Skip to main content

Privacy Policy

Last updated:

On this page

1. Who we are

GpuToLease.ai (the "Service") is operated by AgentHub (agenthub.ie), a company based in Ireland ("we", "us", "our"). We are the controller of the personal data described in this policy.

For anything about this policy or your personal data, email sghaith@agenthub.ie.

This policy explains what personal data we collect when you use the website www.gputolease.ai, create an account and reserve machines, why we collect it, who we share it with, how long we keep it and what rights you have. It should be read with our Terms of Service.

2. The data we collect

2.1 Account data

When you create an account we collect your name, email address and password. Your password is stored only as a salted hash; we can't read it. We also record whether your email address is verified, your account's status (for example, if it's suspended and why) and the country detected when you signed up, which decides the currency and VAT you're charged.

2.2 SSH keys and startup scripts

We store the SSH public keys you add, with their names and fingerprints, and the startup scripts you save. Public keys are not secret, but they can identify you across services. Startup scripts contain whatever you write in them — please don't put passwords, tokens or other secrets in them.

2.3 Reservations

For each reservation we store the plan, dates, the instance name you chose, the machine assigned, the name and public key of the SSH key it was booked with, the startup script text you attached, the amounts charged, and a log of its events (for example: paid, live, completed, emails sent).

2.4 Payment data

Payments are processed by Stripe. You enter your card details on Stripe's page, and we never receive or store your full card number. We receive and store your Stripe customer ID, the IDs of your checkout sessions and payments, the amounts, currency and VAT, and whether a payment succeeded or was refunded.

2.5 Technical data

  • IP address. We use your IP address to detect your country when you visit, which sets the currency shown and whether you can reserve from where you are. It's also recorded with your login sessions, and with messages sent through our contact form to limit abuse.
  • Session data. When you log in we store a session record with your IP address and your browser's user agent, so you stay logged in and we can protect your account.
  • Server logs. Our servers log requests (including IP addresses) for security and troubleshooting.

2.6 Communications

When you use the contact form, we store your name, email address, subject, message and IP address. We also keep emails you send us and our replies, and a record of the service emails we send you.

2.7 What you do on a reserved machine

The files, programs and data you put on a reserved machine are yours. We don't look at them, except where needed to help you when you ask us to, to investigate a suspected breach of our Terms of Service, or where the law requires it. Everything on the machine is erased when your reservation ends, and we keep no backups of it.

PurposeLegal basis (GDPR Article 6)
Creating and running your account; taking reservations; preparing machines with your SSH key and startup script; sending emails about your account and reservationsPerformance of our contract with you
Taking payments, issuing invoices and receipts, charging the right VATPerformance of our contract; legal obligation (tax and accounting law)
Keeping financial recordsLegal obligation
Detecting your country for prices and eligibilityLegitimate interests (showing correct prices and offering the service only where we can)
Security, fraud prevention, rate limiting and investigating abuseLegitimate interests (protecting the Service, our customers and others)
Answering your messagesLegitimate interests; or steps before entering into a contract
Pre-start reminders, "reservation live" and "ending soon" emailsPerformance of our contract (you can turn them off in Settings)
Product news emailsConsent (off by default; withdraw it at any time in Settings)

We don't sell your personal data, we don't use it for advertising, and we don't make decisions about you based solely on automated processing that have legal or similarly significant effects.

4. Who we share it with

We use a small number of service providers ("processors") who handle personal data on our behalf, under contracts that require them to protect it:

  • Stripe — payment processing, invoices and receipts, and fraud prevention. For some purposes, such as meeting its own legal obligations, Stripe acts as an independent controller; see Stripe's privacy policy.
  • Resend — delivery of our emails.
  • Our hosting providers — the servers and database that run the Service.
  • ip-api.com — when our hosting doesn't supply a visitor's country, your IP address is sent to this geolocation service to look it up.

We may also disclose personal data where the law requires it, to protect our rights or the safety of others, or to a successor if our business is transferred (we'll tell you if that happens).

5. International transfers

Some of our providers, including Stripe and Resend, are based in or process data in the United States. Where personal data is transferred outside the European Economic Area, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses or the EU–US Data Privacy Framework where the provider is certified under it.

6. How long we keep it

  • Account data, SSH keys and saved scripts: while your account is open. When you ask us to close your account, we delete or anonymise them within 30 days, except as below.
  • Payment, invoice and reservation records: for 6 years after the end of the financial year they relate to, as Irish tax law requires.
  • Contact messages: up to 2 years after the conversation ends.
  • Login sessions: until they expire or you log out; they're deleted immediately if your account is suspended.
  • Server logs: for a limited period, for security and troubleshooting.
  • Data on reserved machines: erased when each reservation ends. No backups are kept.

7. Cookies and browser storage

We use only what the Service needs to work. There are no analytics or advertising cookies.

NameTypePurposeDuration
gtl.session_token and related gtl. cookiesCookie (essential)Keep you logged inUntil you log out or the session expires
gtl.themeCookie (preference)Remember light, dark or system theme1 year
themeLocal storage (preference)The same theme choice, read by the pageUntil you clear it
Reservation draftSession storageKeep your choices on the reservation page while you add a key or pay; it never leaves your browserUp to 24 hours

Stripe's checkout pages, on Stripe's own domain, use Stripe's cookies to process your payment and prevent fraud; they're covered by Stripe's policies.

You can block or delete cookies in your browser, but you won't be able to log in without the session cookie.

8. Security

We protect personal data with measures appropriate to the risk, including encryption in transit (HTTPS), hashed passwords, encryption at rest for machine access credentials, access controls limited to the people who need them, and wiping every machine at the end of each reservation. No system is perfectly secure, but we work to keep your data safe and will notify you and the authorities of a personal data breach where the law requires.

9. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you and receive a copy;
  • have inaccurate data corrected (you can change your name in Settings yourself);
  • have your data erased, subject to the records we must keep by law;
  • restrict how we use your data in certain circumstances;
  • data portability: receive the data you gave us in a machine-readable format;
  • object to processing based on our legitimate interests; and
  • withdraw consent at any time, where we rely on it (for example, product news), without affecting what we did before.

To exercise any of these rights, email sghaith@agenthub.ie from the address on your account. We'll reply within one month, and may ask you to confirm your identity.

You also have the right to complain to a data protection authority. In Ireland that's the Data Protection Commission (dataprotection.ie); you can also contact the authority where you live or work. We'd appreciate the chance to address your concern first.

10. Children

The Service is not intended for anyone under 18, and we don't knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we'll delete it.

11. Changes to this policy

We may update this policy as the Service or the law changes. We'll post the new version on this page with a new "Last updated" date, and for significant changes we'll tell you by email or on the site before they take effect.

12. Contact