NovaPanel

Privacy Policy

Last updated: 4 May 2026

This is the plain-English version of who we are, what we collect, and what we do with it. The longer formal sections below are the legally-relevant detail; if anything here contradicts that, the formal version wins.

The short version

We're NovaPanel — a UK-based business that sells a self-hosted hosting control panel under a paid licence. To do that, we collect: your email at purchase, the licence key we issue, and basic telemetry (hostname, server IP, panel version, machine fingerprint) that your panel sends us every hour so we can confirm the licence is bound to a real machine.

Payments go through Stripe and PayPal — they hold your card details, not us. Email goes through Google Workspace SMTP. Binary downloads happen on Cloudflare R2. We don't sell your data, don't run advertising trackers, and don't share anything beyond what's required to deliver the service.

1. Who we are

Data controller: NovaPanel.
Country: United Kingdom.
Contact: privacy@novapanel.dev for data-related questions; full registered address available on request.

As a UK-based business, we're regulated by the UK Information Commissioner's Office (ICO). You can complain to the ICO at ico.org.uk if you think we've mishandled your data.

2. What data we collect

2.1 At purchase

2.2 From your panel installation (telemetry)

Once you install NovaPanel and activate a licence, the panel sends a "heartbeat" to our licence server roughly once an hour. The heartbeat contains:

No website content, customer data, database contents, or end-user personal data is sent to us. Telemetry is operational metadata about your panel installation, not anything inside it.

2.3 From the customer portal

When you sign in to license.novapanel.dev/portal via a magic link, we set a session cookie (nps_portal, HttpOnly, Secure, 24-hour TTL) so you stay signed in. We log every action you take in the portal (manage subscription, reset binding, request refund) to an audit log for security and compliance purposes.

2.4 Marketing site

novapanel.dev itself sets no cookies and runs no third-party trackers. No Google Analytics, no Facebook Pixel, no advertising integrations. The site is static HTML served from Cloudflare's CDN; their network logs (standard web-server logs) include your IP and user agent for the duration Cloudflare retains them.

3. Why we collect it (legal basis)

Under UK GDPR we need a legal basis for each kind of processing.

4. Who we share it with

The third parties that handle data on our behalf, and what they handle:

We don't share data with anyone else. We don't sell data, ever. We don't share with advertisers. If we're legally compelled to disclose data (court order, valid law-enforcement request), we'll do so but will notify you unless we're explicitly forbidden from doing so.

5. International transfers

Some of our processors (Stripe Inc, Cloudflare Inc) are based in the US. Transfers rely on the UK-US Data Bridge (an extension of the EU-US Data Privacy Framework) and Standard Contractual Clauses where applicable. You can request a copy of those clauses by emailing privacy@novapanel.dev.

6. How long we keep it

7. Your rights

Under UK GDPR you have the right to:

To exercise any of these, email privacy@novapanel.dev. We respond within 30 days, usually within a few business days.

8. Security

Data at rest is stored in PostgreSQL on encrypted volumes. Sensitive secrets (Stripe API keys, PayPal credentials, SMTP passwords) are encrypted with AES-256-GCM before being written to the database. The encryption master key lives outside the database, in a file readable only by the licence-server process.

Data in transit is HTTPS-only (TLS 1.2+). The licence server's API and the customer portal both refuse non-HTTPS connections.

We don't pass payment card details through our servers — Stripe and PayPal handle PCI-scoped data directly.

9. Children

NovaPanel is sold to professional operators — typically system administrators, developers, or hosting resellers. We don't knowingly collect data from anyone under 16. If you're a parent and believe your child has registered an account, email us and we'll delete the record.

10. Changes to this policy

Material changes will be announced on this page with an updated "Last updated" date and, where the change is significant, by email to active customers. Minor wording fixes won't trigger an email.

Contact

Questions about this policy: privacy@novapanel.dev.
General contact: hello@novapanel.dev.
Customer support: support@novapanel.dev.