What we collect, why, who else sees it, and how to get it deleted.
Last updated 7 September 2026. This English text is the authoritative version.
This matters, so it comes first. FoundryPanel handles two kinds of data and our role is different for each.
| What | Why |
|---|---|
| Email, name, password hash | To create and secure your account |
| Panel name, address, settings | To run your panel |
| Order counts per period | To work out your plan and invoice |
| IP address and last sign-in time | To spot account takeover and abuse |
| Support tickets you send us | To answer you |
We store passwords only as a hash and cannot read them. We do not store your card number โ payments to us go through a payment processor that handles it.
Gateway keys you enter (for your own payment accounts) are stored so your panel can use them. They are never returned by any API response โ screens only show whether a field is filled.
On your instructions, we store what your panel needs to work: member email and password hash, balance and transactions, orders and the links or usernames they contain, tickets, contact details they choose to add, and sign-up and last-seen IP addresses. We hold this for you and delete it when you delete it or close the panel.
Telling your members about this is your job. Your panel ships with a privacy policy page you must fill in.
We use a session cookie to keep you signed in, and browser storage to remember your language and a few screen preferences. That is all. No advertising cookies, no third-party trackers, no analytics that follow you across sites. Because there is nothing to consent to, there is no cookie banner.
If you switch on Google Analytics inside your own panel, that is your choice and your disclosure to make.
| Who | What they see |
|---|---|
| Cloudflare (hosting, database, storage, CDN) | Everything, as the infrastructure it runs on |
| Resend (email delivery) | Recipient address and message content, when we send you mail |
| Our payment processor | What is needed to take your subscription payment |
| Your own providers and gateways | Only what your panel sends them, on your instructions |
We do not sell personal data, and we never will. We do not share it for advertising. We hand data to authorities only when a valid legal order requires it, and we tell you unless we are forbidden from doing so.
On Cloudflare's global network, which means data may be stored and processed outside your country, including outside the EEA and outside Korea. Transfers out of the EEA rely on the European Commission's standard contractual clauses.
You can ask us for a copy of your data, to correct it, to delete it, to restrict what we do with it, or to object. You can close your account and delete your panels yourself, at any time, from the console โ that is the fastest route and needs no request.
For anything else, email support@foundrypanel.com. We answer within 30 days. If you are in the EEA or the UK you may complain to your data protection authority; in Korea, to the Personal Information Protection Commission.
If a request concerns data held inside someone's panel, it has to go to that panel's operator โ we are only the processor there and will forward it.
FoundryPanel is for businesses. It is not for anyone under 18, and we do not knowingly collect data from children. If you believe a child's data reached us, tell us and we will delete it.
If a breach puts your data at risk, we will tell affected account holders and the relevant authority within 72 hours of finding out, with what happened and what to do about it.
If we change this policy in a way that matters, we email the address on your account at least 30 days before it takes effect.