Privacy Policy
This Privacy Policy explains how IPX Tech Holding LLC ("IPX", "we", "us", or "our") collects, uses, discloses, and protects personal information when you visit ipxtechholding.com, create an account, or use the IPX platform and related services (collectively, the "Service"). IPX operates a GPU marketplace and aggregator that lets customers rent GPU compute capacity sourced on demand from third-party cloud providers, with secure SSH access to the rented machine through an IPX gateway. We have written this policy to be consistent with the European Union and United Kingdom General Data Protection Regulation ("GDPR"), general United States privacy practice, and the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"). Please read it alongside our Terms of Service.
1. Who We Are and Scope of This Policy
IPX Tech Holding LLC is a company organized in the United States. For purposes of the GDPR and similar laws, IPX is the data controller responsible for the personal information described in this policy, which means we determine the purposes and means of processing that information. For purposes of the CCPA/CPRA, IPX acts as a business.
This policy applies to personal information we process about visitors to our website, account holders, prospective customers, and others who interact with the Service. It does not cover the content or workloads you choose to run on the GPU machines you rent, and it does not cover the privacy practices of the third-party cloud providers, payment processors, or identity providers described below, each of which maintains its own privacy policy. Important: IPX does not own the underlying GPU hardware and is not the data-center operator. We provision interruptible capacity on third-party infrastructure on your behalf, and there is no uptime service-level agreement.
If you do not agree with this policy, please do not use the Service.
2. Personal Information We Collect
We collect only the personal information we need to operate the Service, bill for usage, secure accounts, and meet our legal obligations. The table below summarizes the categories of personal information we collect, with examples and the source of each category. Some categories map to the statutory categories used in the CCPA/CPRA.
| Category | Example data | Source |
|---|---|---|
| Identifiers | Account email address, username, internal account identifier. | Directly from you at sign-up, or from an OAuth provider if you use it. |
| Account credentials | A salted, hashed password (we never store your password in plain text). We do not store credentials at all if you sign in only through Google or GitHub. | Directly from you when you set a password. |
| Commercial and transaction information | Prepaid credit purchases, credit balance, per-second rental and metering records, spend caps you set, billing history. We never store full payment card numbers. | Generated by your use of the Service; payment events relayed by our payment processor. |
| SSH public keys | The public SSH keys you add so we can inject them into the machines you rent. We never request or store private SSH keys. | Directly from you when you add a key. |
| Internet, usage, device, and log data | IP address, browser and device type, operating system, referring pages, pages and features used, session timestamps, and standard server log entries. | Collected automatically when you use the Service. |
| OAuth profile data | Basic profile information shared by Google or GitHub when you choose to sign in with them, such as your name, email address, and provider account identifier. | From Google or GitHub, only if you use OAuth sign-in. |
| Marketing preferences | Your opt-in choice to receive marketing email, and your subsequent unsubscribe or preference changes. | Directly from you at sign-up or in account settings. |
| Inferences | Limited operational inferences, such as flags relating to suspected fraud, abuse, or account risk, derived from the data above. We do not build advertising or behavioral profiles about you. | Derived by us from the categories above. |
We do not intentionally collect special categories of data under the GDPR (such as health, biometric, or political data) or "sensitive personal information" under the CCPA/CPRA. Account credentials are handled with care, but we use them only to authenticate you and secure your account, never to infer characteristics about you.
3. How We Collect Personal Information
We collect personal information in three main ways.
- Directly from you when you create an account, set a password, add SSH public keys, purchase prepaid credits, configure rentals and spend caps, set your marketing preference, or contact support.
- Automatically through your device and our servers when you use the Service, including IP address, device and browser characteristics, log entries, and cookies or similar technologies (see Section 7).
- From third parties, namely the OAuth identity provider (Google or GitHub) if you choose to sign in with one, and our payment processor (Stripe), which confirms payment events without sharing full card details with us.
4. How and Why We Use Personal Information
We use personal information for the following purposes.
