CHAPTER22 HOSTING PRIVACY POLICY
Chapter22Hosting LLC, a California limited liability company doing business as Chapter22 Hosting ("Chapter22," "Chapter22 Hosting," "Company," "we," "us," or "our"), respects the privacy of our customers and website visitors.
This Privacy Policy explains how Chapter22 collects, uses, stores, protects, discloses, and otherwise processes personal information when individuals:
- Visit Chapter22 websites;
- Create a Chapter22 Account;
- Purchase or use Chapter22 Services;
- Contact Chapter22 support;
- Communicate with Chapter22;
- Participate in promotions;
- Submit abuse or security reports; or
- Otherwise interact with Chapter22.
This Policy also describes privacy rights that may be available to you.
This Privacy Policy should be read together with the Chapter22 Hosting Terms of Service, Acceptable Use Policy, and other applicable policies.
1. Our Privacy Principle
Chapter22 collects only information reasonably necessary to:
- Provide our Services;
- Secure our Services;
- Support our Customers;
- Improve our Services;
- Bill for our Services;
- Prevent fraud and abuse;
- Comply with applicable law; and
- Operate Chapter22 Hosting.
We do not intend to collect personal information simply because it may have commercial value.
2. Information We Collect
The information Chapter22 collects depends upon how an individual interacts with us.
We may collect the following categories of personal information.
2.1 Account Information
When you create or maintain a Chapter22 Account, we may collect:
- Name;
- Email address;
- Account username;
- Account identifiers;
- Password-related authentication information;
- Multi-factor authentication information;
- Account preferences;
- Country or region;
- Billing address;
- Phone number when provided or reasonably required; and
- Other information voluntarily added to your Account.
Passwords should be stored using appropriate security protections and are not intended to be accessible to Chapter22 personnel in plain text.
3. Billing and Transaction Information
When you purchase a Service, Chapter22 may collect:
- Billing name;
- Billing address;
- Transaction amount;
- Currency;
- Product purchased;
- Subscription information;
- Invoice history;
- Payment status;
- Payment-method type;
- Limited payment-method identifiers provided by a payment processor;
- Transaction identifiers;
- Refund records;
- Chargeback information;
- Fraud-prevention information; and
- Applicable tax information.
Chapter22 does not intend to store full payment-card numbers. Full card numbers, security codes, and other sensitive payment credentials should be submitted directly to authorized payment processors where supported.
Payment processors may independently collect and process payment information under their own privacy policies and legal obligations.
4. Technical and Device Information
When you access Chapter22 websites, panels, APIs, or Services, we may automatically collect technical information including:
- IP address;
- Date and time of access;
- Browser type;
- Browser version;
- Device type;
- Operating system;
- Referring page;
- Requested page or resource;
- Login history;
- Session information;
- Authentication events;
- Approximate geographic information derived from an IP address;
- Error information;
- Performance data;
- Network information; and
- Security-related events.
We may use this information to operate and secure our Services, diagnose problems, prevent fraud, and understand how our Services are being used.
5. Service and Server Information
Chapter22 may process information associated with a Customer's hosting environment, including:
- Service type;
- Server identifier;
- Server location;
- IP addresses;
- Resource usage;
- Player counts where applicable;
- Service configuration;
- Software versions;
- Installed applications where technically visible;
- Server status;
- Network traffic metadata;
- Performance metrics;
- Crash information;
- Backup status;
- Administrative actions;
- Service logs; and
- Security events.
Chapter22 does not access Customer Content simply for curiosity, advertising, profiling, or unrelated commercial purposes.
6. Customer Content
Customers may upload or generate information through Chapter22 Services.
Customer Content can include:
- Server files;
- Databases;
- Configuration files;
- Game-server information;
- User-generated content;
- Application data;
- Logs;
- Backups;
- Websites;
- Plugins;
- Mods;
- Scripts; and
- Other Customer-controlled information.
Depending on the Customer's use of a Service, Customer Content may itself contain personal information relating to other individuals.
