Cookie Policy
Last updated: 2026-04-10
Effective Date: 8 April 2025
Last Updated: 8 April 2026
Version: 2.0
Jurisdictions Covered: EU/EEA (GDPR/ePrivacy) • United Kingdom (UK GDPR) • United States (CCPA/CPRA, COPPA) • Global
Postal Address: Ramparts Hosting LLC • PO Box 1 • Alexandria, LA 71301 • USA
1. Introduction
This Cookie Policy explains how Ramparts Hosting (“we”, “us”, or “our”), operating at rampartshosting.com, uses cookies and similar tracking technologies when you visit our website or use our Minecraft server hosting services.
This policy is issued in compliance with:
- Regulation (EU) 2016/679 — General Data Protection Regulation (GDPR)
- Directive 2002/58/EC as amended by Directive 2009/136/EC — EU ePrivacy Directive
- UK GDPR as retained in UK law by the European Union (Withdrawal) Act 2018, supplemented by the Data Protection Act 2018
- California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) — Cal. Civ. Code § 1798.100 et seq.
- Children’s Online Privacy Protection Act (COPPA) — 15 U.S.C. § 6501 et seq.
- Applicable data protection and privacy laws in other jurisdictions where our services are accessed
By using our website, you acknowledge that you have read this Cookie Policy. Where cookies require your consent, we will ask for it explicitly via our cookie consent banner before placing any non-essential cookies.
2. What Are Cookies?
Cookies are small text files placed on your device by websites you visit. They are widely used to make websites work efficiently, to remember your preferences, and to provide information to site operators.
Similar technologies we may use include:
- Local storage — browser-side key/value storage that persists across sessions
- Session storage — temporary browser-side storage cleared when the tab is closed
- Pixel tags / web beacons — invisible images used to record page visits
3. Age Restriction and Children’s Privacy
Ramparts Hosting services are strictly intended for individuals aged 18 years or older. We do not knowingly collect personal data from anyone under 18. By creating an account and using our services, you represent that you are at least 18 years of age. Account holders are solely responsible for ensuring that any end-user activity on servers they operate through our platform complies with applicable laws governing minors.
COPPA Compliance (United States): We do not knowingly collect personal information from children under 13 years of age. If we learn that we have inadvertently collected such information, we will delete it promptly. Parents or guardians who believe a child under 13 has provided us with personal data should contact us immediately at the address in Section 12.
GDPR Article 8 (EU/EEA): Because our services are restricted to adults (18+), the lower age thresholds established under Article 8 (ages 13–16 depending on member state) do not apply to our account holders. Cookie consent is therefore governed by the standard adult consent framework under GDPR Article 7.
UK GDPR / Children’s Code: We do not provide services directed at children and do not engage in the profiling or targeted advertising of minors. The UK Age Appropriate Design Code does not apply to our platform as currently configured.
4. Legal Basis for Processing
Our legal bases for processing data collected through cookies vary by jurisdiction:
- Strictly Necessary (EU/EEA & UK): Art. 6(1)(b) GDPR / UK GDPR — contract performance; exempt from consent under ePrivacy Directive Recital 66.
- Strictly Necessary (US California):Exempt from CCPA opt-out rights as “service providers” cookies used solely to provide a requested service.
- Functional / Preference (EU/EEA & UK): Art. 6(1)(a) GDPR / UK GDPR — your explicit consent via the cookie banner.
- Functional / Preference (US California): Opt-out right applies; honoured via our cookie preference centre and GPC signal.
- Analytics / Performance (EU/EEA & UK): Art. 6(1)(a) GDPR — consent. No cookie-based analytics are currently deployed; see §5.3 for the cookieless analytics we do use.
- Marketing / Targeting (All): Consent. None currently deployed; will require opt-in before any are placed.
5. Categories of Cookies We Use
5.1 Strictly Necessary Cookies
These cookies are essential for the website and dashboard to function. They cannot be switched off and do not require your consent. They are set in response to actions you take, such as logging in or completing a payment.
| Name | Provider | Purpose | Duration | Type |
|---|---|---|---|---|
ramparts_session | Ramparts Hosting | Authenticates your dashboard session after Microsoft OAuth login. | Session | HTTP Cookie |
ramparts_csrf | Ramparts Hosting | CSRF protection token securing all form submissions and API calls. | Session | HTTP Cookie |
cf_clearance | Cloudflare | Records that you have passed a Cloudflare security challenge. | 1 year | HTTP Cookie |
__cf_bm | Cloudflare | Bot management — distinguishes human visitors from automated traffic. | 30 minutes | HTTP Cookie |
msa_session | Microsoft | Session token issued by Microsoft Identity Platform during OAuth 2.0 login flow. | Session | HTTP Cookie |
ESTSAUTHPERSISTENT | Microsoft | Persistent authentication token for returning Microsoft account users (only set if “Stay signed in” is selected). | 90 days | HTTP Cookie |
__stripe_mid | Stripe | Fraud prevention — machine identifier used across payment sessions. | 1 year | HTTP Cookie |
__stripe_sid | Stripe | Fraud prevention — session identifier used during active payment flows. | 30 minutes | HTTP Cookie |
Note: Microsoft and Stripe may update the specific cookies they set as part of their own platform updates. Refer to their respective privacy and cookie policies for a current list: privacy.microsoft.com • stripe.com/privacy.
