1. Who we are
DMS Panel (“we”, “us”, “our”) operates a self-hosted-style web hosting control panel that manages customer Linux servers over SSH. For privacy questions, contact hello@dmspanel.app.
2. What we collect
2.1 Account information
When you register or update your profile we may collect name, email address, organization details, billing address, and similar account fields you provide.
2.2 Authentication and session data
We process login events, OTP / TOTP verification status, device trust choices, IP addresses, user-agent strings, and session identifiers needed to secure your account and detect abuse.
2.3 Server connection metadata
When you add a server we store connection metadata such as hostname / IP, SSH port, authentication method, labels, and health / metric summaries shown in the panel. SSH credentials are encrypted at rest (AES-256-GCM) and are never returned to clients in plaintext.
2.4 Panel activity and audit logs
We record actions taken in the panel (for example deploys, backup jobs, security scans, ticket activity, team invites, billing events) for security, support, and product operation.
2.5 Billing and wallet data
We store plan selection, invoice / payment history, wallet balances and transactions, and payment-method tokens / last4 provided by our payment processor. We do not store full card numbers (PAN) or CVV.
2.6 Support content
If you open a ticket we process the message text, attachments you upload (such as images or PDFs), and related triage metadata.
2.7 Communications preferences
We store which notification types you have enabled. Security-related email (for example login codes) is required to operate the account and cannot be disabled.
2.8 Website analytics (marketing site)
Our public marketing pages may collect basic technical logs (IP, browser type, pages visited) via hosting infrastructure. We do not sell this data for advertising.
3. What we never touch (by design)
DMS Panel is built so that operating the product does not require reading your private server contents. In particular:
- We do not browse or copy your application source code or site files for our own use
- We do not read mailbox contents of mail accounts you manage on your servers
- We do not store payment card PAN / CVV
- Platform Super Admin staff cannot access customer SSH secrets, source trees, mailbox contents, or card details — restrictions are enforced in code, not only policy (see Security)
When you use features such as File Manager, Git deploy, or Database Health, operations run against your server under credentials you supplied. Those features process data transiently as needed to fulfill the action you requested; they are not a license for us to use your content for unrelated purposes.
4. How we use your data
We use personal data to:
- Provide, maintain, and improve the Service
- Authenticate users and protect accounts (OTP, lockouts, session management)
- Connect to and manage servers you authorize
- Process subscriptions, invoices, wallet credits, and referrals
- Deliver transactional email (security codes, billing receipts, alerts)
- Provide optional product / marketing email you can opt out of
- Respond to support tickets and investigate abuse
- Comply with law and enforce our Terms
5. Legal bases (where applicable)
If you are in a region that requires a legal basis for processing (for example GDPR / UK GDPR), we typically rely on:
- Contract — to provide the Service you signed up for
- Legitimate interests — security, fraud prevention, product improvement (balanced against your rights)
- Consent — where required for optional marketing communications
- Legal obligation — when we must retain or disclose information under law
8. How we protect data
Security measures include encryption of secrets at rest, mandatory second-factor login, audit logging of sensitive actions, account lockout after failed attempts, and role-based access for teams. More detail is on the Security page.
No method of transmission or storage is 100% secure. You are responsible for protecting SSH keys, server hardening, and access grants you configure.
9. Super Admin / platform oversight
Platform staff may have audited, read-only (or limited operational) visibility into account metadata needed for support and operations — for example billing status, ticket state, server / site health summaries, and delivery logs. They are deliberately blocked from customer secrets such as SSH credentials, source code, mailbox contents, and payment card details. Super Admin actions themselves are audit-logged.
10. Retention and deletion
We retain account and operational data while your account is active and for a reasonable period afterward as needed for security, billing disputes, backups, and legal compliance.
When you request account deletion, we begin a deletion process that may include a short grace period so you can cancel the request. After deletion completes, personal data is removed or anonymized except where we must retain limited records (for example invoices) under law.
Data that lives only on your connected servers (files, databases, mailboxes) remains under your control; deleting your DMS Panel account does not wipe your servers.
11. Your choices and rights
Depending on your location, you may have rights to access, correct, export, or delete personal data, object to or restrict certain processing, and withdraw consent for optional marketing. You can typically:
- Update profile and notification preferences in account settings
- Manage team access and revoke invites
- Remove connected servers and encrypted credentials from the panel
- Request account deletion from settings or by contacting us
To exercise a privacy right, email hello@dmspanel.app. We may need to verify your identity before responding.
12. Children’s privacy
DMS Panel is not directed to children under 18. We do not knowingly collect personal information from children. If you believe a child has created an account, contact us and we will take appropriate steps.
13. International transfers
We may process and store data in India and in other countries where our infrastructure providers operate. Where required, we use appropriate safeguards for cross-border transfers.
14. Changes to this Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top will change, and material updates may also be announced by email or in-app notice. Continued use after the effective date means you acknowledge the updated Policy.
15. Contact
Privacy questions or requests: hello@dmspanel.app · Contact page