uniz.hostSign in
GuidesContact usTerms of servicePrivacy
Contents
  • 1. Introduction
  • 2. What We Collect
  • 3. What We Use It For
  • 4. Legal Bases
  • 5. Payment Data
  • 6. Data on Customers' Servers and Players' Data
  • 7. The AI Assistant, Outside AI Apps and Cloudflare Tunnel
  • 8. Cookies, Browser Storage and Analytics
  • 9. Who Receives Data
  • 10. Where Data Is Kept and Transfers Abroad
  • 11. Data Security
  • 12. How Long We Keep Data
  • 13. Your Rights
  • 14. Minors
  • 15. Data Protection Contact and Complaints
  • 16. Changes to This Policy
  • 17. Contact Us

Privacy Policy

Effective October 8, 2026
Contents · 17 sections
  • 1. Introduction
  • 2. What We Collect
  • 3. What We Use It For
  • 4. Legal Bases
  • 5. Payment Data
  • 6. Data on Customers' Servers and Players' Data
  • 7. The AI Assistant, Outside AI Apps and Cloudflare Tunnel
  • 8. Cookies, Browser Storage and Analytics
  • 9. Who Receives Data
  • 10. Where Data Is Kept and Transfers Abroad
  • 11. Data Security
  • 12. How Long We Keep Data
  • 13. Your Rights
  • 14. Minors
  • 15. Data Protection Contact and Complaints
  • 16. Changes to This Policy
  • 17. Contact Us

1. Introduction

CODECRAFTCLOUD CO., LTD. (the "Company", "we" or "us"), registration number 0735567008973, with its office at 61/11 Moo 5, Sampathuan Subdistrict, Nakhon Chai Si District, Nakhon Pathom 73120, Thailand, operates uniz.host (the "Platform") and is the data controller, under the Personal Data Protection Act B.E. 2562 (the "PDPA"), for the data described in this policy.

This Privacy Policy explains what personal data we collect, why, on what legal basis, who receives it, where and for how long it is kept, and how you can use your rights.

It applies to every user: Server Owners, Team Members and visitors to the website. For the data of players who connect to a customer's server, see Section 6.

This policy exists in Thai and in English. If the two texts differ, the Thai text prevails.

2. What We Collect

Depending on how you use the Platform, we collect the following:

2.1 Account data

  • From Google when you sign in: your e-mail address, your name and your Google account ID. We never receive or store your password.
  • Your username and display name, which other users can see, for example in a server's team.
  • Your account's role and status, such as suspended or banned.
  • When you were last active, the storage you use and your language setting.

2.2 Profile data (if you add it)

  • Your profile picture and cover image.
  • A short introduction.

2.3 Servers and use of the service

  • Server details: name, game, version, size, address, domain, settings, state and usage history.
  • Data on a server: worlds, files, console logs, mods, backups and archives, which may include players' data such as names and IP addresses.
  • A server's activity log: who did what and when, with the IP address and browser details of the person who did it.
  • Teams: members, invitations and the permissions granted.
  • Public pages: the text, images, links and settings you add.

2.4 Billing

  • Top-ups: the Stripe transaction ID, amount, status and time, the IP address and browser details at checkout, and Meta ad-click identifiers (if any).
  • Your credit account: balance, charges, coupon redemptions and referral rewards.

2.5 How you signed up

  • What first brought you to the website: source, medium, campaign, ad content, the referring website's domain and the first page you visited.
  • Your referral code, and who referred you (if anyone).

2.6 The AI assistant and outside connections

  • Conversations with the AI assistant: your messages, its answers, and what it read or did.
  • The outside AI apps you have allowed, and a log of their calls (the command, its status and the time).
  • Temporary links you create: the server, the port and the generated link address.

2.7 Technical data

  • Your IP address and browser details when you use the website, for security and to keep you signed in.
  • Error reports from your browser: the page address, the error details, browser details and your account ID.
  • Usage data collected by analytics and ad-measurement tools (see Section 8).
  • When you vote for a server: a hash of your IP address (we do not store the address itself).

2.8 Communications

  • E-mails you send us and our replies.
  • Dashboard notifications and e-mails we send you.

Signing in requires a Google account. Without the account data in Section 2.1 we cannot provide the service to you.

3. What We Use It For

We use the data in Section 2 for these purposes:

  • Providing the service: creating, running and managing servers, routing players to the right server, and backing up and archiving data.
  • Accounts: creating accounts, signing you in and keeping accounts secure.
  • Billing: taking payments, charging for use, showing your history and issuing receipts on request.
  • Contacting you: low-balance notices, notices about your servers and answers to your questions.
  • The AI assistant and outside apps: doing what you ask when you use them.
  • Public pages: showing the servers you make public and counting votes.
  • Security: preventing fraud, abuse of the service, attacks and vote inflation.
  • Improving the service: seeing which parts of the website are used and how fast its pages load, and finding errors and places that are hard to use.
  • Measuring advertising: measuring how many sign-ups and top-ups the ads we buy on Meta bring.
  • Legal duties: keeping accounting and tax records and complying with lawful orders.

