This Privacy Policy (the "Policy") describes how MEVCORE (the "Operator") collects, uses, stores and protects the personal data of users of the mevcore.com/en website and customers of its services. The Policy is an integral part of the Public Offer, which contains the Operator's details.
Personal data is processed in accordance with the Law of Ukraine "On Personal Data Protection" and other regulations of Ukraine. By registering on the website, ordering services or contacting us, you confirm that you have read this Policy.
1. What data we collect
1.1 Data you provide yourself:
- account data — first and last name, email address, password (stored only as a hash);
- contact and billing data — phone number, address, company name and tax details, if you provide them for invoices and contracts;
- domain owner data — contact person, address, phone and email required by the registry to register or transfer a domain;
- content of your requests — tickets, live chat messages, attachments, abuse reports.
1.2 Data from sign-in services. If you sign in with Google, Facebook, GitHub or Discord, we receive your name, email address and account ID from that service. Passwords for these services are never shared with us.
1.3 Data collected automatically: IP address, browser and device type, date and time of requests, pages you visited, and activity logs in the client area (sign-ins, settings changes, service operations).
1.4 Payment data. Payments are processed by payment providers. We receive the payment status, amount and transaction ID from them; full bank card details are not stored on our servers.
1.5 Data on your services. Files, databases, email and other content you host on our hosting or servers belong to you. We do not view or use them, except where necessary to provide a service at your request, fix a technical problem or comply with legal requirements.
2. Why we process data
- registering and maintaining your account, signing in to the client area, two-factor authentication;
- providing paid services: hosting, servers, domains, SSL certificates, email;
- invoicing, recording payments, concluding contracts and bookkeeping;
- technical support and responding to requests;
- service notifications — about invoices, service expiry, scheduled maintenance and changes to terms;
- security — detecting fraud, abuse and unauthorised access, and handling abuse reports;
- compliance with the laws of Ukraine.
Marketing emails are sent only with your separate consent, which you can withdraw at any time in your notification settings or via the link in the email.
3. Who we share data with
We do not sell personal data. Data is shared with third parties only to the extent necessary to provide services:
- domain registrars and registries, including Ukrainian Internet Names Center LLC — to register, renew and transfer domains. Some of this data may be published in WHOIS according to the rules of the domain zone;
- certificate authorities — to issue SSL certificates;
- payment providers and banks — to process payments and refunds;
- infrastructure providers (data centres, email services) acting on our behalf and bound by confidentiality;
- government authorities — in the cases and manner expressly provided for by the laws of Ukraine.
If data is transferred outside Ukraine (for example, to registries of international domain zones), it is transferred only to the extent necessary to provide the ordered service.
4. Cookies
The website uses cookies required for it to work: a session cookie for signing in to the client area, a cross-site request forgery (CSRF) protection token, and preferences such as your selected currency. Without these cookies you cannot sign in or place an order. You can delete or block cookies in your browser settings, but some website features will then be unavailable.
5. How long we keep data
- account data — while the account is active;
- invoices, payments and contracts — for the periods set by tax and accounting laws;
- tickets, chat messages and activity logs — for the period needed to provide services and resolve possible disputes;
- server technical logs — for a limited period necessary to ensure security.
After the retention period ends, data is deleted or anonymised.
6. How we protect data
We use encrypted connections (HTTPS), store passwords only as hashes, encrypt sensitive settings, restrict staff access to personal data and keep a log of administrator actions. Two-factor authentication is available for your account — we recommend enabling it.
No method of transmitting or storing data is completely secure. If we detect an incident affecting your data, we will notify you and take steps to limit its consequences.
7. Your rights
Under Article 8 of the Law of Ukraine "On Personal Data Protection", you have the right to:
- know what data about you is processed, for what purpose and to whom it is disclosed;
- access your data;
- request correction of inaccurate or outdated data;
- request deletion of your data or that processing stop, unless this conflicts with the law or the terms of the services provided;
- withdraw consent to data processing;
- file a complaint with the Ukrainian Parliament Commissioner for Human Rights or with a court.
You can change most of your account data yourself in your account settings. To exercise your other rights, write to us — we will reply within 30 calendar days.
8. Children's data
MEVCORE services are intended for persons aged 18 or over, or who have the consent of their parents or legal guardians. We do not knowingly collect children's data. If you believe a child has provided us with their data, let us know and we will delete it.
9. Changes to this policy
We may update this Policy. The new version takes effect when it is published on this page. We will notify registered customers of material changes by email or in the client area.
10. Contacts
For questions about the processing of personal data, contact us:
- by email — info@mevcore.com;
- through the ticket system in the client area;
- other contact options are listed on the Contacts page.