Privacy Policy

This Privacy Policy explains how IPX Tech Holding LLC ("IPX", "we", "us", or "our") collects, uses, discloses, and protects personal information when you visit ipxtechholding.com, create an account, or use the IPX platform and related services (collectively, the "Service"). IPX operates a GPU marketplace and aggregator that lets customers rent GPU compute capacity sourced on demand from third-party cloud providers, with secure SSH access to the rented machine through an IPX gateway. We have written this policy to be consistent with the European Union and United Kingdom General Data Protection Regulation ("GDPR"), general United States privacy practice, and the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"). Please read it alongside our Terms of Service.

1. Who We Are and Scope of This Policy

IPX Tech Holding LLC is a company organized in the United States. For purposes of the GDPR and similar laws, IPX is the data controller responsible for the personal information described in this policy, which means we determine the purposes and means of processing that information. For purposes of the CCPA/CPRA, IPX acts as a business.

This policy applies to personal information we process about visitors to our website, account holders, prospective customers, and others who interact with the Service. It does not cover the content or workloads you choose to run on the GPU machines you rent, and it does not cover the privacy practices of the third-party cloud providers, payment processors, or identity providers described below, each of which maintains its own privacy policy. Important: IPX does not own the underlying GPU hardware and is not the data-center operator. We provision interruptible capacity on third-party infrastructure on your behalf, and there is no uptime service-level agreement.

If you do not agree with this policy, please do not use the Service.

2. Personal Information We Collect

We collect only the personal information we need to operate the Service, bill for usage, secure accounts, and meet our legal obligations. The table below summarizes the categories of personal information we collect, with examples and the source of each category. Some categories map to the statutory categories used in the CCPA/CPRA.

Category Example data Source
Identifiers Account email address, username, internal account identifier. Directly from you at sign-up, or from an OAuth provider if you use it.
Account credentials A salted, hashed password (we never store your password in plain text). We do not store credentials at all if you sign in only through Google or GitHub. Directly from you when you set a password.
Commercial and transaction information Prepaid credit purchases, credit balance, per-second rental and metering records, spend caps you set, billing history. We never store full payment card numbers. Generated by your use of the Service; payment events relayed by our payment processor.
SSH public keys The public SSH keys you add so we can inject them into the machines you rent. We never request or store private SSH keys. Directly from you when you add a key.
Internet, usage, device, and log data IP address, browser and device type, operating system, referring pages, pages and features used, session timestamps, and standard server log entries. Collected automatically when you use the Service.
OAuth profile data Basic profile information shared by Google or GitHub when you choose to sign in with them, such as your name, email address, and provider account identifier. From Google or GitHub, only if you use OAuth sign-in.
Marketing preferences Your opt-in choice to receive marketing email, and your subsequent unsubscribe or preference changes. Directly from you at sign-up or in account settings.
Inferences Limited operational inferences, such as flags relating to suspected fraud, abuse, or account risk, derived from the data above. We do not build advertising or behavioral profiles about you. Derived by us from the categories above.

We do not intentionally collect special categories of data under the GDPR (such as health, biometric, or political data) or "sensitive personal information" under the CCPA/CPRA. Account credentials are handled with care, but we use them only to authenticate you and secure your account, never to infer characteristics about you.

3. How We Collect Personal Information

We collect personal information in three main ways.

4. How and Why We Use Personal Information

We use personal information for the following purposes.

5. Legal Bases for Processing (GDPR)

If you are in the European Economic Area or the United Kingdom, we process your personal information only when we have a valid legal basis under Article 6 of the GDPR. The table below maps each purpose to the legal basis we rely on.

Purpose Legal basis (GDPR Art. 6)
Creating your account, provisioning rentals, providing SSH access, and delivering the Service you request. Performance of a contract (Art. 6(1)(b)).
Processing prepaid credits and per-second billing. Performance of a contract (Art. 6(1)(b)).
Account security, fraud prevention, abuse detection, and maintaining and improving the reliability of the Service. Legitimate interests (Art. 6(1)(f)), namely operating a secure and reliable platform.
Customer support and service communications. Performance of a contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)).
Sending marketing email. Consent (Art. 6(1)(a)), which you may withdraw at any time.
Non-essential cookies and analytics, where applicable. Consent (Art. 6(1)(a)).
Keeping transaction, tax, and accounting records. Legal obligation (Art. 6(1)(c)).

