Privacy Policy

Last updated: March 6, 2026

1. Information We Collect

Account Information: Email address, hashed password, and account preferences.

Usage Data: Instance creation/deletion events, API usage, login timestamps, IP addresses, and billing transactions.

Payment Information: For payments processed through Paddle (our Merchant of Record), payment data such as credit card details, billing address, and tax identifiers are collected and processed by Paddle.com Market Ltd directly. gpuLabs does not receive, process, or store your credit card numbers or payment credentials. For cryptocurrency deposits, we store wallet addresses and transaction hashes.

Technical Data: SSH public keys, API key metadata (names, creation dates, last used timestamps). We store API key hashes, not the raw keys.

2. How We Use Your Information

  • To provide, maintain, and improve the Service
  • To process payments and manage your balance
  • To authenticate your identity and authorize access
  • To monitor for abuse and enforce our Terms of Service
  • To communicate important service updates
  • To generate aggregate, anonymized analytics
  • To comply with tax, legal, and regulatory obligations

3. Data We Do Not Collect

We do not access, monitor, inspect, or log the content of your GPU instances, volumes, or inference endpoints. What you run on your instances is your business. We do not collect personal information beyond what is necessary to operate the Service.

4. Payment Processing and Paddle

All payments (except cryptocurrency) are processed by Paddle.com Market Ltd, which acts as our Merchant of Record. When you make a purchase:

  • Paddle collects your payment details (credit card, PayPal, billing address) directly through its checkout
  • Paddle processes and stores your payment data in accordance with PCI DSS Level 1 standards
  • gpuLabs receives only a confirmation of payment, the amount, and a transaction reference — never your card number or payment credentials
  • Paddle may collect your name, email, billing address, and tax identification number to issue valid tax invoices
  • Paddle's processing of your data is governed by Paddle's Privacy Policy

For cryptocurrency payments, we record the blockchain wallet address and transaction hash on our servers. No additional personal data is collected for crypto transactions.

5. Data Sharing

We do not sell, rent, or trade your personal information to third parties. We may share data only in the following circumstances:

  • Payment Processor (Paddle): We share your email address and account identifier with Paddle to associate payments with your gpuLabs account and enable billing management
  • Infrastructure Providers: We share minimal technical data (instance specifications, region) with our infrastructure partners to provision your resources
  • Legal Compliance: When required by law, regulation, or valid legal process
  • Safety: To protect the rights, safety, and property of gpuLabs, our users, or the public

6. Data Security

We implement industry-standard security measures including:

  • Passwords hashed with bcrypt (12 rounds)
  • API keys hashed with bcrypt (not stored in plaintext)
  • HTTPS/TLS encryption for all API communications
  • JWT tokens with short expiration (15 minutes)
  • Rate limiting on all API endpoints
  • Payment data handled exclusively by Paddle (PCI DSS Level 1 compliant) — card details never touch our servers

However, no method of transmission or storage is 100% secure. We cannot guarantee the absolute security of your data.

7. Data Retention

We retain your account data for as long as your account is active. Transaction history is retained in accordance with applicable tax and accounting regulations. Upon account deletion, your personal data is permanently removed within 30 days, except where retention is required by law. Paddle retains payment transaction records independently in accordance with their own retention policies and legal obligations.

8. Cookies and Tracking

We keep the short-lived access token in session storage and the refresh token in a secure HttpOnly, SameSite cookie. We do not use advertising cookies. Stripe may set strictly necessary cookies during checkout under its own privacy policy.

9. Your Rights

You have the right to:

  • Access and export your account data
  • Correct inaccurate information
  • Delete your account and associated data
  • Revoke API keys at any time
  • Request details of what data we hold about you
  • Object to specific processing activities where legally applicable

To exercise these rights, contact us at privacy@gpulabs.cloud. For rights related to payment data processed by Paddle, you may also contact Paddle directly per their privacy policy.

10. International Data Transfers

gpuLabs operates infrastructure across multiple countries and jurisdictions. Paddle processes payments globally. By using the Service, you acknowledge and consent to the following:

  • Your data may be processed and stored in jurisdictions outside your country of residence
  • We take reasonable steps to ensure that data transfers comply with applicable data protection laws
  • Where required, we rely on standard contractual clauses or other lawful transfer mechanisms
  • Paddle processes payment data in accordance with GDPR, CCPA, and applicable local regulations
  • GPU instances you deploy may be physically located in any of our 40+ datacenter regions worldwide

11. Children's Privacy

The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that a user is under 18, we will promptly terminate their account and delete all associated data. If you believe a minor has created an account, please contact us at privacy@gpulabs.cloud.

12. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you
  • Right to Delete: You may request deletion of your personal information, subject to certain exceptions
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights
  • Right to Opt-Out: We do not sell personal information. If this changes, we will provide an opt-out mechanism

To exercise your CCPA rights, contact us at privacy@gpulabs.cloud. We will verify your identity before processing any request and respond within 45 days.

13. European Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR):

  • Legal Basis: We process your personal data based on contractual necessity (to provide the Service), legitimate interests (security, fraud prevention), and consent (marketing communications)
  • Data Portability: You may request a machine-readable copy of your personal data
  • Right to Erasure: You may request deletion of your data, subject to legal retention obligations
  • Right to Restrict Processing: You may request that we limit our processing of your data
  • Supervisory Authority: You have the right to lodge a complaint with your local data protection authority

Paddle, as our Merchant of Record, independently complies with GDPR for payment data it processes. Paddle's data processing is governed by its own privacy policy and applicable data processing agreements.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised date.

15. Contact

For privacy-related inquiries, contact us at privacy@gpulabs.cloud.

For questions about how Paddle processes your payment data, visit Paddle's Privacy Policy or contact Paddle at privacy@paddle.com.