4. Legal Bases

We process data on these legal bases under the PDPA:

  • Performing our contract with you: accounts, servers, billing, notices, the AI assistant, outside apps and temporary links, under the Terms of Service.
  • Consent: usage analytics with Google Analytics and advertising measurement with the Meta Pixel in your browser, and their cookies, only after you allow them in the cookie banner. You can withdraw it at any time (see Section 8). Cloudflare Web Analytics does not rest on consent; it rests on legitimate interests, below.
  • Legitimate interests: security, fraud prevention, error reports, sign-up attribution, activity logs, the sign-up, checkout-started and top-up events our servers send to Meta's Conversions API, and measuring how fast pages load and how many visits each page gets with Cloudflare Web Analytics, which runs on every page without cookies and without asking in the cookie banner. You can object to this processing (see Section 13).
  • Legal obligations: the financial records that tax and accounting law require us to keep, and responses to lawful orders of public authorities.

5. Payment Data

Top-ups are processed by Stripe, by card or PromptPay. What you enter on Stripe's payment page, such as your card number, falls under Stripe's privacy policy. We never see or store your card number or bank details.

We send Stripe an internal reference and the amount, and receive back the transaction ID, amount and status, to add your credits, show your history and handle refunds.

6. Data on Customers' Servers and Players' Data

Running a game server involves the data of the players who connect to it.

  • Player connections: our systems see players' IP addresses and connection details in order to route them to the right server. The game on a server may record players' names, IP addresses and activity in its logs and files, depending on the game's settings.
  • Responsibility: the player data a customer's server collects is that Server Owner's responsibility. We process it only to run the server for the customer, and access data on a server only as far as needed to provide the service, give support or comply with the law.
  • Customers' domains: when a customer points their own domain at a server, we manage the DNS records needed through Cloudflare.
  • Public pages: when a customer turns on a public page, anyone can see the server's name, address, game, version, state, player counts and their history, description, tags, images, rules, links and votes. The page may appear in the server directory and in search engine results.

7. The AI Assistant, Outside AI Apps and Cloudflare Tunnel

Data leaves our systems when you use these features:

  • Model providers: the AI assistant runs on language models from OpenAI, Anthropic, Google or OpenRouter; we may use any one of them at a given time. Through OpenRouter, data also reaches the developer of the model chosen.
  • What is sent: what you type, the history of that conversation, and the data the assistant reads, such as console logs, files, settings and player lists, which may include players' names and IP addresses. This is sent each time the assistant works.
  • Conversations: we keep at most the 50 most recent conversations per server per user, and delete them all when the account is deleted.
  • Outside AI apps: when you allow another provider's app to reach a server, the data the app reads goes to that app's provider, under that provider's policy. Each access grant lasts 15 minutes and is renewed until you revoke the permission.
  • The log of outside apps' calls is kept for 30 days.
  • Temporary links: visitors who open a link reach the server's web page through Cloudflare, which carries their traffic (see Section 9).

8. Cookies, Browser Storage and Analytics

The Platform uses cookies, browser storage and analytics as follows:

  • The session cookie (essential): holds the token that keeps you signed in, for 7 days. It is httpOnly and Secure, so scripts on the page cannot read it.
  • The __Host-oauth_nonce cookie (essential): ties a Google sign-in to the browser that started it, so a sign-in begun elsewhere cannot be completed in yours. It lasts 10 minutes.
  • The uz.sidebar cookie: remembers whether you keep the dashboard's sidebar open or collapsed, for 1 year.
  • The uniz_consent cookie (essential): remembers which optional cookies you allowed, for 12 months.
  • Browser storage: your theme, language and display settings, a hint that you have signed in before, the name and e-mail address of the last account signed in on this browser (to suggest it next time), the country detected from your connection (to suggest a language), a draft of a server you are creating, and the referral code and the source that brought you, which are sent to us after you sign up.
  • Usage analytics (only if you allow it): Google Analytics (with cookies such as _ga) counts visits and use.
  • Cloudflare Web Analytics (every page, no cookies): Cloudflare adds a script to every page of the website, including the sign-in pages, to measure how fast pages load and how many visits each page gets. Each time you open a page or move to another one, it sends Cloudflare the page address (Cloudflare says it does not record the part after "?"), the page you came from and load-time measurements; Cloudflare's reports also show your country, browser, operating system and device type. It sets no cookies and stores nothing in your browser. Cloudflare says it receives your IP address with each request, but discards it at the nearest Cloudflare data centre and does not store it in its core databases or logs. This script is not covered by the cookie banner: we rely on legitimate interests (see Section 4). You can object by e-mail to [email protected] (see Section 13), but the website cannot switch it off for one person. Some ad blockers block this script.
  • Advertising measurement (only if you allow it): the Meta Pixel sets the _fbp and _fbc cookies, and we set our own uz_fbc cookie (90 days), to link a top-up to the ad that brought you.
  • Google Analytics and the Meta Pixel do not load on a page whose address carries a secret, such as a sign-in code or an authorisation code. Cloudflare Web Analytics does load on those pages (see above).

