Privacy Policy
How LayerOne collects, uses, retains, and protects personal information, and how California residents can exercise CCPA rights, including Do Not Sell or Share.
Last updated: September 3, 2026
LayerOne, LLC ("LayerOne", "we", "us", or "our") respects your privacy. This Privacy Policy explains what personal information we collect, how we use it, and the choices available to you when you visit layeronecloud.com, use our client portal, or consume our VPS hosting services (collectively, the "Services").
This policy applies to our U.S. operations and is written for customers and visitors in the United States, including California residents who have rights under the California Consumer Privacy Act ("CCPA"), as amended by the California Privacy Rights Act.
1. Who we are
LayerOne, LLC is a Florida limited liability company providing VPS hosting from infrastructure in the Tampa, Florida metro area. Our mailing address is 5005 W Laurel St Ste 100 1010, Tampa, FL 33607, United States. For privacy inquiries, contact support@layeronecloud.com.
2. Information we collect
We collect information in the following categories:
- Identifiers: email address, mobile telephone number (only if you give us one, as described in Section 7), account identifiers, IP address, and similar device or session identifiers.
- Account information: authentication events and access preferences (such as admin/client mode for staff accounts).
- Commercial information: invoices, payment status, account credit ledger entries, order history, plan selections, and billing correspondence. Full payment card numbers are processed by our payment providers; we store only tokens and references needed to reconcile payments.
- Support and communications: tickets, live chat transcripts, optional Support Bot conversations, contact form submissions, and email correspondence with our team.
- Service and technical data: VM identifiers, plan assignments, IP allocations, provisioning status, console session metadata, and configuration required to operate your VPS.
- Internet and network activity: standard server logs (such as IP address, user agent, requested URL, and timestamps), cookies described in Section 8, and, when enabled, first-party session recordings of the public website and client portal.
- Professional information: company name and tax ID, if you provide them.
- Security and abuse data: login rate-limit counters, webhook delivery logs, audit events, network abuse reports, and technical logs needed to protect the platform.
- Identity verification: government-issued identification and related information, only if we request KYC because an account, payment, or activity is flagged for suspected fraud, abuse, or similar risk, as described in our Terms of Service. Identity documents are collected by Didit; we do not store ID images on this platform.
We collect this information from you (when you create an account, pay, open a ticket, or use the Support Bot), from your devices (logs, cookies, and analytics), from our service providers (for example payment confirmations from Stripe), and from partners whose referral or advertising links you click.
We do not collect health data. We do not intentionally collect government ID numbers or other identity documents except when we request identity verification as described above. We do not collect personal information to sell it.
3. How we use information
We use personal information to:
- Create and administer accounts and authenticate users
- Provision, bill, suspend, and terminate VPS services
- Process payments and maintain account credit
- Provide customer support and respond to inquiries, including through live chat and the optional Support Bot
- Monitor reliability, investigate incidents, and prevent fraud or abuse
- Verify identity when an account is flagged for suspected fraud, abuse, or similar risk
- Comply with law, enforce our Terms of Service and Acceptable Use Policy, and protect our rights
- Improve the Services and communicate operational, billing, and legal updates
- Send optional marketing email where you have not unsubscribed
- Send text messages to a mobile number you have given us, as described in Section 7
- Measure how the website and portal are used, when analytics is enabled
Optional marketing email honours unsubscribe requests. Service, billing, and legal notices (including Privacy Policy updates) are not marketing and continue after an unsubscribe.
4. Sale, sharing, and disclosures
We do not sell personal information and we do not share customer lists with data brokers.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All of the categories described in this policy exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties. Your mobile number and your record of consent are used only to deliver the messages described in Section 7, and are disclosed only to the messaging provider that hands those messages to your mobile carrier.
When analytics is enabled in our operations console, we send page-use information to Google. Under California law that can count as "sharing" for cross-context behavioral advertising even though we do not run ads on the site. California residents can opt out on our Do Not Sell or Share My Personal Information page. We also honor the Global Privacy Control (GPC) browser signal as an opt-out of that sharing.
First-party session recording, when enabled, stays on LayerOne systems. It is not a sale or share.
