Privacy Policy
Last updated: August 2026
Accurate, but not yet lawyer-reviewed.
This describes what the platform actually collects and how long it keeps it, checked against the running system. It has not been reviewed by a lawyer. Before charging customers it should be, particularly the sections on player data and on international players, where obligations beyond Australian law may apply.
1. Who we are
Sapling Hosting (ABN 67 258 304 892) operates Sapling, a game server hosting platform at saplinghosting.net. We host servers for Minecraft, Palworld, Rust, 7 Days to Die, Project Zomboid, Factorio and others, along with the control panel used to manage them. We are based in New South Wales, Australia.
2. Two different kinds of people
This policy covers two groups, and the difference matters because only one of them ever agreed to anything with us.
- ACCOUNT HOLDERS — customers who sign up, rent a server and pay us. Sections 3 to 5 are about you.
- PLAYERS — people who connect to a server somebody else rents. You have no account with us and no relationship with us. We still end up holding some information about you, and section 6 says exactly what.
If you rent a server from us, you decide who plays on it and what happens there. That makes you responsible for telling your players what is recorded on your server — including, on Rust, that in-game chat is logged and visible to you. We provide the tools; the relationship with your players is yours.
3. What we collect about account holders
- Your name, email address, and — for password sign-ups — a hashed password. We never store the password itself.
- OAuth profile information from Google, Discord or Facebook if you sign in that way: typically email, display name and avatar URL.
- Server metadata: name, game, plan, region, mods and configuration for each server you create. This is what lets us actually build and run it.
- Operational data: IP addresses (including the address of your last sign-in), user agent strings, and request logs, used for security and abuse prevention.
- Support tickets and anything you write in them.
- Billing records: invoices, amounts, and payment status. Card numbers go directly to our payment processor and never reach our systems.
4. What we do with it
- Run your servers and the control panel.
- Authenticate you and protect your account.
- Send transactional email: verification, password resets, security notices, billing, and alerts about your servers.
- Investigate abuse, fraud and security incidents.
- Understand how the platform is used, in aggregate.
We do not sell personal information. We do not use it to train AI models. We do not show third-party advertising. We do not send marketing email unless you ask us to.
5. Who we share it with
Only the providers needed to deliver the service. Each sees only what it needs:
- Cloudflare — transactional email delivery, the tunnel that serves this site, and R2 object storage for backups.
- Stripe — payments and invoicing. Card details are handled entirely by Stripe.
- Steam (Valve) — when you or your players use a Steam-based game, we query Steam's public API for account standing and profile names using Steam IDs.
- Our own infrastructure — the game servers, database and panel all run on hardware we own and operate in Australia. The panel software (Pelican) is self-hosted, not a third-party service.
Backups are stored in Cloudflare R2, which may hold them outside Australia. We may also disclose information where the law requires it — for example a valid Australian court order — and we will resist requests that are broader than the law allows.
6. What we hold about players
If you play on a server hosted here without having an account with us, this is the whole list. It exists so server owners can moderate their own communities.
- Your in-game name, and your Steam ID where the game provides one.
- Join and leave times, kept as a session history so owners can see who plays and for how long. This history is not automatically deleted.
- On Rust servers only: in-game chat messages, with the sender and time, kept for 30 days and visible to that server's owner. Other games are read live and not stored.
- Ban and moderation records for the server you were banned from.
We do not store player IP addresses. Where a game exposes them to us, they are discarded rather than recorded, and they are never shown on public pages such as the live map.
If you want your player data removed from a server, the fastest route is the owner of that server. You can also contact us directly using the address in section 11.
7. How long we keep things
Different data has genuinely different lifespans, so rather than one number:
- Account data — while your account is open, plus a short grace period after you close it.
- Deleted servers — a 7-day window in which you can change your mind, after which the server and its data are destroyed once a verified archive exists.
- Server performance samples — 30 days.
- Rust chat — 30 days.
- Security and firewall event logs — 14 days.
- Player session history — kept indefinitely, because it is how a server owner sees their community over time. Each row is a name, a time and a server.
- Server backups — on the retention schedule shown on your server's Backups tab; older automatic backups are pruned, and ones you make yourself are kept until you delete them.
- Invoices and financial records — five years, which Australian tax law requires.
8. Your rights
You can ask us to:
- Give you a copy of the personal information we hold about you.
- Correct anything that is wrong.
- Delete your account and the personal information tied to it, other than records we are legally required to keep.
- Stop or limit particular uses, where the law allows it.
Email the address in section 11 and we will respond within 30 days. If you are unhappy with how we handle it, you can complain to the Office of the Australian Information Commissioner.
9. Security
Passwords are hashed with bcrypt and never stored in readable form. Credentials we hold for other services are encrypted at rest. Traffic is served over TLS. Access to production systems is limited to a small number of operators, optional two-factor authentication is available on your account, and backups are taken nightly and stored off-site. No system is perfectly secure, and we will tell you promptly if something happens that affects your data.
10. Children
Sapling is not directed at children under 13, and accounts are for adults or for a parent or guardian acting on a child's behalf. Games hosted here are often played by younger players; we hold the same limited player information described in section 6 regardless of age. If you believe we hold information about a child under 13, contact us and we will delete it.
11. Contact
Questions, requests or complaints: [email protected]. We will update this page when our practices change, and flag anything material on your dashboard or by email before it takes effect.