1.Who we are
Solana Vibe Station (“SVS”, “we”, “us”) is operated by Byte Bunkers Corporation, a Delaware corporation. For privacy questions and data-rights requests, contact security@solanavibestation.com. For the purposes of EU/UK data-protection law, Byte Bunkers Corporation is the data controller for personal data described in this policy.
2.What we collect
The categories below cover all personal data we collect through our website, customer portal, and APIs.
- Account information. At registration we collect your email address, first and last name, and password. Company name and phone number are optional. Passwords are stored hashed, on infrastructure we own and operate.
- Discord-linked accounts. If you sign in with Discord, your Discord email (only when Discord reports it as verified) is used as your account email, the same way a normal email/password signup would be. Your Discord user ID and username are linked to your account so support staff can verify inquiries.
- Billing data. Invoices and plan selection are stored in our billing system, hosted on infrastructure we own. Credit-card payments are processed by Stripe; we receive and store only a Stripe-issued payment-method token plus the card brand and the last four digits, used for display. The full card number, expiration, and CVV never touch our infrastructure. Cryptocurrency payments are processed by NOWPayments — we send them the invoice amount and target currency; they handle the wallet address and on-chain transaction data.
- IP addresses. When you reply to a support ticket from the portal, your IP address is recorded with the ticket for abuse-prevention and audit purposes. Reverse-proxy and CDN access logs may also retain IP addresses subject to their provider’s retention policies.
- Service usage. VPS console sessions are proxied in real time and not recorded. Aggregate RPC traffic metrics (latency percentiles, method counts) are collected at our infrastructure layer for operational monitoring; they are shown in aggregate at /monitor/response-time.
- Account-state records. If an account is blocked for Acceptable-Use violations, we retain the associated email address to prevent re-registration. Transient operational records created while a request is being processed are cleared once the operation completes.
3.What we don’t collect
We currently do not load third-party analytics or behavioral-tracking scripts on this site. We do not build advertising profiles and we do not sell personal data. If we introduce analytics in the future, we will update this policy before doing so.
4.Where your data is processed
Account details, invoices, support tickets, and service infrastructure are hosted on hardware we own and operate — no third party holds this data on our behalf. The third parties below process specific categories of personal data for us; each operates under its own privacy policy.
Third-party processors
- Stripe — credit-card payment processing. Stripe receives the full card number, expiration, and CVV; we receive and store only a tokenized payment-method ID plus the card brand and last four digits for display.
- NOWPayments — cryptocurrency payment processing (invoice amount, target currency, wallet address, on-chain payment data).
- Discord — OAuth identity provider when you use Discord sign-in; also the source channel for operational announcements mirrored to the in-portal notification bell.
6.Retention
- Our internal audit log is automatically pruned at 90 days.
- Billing history is retained for the term required by applicable financial-records law.
- Reverse-proxy access logs are retained per the upstream provider’s retention policy.
- Account-block records are retained for a reasonable period to prevent re-registration after an Acceptable-Use enforcement action.
7.Your rights (EEA / UK — GDPR)
If you are in the European Economic Area or the United Kingdom, the General Data Protection Regulation gives you the rights to access, rectify, erase, restrict processing of, port, and object to processing of your personal data, and to lodge a complaint with your local supervisory authority.
To exercise these rights, email security@solanavibestation.com. Two points to flag up front:
- Requests are fulfilled across our internal systems and our payment processors. We will acknowledge your request within 5 business days and aim to complete it within 30 days.
- Erasure is honored except where retention is required by applicable law (tax, AML/KYC, accounting), where retention is necessary to detect or prevent fraud or abuse (including account-block records), or where data is held by payment processors subject to their own retention requirements. We will tell you which data we can and cannot delete.
8.California privacy rights (CCPA / CPRA)
If you are a California resident, you have the rights to know what personal information we collect, delete it, correct it, opt out of any sale or sharing of it (we do not sell or share personal information for cross-context behavioral advertising), and not to be discriminated against for exercising any of these rights. The legal-retention and payment-processor carve-outs described above apply equally to CCPA/CPRA deletion requests.
To exercise these rights, email security@solanavibestation.com.
9.Children
Our service is not directed to individuals under the age of 16, and we do not knowingly collect personal data from anyone under 16. If you believe a minor has registered, please contact us.
10.International transfers
Byte Bunkers Corporation is based in the United States of America and processes personal data in the USA. By using the service from outside the USA, you understand that your data is transferred to and processed in the USA.
11.Changes to this policy
Material changes are notified by email and in the in-portal notification bell at least 30 days in advance. Non-material clarifications take effect on publication; we will update the “Last updated” date at the top of this page when we make any change.
12.Contact
Email security@solanavibestation.com for any privacy-related question or data-rights request.