Customers are responsible for ensuring that they have a lawful basis to collect, use, store, or otherwise process personal information they place on Chapter22 infrastructure.
Chapter22 processes Customer Content only as reasonably necessary to provide, maintain, secure, support, or comply with legal obligations relating to the Services.
7. Chapter22'S Role for Customer Content
For information Chapter22 collects directly to operate Accounts, billing, support, security, and its own business, Chapter22 generally determines why and how that information is processed.
For personal information uploaded or controlled by a Customer through a hosted Service, the Customer generally determines the purpose of that processing.
Where applicable privacy law distinguishes between a controller/business and a processor/service provider, Chapter22 may act as a processor or service provider with respect to Customer-controlled data.
Customers subject to laws requiring a separate data-processing agreement should contact:
privacy@chapter22hosting.com
Where required and appropriate, additional data-processing terms may be established.
8. Support Communications
When you contact Chapter22 support, we may collect:
- Your name;
- Account information;
- Email address;
- Ticket contents;
- Chat contents;
- Attachments;
- Screenshots;
- Diagnostic information;
- Server information;
- Communications history; and
- Other information you choose to provide.
Support communications may be retained for troubleshooting, training, quality assurance, fraud prevention, security, dispute resolution, and operational history.
Customers should avoid sending unnecessary passwords, private keys, full payment-card numbers, or other highly sensitive information through support tickets.
9. Abuse and Security Information
Chapter22 may collect information relating to suspected violations of our Terms of Service or Acceptable Use Policy.
This may include:
- IP addresses;
- Network logs;
- Abuse complaints;
- Security reports;
- Server identifiers;
- Relevant Customer Content;
- Screenshots;
- Attack information;
- Malware indicators;
- Email headers;
- Domain information;
- Communications;
- Account history; and
- Other evidence reasonably necessary to investigate the incident.
Such information may be retained longer than ordinary logs where necessary for an active investigation, legal matter, fraud matter, security incident, or repeat-abuse determination.
10. Information from Third Parties
Chapter22 may receive information from third parties including:
- Payment processors;
- Fraud-prevention providers;
- Datacenter operators;
- Infrastructure providers;
- Domain providers;
- Network providers;
- Game or software providers;
- Security researchers;
- Abuse reporters;
- Copyright holders;
- Customers;
- Government authorities; and
- Law enforcement.
We use such information only for legitimate operational, security, legal, billing, fraud-prevention, or support purposes.
11. How We Use Personal Information
Chapter22 may use personal information to:
Provide Services
- Create and maintain Accounts;
- Provision servers;
- Process orders;
- Provide control-panel access;
- Authenticate users;
- Deliver requested products;
- Process cancellations;
- Perform migrations;
- Create and restore backups; and
- Maintain infrastructure.
Process Payments
- Generate invoices;
- Process recurring payments;
- Process refunds;
- Maintain transaction records;
- Collect applicable taxes;
- Address chargebacks; and
- Detect payment fraud.
Provide Customer Support
- Respond to tickets;
- Diagnose technical problems;
- Restore Services;
- Investigate outages;
- Assist with configuration; and
- Communicate with Customers.
Secure Chapter22
- Detect unauthorized access;
- Prevent fraud;
- Investigate compromised Accounts;
- Detect attacks;
- Identify malware;
- Monitor network stability;
- Enforce rate limits;
- Protect Customers; and
- Enforce Chapter22 policies.
Improve Services
- Analyze Service performance;
- Diagnose errors;
- Understand product usage;
- Improve infrastructure;
- Evaluate reliability;
- Improve the customer experience; and
- Develop new products.
Communicate With Customers
- Send invoices;
- Send renewal notices;
- Send price-change notices;
- Provide maintenance notices;
- Communicate outages;
- Send security alerts;
- Communicate policy changes; and
- Provide other Service-related information.
Comply With Law
- Maintain required business records;
- Respond to valid legal process;
- Meet accounting obligations;
- Comply with tax obligations;
- Address regulatory obligations; and
- Protect legal rights.