- Provide and operate the Service, including creating and authenticating your account, provisioning GPU machines on third-party providers, injecting your public SSH keys, and routing your connection through the IPX gateway.
- Billing and metering, including processing prepaid credit purchases through our payment processor, metering rentals per second, enforcing the spend caps you set, and reclaiming machines when a cap or balance is reached.
- Account security and fraud prevention, including detecting and preventing unauthorized access, abuse, and fraudulent transactions.
- Customer support, including responding to your questions and troubleshooting issues.
- Service improvement, including understanding how the Service is used so we can maintain reliability and improve features.
- Marketing communications, where you have opted in, to send you product updates and offers (see Section 8).
- Legal, tax, and accounting compliance, including keeping required transaction records and responding to lawful requests.
5. Legal Bases for Processing (GDPR)
If you are in the European Economic Area or the United Kingdom, we process your personal information only when we have a valid legal basis under Article 6 of the GDPR. The table below maps each purpose to the legal basis we rely on.
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Creating your account, provisioning rentals, providing SSH access, and delivering the Service you request. | Performance of a contract (Art. 6(1)(b)). |
| Processing prepaid credits and per-second billing. | Performance of a contract (Art. 6(1)(b)). |
| Account security, fraud prevention, abuse detection, and maintaining and improving the reliability of the Service. | Legitimate interests (Art. 6(1)(f)), namely operating a secure and reliable platform. |
| Customer support and service communications. | Performance of a contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)). |
| Sending marketing email. | Consent (Art. 6(1)(a)), which you may withdraw at any time. |
| Non-essential cookies and analytics, where applicable. | Consent (Art. 6(1)(a)). |
| Keeping transaction, tax, and accounting records. | Legal obligation (Art. 6(1)(c)). |
Where we rely on legitimate interests, we balance those interests against your rights and freedoms, and you may object as described in Section 12. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
6. SSH Keys
The public SSH keys you add are stored with your account and injected into the machines you rent so you can connect to them through the IPX gateway. The gateway operates as a reverse tunnel, so the underlying provider's IP address is not exposed to you and your public key is used only for the duration and purpose of your rentals. We never request, receive, or store your private SSH keys. Keep your private keys secure; anyone who holds them can access machines that trust your public key.
7. Cookies and Similar Technologies
We use a small number of cookies and similar technologies. Essential and session cookies are necessary to operate the Service, for example to keep you signed in and to protect against cross-site request forgery. These cannot be switched off through our interface because the Service will not function without them. Where we use analytics or other non-essential technologies to understand aggregate usage, we rely on your consent where required by law.
You can control cookies through your browser settings, including blocking or deleting cookies, though blocking essential cookies may prevent the Service from working. Where a consent banner or preference control is presented to you, you can use it to accept or decline non-essential cookies and to change your choice later. We honor recognized opt-out preference signals, such as Global Privacy Control, where applicable law requires.
8. Marketing Communications
Marketing email is optional and opt-in. You choose at sign-up whether to receive it, and you can change your preference at any time in your account settings. Every marketing message we send includes a clear identification of the sender and a working unsubscribe link, consistent with the United States CAN-SPAM Act, and we honor unsubscribe requests promptly. If you are in the EEA or the United Kingdom, your consent is the legal basis for marketing email, and you may withdraw that consent at any time with the same effect as unsubscribing. Withdrawing consent or unsubscribing from marketing does not stop transactional or service messages, such as billing receipts, security notices, and important account communications, which we send as part of operating the Service.
