Legal
Privacy Policy
What information WheatCompute actually collects, why it is used, where it is shared, and the choices available to you.
Effective and last updated: 13 August 2026
1. Scope and responsibility
This policy covers https://wheatcompute.cloud, Billing, the Pterodactyl Panel, WheatCompute’s Discord integration and bot, support, referrals, payment records, and hosting operations. WheatCompute determines why and how this information is processed for these services.
2. Information we actually store
- Account: first and last name, email, role, verification time, password hash, optional encrypted/secured two-factor secret, language, username, account UUID, and timestamps.
- Sessions and security: session identifier and payload, account ID, IP address, browser/user-agent, last activity, login and account audit events, URLs, changed values, event properties, and timestamps.
- Orders and billing: ordered products and plans, quantity, service label/status, currency, price, coupons, renewal/expiry dates, invoice number/status/due date, transaction amount, fee, gateway, Stripe transaction or subscription identifiers, and credit records. WheatCompute does not store complete payment-card numbers or card security codes.
- Support: ticket subject, department, priority, linked service, assignment, message content, attachments you submit, and timestamps.
- Discord: Discord user ID, link status/time, short-lived hashed link code and expiry; when Discord OAuth is used, Discord may provide your verified email, display name, and account ID for login/account creation.
- Referrals: referral code, enabled state, reward/discount settings, aggregate visits and signups, and referral attribution.
- Panel and hosting: server name/description/UUID, owner and subusers, permissions, node/allocation, resource limits, image/startup configuration, status, activity/IP logs, API key identifiers/tokens and allowed IPs, SSH public keys/fingerprints, databases, backups, schedules, console activity, and files or other content you place on a server.
- Website/network: request time, hostname/path, response status, IP address, referrer, browser/user-agent, and Cloudflare security/CDN request data.
3. Why we process it
We use information to create and authenticate accounts; provision and operate servers; process orders and renewals; prevent fraud and abuse; enforce stock and per-user limits; provide support; send operational/payment notifications; link Discord, Billing, and Panel identities; administer referrals; investigate incidents; maintain logs and backups; comply with law; and improve reliability.
4. Services that receive data
- Stripe receives payment, billing, device, and fraud-prevention information and returns transaction/subscription identifiers and status.
- Cloudflare proxies the public website and may process IP addresses, request metadata, security signals, and cookies for DNS, CDN, TLS, and abuse protection.
- Discord processes OAuth/login and bot interactions; payment-success or operational notifications sent to configured Discord channels/webhooks may contain order event information but should not contain card details.
- Pterodactyl/Wings processes the account, server configuration, commands, files, and usage necessary to provide hosting.
- Vercel Web Analytics is loaded by the production landing page to provide aggregate website usage measurements.
These providers may process data in other countries under their own privacy terms. We do not sell personal data.
5. Retention
- Billing and Panel browser sessions are configured to expire after 120 minutes of inactivity, although remember-me/authentication tokens may last longer.
- Nginx website access/error logs rotate daily and keep 14 rotated logs on this machine.
- Expired Discord link codes are cleared when used, replaced, or cleaned up; the Discord ID remains while the account is linked.
- Account, order, invoice, transaction, service, support, referral, security-audit, and panel activity records are retained while needed to operate the account and afterward where reasonably necessary for accounting, fraud prevention, disputes, security, or legal obligations.
- Hosted files, databases, and backups may be deleted after service expiry, cancellation, termination, or reinstallation. Customers must maintain independent copies.
6. Your choices and rights
You may update account details, change credentials, unlink Discord, manage cookies through your browser, export hosted content while the service is active, or ask us to access, correct, erase, or explain processing of personal data. Some billing, fraud, security, or legal records may need to be retained. We will verify requests before acting.
Indian users may also have rights and duties under the Digital Personal Data Protection Act, 2023 as its provisions apply. You may first raise a grievance with WheatCompute using the contact below.
7. Security and contact
We use password hashing, TLS, access controls, database permissions, two-factor options, Cloudflare, audit logs, and isolated service infrastructure. No system is risk-free, so use a unique password, enable two-factor authentication, protect API/SSH keys, and report suspicious activity promptly.
Contact us through a billing support ticket at billing.wheatcompute.cloud or email [email protected].