Privacy Policy
Effective date: 26th May 2026
Introduction
This Privacy Policy ("Policy") describes how eXact Digital LLC ("eXact Digital," "we," "us," or "our"), a Colorado limited liability company, collects, uses, discloses, and protects your personal information when you access our website https://exact.gg, use our hosting, VPS, or related online infrastructure services, register for an account, or otherwise interact with our products, services, or communications.
This Policy is intended to help you understand your privacy rights, the categories of information we process, and how eXact Digital LLC processes personal information in accordance with applicable privacy laws to the extent they apply to our Services.
1. Introduction & Company Information
eXact Digital LLC is a hosting and online infrastructure company organized and operated as follows:
eXact Digital LLC
Organized in: Colorado, United States
Business website: https://exact.gg
Contact: support@exact.gg
eXact Digital LLC determines the purposes and means of processing personal information we collect from you as a customer, visitor, or user of our Services, unless otherwise stated (for example, when acting as a domain registrar's data processor for WHOIS data).
2. Scope of This Policy
This Privacy Policy applies to:
- All customers using our hosting, VPS, domain, email, and related online infrastructure services;
- Visitors to our website and subdomains;
- Users on free plans, promotional plans, or affiliated with resellers;
- Individuals communicating with us via support tickets, email, or chat;
- Any other user whose data we may process during the course of providing our services.
This Policy does not cover third-party websites or services you may access through our platform (e.g., linked payment processors, external web builders), which are governed by their own privacy terms.
3. Applicability and User Rights
This Policy applies globally, but certain rights and disclosures may vary depending on your location:
- If you are located in the European Economic Area or another jurisdiction with additional privacy protections, additional rights may apply under the GDPR or other applicable privacy laws to the extent those laws apply to our Services.
- Depending on your U.S. state of residence and subject to applicable law, you may have rights under applicable U.S. state privacy laws.
- All users are entitled to transparency, choice, and control over their data, subject to applicable laws.
Our Services are not directed to individuals under the age of 18, and we do not knowingly collect personal information from minors.
4. Our Commitment to Data Protection
We are committed to upholding the highest standards of privacy and data protection. This includes:
- Processing personal information lawfully, fairly, and transparently;
- Collecting only the information we need for specific and legitimate purposes;
- Keeping information accurate, secure, and retained only as long as necessary;
- Allowing users to exercise applicable rights to access, correct, delete, or restrict their information;
- Not sharing, selling, or transferring personal information without a lawful basis.
We implement appropriate technical and organizational measures to safeguard your personal information, including encryption, secure authentication, internal access controls, and data minimization procedures.
5. Legal Bases for Processing
If you are located in the European Economic Area or another jurisdiction requiring a lawful basis for processing, we rely on one or more of the following legal bases, as applicable:
- Contractual Necessity: To provide the Services you have requested, including account creation, service provisioning, billing, and support.
- Legitimate Interests: For purposes such as fraud detection, analytics, service optimization, security monitoring, abuse prevention, and protecting our infrastructure and users — where these interests are not overridden by your privacy rights.
- Consent: For non-essential cookies, marketing communications, or optional information you choose to provide.
- Legal Obligation: To comply with applicable laws such as tax regulations, anti-money laundering requirements, or ICANN/WHOIS domain data rules.
Where consent is required, you will be asked explicitly, and you may withdraw your consent at any time by emailing support@exact.gg. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal. For users in other jurisdictions, we process personal information on bases consistent with applicable local law.
6. Account and Identity Information
When you create an account or purchase a service from eXact Digital LLC, we collect the following categories of personal information:
- Basic Information: Name, email address, username, and account password (stored in hashed form);
- Contact Details: Phone number (if provided), billing address, country, city/postcode;
- Business Information (where applicable): Company name, business type, and VAT/tax identification number if provided;
- Account Preferences and Promotional Data: Language preferences, service plan details, promo codes, free trial status, or referral information.
This information is necessary to:
- Create and manage your account;
- Contact you regarding service status or security issues;
- Verify your identity for fraud prevention;
- Comply with billing, tax, and contractual obligations.
We do not collect government identification numbers or sensitive personal information unless required for compliance (for example, domain registration ID verification under ICANN rules).