12. Legal Bases for Processing
Where applicable law requires Chapter22 to identify a legal basis for processing personal information, processing may rely upon one or more of the following:
Performance of a Contract
Processing may be necessary to provide Services requested by the Customer or perform obligations under the Terms of Service.
Examples include:
- Creating an Account;
- Provisioning a server;
- Processing a payment;
- Providing support; and
- Managing a subscription.
Legitimate Interests Chapter22 may process information where reasonably necessary for legitimate business interests that are not overridden by applicable individual rights.
Examples may include:
- Preventing fraud;
- Securing infrastructure;
- Investigating abuse;
- Improving Service reliability;
- Maintaining network performance; and
- Defending legal claims.
Legal Obligations Chapter22 may process information where necessary to comply with applicable law, court orders, tax rules, accounting requirements, or other legal obligations.
Consent Where required, Chapter22 may rely on consent.
Examples may include:
- Optional analytics cookies;
- Marketing communications; and
- Other optional processing activities.
Where processing is based on consent, consent may generally be withdrawn for future processing.
13. Transactional Communications
Certain communications are necessary to operate an Account or Service.
Customers may receive communications concerning:
- Account creation;
- Account security;
- Password changes;
- Invoices;
- Failed payments;
- Renewals;
- Cancellations;
- Service suspensions;
- Service termination;
- Planned maintenance;
- Outages;
- Security incidents;
- Abuse complaints;
- Material policy changes; and
- Other operational matters.
These communications are not treated as optional marketing messages merely because they are sent by email.
Customers generally cannot opt out of essential Service-related communications while maintaining an active Service.
14. Marketing Communications
Chapter22 may send promotional or marketing communications only where the recipient has provided appropriate permission or where otherwise permitted by applicable law.
Chapter22 intends to use an opt-in approach for promotional email marketing.
Marketing communications will provide a method to unsubscribe.
Unsubscribing from marketing does not prevent Chapter22 from sending necessary transactional or security communications.
Chapter22 does not sell marketing mailing lists containing Customer personal information.
15. We Do Not Sell Personal Information
Chapter22 does not sell Customer personal information.
Chapter22 does not exchange Customer personal information with third parties for monetary payment in exchange for the right to use that information for the third party's independent marketing purposes.
Chapter22 also does not sell lists of:
- Customer names;
- Email addresses;
- Billing information;
- Server activity;
- Support history; or
- Account information.
If Chapter22's practices materially change in the future, this Privacy Policy and any legally required privacy controls will be updated before such practices are implemented.
16. Targeted Advertising and Data Sharing
Chapter22 does not intend to share Customer personal information for cross-context behavioral advertising or similar third-party targeted advertising.
Chapter22 may advertise its own products and Services based upon Chapter22's direct relationship with a Customer where permitted by law.
Chapter22 does not authorize third-party advertising companies to build independent advertising profiles from private Customer Account or hosting information.
17. Analytics
Chapter22 may use analytics services such as Google Analytics, Microsoft Clarity, or comparable technologies to understand website performance and usage.
Analytics may collect information such as:
- Pages visited;
- Session duration;
- General traffic source;
- Device information;
- Browser information;
- Approximate geographic region;
- Interactions with the website; and
- Technical performance.
Where legally required or appropriate, nonessential analytics technologies will be subject to Customer or visitor choice.
Declining optional analytics should not prevent access to the core Chapter22 website or purchased Services.
18. Cookies and Similar Technologies
Chapter22 websites may use cookies, local storage, pixels, or similar technologies.
We generally classify these technologies as follows.
Essential Cookies Essential technologies support functions such as:
- Authentication;
- Account security;
- Shopping cart functionality;
- Session management;
- Fraud prevention;
- Load balancing; and
- Customer preferences necessary to operate the site.
Essential cookies may remain enabled because the website or Service may not function properly without them.
Analytics Cookies Analytics technologies help Chapter22 understand website performance and visitor interactions.
Where appropriate or legally required, users may disable these cookies.
