protection and intermediary rules, contact our grievance officer at support@spaceflare.org (marked "Grievance") or by post to ALTIS TECH SOLUTIONS at the address above. We acknowledge grievances within 24 hours and aim to resolve them within 15 days.
12. Children
The Services are business products and are not directed at anyone under 18. We do not knowingly collect personal data from children. If we learn that we have, we will delete it promptly. If you believe a child has provided us personal data, contact us at support@spaceflare.org.
13. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you by email or by a notice in the Console before the change takes effect. The version history at the bottom of this page records every published revision.
14. Contact us
Questions, requests, or complaints about this policy or our handling of personal data:
- Privacy contact: support@spaceflare.org
- Postal address: ALTIS TECH SOLUTIONS (PingLess Studios), Room 110 Krishna Galaxy, First Floor, Mharal Pada Road, Near Tharwani, Varap, Shahad 421103, Dist: Thane, Maharashtra, India
- GST: 27EVKPG7066M1ZV
Version history
| Date | Change |
|---|---|
| Full revision: every product's data flows covered, retention schedule finalized, India DPDP rights and grievance contact added. | |
| Initial publication. |