7. Hosting/VPS Technical Data and Service Logs
As a hosting and VPS provider, eXact Digital LLC may process technical information related to customer services. When you interact with our website, servers, or services, we automatically collect technical usage data, including:
- IP addresses, server identifiers, and network activity;
- Device type, browser type, operating system, and session logs;
- Login timestamps, authentication attempts, and authentication logs;
- Pages viewed, features used, and clickstream data on our website and control panel;
- Bandwidth usage, CPU usage, RAM usage, disk usage, and resource consumption (for VPS and hosting users);
- Error logs, file access history, security logs, control panel actions, and abuse reports.
This technical data is collected and processed for:
- Service delivery, provisioning, resource management, and performance monitoring;
- System security, abuse prevention, network protection, and fraud mitigation;
- Diagnosing errors, troubleshooting, and improving platform performance.
We may use technical and usage information to detect, prevent, investigate, and respond to spam, malware, phishing, fraud, unauthorized access, denial-of-service activity, excessive resource usage, network abuse, violations of our Terms of Service, and other harmful or unlawful activity. However, we do not undertake a general obligation to monitor all customer content or activity. This information may be processed by internal tools or trusted third-party providers (see Section 18), including Cloudflare (analytics and DDoS protection) and our external fraud detection system. Usage of scripts and automation-based applications is permitted as long as it remains within our fair usage thresholds and does not cause network abuse or disruption.
We automatically take regular backups for standard web hosting accounts as a complimentary service. However, customers are responsible for maintaining independent backups, as redundancy is not guaranteed.
8. Payment and Transaction Data
When you purchase a service through our Platform, we collect and process transaction-related data. This includes:
- Payment status and invoice history
- Transaction identifiers
- Currency and subscription type
- Partial payment card metadata (for example, last four digits of a card number); payment information may be processed by third-party payment processors. eXact Digital LLC does not intentionally store full payment card numbers unless expressly stated or required for a specific payment method.
All payment processing is handled via third-party payment providers (such as Stripe, PayPal, or cryptocurrency gateways). These processors collect and handle your full payment information in accordance with PCI DSS and other applicable financial regulations. Their privacy practices are governed by their own privacy policies.
We retain limited payment metadata to:
- Generate invoices and support financial reporting;
- Fulfill our contractual and legal accounting obligations;
- Investigate payment disputes and chargebacks.
For cryptocurrency payments, refunds are not available due to volatility and technical limitations (see Refund Policy). By using such methods, you agree to assume the associated risks.
9. Communications and Support Logs
When you contact us or open a support ticket, we may collect:
- Your contact email and IP address
- Timestamps and conversation content (via email, chat, or Discord)
- Support-related metadata (assigned agent, ticket category, resolution status)
We retain support communications to:
- Track, resolve, and improve user support;
- Maintain service records for audit or training purposes;
- Respond to future queries and dispute resolutions;
- Enforce our Terms of Service or investigate abuse reports.
Support data is stored securely and accessible only to authorized staff under strict access controls. You may request deletion of non-critical communications by emailing support@exact.gg.
11. Anti-Fraud and Risk Screening
To prevent fraud, protect our infrastructure, and enforce fair usage, we may employ a dedicated anti-fraud system provided by a trusted third-party vendor. This system may process:
- Device/browser fingerprint data
- IP reputation, geolocation, VPN/proxy use
- Behavioral patterns (e.g., session frequency, access velocity)
- Data from other users on the same network or ISP
Data processed by this tool is automatically evaluated to:
- Flag high-risk signups or transactions;
- Prevent abusive signups or repeat offenders;
- Enforce cooldowns, rate limits, or manual verification steps.
The anti-fraud system operates as an independent data processor under contractual obligations. Personal information processed for fraud and risk screening is not used for profiling unrelated to our platform or Services.
11A. Analytics and Usage Tracking
We may use analytics tools and similar technologies to understand website traffic, usage patterns, platform performance, and user interactions. These tools may collect information such as IP address (which may be anonymized or truncated), device information, browser type, pages visited, referring URLs, and approximate location derived from IP address.
Analytics data is used to improve the Services, understand usage trends, identify technical issues, and enhance platform performance. We do not use analytics data to serve behavioral advertising to our users. Where analytics tools involve the use of cookies, our Cookies section (Section 10) applies.
12. Domain WHOIS Data
If you register a domain name through us, we are required by ICANN regulations and domain registries to collect and share WHOIS information. This may include:
- Registrant name
- Contact email and phone
- Postal address
- Technical and administrative contact info
WHOIS data is made publicly available (unless privacy protection is purchased) and may be accessed through public WHOIS lookups. We process this data on the basis of:
- Legal obligation under domain name registry agreements;
- Contractual necessity to fulfill your registration request.