Marketing Cookies Marketing technologies may be used only where permitted and appropriate.
Chapter22 does not use marketing cookies to sell Customer personal information or to authorize unrelated third parties to create behavioral advertising profiles from private Chapter22 Account activity.
Where marketing cookies are used, they will be treated as optional where required.
19. Cookie Preferences
Where Chapter22 deploys nonessential analytics or marketing technologies, visitors may be provided with a cookie preference interface.
That interface may allow users to:
- Accept optional cookies;
- Reject optional cookies;
- Adjust cookie categories; and
- Change previously selected preferences.
Essential technologies may not be disableable through the Chapter22 preference interface where they are necessary for site operation or security.
20. Global Privacy Control
Chapter22 will recognize legally applicable browser-based privacy preference signals such as Global Privacy Control ("GPC") where required.
Because Chapter22 does not sell personal information or share it for cross-context behavioral advertising, such signals should generally be consistent with Chapter22's existing practices.
If Chapter22 introduces a processing activity in the future that is subject to a legally recognized opt-out signal, Chapter22 will implement appropriate technical handling of that signal.
21. How We Disclose Information
Chapter22 may disclose personal information to third parties only when reasonably necessary for legitimate purposes described in this Policy.
Recipients may include the following.
Service Providers Chapter22 may use providers supporting:
- Payment processing;
- Server infrastructure;
- Datacenters;
- Network connectivity;
- DDoS protection;
- Customer support;
- Email delivery;
- Analytics;
- Monitoring;
- Fraud prevention;
- Accounting;
- Domain registration;
- Software licensing;
- Backup infrastructure; and
- Other business operations.
These providers may receive only information reasonably necessary to perform their functions.
Professional Advisors
Chapter22 may disclose information to:
- Attorneys;
- Accountants;
- Auditors;
- Insurance providers; and
- Other professional advisors
where reasonably necessary.
Legal and Governmental Disclosures Chapter22 may disclose personal information where reasonably believed necessary to:
- Comply with applicable law;
- Respond to valid legal process;
- Respond to a court order;
- Address a lawful governmental request;
- Protect the rights or safety of another person;
- Investigate fraud or abuse; or
- Defend Chapter22's legal rights.
22. Law-Enforcement Requests
Chapter22 may receive subpoenas, warrants, court orders, preservation requests, or other legal demands.
Chapter22 will evaluate legal requests and may reject, challenge, narrow, or seek clarification of requests that appear invalid, overbroad, or otherwise deficient.
Where legally permitted and appropriate, Chapter22 may notify affected Customers.
Chapter22 may preserve relevant information when legally required to do so.
23. Business Transfers
If Chapter22 is involved in a:
- Merger;
- Acquisition;
- Corporate restructuring;
- Financing;
- Bankruptcy;
- Sale of assets; or
- Transfer of the hosting business,
personal information may be disclosed or transferred as part of that transaction.
Any successor receiving personal information remains subject to applicable privacy obligations.
Chapter22 will provide legally required notice if a transaction materially changes how Customer personal information will be used.
24. Employee and Contractor Access
Chapter22 employees and contractors do not have unrestricted authorization to browse Customer servers or Customer Content.
Access should be limited according to job responsibilities and legitimate operational need.
Authorized personnel may access relevant systems or Customer Content where reasonably necessary to:
- Resolve a support request;
- Diagnose a technical issue;
- Restore data;
- Perform maintenance;
- Investigate abuse;
- Investigate a security incident;
- Protect Chapter22 infrastructure;
- Prevent fraud;
- Respond to a legal requirement; or
- Perform another legitimate operational function.
Chapter22 intends to maintain role-based or otherwise appropriate access controls for privileged infrastructure.
Employees and contractors may be subject to confidentiality and security obligations appropriate to their level of access.
25. Customer Support Access
When a Customer requests assistance, support personnel may need access to server configuration, files, logs, databases, or other Customer Content.
Chapter22 will attempt to limit such access to information reasonably necessary to investigate or resolve the request.
