Rust Server Manager
Features Pricing Contact Discord Customer Portal

Privacy Policy

Last updated: 12 September 2026

Who we are

Rust Server Manager is the seller of RSM Web and the controller for the personal data we collect about users of this site and the customer portal — we decide what is collected and why. “Rust Server Manager” is our registered legal name and also the name the product trades under; there is no separate trading name.

Our principal place of business is Pretoria North, Gauteng, South Africa.

For any privacy question, or to exercise the rights set out below, email support@rustservermanager.com.

What we store

  • Your email address and a bcrypt hash of your password — never the password itself.
  • Session metadata when you sign in: IP address, browser user-agent string, and last-active time, so you can see and revoke your own active sessions.
  • Machine metadata for each RSM Web installation connected to your account: a machine label you (or RSM Web) provide, its IP address when the machine was registered, and when it was last seen — used only to enforce the three-machine limit and let you manage your own machines.
  • If you ask us to verify a pre-existing purchase, we look up matching PayPal transactions for the email you provide and keep a record of that search (who searched, what was found) for our own audit trail.

Why we're allowed to hold it

Each thing above is held on one of these grounds:

  • To perform our contract with you — your email address and password hash, your licenses, and the machine metadata that enforces the three-machine limit. Without these we cannot give you an account or a working license.
  • Our legitimate interests — session metadata and the purchase-verification audit trail, which exist to keep accounts secure, let you revoke your own sessions, and let us resolve disputes about who owns a license.
  • Your consent — marketing email, if you ever opt in. You can withdraw it at any time.
  • A legal obligation — where we're required to keep or disclose something by law.

Email

We send account-related email only: verification, password resets, and license-related notices. No marketing email unless you separately opt in somewhere that says so.

Who else sees it

We don't sell your data and we don't share it beyond what running the service requires. The categories of recipient are:

  • Paddle, our reseller and the merchant of record for purchases made through this site. Paddle handles the sale, payment, tax compliance and invoicing, and processes refunds and chargebacks. Paddle collects your payment details directly and is an independent controller of that data — we never see or store your card details. See Paddle's privacy notice.
  • PayPal, for purchases made before we moved to Paddle, and when you explicitly ask us to verify one.
  • Service providers who host and operate the service on our behalf — our hosting and email providers, and Cloudflare, which sits in front of this site and the portal to route traffic and block abuse.
  • Professional advisers (legal, accounting), and authorities, where required by law or to protect rights and safety.

We don't run third-party advertising trackers on this site or the account portal.

How long we keep it

Account data — your email address, password hash, licenses and machines — is kept for as long as your account exists. Delete your account and it goes with it, except where we're required to keep a record for longer (for example, transaction records Paddle and we must retain for tax purposes). Session metadata is kept only while the session is active and for a short period afterwards so you can review recent sign-ins. The purchase-verification audit trail is kept while it remains relevant to proving who owns a license.

Keeping it safe

We use appropriate technical and organisational measures to protect your data: passwords are stored only as bcrypt hashes and never in plain text, traffic to this site and the portal is encrypted in transit with TLS, and access to production systems is restricted to the people who need it.

Cookies and local storage

Strictly necessary only. There are no analytics or advertising cookies on this site or the portal, so there is nothing to opt in or out of.

  • Your sign-in token is held in your browser's local storage (or session storage, if you didn't tick “remember me”) rather than in a cookie. It stays on your device and is sent only to our API.
  • One small cookie, rsm_session_hint, is set across rustservermanager.com. It contains nothing but the fact that someone is signed in — no identifier, no email, no role — and exists only so this site's header can show a “Customer Portal” link instead of “Sign in”. It is never used to authenticate anything.
  • Cloudflare sets its own cookies for the anti-abuse check on the sign-in and registration forms, and for basic security and traffic routing.

Signing out, or clearing site data in your browser, removes all of these.

Your data, your account

You can ask us to:

  • Access — get a copy of what we hold about you.
  • Correct — fix anything inaccurate.
  • Delete — erase your data. Deleting your account also revokes any license tied to it.
  • Restrict or object — limit how we use it, or object to processing based on our legitimate interests.
  • Port — receive your data in a portable format.
  • Withdraw consent — where we relied on your consent, withdraw it at any time.

Email support@rustservermanager.com and we'll respond within one month. If you think we've handled your data badly, you're entitled to complain to your local data protection authority.

Changes

We may update this policy; material changes will be reflected here with an updated date.

© Rust Server Manager
Features Pricing Contact Discord Terms Refunds Privacy