5.2 Functional / Preference Cookies
These cookies enable enhanced functionality and personalisation. They are only placed with your consent. Declining them means certain preferences will not be remembered between sessions.
| Name | Provider | Purpose | Duration | Type |
|---|---|---|---|---|
ramparts_pref | Ramparts Hosting | Stores non-essential UI preferences such as dashboard theme and panel layout. The dashboard functions fully without this cookie. | 1 year | HTTP Cookie |
ramparts_locale | Ramparts Hosting | Remembers your preferred language setting for the dashboard. | 1 year | HTTP Cookie |
ramparts_tz | Ramparts Hosting | Stores your time-zone preference for displaying server and backup timestamps. | 1 year | HTTP Cookie |
5.3 Analytics / Performance Cookies
We do not currently deploy any cookie-based analytics. Our marketing site uses two cookieless analytics layers which do not set cookies and, under the ePrivacy Directive Recital 66 and equivalent UK guidance, do not require consent:
- Cloudflare Web Analytics — server-side aggregation at the Cloudflare edge. No cookies, no device identifiers, no cross-site tracking.
- Plausible Analytics — used in its cookieless mode. It does not set cookies, does not use
localStorage, does not generate persistent device or user identifiers, and does not share data with third parties. You can verify this in your browser’s developer tools (Application → Cookies) on any page of this site.
If we ever introduce cookie-based analytics, this policy will be updated and your explicit consent will be sought via the cookie banner before any analytics cookies are placed.
5.4 Marketing / Targeting Cookies
We do not currently use marketing or advertising cookies. Should we introduce them in the future, we will update this policy and obtain your explicit opt-in consent before they are placed. We will never introduce marketing cookies without a prior policy update and renewed consent.
6. Your Consent and How to Manage It
When you first visit rampartshosting.com, you will be presented with a cookie consent banner. You may:
- Accept all — strictly necessary and any optional cookies
- Reject all — only strictly necessary cookies will be set
- Customise your preferences — individually enable or disable each optional category
Note on “Reject all”: strictly necessary cookies (authentication, CSRF protection, payment fraud prevention, Cloudflare DDoS and bot mitigation) continue regardless of your choice. They are exempt from consent under ePrivacy Directive Recital 66 because without them the site and customer dashboard cannot perform the services you have explicitly requested. “Reject all” therefore means rejecting all optional categories while the exempt strictly necessary category remains active — this is the standard interpretation under GDPR, UK GDPR, and CCPA/CPRA.
Your consent choice is recorded and respected throughout your session and on return visits. You may withdraw or change your consent at any time by clicking “Cookie Preferences” in the website footer.
EU/EEA and UK: Consent meets the requirements of GDPR Article 7 and Recital 32 — it is freely given, specific, informed, and unambiguous. We do not use pre-ticked boxes or infer consent from inaction.
United States (CCPA/CPRA):California residents have the right to opt out of the “sale” or “sharing” of personal information. We do not sell or share your personal information as those terms are defined under the CCPA/CPRA. Our cookie preference centre and the GPC signal (see Section 7) allow you to manage optional cookies independently.
7. Do Not Track (DNT) and Global Privacy Control (GPC)
Do Not Track (DNT): Browsers may send a DNT signal indicating that you prefer not to be tracked across websites. Because there is no uniform standard governing DNT signals, our website does not currently respond to DNT signals differently from non-DNT sessions. We rely instead on our cookie consent banner to obtain and record your preferences.
Global Privacy Control (GPC):We honour the GPC signal as a valid opt-out of the sale or sharing of personal information under the CCPA/CPRA. When our systems detect a GPC signal from your browser, we will treat it as a request to decline all optional cookies in the same way as manually selecting “Reject all” in the consent banner.
8. Managing Cookies via Your Browser
You can control or delete cookies through your browser settings. Instructions for common browsers:
- Google Chrome:
chrome://settings/cookies - Mozilla Firefox:
about:preferences#privacy - Microsoft Edge:
edge://settings/cookies - Safari:Preferences > Privacy > Manage Website Data
- Opera:Settings > Advanced > Privacy & security > Site Settings > Cookies
Blocking strictly necessary cookies may prevent core parts of our website and customer dashboard from functioning correctly.
9. Third-Party Services and Their Cookies
The following third parties may set cookies on your device when you interact with their services embedded in or integrated with our platform. Each has its own privacy and cookie policies, which we encourage you to review.
