Privacy
This privacy notice explains the processing of personal data at MarvinMC Hosting. Version: 2026-10-04.
Controller
The controller is Marvin Leonhardt. Full contact details are available in the legal notice.
Purposes and data categories
Only data required for operation, contract performance, billing, support, security, abuse prevention and legal obligations is processed. This includes identification and contact data, account data, payment and billing data, server and configuration data, connection and security data, and support communications.
Based on the current system, data is not used for personalised advertising and personal data is not sold.
Registration, login and account
Registration and login process the username, email address, password hash, customer number, account type, timestamps, email confirmation and consent to the applicable terms version. Passwords are not stored in plain text. Time-limited hashed one-time tokens and pseudonymised delivery data are processed for email confirmation and abuse prevention.
If a passkey is added, the public credential, credential identifier, device-provided transport and backup characteristics, signature counter, creation time and last use are stored. Biometric data and the private passkey remain on the user device or with its passkey provider and are not transmitted to MarvinMC Hosting.
When an email address is changed, the previous and new addresses and a hashed one-time token are processed. A security notice is sent to the previous address. The reversal link is valid for 24 hours; used or expired tokens are subsequently removed automatically.
If the email address of a newly registered account is not verified within 30 days, the account and registration-only data are deleted automatically. Business records, payment, invoice, withdrawal or comparable evidence data are not deleted contrary to statutory retention or evidentiary duties.
Hosting, servers and content
To provide hosting, the system processes the server name, selected plan, term, resources, IP and port assignments, subdomains, FTPS credentials, database data, files, backups, console and operational data on the nodes used for the service. Access is required for contract performance, administration, troubleshooting, security and handling support or infringement notices.
Content is not evaluated for advertising. Content may need to be reviewed or secured for security, abuse prevention, a notice or a legal or official obligation.
Payments, balance and invoices
Depending on activation, PayPal, Stripe and PaysafeCard may be used as payment providers. Payment details are generally processed by the selected provider. MarvinMC Hosting receives, in particular, payment method, payment reference, amount, currency, status, timestamps and data required for crediting, refunds and invoicing. Balance entries, server bookings and invoices are documented in the panel.
Hosting contributions and donation pages
When an account holder enables a donation page, its title, description, custom link, selected design, uploaded images, own content and public username are visible to anyone with the link. Contributions can be paid without creating an account. We process the recipient account, amount, selected payment provider, payment reference and status, timestamps, the accepted terms version, and, for signed-in donors, their account identifier. An optional email address is used for payment and refund confirmations; when relevant it is also passed to the selected payment provider for this payment. It is not shown to the recipient.
Security checks use a PHP session, a session-bound request identifier and pseudonymised network and email identifiers to limit repeated payment attempts. Related accounts may contribute to each other. Affiliate rewards are based on actual hosting usage paid from purchased credit, not contributions or deposits. Private payment-confirmation links are protected by random access tokens; the token is stored as a hash and an encrypted secret. These links must not be shared. Financial records follow the retention rules described below; temporary rate-limit records are removed after their validity period.
Electronic withdrawal function
When the electronic withdrawal function is used, the name, contract reference, confirmation email address, receipt time, a pseudonymised IP identifier and a hash of the browser identifier are processed. This is necessary to receive, confirm, process and document the withdrawal declaration under Article 6(1)(b), (c) and (f) GDPR. The receipt confirmation is sent by email; a copy is sent to the contact address stated in the legal notice.
The information is retained for processing and until applicable evidentiary, retention and limitation periods expire, and is then deleted unless an ongoing dispute or legal obligation requires longer retention.
Cookies and authentication
The panel uses technically necessary session, authentication and CSRF cookies to protect logins, manage sessions and prevent abusive requests. These cookies are required for the member area requested by the user. Based on the current system, no non-essential analytics or advertising cookies are set.
Where applicable, storing information in or accessing information from end devices is governed by Section 25 TDDDG. Non-essential consent can be withdrawn at any time with effect for the future.
Security check
A security check is used during login, registration, withdrawal and, depending on the server action, other operations. Depending on the assessed abuse risk, an image code or a local proof-of-work calculation is used. The displayed task, submitted solution, technical verification data, shortened risk signals and the session required for abuse prevention are processed. The service marvinmc.dev is contacted to provide and verify the check.
Discord connection
The optional Discord connection processes the Discord ID, username, display name, avatar identifier and encrypted OAuth credentials. The hosting username, paying-customer status and active server counts by package type are sent to Discord for Linked Roles. If a global or server-specific event webhook is enabled, the server action, server name, internal server ID, node, timestamp and acting user are sent to Discord. Stored webhook URLs are encrypted and are not disclosed in the panel.
When the support system is used, the ticket number, subject, messages, submitted attachments, hosting username and contact details required for follow-up questions are transferred to a non-public Discord forum channel. This allows authorised support staff to process the request and return their replies to the web panel. Please do not include data in support messages that is not required to handle the request.
Access logs
When the website is accessed and used, the IP address, timestamp, requested URL, referrer, browser and device information, HTTP method, request result, security data and error data may be processed. This supports operation, security, troubleshooting, abuse prevention and defence against attacks.
Recipients and processors
Recipients may include hosting and node infrastructure used for operation, email and support providers, payment providers, Discord when a connection or webhook is enabled, and authorities or courts where required. Where required, processing agreements under Article 28 GDPR are concluded with processors.
Transfers to third countries
Depending on the payment, communication or integration service used, data may be processed outside the European Union or European Economic Area. Transfers take place only where the requirements of Articles 44 et seq. GDPR are met, in particular on the basis of an adequacy decision, appropriate safeguards such as standard contractual clauses or a valid statutory exception.
Legal bases
Account management, orders, hosting, billing and requested support are processed for pre-contractual measures and contract performance under Article 6(1)(b) GDPR. Tax, commercial and official obligations are based on Article 6(1)(c) GDPR. Security logs, abuse prevention, troubleshooting and the defence or enforcement of claims are based on Article 6(1)(f) GDPR; the legitimate interests are secure, stable and economic operation and the protection of users, infrastructure and legal positions. Where an optional function requires consent, Article 6(1)(a) GDPR applies.
Contract and account data marked as required is necessary to create an account or provide the service. Without this data, the relevant function or contract cannot be provided. Based on the current system, no decision based solely on automated processing with legal or similarly significant effects within the meaning of Article 22 GDPR takes place.
Retention period
Registration-only data for an account on which no email address has ever been verified is deleted 30 days after registration. A later email-address change does not start this deletion process for a previously verified account. Other account data is retained while the account exists or while claims and legal obligations require further retention. Invoices, accounting records and comparable business documents are retained according to tax and commercial retention duties, commonly six, eight or ten years depending on the document. Security and log data is deleted or anonymised when it is no longer required for operation, security or evidence.
After the contract ends, server content and access data are deleted within the periods described in the terms unless a legal duty or legitimate reason requires longer retention.
Data subject rights
Data subjects have, subject to the GDPR, rights to access, rectification, erasure, restriction of processing and data portability. Processing based on Article 6(1)(f) GDPR may be objected to under Article 21 GDPR on grounds relating to the data subject’s particular situation. Consent may be withdrawn at any time with effect for the future. The lawfulness of processing before withdrawal remains unaffected.
Right to lodge a complaint
There is a right to lodge a complaint with a data protection supervisory authority. For the provider location in Hesse, this is in particular the Hesse Commissioner for Data Protection and Freedom of Information.