On your first visit, a banner asks whether we may use two optional kinds of cookie: usage analytics and advertising measurement. Both stay off until you turn them on; the essential cookies are always on. We keep your choice for 12 months and then ask again. You can change it at any time with "Cookie settings" at the bottom of the public pages or on your account settings page. When you turn a kind off, we delete its cookies from your browser as far as we can and reload the page. Your choice covers only Google Analytics and the Meta Pixel in your browser. It does not cover Cloudflare Web Analytics, which sets no cookies (see above), and it does not stop the data our servers send to Meta (see Section 9). To stop that, object by e-mail to [email protected]: when you object, we stop sending your data from our servers to Meta. If you block the essential cookies, you cannot sign in.

9. Who Receives Data

We do not sell, rent or trade your personal data. We share data with the following providers, only as far as each one's task requires:

  • Stripe: card and PromptPay payments, and refunds. Privacy policy: https://stripe.com/privacy
  • Google: Google sign-in, Google Analytics, language models for the AI assistant (Section 7), and Gmail, the mailbox that receives the e-mails you send to [email protected]. Privacy policy: https://policies.google.com/privacy
  • Meta: advertising measurement. Data reaches Meta by two routes. The first is the Meta Pixel in your browser, only if you allow it (see Section 8), which sends page views, top-ups and Meta's automatic events, such as button clicks. The second is our servers, which send sign-up, checkout-started and top-up events to Meta's Conversions API with your e-mail address and account ID as SHA-256 hashes, your IP address and browser details in readable form, ad-click identifiers (only if you allow advertising measurement), the amount and the page address. A hashed e-mail address exists so that Meta can match it to an account, so it is still personal data. Privacy policy: https://www.facebook.com/privacy/policy/
  • Brevo: sending system e-mails, such as low-balance notices and account e-mails. Privacy policy: https://www.brevo.com/legal/privacypolicy/
  • Cloudflare: network and attack protection, DNS for customers' domains, Turnstile on the vote button, measuring how fast our pages load and how many visits each page gets (Cloudflare Web Analytics, see Section 8), storage for profile pictures and images (R2), temporary links to servers' web pages (trycloudflare.com), and receiving e-mail sent to [email protected] and forwarding it to our mailbox (Email Routing). Privacy policy: https://www.cloudflare.com/privacypolicy/
  • MongoDB (Atlas): the Platform's database, located in Singapore. Privacy policy: https://www.mongodb.com/legal/privacy-policy
  • Language-model providers: OpenAI, Anthropic, Google and OpenRouter, for the AI assistant as in Section 7.
  • Discord: internal alerts to our team, which may include customers' server names.
  • Grafana Labs (Grafana Cloud): the logs of our player connection router, which include the IP addresses of connecting players, for security and troubleshooting.

We may also disclose data where the law, a court order or an order of a public authority requires it, to enforce the Terms of Service, or to protect the rights, property or safety of the Company, our users or others.

10. Where Data Is Kept and Transfers Abroad

Your data is kept in the following places:

  • Thailand: game servers, Server Data, backups, archives and our traffic relay.
  • Singapore: the Platform's database (MongoDB Atlas), which holds account data, billing data and conversations with the AI assistant.
  • The United States and other countries: the providers in Section 9, namely Stripe, Google, Meta, Brevo, Cloudflare, Grafana Labs, Discord and the language-model providers, which process data in their own data centres in several countries.

We transfer data abroad only as the PDPA allows. Transfers needed to provide the service under our contract with you (the database, payments, e-mail, networking, and the AI assistant when you use it) rely on the exception that they are necessary to perform the contract. Usage analytics, page-load measurement (Cloudflare Web Analytics), advertising measurement, internal alerts and connection logs rely on appropriate safeguards, such as the standard contractual clauses in each provider's data processing terms.

11. Data Security

We use technical and organisational measures to protect your data, including:

  • Sign-in is through Google only, so we store no passwords.
  • Access tokens are short-lived and kept in the page's memory; the refresh token is kept in an httpOnly cookie.
  • Sign-in sessions expire by themselves after 7 days, and tokens from signed-out sessions are blocked from being reused.
  • RCON passwords, the hash of the SFTP password and the Palworld admin password are kept in the system's secret store, separate from the database. Other passwords in a game's settings, such as the password players use to join, are kept in the database with the server's other settings.
  • Data between your browser and our systems is encrypted with HTTPS.