We disclose personal information to service providers that process it for us, as described in Section 5, and when required by law, subpoena, or court order, or when we believe disclosure is necessary to protect rights, safety, or the integrity of the Services.
5. Payment processors and service providers
We use trusted third parties who process information on our behalf, including:
- Stripe, Inc.: card, ACH, and crypto (stablecoin) payments
- PayPal: one-time account-credit purchases and customer-approved monthly credit deposits
- Railway Corp. and other infrastructure vendors: application hosting, databases, caching, and background job processing for our platform
- Cloudflare, Inc.: transactional and campaign email delivery
- OpenAI: optional Support Bot replies, only if you choose to use that feature and provide it with information, as described in Section 6
- Google LLC: website and portal analytics when that tag is enabled in our operations console, unless you have opted out of sharing
- Didit: identity verification (KYC) when we request it, including government-issued identification submitted through Didit's flow. See Didit's privacy policy.
- Our messaging provider: delivery of text messages to your mobile carrier, only if you have opted in to text messaging. The provider handles your number solely to deliver our messages and may not use it for its own purposes.
These providers are permitted to use information only as needed to deliver their services to us, except where their own terms apply to information you choose to send them (see Section 6 for OpenAI). Their privacy practices are governed by their own policies.
6. Support Bot and OpenAI
The signed-in client portal includes an optional Support Bot (the Chat assistant). Using it is voluntary. If you never open it or never send it a message, we do not send your information to OpenAI for that feature. The Chat bar can still connect you with a person even when the Support Bot is turned off.
If you choose to use the Support Bot and provide it with information, we transmit that conversation (the text you send and prior messages in that chat) to OpenAI so it can generate a reply. We may also send retrieved public documentation and catalog facts the bot needs to answer. Do not send passwords, API keys, payment card numbers, or other secrets to the Support Bot.
Information OpenAI receives is processed under OpenAI's own terms and Privacy Policy. Whether OpenAI retains or further uses that information is governed by OpenAI, not by LayerOne. Review OpenAI's Privacy Policy before using the Support Bot if that processing matters to you.
Human live chat, tickets, and email to support@layeronecloud.com do not require the Support Bot. Questions about this policy or the Support Bot: support@layeronecloud.com.
7. Text messaging (SMS)
LayerOne operates a text messaging program. Taking part is optional, and you are never required to give us a mobile number to open an account, buy a plan, or get support.
What we collect
- The mobile telephone number you give us
- A record of your consent: the date and time, the method you used, and the wording you were shown when you opted in
- Message delivery status returned by your carrier, and the content of messages you send us in reply
- A record of any opt-out, so we can honour it
What we use it for
A mobile number you give us is used only to send the messages described in our Terms of Service: two-factor and sign-in security codes, service and account alerts (such as outages, planned maintenance, low account credit, and failed payments), replies to your support tickets and live chats, and, where you have given separate express written consent, marketing messages about offers and new plans.
Security codes and account alerts are sent only to customers who have opted in to receive them by text. Marketing messages require their own consent and are never sent on the strength of a number you gave us for security or support.
We do not share your mobile number
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All of the categories described in this policy exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties. We do not sell mobile numbers, we do not rent them, we do not pass them to data brokers or advertising networks, and we do not include them in any list we make available to another company. The only disclosure is to the messaging provider that hands our messages to your mobile carrier, which may use your number solely to deliver those messages.
Frequency and cost
Message frequency varies, because most messages are triggered by activity on your own account rather than sent on a schedule.
Message and data rates may apply. Any charge comes from your mobile carrier under your own plan, not from LayerOne.
Stopping messages and getting help
Reply STOP to any message to end that messaging program. We will send one confirmation and then stop. Reply HELP for help, or contact support@layeronecloud.com or +1 (813) 212-3723.
Opting out of text messages does not close your account and does not stop service, billing, security, and legal notices reaching you by email. Email remains the channel of record for anything that affects whether your servers keep running.
How long we keep it
We keep your number for as long as you are opted in. After you opt out we keep the record of your consent and of your opt-out, and nothing else about the number, for as long as we may need to show that we had permission to message you and that we honoured your request to stop.