Note: Some country-code domains (.us, .eu, .ca, etc.) are subject to national or regional laws that may limit or restrict public exposure of WHOIS data.
13. Free Plans, Promotions, and Usage Tracking
If you sign up for our eXact Lite free plan or use a promotional code (e.g., FREEMONTH), we may collect additional metadata, such as:
- Referral codes or partner attribution
- Sign-up timestamps and IP logs
- Promo usage frequency (to prevent abuse)
- Free tier usage metrics (bandwidth, storage, login frequency)
This data is used to:
- Detect repeated abuse of promo codes;
- Limit free plan usage in accordance with fair use thresholds;
- Improve conversion tracking and optimize plan design.
We do not sell, advertise against, or profile free plan users. All data is retained only for the duration needed to support our legitimate platform operation and abuse prevention.
13A. Customer-Hosted Content
Customers are responsible for the content, files, applications, databases, websites, and other materials they upload, host, transmit, or store through the Services ("Customer Content"). eXact Digital LLC generally processes Customer Content only as reasonably necessary to provide, maintain, secure, troubleshoot, support, investigate abuse, comply with legal obligations, enforce our Terms of Service, or protect the Services, infrastructure, users, or third parties.
eXact Digital LLC does not claim ownership of Customer Content. Customers remain solely responsible for ensuring their content and use of the Services comply with applicable laws and our Terms of Service.
14. How We Use Your Personal Information
We use your personal information for the following purposes, consistent with applicable law:
- To deliver our Services — including account setup, hosting and VPS provisioning, domain registration, SSL provisioning, and technical access;
- To process transactions and billing — generating invoices, handling renewals, and managing payment status;
- To protect our platform and infrastructure — including abuse prevention, fraud mitigation, security monitoring, access control, and IP reputation management;
- To improve our products — through technical diagnostics, usage analysis, feature usage metrics;
- To communicate with you — including service alerts, updates, scheduled maintenance, ticket responses, or security issues;
- To fulfill legal and regulatory obligations — including tax law, ICANN compliance, and fraud reporting;
- To enforce our Terms of Service — including account suspensions, usage audits, or formal notices;
- To conduct internal analytics — understanding growth trends, usage frequency, and market demand.
- To support rebranding tools — for resellers or white-label customers, while enforcing brand impersonation safeguards.
We do not:
- Sell or rent your personal information;
- Use your information for programmatic advertising;
- Combine your personal information with third-party databases for marketing purposes.
15. Marketing Communications and Your Choices
15.1 With your consent or under our legitimate interest (where permitted by law), we may send you marketing communications regarding new features, service offers, affiliate programs, or announcements.
15.2 These communications may be sent via:
- Email newsletters
- In-app messages
- SMS or WhatsApp (if opted-in)
- Discord (for all users)
15.3 You may opt out of non-essential communications at any time by:
- Clicking the “unsubscribe” link in our emails;
- Updating your communication preferences in your Account dashboard;
- Emailing support@exact.gg with the subject line "OPT OUT".
15.4 Essential service-related notices (e.g., billing alerts, downtime warnings, policy changes) will still be sent regardless of your marketing preferences, as they are required for contractual performance.
16. Third-Party Services and Data Sharing
16.1 We share personal information with third parties only where necessary to:
- Deliver the Services (e.g., payment processing, fraud screening, DNS management);
- Comply with legal obligations (e.g., domain registration with ICANN);
- Maintain the functionality and integrity of our infrastructure.
16.2 Third parties and categories of recipients with whom your information may be shared include:
- Hosting infrastructure providers, data centers, and cloud and network providers;
- Payment processors (such as Stripe, PayPal, and cryptocurrency gateways);
- Anti-fraud and security vendors (such as Cloudflare, Sensfrx, or equivalent providers);
- Email, communication, and CRM tools (for transactional email delivery, support, and account notifications);
- Domain registries, WHOIS directory services, and domain registrar partners; analytics providers; professional advisers (legal, financial, and accounting); and law enforcement or regulators where required by applicable law.
16.3 These providers are contractually bound to:
- Only process data on our instructions;
- Implement appropriate security measures;
- Not use your data for their own marketing purposes.
16.4 We do not sell, rent, or otherwise monetize your personal information to third parties.
16.5 We may share relevant account, technical, usage, or abuse-related information with upstream providers, data centers, network operators, law enforcement, regulators, complainants, or affected third parties where we reasonably believe it is necessary to investigate abuse, respond to security incidents, comply with legal obligations, enforce our Terms of Service, protect IP reputation, prevent harm, or protect the Services, infrastructure, users, or third parties.
