1.Who is responsible for your data
Your data is processed by HQClouds — the company that operates hqclouds.com, registers domains, and rents out VPS servers.
For any questions about your data, write to [email protected]. For abuse reports or complaints about how our services are being used, write to [email protected].
Data processing is governed by the law of the operator's country of registration. Service messages are sent from a technical address that we do not monitor, so replying to them achieves nothing — write to [email protected] instead.
Read this policy alongside our Terms of Service (the /terms page) and our Acceptable Use Policy (the /abuse page).
2.Account and payment data
When you sign up, we store your email address and password. The password is stored only as a hash — the original string cannot be recovered from it, and we do not know it. We also remember your chosen interface language and currency.
For your account balance, we keep a history of transactions: top-ups, charges for purchases and renewals, and refunds. That way your view of the money matches ours.
Balance top-ups are handled by third-party payment providers. You enter card and wallet details on their side — the platform never receives or stores them.
3.Technical data and correspondence
When you open the site, we record your IP address, browser user agent, and request logs. These records keep the service running and let us investigate failures and protect against abuse.
If you contact support, we keep the ticket itself and all correspondence within it. That way we can look back at your request instead of asking you the same questions twice.
We aim to collect only what is listed in this policy. But anything you send us in a ticket — screenshots, files, other people's contact details — reaches us together with that ticket, so please do not send more than you need to.
4.Why we collect data and on what basis
To deliver the service: register a domain in your name, create a server, issue access credentials, and renew the period you have paid for. The basis here is the contract between you and us.
To accept payment and maintain your balance: credit top-ups, charge the cost of a purchase, and refund money to your balance if server creation fails. This is also performance of the contract.
To comply with mandatory rules — above all the requirements of ICANN and domain zone registries, without which a domain can neither be registered nor kept — and with the requirements of the law of the operator's country of registration.
To maintain security, combat abuse, and answer support requests — this is our legitimate interest. Web analytics and advertising tags run on the basis of your consent, and you can withdraw it.
5.Domain WHOIS contacts
This is the most important section for anyone buying a domain, and we will say it plainly: the registrant's contact details — name, organization, email, phone, and address — must be passed to our partner registrar and to the registry of the domain zone. Without them a domain cannot be registered at all, and there is no way around this requirement.
You become the registrant of the domain. ICANN and registry rules require these contacts to be accurate and up to date: inaccurate details can lead to problems with the domain. We additionally confirm the registrant's email — you receive a message with a link, and that link is valid for a limited time.
Depending on the rules of the specific zone, some or all of this data may be visible in public WHOIS services. The extent of disclosure is set by the zone registry and the registrar, not by HQClouds.
Domains are subject to zone rules on disputes (UDRP/URS) and, after expiration, to grace and redemption periods. Within those procedures, registrant data is used as the zone rules prescribe.
If you register a domain for someone else — another person or another company — you are responsible for having their consent to pass these contacts to the registrar and the registry.
6.Cookies on the site
We use functional cookies: your session (to keep you signed in), your chosen language, and your chosen currency. Without them, the customer portal and the cart will not work.
We also set a marketing visitor identifier — a cookie on our own domain, not a third-party one, which lasts up to a year. It lets us link a visit to the advertising source you came from.
You can disable or delete cookies in your browser settings. The site will then stop recognizing you: you will have to sign in again, and your language and currency will reset on every visit.
7.Marketing tags and advertising
When you arrive via an advertising link, we store UTM tags, ad click identifiers (yclid, gclid, fbclid), the referrer, and the landing page.
This serves exactly one purpose: seeing which ads bring in customers, so we do not waste ad budget. We do not sell this data and do not build profiles from it for third-party advertisers.
8.Web analytics and on-page session recording
The site uses Yandex.Metrica and Google Analytics 4. They collect anonymized visit statistics: which pages are opened, where visitors come from, and how long they stay.
Session recording is enabled in Metrica — it captures on-page activity: mouse movement, scrolling, clicks, and form field input. We review these recordings to find places where the interface gets in people's way.