9. How We Disclose and Share Information
We share personal information only as needed to operate the Service, comply with law, or protect rights, and only with the categories of recipients listed below. These recipients act as our service providers, processors, or sub-processors, or are providers you choose to connect to.
| Recipient | Role | What is shared |
|---|---|---|
| Stripe | Payment processor. | Information needed to process prepaid credit purchases. Stripe handles card details directly; we never receive or store full card numbers. |
| GPU cloud providers | Third-party infrastructure on which we provision rentals. | The technical information needed to launch and configure a rented machine, including your public SSH key. |
| Amazon Web Services (AWS) | Cloud hosting for the IPX platform. | Data processed and stored as part of hosting the Service. |
| Google / GitHub | OAuth identity providers. | Only if you use OAuth sign-in; we receive basic profile data and exchange authentication tokens with the provider you choose. |
We may also disclose personal information: to professional advisers such as lawyers and accountants; to comply with a law, regulation, legal process, or enforceable governmental request; to enforce our Terms of Service or protect the rights, property, or safety of IPX, our users, or others; and in connection with a merger, acquisition, financing, or sale of assets, in which case we will continue to protect your information consistent with this policy.
We do not sell your personal information for money. We also do not disclose your personal information for cross-context behavioral advertising. See Section 13 for how this is treated under the CCPA/CPRA.
10. International Data Transfers
IPX is based in the United States, and our hosting and several of our service providers are located in or process data in the United States. If you access the Service from outside the United States, your personal information may be transferred to, stored in, and processed in the United States and other countries whose data protection laws may differ from those in your jurisdiction.
For transfers of personal information from the EEA, the United Kingdom, or Switzerland, we put in place appropriate safeguards as required by law, which include the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, and equivalent mechanisms with our service providers. You may contact us at contact@ipxtechholding.com to ask about the safeguards we use.
11. Data Retention
We keep personal information for as long as your account is active and for as long as we need it for the purposes described in this policy. After your account is closed, we retain certain information where necessary to meet legal, tax, accounting, and regulatory obligations, to resolve disputes, to prevent fraud and abuse, and to enforce our agreements. When personal information is no longer needed for these purposes, we delete it or anonymize it so it can no longer be associated with you. Transaction and billing records are generally retained for the periods required by applicable tax and accounting law.
12. Security
We use technical and organizational measures designed to protect personal information, including encryption of data in transit, storing passwords only in salted and hashed form, restricting access to those who need it, and operating on reputable cloud infrastructure. No method of transmission or storage is perfectly secure, however, and we cannot guarantee absolute security. You are responsible for keeping your account credentials and private SSH keys confidential, and you should notify us promptly at contact@ipxtechholding.com if you believe your account has been compromised.
13. Your GDPR Rights (EEA and UK)
If you are in the EEA or the United Kingdom, you have the following rights in respect of your personal information, subject to conditions and exceptions in applicable law.
- Access: to obtain confirmation of whether we process your personal information and a copy of it.
- Rectification: to have inaccurate personal information corrected and incomplete information completed.
- Erasure: to have your personal information deleted in certain circumstances (the "right to be forgotten").
- Restriction: to ask us to restrict processing in certain circumstances.
- Portability: to receive certain personal information in a structured, commonly used, machine-readable format and to have it transmitted to another controller where technically feasible.
- Objection: to object to processing based on our legitimate interests, and to object at any time to processing for direct marketing.
- Withdraw consent: to withdraw consent at any time where we rely on it, without affecting prior processing.
- Lodge a complaint: to complain to your local data protection supervisory authority. In the United Kingdom this is the Information Commissioner's Office (ICO). We would, however, appreciate the chance to address your concerns first.
To exercise these rights, contact us at contact@ipxtechholding.com. We will respond within the timeframes required by applicable law, generally within one month under the GDPR, and we may need to verify your identity before acting on a request.
14. Your California Privacy Rights (CCPA/CPRA)
If you are a California resident, the CCPA/CPRA gives you specific rights regarding your personal information. We honor these rights as described below.
14.1 Your rights
- Right to know and access: to request the categories and specific pieces of personal information we have collected about you, the sources, the business or commercial purposes for collecting it, and the categories of third parties to whom we disclose it.
- Right to delete: to request deletion of personal information we collected from you, subject to legal exceptions.
- Right to correct: to request correction of inaccurate personal information.
