Last updated: 3 October 2026.
This policy explains what OpenSysLab (“we”, “us”) collects and does with personal data when you use opensyslab.co and the servers you rent from us. It is written to be read in one sitting.
The short version
- We collect what we need to run the store and your servers: your email, your orders, and your servers’ status.
- Your AI API key is validated when you submit it and then lives only on your server. We never store it.
- Your business data lives on your private server. We do not have a copy of it, and we do not run advertising or analytics trackers.
- Payments are handled by PayPal. We never see or store card numbers.
What we collect
- Account and order data. Your billing email, name, and the products, options (region, spec, backup), and amounts of your orders. If you check out as a guest, an account is created for your billing email so your servers can attach to it.
- Server metadata. For each server: the region, size, backup choice, IP address, and provisioning status. This is operational data, not content.
- Support correspondence. Emails you send us, kept as long as needed to resolve the thread.
- Technical cookies. WordPress and WooCommerce set session and cart cookies so sign-in and checkout work. We do not use advertising, retargeting, or third-party analytics cookies.
What we deliberately do not collect
- Your AI API key. It is checked against the vendor when you start a server, transmitted to your server for provisioning, and never written to our database.
- Your app data and conversations. Business data, files, and chat history live in the database on your private server. We have no pipeline that copies them anywhere.
- Payment card details. Checkout happens on PayPal. We receive a payment confirmation, not card numbers.
How we use what we collect
- To provision, operate, secure, and bill your servers.
- To send transactional email: order confirmations, server-ready emails with credentials, and security notices.
- To answer support requests.
- To meet legal obligations, such as accounting and tax record-keeping.
Who else sees your data
- DigitalOcean hosts the virtual machines; their processing is governed by their own privacy terms.
- Our hosting mail server delivers transactional email on our behalf.
- PayPal processes payments under its own privacy policy.
- Your chosen AI model provider receives the prompts and agent outputs you generate, under your own API key and that provider’s data policy. Choose a vendor whose retention terms you are comfortable with.
Where your data lives and for how long
Your server and its data are created in the region you chose at purchase and stay there. Order and billing records are retained for as long as accounting law requires. Server metadata is removed when the server is deleted. Backup snapshots, if you chose Daily backups, expire on a rolling 7-day window; they are for disaster recovery, not archiving.
Your rights
You can ask to see, correct, or delete the personal data we hold about you at any time by writing to info@opensyslab.co. Export anything stored on your server before deleting it — we cannot recover it afterwards.
Security
Servers are isolated per customer at the hypervisor level, keys are transmitted only for provisioning, and access to production systems is limited to the people operating the service. No system is perfectly secure; if we suffer a breach affecting your data, we will notify you without undue delay.
Questions
Privacy questions go to info@opensyslab.co. [TODO: add registered legal entity and jurisdiction before public launch.]