Privacy Policy
Last updated: 23 September 2026
Accurate, but not yet lawyer-reviewed.
This has been checked against what the platform actually does, but has not yet been reviewed by a lawyer.
1. Who We Are
Sapling Hosting (ABN 67 258 304 892) operates Sapling, a game server hosting platform at saplinghosting.net. We host servers for Minecraft, Palworld, Rust, 7 Days to Die, Project Zomboid, Factorio and other games, along with the control panel used to manage them. We are based in New South Wales, Australia.
We handle personal information in line with the Australian Privacy Principles under the Privacy Act 1988 (Cth). This policy explains what we collect, why, who we share it with, and the choices you have.
2. Two Different Kinds of People
This policy covers two groups, and the difference matters because only one of them ever agreed to anything with us.
- Account holders — customers who sign up, rent a server and pay us. Sections 3 to 5 are about you.
- Players — people who connect to a server somebody else rents. You have no account with us and no direct relationship with us. We still end up holding some information about you, and section 6 says exactly what.
If you rent a server from us, you decide who plays on it and what happens there. That makes you responsible for telling your players what is recorded on your server — including, where it applies, that in-game chat is logged and visible to you. We provide the tools; the relationship with your players is yours.
3. What We Collect About Account Holders
- Your name, email address, and — for password sign-ups — a hashed password. We never store the password itself.
- Sign-in information from Google, Discord or Facebook if you use them: typically email, display name and avatar URL.
- Server metadata: the name, game, plan, region, mods and configuration of each server you create. This is what lets us build and run it.
- Operational data: IP addresses (including the address of your last sign-in), device and browser information, and request logs, used for security and abuse prevention.
- Support tickets and anything you write in them.
- Billing records: invoices, amounts, and payment status. Card numbers go directly to our payment provider and never reach our systems.
- Your agreement to our terms: which version you accepted, and when.
4. What We Do With It
- Run your servers and the control panel.
- Authenticate you and protect your account.
- Send you transactional email: verification, password resets, security notices, billing, and alerts about your servers.
- Provide support and respond to your requests.
- Investigate abuse, fraud and security incidents, and enforce our terms.
- Understand how the platform is used, in aggregate, to improve it.
- Meet our legal and tax obligations.
We do not sell personal information. We do not use it to train AI models. We do not show third-party advertising. We do not send marketing email unless you ask us to.
5. Who We Share It With
Only the providers needed to deliver the Service, and only what each needs:
- Cloudflare — transactional email delivery, the network that serves this site, and object storage (R2) for backups.
- Stripe — payments and invoicing. Card details are handled entirely by Stripe under its own privacy terms.
- Steam (Valve) — when you or your players use a Steam-based game, we query Steam's public API for account standing and profile names using platform IDs.
- Our own infrastructure — the game servers, database and panel run on hardware we own and operate in Australia. The panel software (Pelican) is self-hosted, not a third-party service.
We may also disclose information where the law requires it — for example a valid Australian court order — and we will resist requests that are broader than the law allows. If we are ever involved in a business sale or restructure, information may be shared with the party taking over, under this policy.
6. What We Hold About Players
If you play on a server hosted here without having an account with us, this is the whole list. It exists so server owners can moderate their own communities.
- Your in-game name, and your platform ID (such as a Steam ID) where the game provides one.
- Join and leave times, kept as a session history so owners can see who plays and for how long. This history is not automatically deleted.
- On some games (for example Rust): in-game chat messages, with the sender and time, kept for a limited period and visible to that server's owner. Other games are read live and not stored.
- Ban and moderation records for the server you were actioned on.
We do not store player IP addresses. Where a game exposes them to us, they are discarded rather than recorded, and they are never shown on public pages such as a live map.
If you want your player data removed from a server, the fastest route is the owner of that server, who controls it. You can also contact us using the details in section 12.
7. Cookies and Analytics
- Essential cookies — we use a small number of cookies that are necessary to sign you in and keep your session secure. The Service does not work without them.
- Analytics — we use Cloudflare Web Analytics to understand site usage in aggregate. It is privacy-first and does not use cookies or fingerprinting to track you across sites.
- We do not use advertising cookies or third-party tracking.
8. How Long We Keep Things
Different data has genuinely different lifespans, so rather than one number:
- Account data — while your account is open, plus a short grace period after you close it.
- Deleted servers — a 7-day window in which you can change your mind, after which the server and its data are destroyed once a verified archive exists.
- Server performance samples — 30 days.
- Stored in-game chat (where it applies) — 30 days.
- Security and firewall event logs — 14 days.
- Player session history — kept indefinitely, because it is how a server owner sees their community over time. Each row is a name, a time and a server.
- Server backups — on the retention schedule shown on your server's Backups tab; older automatic backups are pruned, and ones you make yourself are kept until you delete them.
- Invoices and financial records — five years, as Australian tax law requires.
9. How We Protect Your Information
Passwords are hashed and never stored in readable form. Credentials we hold for other services are encrypted at rest, and traffic is served over TLS. Access to production systems is limited to a small number of operators, two-factor authentication is available on your account, and backups are taken nightly and stored off-site.
No system is perfectly secure. If a data breach occurs that is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme.
10. Your Rights
You can ask us to:
- Give you a copy of the personal information we hold about you.
- Correct anything that is wrong or out of date.
- Delete your account and the personal information tied to it, other than records we are legally required to keep.
- Stop or limit particular uses, where the law allows it.
Email the address in section 12 and we will respond within a reasonable time, and in any case within 30 days. If you are unhappy with how we handle your information or a request, you can complain to us first, and then to the OAIC (oaic.gov.au).
11. Children
Sapling is not directed at children under 13, and accounts are for adults or for a parent or guardian acting on a child's behalf. Games hosted here are often played by younger players; we hold the same limited player information described in section 6 regardless of age. If you believe we hold information about a child under 13, contact us and we will delete it.
12. Contact and Changes
Questions, requests or complaints: support@saplinghosting.net.
We will update this policy when our practices change. If a change is material, we will tell you and, where it affects account holders, ask you to acknowledge the updated policy before you keep using the Service. The "last updated" date at the top always reflects the current version.