16.6 We also offer tools to enable rebranded access for resellers, provided that users do not claim to be eXact Digital. Rebranding is permitted for this purpose, but users must clearly represent that they use eXact Digital LLC's infrastructure and Services, not that they are eXact Digital LLC.
17. International Data Transfers
17.1 eXact Digital LLC is based in the United States. If you access or use the Services from outside the United States, your personal information may be transferred to, stored in, or processed in the United States and other countries where we or our service providers operate. These countries may have data protection laws that differ from those in your jurisdiction.
17.2 Where required by applicable law, we use appropriate safeguards for international transfers. For users located in the European Economic Area or other jurisdictions requiring transfer mechanisms, safeguards may include:
- Standard Contractual Clauses as approved by the European Commission or other applicable authorities;
- Adequacy decisions recognized by applicable authorities;
- Other lawful transfer mechanisms as permitted under applicable privacy law.
- Explicit consent, where appropriate.
17.3 Our service providers and infrastructure partners (such as Cloudflare and our anti-fraud vendor) may operate or process data in the United States or other countries. These providers are contractually committed to appropriate data protection standards.
17.4 You may request information about our current data transfer mechanisms by contacting support@exact.gg.
18. Legal Disclosures and Law Enforcement Requests
18.1 We may disclose personal information:
- If required to do so by law, regulation, subpoena, or court order;
- To enforce our Terms of Service or investigate potential violations;
- To respond to abuse complaints or copyright infringement notices;
- To detect, prevent, or otherwise address fraud, security, or technical issues;
- If disclosure is necessary to protect the rights, property, or safety of eXact Digital LLC, its users, or the public.
18.2 Requests from law enforcement agencies will only be honored where:
- They are legally valid and enforceable under applicable U.S. federal or state law or other applicable law in the relevant jurisdiction;
- They are narrowly tailored to specific data points;
- We are permitted to notify the affected user (unless prohibited by law).
18.3 We do not provide bulk, blanket, or proactive access to user data for surveillance purposes.
19. Your Privacy Rights
Depending on your location and applicable law, you may have the following rights regarding your personal information. Your rights may vary depending on where you live and the laws that apply:
- Right of Access – to request a copy of the personal information we hold about you;
- Right to Correction – to correct inaccurate or incomplete information;
- Right to Deletion – to request deletion of your personal information in certain circumstances;
- Right to Restriction – to limit how your information is used under specific circumstances;
- Right to Portability – to receive your information in a structured, commonly used, machine-readable format where applicable;
- Right to Object – to object to processing based on legitimate interests or for direct marketing purposes;
- Right not to be subject to solely automated decisions that produce legal or similarly significant effects, where applicable;
- Right to withdraw consent at any time where processing is based on consent;
- Right to lodge a complaint with a supervisory authority or data protection authority where applicable.
To exercise any of these rights, please email us at support@exact.gg with the subject line "DATA RIGHTS REQUEST". We will respond to verified requests as required by applicable law. We may request proof of identity to protect your account and the integrity of our response process.
19A. U.S. State Privacy Rights
19A.1 Depending on your U.S. state of residence and subject to applicable law, you may have rights to request access to, correction of, deletion of, or a copy of certain personal information we hold about you, and to opt out of certain processing activities where applicable.
19A.2 We will respond to verified requests as required by applicable U.S. state privacy law. These rights are subject to legal exceptions and may not apply in all circumstances. eXact Digital LLC will not discriminate against you for exercising applicable privacy rights.
19A.3 California residents may have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) where those laws apply to our Services, including the right to know what personal information is collected, the right to request deletion, and the right to opt out of the sale of personal information. We do not sell personal information as defined under the CCPA.
19A.4 To submit a privacy rights request, please email support@exact.gg with the subject line "U.S. PRIVACY RIGHTS REQUEST" and provide sufficient information for us to verify your identity.
20. Consent Management and Opt-Outs
20.1 You have full control over your consent preferences for the following:
- Marketing communications;
- Non-essential cookies;
- Data processing for optional features (e.g., promo tracking, affiliate attribution);
- Public WHOIS exposure for domains.
20.2 Consent may be withdrawn at any time by:
- Updating your preferences in your account;
- Emailing support@exact.gg;
- Adjusting browser or device settings for cookies and tracking tools.