Customers should not assume that information stored on a managed Internet-connected server can remain technically inaccessible to authorized infrastructure administrators under all circumstances.
26. Automated Decision-Making
Chapter22 may use automated systems to assist with:
- Fraud detection;
- Login security;
- Spam prevention;
- Payment-risk assessment;
- DDoS mitigation;
- Abuse detection; and
- Infrastructure monitoring.
Where applicable law provides rights concerning solely automated decisions that produce legal or similarly significant effects, Chapter22 will honor those rights where applicable.
Chapter22 does not intend to make significant employment, credit, housing, insurance, or similar eligibility determinations about Customers using hosting Account information.
27. Data Retention Principle
Chapter22 does not intend to retain personal information indefinitely merely because storage is available.
Information is retained based upon factors including:
- Why it was collected;
- Whether an Account remains active;
- Legal requirements;
- Accounting obligations;
- Security needs;
- Fraud prevention;
- Dispute resolution;
- Technical necessity; and
- Legitimate operational requirements.
When information is no longer reasonably necessary, Chapter22 may delete, anonymize, aggregate, or otherwise dispose of it.
28. Standard Retention Periods
Chapter22 intends to use the following general retention periods unless a longer or shorter period is reasonably necessary or required by law.
Financial, Billing, and Tax Records Generally retained for up to seven years, including information necessary for:
- Accounting;
- Tax compliance;
- Transaction history;
- Refund records;
- Chargeback evidence; and
- Financial audits.
Support Tickets Support communications may generally be retained for up to three years after ticket closure.
A ticket may be retained longer where associated with:
- Litigation;
- Fraud;
- Abuse;
- A continuing technical issue;
- A security incident; or
- Another legitimate business or legal requirement.
Security and Access Logs Ordinary security and access logs may generally be retained for up to 12 months.
Relevant logs may be retained longer where necessary for:
- Security investigations;
- Abuse investigations;
- Fraud prevention;
- Litigation;
- Legal preservation obligations; or
- Repeat-incident analysis.
Closed Account Information Account profile information associated with a closed Account will be deleted or anonymized when no longer reasonably required.
Information may remain where necessary for:
- Financial records;
- Tax obligations;
- Fraud prevention;
- Security;
- Legal claims;
- Enforcement history; or
- Other lawful retention requirements.
29. Server Data After Cancellation
Following normal termination of a canceled Service, Customer Content may be retained for up to seven days where technically practical.
This is a potential recovery window only.
Retention and recovery are not guaranteed.
Customer Content may be deleted sooner when:
- Technical systems automatically release storage;
- Retention is impractical;
- A serious security threat exists;
- The Account was terminated for significant abuse;
- Continued retention would violate law; or
- Infrastructure circumstances make continued retention unreasonable.
After the applicable retention period, Customer Content may be permanently and irreversibly deleted.
Customers are responsible for maintaining their own independent backups.
30. Backups and Deleted Information
Copies of information may temporarily remain in backup systems after deletion from active systems.
Backup copies may be retained until overwritten or expired according to Chapter22's normal backup rotation.
Chapter22 will not intentionally restore deleted personal information from backup solely for ordinary operational use after a valid deletion request unless continued processing is legally permitted or required.
Backup architecture may make immediate deletion of an individual record from every backup technically impractical.
31. Data Security
Chapter22 uses reasonable administrative, technical, and physical safeguards intended to protect personal information.
Depending on the system, protections may include:
- Access controls;
- Authentication controls;
- Multi-factor authentication;
- Encryption;
- Network segmentation;
- Firewalls;
- Monitoring;
- Logging;
- DDoS mitigation;
- Vulnerability management;
- Software updates;
- Credential controls;
- Employee access restrictions; and
- Security procedures.
No Internet-based system can be guaranteed to be completely secure.
Customers are responsible for securing credentials, applications, plugins, software, and configurations under their control.