You can limit analytics in your browser: use a blocker or disallow third-party scripts, and delete the marketing cookie. That is also how you withdraw consent to analytics and advertising tags; you can additionally tell us at [email protected]. The core features of the site keep working, but it becomes harder for us to notice and fix rough edges.
9.Who we share data with
The domain registrar and the zone registry — the registrant's WHOIS contacts. This is a mandatory condition of registration.
The server infrastructure provider — the data needed to create your VPS and keep it running.
Payment providers — to process balance top-ups. Web analytics providers (Yandex.Metrica, Google Analytics) — visit data. Our CDN/DNS provider, through which requests to the site pass — the technical details of those requests. The email delivery service — the recipient address and the contents of messages, including order notifications.
We do not sell your data and do not share it with anyone outside the categories listed above — except where disclosure is required under the law of the operator's country of registration, for example in response to a lawful request from a competent authority.
10.Transfers outside the operator's country of registration
Our partners — the domain registrar, zone registries, the server infrastructure provider, payment providers, analytics providers, the CDN/DNS provider, and the email delivery service — operate in various countries, including outside the operator's country of registration. By using the service you understand that your data travels to them across borders, where local rules apply to it.
You choose the server location yourself when ordering — it determines which country your VPS physically runs in and where the data you put on it is held.
11.How we protect data
Account passwords are stored only as hashes.
The server credentials we issue to customers are stored encrypted, and the encryption key is kept outside the database. That said, we email you the credentials for a new server, so they pass through the email delivery service. Keep your mailbox well protected and change the root password after your first login.
Access to data is limited to those who need it to run the service.
12.Data on your server
Everything you put on your VPS — files, databases, the mail of your own projects, the data of your own users — is under your control. We do not use that content for our own purposes, and we are not responsible for how you handle other people's data on your server.
There are no backups by default. If you need copies, make them yourself and keep them off the server.
What happens if you do not pay: when the paid period ends, the service tries to renew automatically and charge your balance. If the balance is short, a grace period of about 24 hours begins — the server is still running. After that the server is powered off. Roughly six days after the power-off, the server is deleted together with all its data, and recovery is impossible.
You can turn auto-renewal off in the portal — the service then simply ends on schedule and the server follows the same path. Take everything you need off the server in advance.
13.How long we keep data
For as long as your account exists, we keep its data and the history attached to it.
We may keep certain records longer where mandatory rules require it — for example ICANN and zone registry requirements for registered domains, or the record-keeping requirements of the law of the operator's country of registration. In such cases the specific periods are not set by us.
Deleting your account does not erase everything: balance transaction history, request logs, and support correspondence may be retained for as long as we need them for accounting, dispute resolution, and protection against abuse.
Data passed to the registrar, the zone registry, payment providers, analytics providers, and the other recipients is stored by them under their own rules. Deleting your account with us does not erase records on their side.
14.Your rights
You can request access to your data, correct inaccuracies, delete your account, object to processing, and withdraw consent to analytics and advertising tags.
To do so, write to [email protected] from the email address your account is registered to — that way we can confirm the request comes from the account owner. We reply within the period set by the law of the operator's country of registration.
One important limit: deleting your account does not undo what has already been done. A domain registration is non-refundable once it has gone through at the registrar, and registrant data remains in the zone registry on that zone's terms.
If our answer does not satisfy you, you have the right to complain to the data protection supervisory authority of the operator's country of registration.
15.Children's data
The service is not intended for children: it may be used only by those who can enter into a contract on their own under the law of the operator's country of registration. We do not knowingly collect children's data.
If you become aware that an account was created by a child, tell us at [email protected] and we will look into it and delete that data.
16.Changes to this policy
We may change this policy — for example when registrar requirements change or when the set of services we use changes. The current version is always published on this page.
For significant changes we aim to notify you by email at the address on your account. By continuing to use the service after a new version is published, you accept it. If anything is unclear, ask at [email protected] before continuing.
17.Language of this document and the version in force
The Russian version of this document is the original; the English version is a translation. If the two differ, the Russian version determines the meaning.
The version in force, with the date it was last updated, is published on this page. Earlier versions no longer apply.