legal
Privacy Policy
Last updated: September 14, 2026
1. Overview
This policy describes what data Pyxsoft Computing Ltd, a company registered in the United Kingdom ("Pyxsoft", "we"), collects when you visit corepanel.net, purchase a CorePanel subscription, or run the CorePanel software, and how we use it. CorePanel is self-hosted: your websites, email and databases live on your server, and we have no access to them.
2. Data we collect
Website. corepanel.net collects standard server logs (IP address, user agent, pages visited) used for security and aggregate traffic statistics. We do not run third-party advertising trackers.
Purchases. Payments are processed by our Merchant of Record, Paddle. Paddle collects the billing information needed to complete your order (name, email, country, payment details) under its own privacy policy. We never see or store your card or PayPal credentials. From Paddle we receive your email address, the product purchased and the subscription status, which we store to manage your license.
Licensing. When you activate or validate a paid license, the CorePanel software contacts our license service and we record: the license key, your server's public IP address (as observed on the connection), the hostname you configure, the CorePanel version, and timestamps. This is the minimum needed to enforce per-server licensing. The free Personal edition requires no license, no registration, and performs no license phone-home.
Usage statistics. By default, a CorePanel server sends one
check-in per day so that we know how many servers are running and on what. It contains a random installation id generated at install time, the CorePanel
version and edition, the operating system and architecture, how long ago it was
installed, counts of accounts, domains, mailboxes, databases, applications and
WordPress sites, and the names of the features that are enabled. It contains no
hostnames, no domain names, no email addresses and no account names. We keep the
public IP address the check-in arrives from, resolve it to a country, and may look
up its reverse DNS (PTR) record. CorePanel staff can see that address and its
reverse DNS for each installation, to support customers and to detect abuse. You
can turn this off at any time in
Server → Settings, with corepanel telemetry disable,
or fleet-wide with COREPANEL_NO_TELEMETRY=1; nothing else about your
server changes. The full field list is in the
documentation.
The cPanel migration tool. corepanel-transform checks
a cPanel server and converts it into a CorePanel one. By default it reports what it
found and what it did: a one-way hash of the server's machine id, a random id for
the transformation, the versions found on that server (OS, cPanel, database, PHP,
and the names of the mail, DNS and FTP daemons), counts of accounts, domains,
mailboxes and databases, the migration score and the stable codes of what the check
found, and for each stage whether it finished, how long it took, how long sites were
offline, and the id of the step that stopped it if one did. It contains no
hostnames, no domain names, no account names and no error messages — the
step's identifier travels, never its text. It carries no license key, and the tool
runs on a server that is not a CorePanel installation. Turn it off with
--no-telemetry on any command or COREPANEL_NO_TELEMETRY=1
in the environment; the full field list is in the
documentation.
Support. If you email us, we keep the correspondence.
3. What we do not collect
The CorePanel software does not send us your hosted sites' content, your users' data, your email, analytics about your visitors, or your panel credentials.
4. How we use data
We use the data above to deliver and enforce licenses, provide support, prevent fraud and abuse, and send transactional email about your subscription (receipts and renewal notices are sent by Paddle). We only send marketing email with your consent, and every such email includes an unsubscribe link.
5. Sharing
We do not sell personal data. We share it only with processors necessary to run the service — Paddle (payments) and our hosting infrastructure providers — or when required by law.
6. Retention & security
License and purchase records are kept for as long as your license exists and as required for tax and accounting obligations. Server logs are rotated on a short schedule. Data is transmitted over TLS and stored on access-controlled systems.
Reports from the cPanel migration tool are kept under the same window and the same terms as the check-ins below, and are purged by the same pass.
Usage check-ins are kept as a daily series for up to 24 months, which is what makes year-on-year comparison possible, together with the address each installation last checked in from and its reverse DNS. A check-in carries no license key and is not stored against a customer account or an order. Disabling them stops future check-ins but does not remove earlier ones — your server has no way to reach our records. To have the data held under your installation id deleted, send us that id (it is shown in Server → Settings) at info [at] corepanel [dot] net.
7. Your rights
Under the UK GDPR — and, depending on your jurisdiction, the EU GDPR or similar laws — you may have rights to access, correct, export or delete your personal data, and to object to or restrict its processing. To exercise them, contact info [at] corepanel [dot] net. For billing data held by Paddle, we will coordinate with Paddle or you may contact them directly.
8. Changes & contact
We may update this policy; material changes will be announced on this page with an updated date. Questions: info [at] corepanel [dot] net.