32. Security Incidents and Data Breaches
If Chapter22 becomes aware of a security incident involving personal information, Chapter22 may:
- 1. Investigate the incident;
- 2. Contain affected systems;
- 3. Preserve relevant evidence;
- 4. Determine the scope of affected information;
- 5. Remediate vulnerabilities;
- 6. Notify affected service providers or authorities where appropriate; and
- 7. Notify affected individuals where required by applicable law.
Notifications will be made according to applicable legal requirements.
33. International Operations
Chapter22 provides Services to Customers worldwide.
Chapter22Hosting LLC is based in the United States.
Personal information may therefore be processed in:
- The United States;
- The Customer's selected server region;
- Locations where Chapter22 infrastructure operates; and
- Locations where authorized service providers operate.
Privacy protections may differ between jurisdictions.
Where applicable law requires safeguards for international transfers of personal information, Chapter22 will use appropriate lawful transfer mechanisms.
34. European Economic Area, United Kingdom, and Similar Privacy Rights
Where the GDPR, UK GDPR, or comparable law applies to Chapter22's processing, individuals may have rights including:
- The right to be informed;
- The right to access personal information;
- The right to correct inaccurate information;
- The right to request erasure;
- The right to restrict certain processing;
- The right to data portability;
- The right to object to certain processing;
- The right to withdraw consent where processing is based on consent; and
- Certain rights concerning automated decision-making.
These rights are not absolute and may be subject to legal exceptions.
For example, Chapter22 may be required to retain transaction information even after an Account holder requests deletion.
Privacy requests may be sent to:
privacy@chapter22hosting.com
Where required by applicable law, individuals may also have the right to complain to an appropriate data-protection authority.
35. International Data Transfers
Where applicable privacy law restricts international transfer of personal information, Chapter22 will use legally recognized safeguards where required.
Depending upon the circumstances, these may include:
- Adequacy mechanisms;
- Contractual safeguards;
- Standard contractual clauses;
- Service-provider contractual obligations; or
- Other legally recognized transfer mechanisms.
Chapter22 will implement specific mechanisms applicable to its actual providers and processing activities as the infrastructure environment develops.
36. California Privacy Rights
California residents may have rights under applicable California privacy law.
Depending upon whether Chapter22 is legally subject to a particular requirement and whether an exception applies, these rights may include:
Right to Know
You may request information regarding personal information Chapter22 has collected about you.
Right to Access
You may request access to eligible personal information.
Right to Delete
You may request deletion of eligible personal information, subject to legal exceptions.
Right to Correct
You may request correction of inaccurate personal information.
Right to Opt Out of Sale or Sharing
California law may provide a right to opt out of the sale or sharing of personal information.
Chapter22 does not sell personal information and does not share personal information for cross-context behavioral advertising.
Right to Limit Certain Uses of Sensitive Personal Information
Where applicable, California residents may have rights relating to certain uses or disclosures of sensitive personal information.
Chapter22 does not intend to use sensitive personal information for unrelated profiling or advertising purposes.
Right to Non-Discrimination
Chapter22 will not unlawfully discriminate against a Customer for exercising a legally protected privacy right.
37. California Categories of Personal Information
Depending upon Customer interaction with Chapter22, categories of information collected may include:
Identifiers Examples:
- Name;
- Email address;
- IP address;
- Account identifier; and
- Online identifiers.
Purposes: Account operation, authentication, billing, security, support, and communications.
Customer Records Information Examples:
- Billing address;
- Contact information; and
- Transaction information.
Purposes: Billing, support, accounting, fraud prevention, and legal compliance.
Commercial Information Examples:
- Products purchased;
- Subscription history;
- Renewal history;
- Refunds; and
- Transaction history.
Purposes: Service delivery, billing, support, accounting, and product administration.
Internet or Electronic Network Activity Examples:
- Login records;
- Website activity;
- Device information;
- Network logs;
- Server activity; and
- Security events.
Purposes: Service delivery, analytics, network security, fraud prevention, troubleshooting, and abuse prevention.
Approximate Geolocation
Chapter22 may infer an approximate location from an IP address.