Where we rely on legitimate interests, we balance those interests against your rights and freedoms, and you may object as described in Section 12. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

6. SSH Keys

The public SSH keys you add are stored with your account and injected into the machines you rent so you can connect to them through the IPX gateway. The gateway operates as a reverse tunnel, so the underlying provider's IP address is not exposed to you and your public key is used only for the duration and purpose of your rentals. We never request, receive, or store your private SSH keys. Keep your private keys secure; anyone who holds them can access machines that trust your public key.

7. Cookies and Similar Technologies

We use a small number of cookies and similar technologies. Essential and session cookies are necessary to operate the Service, for example to keep you signed in and to protect against cross-site request forgery. These cannot be switched off through our interface because the Service will not function without them. Where we use analytics or other non-essential technologies to understand aggregate usage, we rely on your consent where required by law.

You can control cookies through your browser settings, including blocking or deleting cookies, though blocking essential cookies may prevent the Service from working. Where a consent banner or preference control is presented to you, you can use it to accept or decline non-essential cookies and to change your choice later. We honor recognized opt-out preference signals, such as Global Privacy Control, where applicable law requires.

8. Marketing Communications

Marketing email is optional and opt-in. You choose at sign-up whether to receive it, and you can change your preference at any time in your account settings. Every marketing message we send includes a clear identification of the sender and a working unsubscribe link, consistent with the United States CAN-SPAM Act, and we honor unsubscribe requests promptly. If you are in the EEA or the United Kingdom, your consent is the legal basis for marketing email, and you may withdraw that consent at any time with the same effect as unsubscribing. Withdrawing consent or unsubscribing from marketing does not stop transactional or service messages, such as billing receipts, security notices, and important account communications, which we send as part of operating the Service.

9. How We Disclose and Share Information

We share personal information only as needed to operate the Service, comply with law, or protect rights, and only with the categories of recipients listed below. These recipients act as our service providers, processors, or sub-processors, or are providers you choose to connect to.

Recipient Role What is shared
Stripe Payment processor. Information needed to process prepaid credit purchases. Stripe handles card details directly; we never receive or store full card numbers.
GPU cloud providers Third-party infrastructure on which we provision rentals. The technical information needed to launch and configure a rented machine, including your public SSH key.
Amazon Web Services (AWS) Cloud hosting for the IPX platform. Data processed and stored as part of hosting the Service.
Google / GitHub OAuth identity providers. Only if you use OAuth sign-in; we receive basic profile data and exchange authentication tokens with the provider you choose.

We may also disclose personal information: to professional advisers such as lawyers and accountants; to comply with a law, regulation, legal process, or enforceable governmental request; to enforce our Terms of Service or protect the rights, property, or safety of IPX, our users, or others; and in connection with a merger, acquisition, financing, or sale of assets, in which case we will continue to protect your information consistent with this policy.

We do not sell your personal information for money. We also do not disclose your personal information for cross-context behavioral advertising. See Section 13 for how this is treated under the CCPA/CPRA.

10. International Data Transfers

IPX is based in the United States, and our hosting and several of our service providers are located in or process data in the United States. If you access the Service from outside the United States, your personal information may be transferred to, stored in, and processed in the United States and other countries whose data protection laws may differ from those in your jurisdiction.

For transfers of personal information from the EEA, the United Kingdom, or Switzerland, we put in place appropriate safeguards as required by law, which include the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, and equivalent mechanisms with our service providers. You may contact us at contact@ipxtechholding.com to ask about the safeguards we use.

11. Data Retention

We keep personal information for as long as your account is active and for as long as we need it for the purposes described in this policy. After your account is closed, we retain certain information where necessary to meet legal, tax, accounting, and regulatory obligations, to resolve disputes, to prevent fraud and abuse, and to enforce our agreements. When personal information is no longer needed for these purposes, we delete it or anonymize it so it can no longer be associated with you. Transaction and billing records are generally retained for the periods required by applicable tax and accounting law.