20.3 Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
20.4 Some features may be disabled or unavailable if you withdraw consent for essential processing activities (e.g., DNS propagation for domains).
21. Account Deletion and Data Retention
21.1 You may request permanent deletion of your account and personal information by:
- Navigating to your Account settings;
- Emailing support@exact.gg with the subject line "ACCOUNT DELETION".
21.2 Upon account deletion:
- Your services will be terminated;
- Your personal information will be anonymized, redacted, or deleted from active systems within 30 days of verified deletion, unless a longer period is required by law.
21.3 We retain personal information for as long as reasonably necessary to provide the Services, maintain business records, comply with legal obligations, resolve disputes, enforce agreements, prevent fraud and abuse, protect security, and operate our business. Specific retention categories include:
- Billing and financial records retained as needed for tax, accounting, or legal obligations;
- Support communications retained as needed for service history, training, audit, and dispute resolution;
- Account and identity data retained while your account is active and for a reasonable period afterward;
- Technical logs, security logs, and abuse records retained for limited periods, unless needed longer for investigation, legal compliance, dispute resolution, or abuse prevention.
21.4 Deleted data is removed from production databases. Backup copies may persist temporarily and will be permanently purged within 90 days of scheduled backup rotation.
22. Children's Privacy
22.1 The Services are not intended for children under the age of 13, and we do not knowingly collect personal information from children under 13 (or the minimum age required by applicable law in your jurisdiction). Our Services are intended for use by individuals aged 18 and older.
22.2 If we become aware that we have collected personal information from a child under 13 without verified parental consent, we will take appropriate steps to delete such information promptly.
22.3 If you believe that a minor may have provided us with personal information, please contact us immediately at support@exact.gg so we can investigate and take appropriate action.
23. Security Measures
23.1 We use reasonable administrative, technical, and organizational measures designed to protect your personal information from unauthorized access, disclosure, alteration, or destruction. These include:
- HTTPS and TLS encryption on all services;
- Two-factor authentication for administrator accounts;
- Role-based access control for internal staff;
- Intrusion detection systems and firewalls;
- Regular vulnerability scans and security audits.
23.2 However, no hosting environment, transmission method, storage system, or security measure is completely secure, and we cannot guarantee absolute security.
23.3 Users are responsible for safeguarding their own credentials, choosing strong passwords, and logging out of their accounts after use. If you believe your account has been compromised, contact support@exact.gg immediately.
24. Changes to This Policy
24.1 We may update this Privacy Policy from time to time to reflect:
- Changes in our practices or services;
- Legal or regulatory developments;
- New technologies or third-party integrations.
24.2 When we make material changes, we will notify you via:
- Email (if your contact details are available);
- An announcement or banner on our website;
- A change in the "Last Updated" date at the top of this policy.
24.3 Your continued use of the Services after a policy update constitutes acceptance of the changes. If you disagree with the changes, you may terminate your account as described in Section 21.
25. How to Contact Us
For questions, requests, or concerns regarding this Privacy Policy or your privacy rights, you may contact us at:
eXact Digital LLC
Email: support@exact.gg
For legal notices:
- Email: All inquiries (including privacy, abuse, and legal): support@exact.gg
- Subject: "PRIVACY POLICY – LEGAL REQUEST"
We aim to respond to all verified requests within 30 days. Where necessary, we may extend this timeframe with notice in accordance with applicable law.
26. Company / Data Controller Information
Unless stated otherwise, the entity responsible for processing personal information under this Policy is:
eXact Digital LLC
A Colorado limited liability company
Business website: https://exact.gg
Contact: support@exact.gg
eXact Digital LLC processes personal information in accordance with applicable privacy laws to the extent they apply to our Services.
27. Governing Law and Jurisdiction
27.1 This Privacy Policy shall be governed by and interpreted in accordance with the laws of the State of Colorado and applicable U.S. federal law, without regard to conflict of law principles.
27.2 Any disputes arising out of or in connection with this Policy shall be subject to the jurisdiction of the courts located in Colorado, United States, unless applicable privacy law in your jurisdiction mandates otherwise or requires local dispute resolution.
28. Support Channels
We offer customer support through the following channels:
- Ticket submissions via the client portal at https://exact.gg
- Email correspondence via support@exact.gg
- Live chat via our website (when available)
- Discord (available to all users)
These support options are available to assist with general inquiries, technical issues, billing, abuse reports, and privacy-related requests. We aim to respond promptly across all channels, with priority given to urgent or service-impacting matters.