Purposes: Fraud prevention, security, localization, tax compliance, and server-region functionality.
Chapter22 does not intend to collect precise GPS location through its standard hosting Services.
Communications Examples:
- Support tickets;
- Emails;
- Abuse reports; and
- Customer communications.
Purposes: Support, security, dispute resolution, quality assurance, and legal compliance.
Sensitive Personal Information Chapter22 may process information considered sensitive under applicable law when necessary to operate a Service, such as Account authentication credentials or payment-related information.
Chapter22 does not use sensitive personal information for unrelated advertising or profiling.
38. Sources of Personal Information
Chapter22 may receive personal information:
- Directly from you;
- Automatically from your browser or device;
- Through your use of Chapter22 Services;
- From payment processors;
- From service providers;
- From infrastructure providers;
- From fraud-prevention services;
- From authorized users;
- From support communications;
- From abuse reporters;
- From security researchers;
- From legal or governmental authorities; and
- From other sources where permitted by law.
39. Sale and Sharing Disclosure
During the period covered by this Policy, Chapter22's policy is:
Personal information sold: None.
Personal information shared for cross-context behavioral advertising: None.
Chapter22 does not knowingly sell or share personal information of individuals under 18.
Because Chapter22 does not permit individuals under 18 to establish Accounts, Chapter22 does not intentionally operate an under-18 Customer data marketplace or advertising program.
40. Requesting Your Personal Information
Depending upon applicable law, you may request:
- Confirmation that Chapter22 processes your personal information;
- A copy of eligible personal information;
- Categories of information collected;
- Purposes for processing;
- Categories of recipients;
- Correction of inaccurate information;
- Deletion of eligible information;
- Portability of eligible information;
- Restriction of certain processing;
- Objection to certain processing; or
- Withdrawal of consent.
Requests should be submitted to:
privacy@chapter22hosting.com
Chapter22 may provide an additional privacy-request interface through the Customer Account or website.
41. Verifying Privacy Requests
Chapter22 must protect Customer information from unauthorized privacy requests.
We may therefore require reasonable verification before granting access, correction, deletion, or portability requests.
Verification may involve:
- Confirming Account access;
- Confirming an email address;
- Authentication through the Customer panel;
- Providing transaction details;
- Confirming Service information; or
- Other reasonable identity-verification steps.
Chapter22 will not request unnecessary sensitive information merely to process a privacy request.
42. Authorized Agents
Where applicable law permits use of an authorized agent to submit a privacy request, Chapter22 may require reasonable evidence that the agent is authorized to act for the individual.
Chapter22 may also require direct verification from the individual where permitted by law.
43. Responding to Privacy Requests
Chapter22 will respond to valid privacy requests within the period required by applicable law.
Some requests may require additional time where legally permitted.
Chapter22 may deny or limit a request where:
- Identity cannot reasonably be verified;
- Information must legally be retained;
- The request affects another person's rights;
- Retention is necessary to complete a transaction;
- Information is required for security or fraud prevention;
- Information is necessary to establish or defend legal claims;
- Another legal exception applies; or
- The request is manifestly unfounded or excessive where applicable law permits refusal.
Where required, Chapter22 will explain the reason for denying a request.
44. Privacy Request Appeals
Where applicable law provides a right to appeal a privacy decision, an individual may request review by contacting:
privacy@chapter22hosting.com
The request should identify the original privacy request and explain why the individual believes the decision should be reconsidered.
Chapter22 will process appeals as required by applicable law.
45. Children and Minors
Chapter22 Services are intended for individuals 18 years of age or older.
Individuals under 18 may not independently create a Chapter22 Hosting Account.
Chapter22 does not knowingly solicit personal information from children for purposes of Account creation.
If Chapter22 discovers that an Account was created by an individual under 18 in violation of our Terms, Chapter22 may terminate the Account.
Personal information associated with the Account may be deleted unless retention is reasonably necessary or legally required.