- Right to opt out of sale or sharing: California law gives you the right to opt out of the "sale" or "sharing" (for cross-context behavioral advertising) of personal information. We do not sell your personal information and we do not "share" it for cross-context behavioral advertising, so there is nothing for you to opt out of, but we honor recognized opt-out preference signals such as Global Privacy Control regardless.
- Right to limit use of sensitive personal information: we do not use or disclose sensitive personal information for purposes that would trigger this right, so no separate limitation is required, but you may contact us with any questions.
- Right to non-discrimination: we will not discriminate or retaliate against you for exercising any of your privacy rights, for example by denying service, charging different prices, or providing a different level of quality.
14.2 How to exercise your rights
You can exercise these rights by emailing contact@ipxtechholding.com. We will verify your request by confirming that you control the account or email address associated with the personal information, and we may ask for additional information to confirm your identity. You may use an authorized agent to submit a request on your behalf; we may require the agent to provide proof of your written permission and may still ask you to verify your own identity directly. We will respond within the timeframes the CCPA/CPRA requires, generally within 45 days, with an extension where permitted.
14.3 Categories of personal information and our disclosures in the past 12 months
In the past 12 months, we have collected the categories of personal information described in Section 2 (identifiers; account credentials; commercial and transaction information; SSH public keys; internet, usage, device, and log data; OAuth profile data; marketing preferences; and inferences). We have disclosed for a business purpose certain of these categories (for example, identifiers, commercial and transaction information, and SSH public keys) to the categories of recipients listed in Section 9, namely our payment processor, GPU cloud providers, our cloud host, and OAuth identity providers where you use them. We have not sold and have not "shared" (for cross-context behavioral advertising) any category of personal information.
14.4 "Shine the Light"
California's "Shine the Light" law (Civil Code Section 1798.83) lets California residents request information about disclosures of personal information to third parties for their own direct marketing purposes. We do not disclose your personal information to third parties for their own direct marketing. You may contact us at contact@ipxtechholding.com with any related questions.
15. Other US State Privacy Rights
Residents of certain other US states, including Virginia, Colorado, Connecticut, Utah, and Texas, may have rights similar to those described above, such as the rights to access, correct, delete, and obtain a copy of their personal information, and to opt out of targeted advertising, sale, or certain profiling. Because we do not sell personal information or use it for targeted advertising or profiling with legal effects, several of these do not apply in practice, but you may exercise any rights you have, and appeal a decision where your state provides an appeal right, by contacting us at contact@ipxtechholding.com. We will honor these rights as required by your state's law.
16. Children's Privacy
The Service is intended for users who are at least 18 years old and able to form a binding contract. We do not offer the Service to anyone under 16, and we do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact us at contact@ipxtechholding.com and we will take steps to delete it.
17. Automated Decision-Making
We do not engage in automated decision-making that produces legal or similarly significant effects about you without human involvement. We use automated checks to help detect fraud, abuse, and account risk and to enforce the spend caps and balances that govern rentals, but material decisions affecting your account involve human review where required by applicable law. If you have questions about these processes, contact us at contact@ipxtechholding.com.
18. EU/UK Representative and Data Protection Officer
You can reach our privacy team, including any EU or UK representative or data protection officer we appoint, at contact@ipxtechholding.com. Where the GDPR or UK GDPR requires us to designate a representative or a data protection officer, we will appoint one and you may contact them through that address.
19. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page, and, where the changes are material, we will provide additional notice as required by law, for example by email or an in-product notice. Your continued use of the Service after an update takes effect means you accept the revised policy.
20. How to Contact Us
For privacy questions, to exercise your rights, or for any other legal questions, contact us at contact@ipxtechholding.com. You can also reach us through our website at ipxtechholding.com. IPX Tech Holding LLC is the entity responsible for the personal information described in this policy, and this policy is governed by the laws of the State of California, United States, without regard to its conflict-of-laws rules, except where mandatory data protection law in your jurisdiction applies. Please also review our Terms of Service.