- Cloudflare, Inc. (USA) — DDoS protection, CDN, and bot management for all traffic to rampartshosting.com. cloudflare.com/privacypolicy
- Microsoft Corporation (USA) — OAuth 2.0 / Xbox Live authentication for the customer dashboard (Minecraft UUID-based identity). privacy.microsoft.com
- Stripe, Inc. (USA) — Payment processing and subscription management; fraud prevention cookies placed during checkout. stripe.com/privacy
- Backblaze, Inc. (USA) — Operator-side backup storage; no user-facing cookies are placed by Backblaze. backblaze.com/company/privacy
10. International Data Transfers
All of our third-party service providers are based in the United States. Where personal data collected via cookies is transferred outside the European Economic Area (EEA) or the United Kingdom, we ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs) — approved by the European Commission under GDPR Article 46(2)(c); our primary and most robust safeguard for all US-based providers.
- UK International Data Transfer Agreement (IDTA) — UK equivalent of SCCs, applicable to data transferred from the UK to our US-based providers under UK GDPR.
- EU–US Data Privacy Framework (DPF) — applicable where a US provider is certified under the DPF. This framework remains subject to legal challenge; SCC coverage is maintained in parallel as a fallback.
You may request a copy of applicable transfer safeguards by contacting us using the details in Section 12.
11. Your Rights by Jurisdiction
11.1 EU/EEA Rights (GDPR)
- Right of Access (Art. 15): Request a copy of the personal data we hold about you, including data collected through cookies.
- Right to Rectification (Art. 16): Ask us to correct inaccurate or incomplete personal data.
- Right to Erasure (Art. 17): Request deletion of your personal data where there is no compelling reason for continued processing.
- Right to Restrict Processing (Art. 18): Ask us to suspend processing of your data in certain circumstances.
- Right to Data Portability (Art. 20): Receive your data in a structured, commonly used, machine-readable format.
- Right to Object (Art. 21): Object to processing based on legitimate interests or for direct marketing.
- Right to Withdraw Consent (Art. 7(3)): Withdraw consent for optional cookies at any time via the preference centre. Does not affect the lawfulness of prior processing.
- Right to Lodge a Complaint (Art. 77): Complain to your local supervisory authority. See edpb.europa.eu for the full list of EEA authorities.
11.2 UK Rights (UK GDPR / Data Protection Act 2018)
UK residents hold equivalent rights to those listed above under UK GDPR. The relevant supervisory authority is the Information Commissioner’s Office (ICO): ico.org.uk — 0303 123 1113.
11.3 California Rights (CCPA / CPRA)
- Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected, the sources, the business purpose, and whether it has been sold or disclosed.
- Right to Delete: Request deletion of personal information we have collected, subject to certain exceptions.
- Right to Correct: Request correction of inaccurate personal information we hold about you.
- Right to Opt Out of Sale/Sharing: We do not sell or share your personal information. If this changes, you will have the right to opt out, and we will update this policy accordingly.
- Right to Limit Use of Sensitive PI: Limit our use of sensitive personal information to permitted purposes. We do not use sensitive personal information beyond what is necessary to provide our services.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.
To submit a verifiable consumer request under CCPA/CPRA, contact us using the details in Section 12. We will respond within 45 calendar days as required by law, with a possible 45-day extension where reasonably necessary.
11.4 Other Jurisdictions
Residents of other jurisdictions with applicable privacy laws (including Virginia VCDPA, Colorado CPA, Brazil LGPD, Canada PIPEDA / Law 25, Australia Privacy Act) may have equivalent rights. We commit to honouring the spirit of data subject rights across all jurisdictions we serve. Please contact us to exercise any applicable rights.
12. Contact and Data Controller Details
For all cookie-related enquiries, data subject requests, rights exercises, or complaints:
- Data Controller / Business: Ramparts Hosting LLC
- Website: rampartshosting.com
- Privacy / Data Requests: privacy@rampartshosting.com
- Postal Address: Ramparts Hosting LLC • PO Box 1 • Alexandria, LA 71301 • USA
- EU Response Time: Within 30 calendar days (GDPR Article 12)
- UK Response Time: Within 30 calendar days (UK GDPR)
- US Response Time: Within 45 calendar days, extendable by a further 45 days (CCPA/CPRA)
13. Changes to This Cookie Policy
We may update this Cookie Policy to reflect changes in technology, regulation, or our practices. The “Last Updated” date at the top of this document will always reflect the most recent revision.
For material changes — particularly those affecting cookies that require consent — we will notify you via a prominent banner on the website and, where required by applicable law, re-obtain your consent before placing any new optional cookies.
Continued use of our website after a policy update constitutes acknowledgement of the revised policy but does not constitute consent to new optional cookies unless you have actively provided it via the consent banner.
14. Supervisory Authorities
If you believe we have not adequately addressed your concerns, you have the right to complain to the relevant supervisory authority for your jurisdiction:
- EU/EEA: Member State Data Protection Authority (varies by country) — edpb.europa.eu/about-edpb/members
- United Kingdom:Information Commissioner’s Office (ICO) — ico.org.uk
- United States (California): California Privacy Protection Agency (CPPA) — cppa.ca.gov
- United States (Federal): Federal Trade Commission (FTC) — COPPA enforcement — ftc.gov/privacy
— End of Cookie Policy —
See also: Privacy Policy • Terms of Service • Acceptable Use Policy • Imprint