If you believe a minor has improperly created a Chapter22 Account, contact:
privacy@chapter22hosting.com
Nothing in this section permits Chapter22 Services to be used for unlawful exploitation of minors.
46. Third-Party Links and Services
Chapter22 websites or Services may contain links to third-party websites, software, games, plugins, social networks, payment processors, or other services.
Chapter22 does not control the privacy practices of independent third parties.
Customers should review the privacy policies of those services before providing personal information to them.
47. Third-Party Games and Applications
A game server or application hosted through Chapter22 may independently collect information about players or users.
That information may be controlled by:
- The Chapter22 Customer;
- A game publisher;
- A plugin developer;
- A third-party platform; or
- Another independent party.
Chapter22 is not responsible for the privacy practices of independent Customers or third-party applications merely because they use Chapter22 infrastructure.
Customers operating services that collect information from their own users are responsible for providing any privacy notices and obtaining any permissions required by applicable law.
48. Social Media
If you interact with Chapter22 through social-media platforms, those platforms may independently collect information regarding your interaction.
Their privacy practices are governed by their own policies.
Chapter22 may receive information that a platform makes available to account operators, such as:
- Username;
- Public profile information;
- Comments;
- Messages; or
- Interaction data.
49. Do Not Track
Some browsers transmit "Do Not Track" signals.
Because there is no single universally applied technical standard governing every form of Do Not Track signal, Chapter22 may not respond uniformly to generic Do Not Track signals.
Chapter22 will, however, honor legally recognized privacy preference signals such as Global Privacy Control where applicable.
50. Data Minimization
Chapter22 will make reasonable efforts to avoid collecting personal information that is not reasonably necessary for an identified business or legal purpose.
Personnel should not access Customer personal information simply because technical access is available.
Chapter22 will periodically evaluate whether retained categories of personal information remain reasonably necessary.
51. Purpose Limitation
Chapter22 will not use personal information for a materially unrelated purpose without considering whether:
- Additional notice is required;
- Consent is required;
- A new legal basis is necessary; or
- Applicable law otherwise restricts the new use.
52. Changes to This Privacy Policy
Chapter22 may update this Privacy Policy to reflect:
- New products;
- New infrastructure;
- Changes in data practices;
- Changes in service providers;
- New privacy laws;
- Security requirements;
- Operational changes; or
- Clarification of existing practices.
The effective date and version number at the top of this Policy will identify the current version.
If a change materially affects how Chapter22 uses personal information, Chapter22 will provide additional notice where appropriate or legally required.
Where consent is legally required for a new processing activity, Chapter22 will obtain it.
53. Contact Chapter22 About Privacy
Questions or requests concerning this Privacy Policy may be submitted to:
Chapter22Hosting LLC Doing Business As: Chapter22 Hosting California, United States
Website: chapter22hosting.com Privacy: privacy@chapter22hosting.com Mailing Address: [BUSINESS MAILING ADDRESS]
54. Summary of Chapter22'S Privacy Commitments
Chapter22's privacy practices are built around the following commitments:
- We do not sell Customer personal information.
- We do not share Customer personal information for cross-context behavioral
advertising.
- We do not store full payment-card information when payment processors can
securely handle it instead.
- Marketing email is opt-in.
- Necessary Account and Service communications remain transactional.
- Nonessential analytics and marketing cookies will be optional where appropriate
or required.
- Customers may exercise applicable privacy rights through
privacy@chapter22hosting.com.
- Authorized personnel access Customer information only for legitimate operational
purposes.
- Financial records may generally be retained for seven years.
- Support tickets may generally be retained for three years after closure.
- Ordinary access and security logs may generally be retained for twelve months.
- Canceled server data may remain recoverable for up to seven days where
technically practical, but recovery is not guaranteed.
- Chapter22 will honor legally applicable Global Privacy Control signals.
- Chapter22 does not permit individuals under 18 to independently create Accounts.
- Chapter22 collects only information reasonably necessary to provide, secure,
support, improve, and bill for its Services.
Chapter22Hosting LLC Privacy Policy — Version 1.0