8. Cookies and similar technologies
We use cookies and similar technologies required for the Services to function, including:
- Session cookies: keep you signed in to the client portal and operations console
- CSRF tokens: help prevent cross-site request forgery on form submissions
- Session-recording cookie (
l1_sr): when session recording is enabled, ties replay chunks from one visit together so a checkout is not split when you sign in - Referral and advertising cookies (
l1_ref,l1_ad): set when you click a partner or tracked ad link, so a later signup can be attributed - Share-opt-out cookie (
l1_share_optout): remembers a Do Not Sell or Share choice on this browser
We do not use third-party advertising cookies. When analytics is enabled and you have not opted out, we load a Google tag (gtag.js). Google may set cookies and collect device and usage information as described in Google's Privacy Policy. Credential-bearing URLs (such as console sessions and password-reset links) are excluded from analytics collection.
When session recording is enabled in our operations console, we store a first-party replay of how the public website and client portal are used (mouse movement, clicks, and on-page content). Typed input values and on-page secrets are masked. Operators can replay those sessions to diagnose checkout and portal problems. Session recording can be turned off in the operations console. We do not send this replay data to a third-party vendor.
You can control cookies through your browser settings. Disabling essential cookies may prevent sign-in and checkout from working. California residents can opt out of analytics sharing at /do-not-sell/.
9. Data retention and deletion
We retain information for as long as needed to provide the Services, resolve disputes, enforce agreements, and meet legal, tax, and accounting requirements.
Typical retention practices include:
- Active account and billing records: retained while your account exists and for a reasonable period afterward
- Invoice and payment records: retained as required for tax and audit purposes (often seven years or as required by law)
- Support tickets and chat transcripts: retained for operational history and quality review
- Security and audit logs: retained for a limited period appropriate to investigation needs
- Identity verification records: retained for as long as needed to complete the review, prevent repeat fraud, and meet legal retention obligations
- Session recordings: retained for the period configured in the operations console (default 14 days)
- VPS disk contents: deleted when services are cancelled or removed under our billing deletion policy described in the Terms of Service
Encrypted credentials (such as VM root passwords and ticket secrets) are purged according to operational schedules documented in our platform.
10. Security
We implement administrative, technical, and organizational measures designed to protect personal information, including access controls, encryption of sensitive fields at rest, HTTPS for data in transit, and staff access restrictions. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
11. California privacy rights
If you are a California resident, you have the right to:
- Know the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the categories of third parties we disclose it to
- Delete personal information we hold about you, subject to exceptions (including records we must keep for tax, fraud prevention, or outstanding billing)
- Correct inaccurate personal information
- Opt out of the sale or sharing of personal information
- Non-discrimination for exercising these rights
To exercise these rights, submit a request at /privacy/request/ or email support@layeronecloud.com. Signed-in customers can download a copy of their information from Account settings. We will verify your identity before completing a request. We aim to respond within 45 calendar days. Authorized agents may submit a request on your behalf; we will still need to verify the consumer and the agent's authority.
To opt out of sale or sharing, visit Do Not Sell or Share My Personal Information. If your browser sends a Global Privacy Control signal, we treat it as an opt-out of analytics sharing without any further action from you.
We do not use or disclose sensitive personal information for purposes that would require a separate "Limit the Use of My Sensitive Personal Information" control.
You may update some account contact details through support. You may choose not to use the Support Bot; tickets, email, and live chat with staff remain available.
12. Children's privacy
The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. You must be at least 18 to create an account. If you believe a child has provided us information, contact us and we will take appropriate steps to delete it.
13. Changes to this policy
We may update this Privacy Policy by posting a revised version on our website and updating the "Last updated" date. Material changes will be communicated through the client portal or email where practicable.
14. Contact
Privacy questions or requests: support@layeronecloud.com or /privacy/request/.
Mailing address: LayerOne, LLC, 5005 W Laurel St Ste 100 1010, Tampa, FL 33607, United States.
Questions about this policy?
Open a ticket and an engineer will point you at the clause that applies. Service email still arrives even if you unsubscribe from marketing.