No system is perfectly secure. If a personal data breach happens, we will notify the Office of the Personal Data Protection Committee, and notify you where the risk is high, as the PDPA requires.

12. How Long We Keep Data

We keep data only as long as its purpose needs, as follows:

  • Account and profile data, sign-up attribution and referral codes: kept while the account exists. Inactivity alone never leads to an account being deleted.
  • Account deletion: when you ask us by e-mail at [email protected] to delete your account, we delete the account and the personal data tied to it within 30 days, including its servers, their Server Data and conversations with the AI assistant, except billing records, e-mails with us and the log of our team's actions, which are kept for the periods in this section.
  • Billing records: top-ups, payment records, the credit account, coupon redemptions and referral rewards are kept for at least 5 years under Thai tax law.
  • The log of actions our team takes on accounts and servers is kept for as long as it is needed for security and audit; it has no automatic deletion today.
  • Server Data: kept while the server exists. When you delete a server, all of its data, including its backups, is deleted at once. Files deleted in the file manager stay in the trash for 7 days, and automatic backups are kept in the number you set until the server is archived: the archive copy then replaces them, while backups you made or uploaded yourself stay until the archived server's deletion deadline.
  • Archived servers: Server Data is deleted permanently 90 days after the server was archived, or 30 days for an account that has never made a paid top-up, unless it is restored first, as set out in Section 7 of the Terms of Service.
  • Conversations with the AI assistant: at most the 50 most recent per server per user, deleted when the account is deleted.
  • System logs: server activity logs 30 days, browser error reports 30 days, outside apps' call logs 30 days, system performance metrics 30 days, read notifications 7 days, vote records 7 days, and records of crashes caused by mod files 180 days.
  • E-mails with us: kept for 2 years after the last contact.
  • Data already sent to the providers in Section 9, such as Google, Meta, Grafana Labs and Discord, is kept for each provider's own retention period.

13. Your Rights

Under the PDPA, you have the right:

  • to access your personal data and get a copy of it;
  • to have inaccurate or incomplete data corrected;
  • to have your data deleted or destroyed, including your account, subject to the exceptions in Section 12 and in the law, such as billing records we must keep;
  • to object to processing based on legitimate interests, such as the events our servers send to Meta;
  • to have the use of your data restricted where the law provides;
  • to withdraw consent where processing is based on consent, such as the analytics and advertising cookies, without affecting processing done before the withdrawal;
  • to receive your data in a machine-readable format and have it sent to someone else, where the law makes this right available;
  • to complain to the Office of the Personal Data Protection Committee (see Section 15).

There is no button for these rights in the dashboard yet. Please send your request by e-mail to [email protected] from the e-mail address of your account. We may ask for more information to confirm your identity, and will reply within 30 days of receiving the request. If we refuse a request as the law allows, we will tell you why.

14. Minors

Users under 20 years of age need the consent of a parent or guardian before using the Platform. We do not check ages at sign-up.

If you are a parent or guardian and believe a minor in your care uses the Platform without consent, contact [email protected] so we can take appropriate action, including deleting the account.

15. Data Protection Contact and Complaints

The Company has not appointed a Data Protection Officer (DPO). You can contact us about any personal data matter, including the rights in Section 13, at [email protected].

If you believe we process your data in a way that does not comply with the PDPA, you have the right to complain to the Office of the Personal Data Protection Committee (PDPC).

16. Changes to This Policy

We may change this policy. We will announce a revised version at least 7 days before it takes effect, on the website or our announcement channels, such as Discord, and the revised version shows its effective date at the top of this page. We do not promise to announce changes by e-mail or in the dashboard, so please check this page from time to time.

If you keep using the Platform after the effective date, you acknowledge the revised policy.

For a new user who signs up after this version of the policy is published, it applies from their first use of the Platform. For existing users, it applies from the effective date shown at the top of this page.

17. Contact Us

For questions or requests about this policy or your personal data, please contact us by e-mail.

CODECRAFTCLOUD CO., LTD., registration number 0735567008973

61/11 Moo 5, Sampathuan Subdistrict, Nakhon Chai Si District, Nakhon Pathom 73120, Thailand

E-mail: [email protected]

uniz.host

Game servers that are easy to start; pay only while the server is on

Join the community on Discord
Product
  • Pricing
  • Create a server
  • Public servers
  • Wiki
Games
  • Minecraft
  • Palworld
  • Valheim
  • Enshrouded
  • 7 Days to Die
  • Core Keeper
  • Factorio
  • All games
Company
  • Contact us
  • Privacy
  • Terms of service
© 2026 uniz.host