12. Security

We use technical and organizational measures designed to protect personal information, including encryption of data in transit, storing passwords only in salted and hashed form, restricting access to those who need it, and operating on reputable cloud infrastructure. No method of transmission or storage is perfectly secure, however, and we cannot guarantee absolute security. You are responsible for keeping your account credentials and private SSH keys confidential, and you should notify us promptly at contact@ipxtechholding.com if you believe your account has been compromised.

13. Your GDPR Rights (EEA and UK)

If you are in the EEA or the United Kingdom, you have the following rights in respect of your personal information, subject to conditions and exceptions in applicable law.

To exercise these rights, contact us at contact@ipxtechholding.com. We will respond within the timeframes required by applicable law, generally within one month under the GDPR, and we may need to verify your identity before acting on a request.

14. Your California Privacy Rights (CCPA/CPRA)

If you are a California resident, the CCPA/CPRA gives you specific rights regarding your personal information. We honor these rights as described below.

14.1 Your rights

14.2 How to exercise your rights

You can exercise these rights by emailing contact@ipxtechholding.com. We will verify your request by confirming that you control the account or email address associated with the personal information, and we may ask for additional information to confirm your identity. You may use an authorized agent to submit a request on your behalf; we may require the agent to provide proof of your written permission and may still ask you to verify your own identity directly. We will respond within the timeframes the CCPA/CPRA requires, generally within 45 days, with an extension where permitted.

14.3 Categories of personal information and our disclosures in the past 12 months

In the past 12 months, we have collected the categories of personal information described in Section 2 (identifiers; account credentials; commercial and transaction information; SSH public keys; internet, usage, device, and log data; OAuth profile data; marketing preferences; and inferences). We have disclosed for a business purpose certain of these categories (for example, identifiers, commercial and transaction information, and SSH public keys) to the categories of recipients listed in Section 9, namely our payment processor, GPU cloud providers, our cloud host, and OAuth identity providers where you use them. We have not sold and have not "shared" (for cross-context behavioral advertising) any category of personal information.

14.4 "Shine the Light"

California's "Shine the Light" law (Civil Code Section 1798.83) lets California residents request information about disclosures of personal information to third parties for their own direct marketing purposes. We do not disclose your personal information to third parties for their own direct marketing. You may contact us at contact@ipxtechholding.com with any related questions.

15. Other US State Privacy Rights

Residents of certain other US states, including Virginia, Colorado, Connecticut, Utah, and Texas, may have rights similar to those described above, such as the rights to access, correct, delete, and obtain a copy of their personal information, and to opt out of targeted advertising, sale, or certain profiling. Because we do not sell personal information or use it for targeted advertising or profiling with legal effects, several of these do not apply in practice, but you may exercise any rights you have, and appeal a decision where your state provides an appeal right, by contacting us at contact@ipxtechholding.com. We will honor these rights as required by your state's law.

16. Children's Privacy

The Service is intended for users who are at least 18 years old and able to form a binding contract. We do not offer the Service to anyone under 16, and we do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact us at contact@ipxtechholding.com and we will take steps to delete it.

17. Automated Decision-Making

We do not engage in automated decision-making that produces legal or similarly significant effects about you without human involvement. We use automated checks to help detect fraud, abuse, and account risk and to enforce the spend caps and balances that govern rentals, but material decisions affecting your account involve human review where required by applicable law. If you have questions about these processes, contact us at contact@ipxtechholding.com.

18. EU/UK Representative and Data Protection Officer

You can reach our privacy team, including any EU or UK representative or data protection officer we appoint, at contact@ipxtechholding.com. Where the GDPR or UK GDPR requires us to designate a representative or a data protection officer, we will appoint one and you may contact them through that address.

19. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page, and, where the changes are material, we will provide additional notice as required by law, for example by email or an in-product notice. Your continued use of the Service after an update takes effect means you accept the revised policy.

20. How to Contact Us

For privacy questions, to exercise your rights, or for any other legal questions, contact us at contact@ipxtechholding.com. You can also reach us through our website at ipxtechholding.com. IPX Tech Holding LLC is the entity responsible for the personal information described in this policy, and this policy is governed by the laws of the State of California, United States, without regard to its conflict-of-laws rules, except where mandatory data protection law in your jurisdiction applies. Please also review our Terms of Service.