Privacy Policy
- 1. Scope
- 2. Personal Data We Collect
- 3. How Personal Data Is Used
- 4. Legal Bases
- 5. Customer Data and Processing Roles
- 6. Provider Credentials and Sensitive Configuration Data
- 7. Payments
- 8. Cookies and Similar Technologies
- 9. How Personal Data Is Shared
- 10. International Data Transfers
- 11. Data Retention
- 12. Data Export, Deletion, and Account Closure
- 13. Security
- 14. Security Incidents
- 15. Marketing Communications
- 16. Your Privacy Rights
- 17. Automated Operational Processing
- 18. Children’s Privacy
- 19. Third-Party Services and Links
- 20. Changes to This Privacy Policy
- 21. Contact Us
This Privacy Policy explains how Nova Panel collects, uses, shares, and protects personal data in connection with the Nova Panel website, demo and test environments, Nova Panel software platform, Nova Connect, application and contact forms, accounts, and related communications collectively referred to as the “Service.”
Nova Panel is an independent software project currently available in limited beta. References to “Nova Panel,” “we,” “us,” and “our” mean the person or team operating the Service under the Nova Panel name.
For privacy questions or requests, contact [email protected].
1. Scope
This Privacy Policy applies when you:
- visit the Nova Panel website;
- submit a demo, setup, contact, onboarding, partnership, or other application form;
- create or administer a Nova Panel account;
- create, configure, or operate a Nova Panel;
- connect a custom domain;
- use Nova Connect;
- communicate with support or onboarding;
- use a demo, beta, Free, paid, or other production version of the Service;
- receive operational or marketing communications from Nova Panel.
When a Nova Panel customer uses the Service to process personal data relating to its own staff, customers, users, or other individuals, that customer generally determines why and how the data is processed.
In that context, Nova Panel processes the data on the customer’s behalf according to:
- the customer’s instructions;
- the Service configuration;
- the applicable agreement;
- any applicable data-processing terms;
- legal requirements.
This Privacy Policy does not govern the independent privacy practices of:
- Nova Panel customers;
- SMM providers;
- payment gateways;
- domain registrars;
- external authentication providers;
- other third parties.
Customers are responsible for providing their own users with an appropriate privacy notice.
2. Personal Data We Collect
The information collected depends on how you interact with the Service.
Nova Panel may collect:
- name and business name;
- email address;
- telephone number;
- Telegram handle;
- other contact details;
- job title, role, and team information;
- information submitted through demo, setup, contact, onboarding, partnership, or other forms;
- account credentials and authentication information;
- onboarding, migration, integration, and configuration details;
- communications, support requests, feedback, and survey responses;
- billing contact details and transaction records;
- information provided when requesting custom integrations or technical assistance;
- any other information you choose to provide.
When the Service is used, Nova Panel may process:
- user, administrator, and team account information;
- account roles and permissions;
- panel settings and configuration;
- panel name, logo, branding, pages, themes, and content;
- languages and currencies;
- custom domains;
- DNS configuration;
- domain-verification status;
- SSL status and related technical diagnostics;
- service catalogs and categories;
- prices, limits, and service settings;
- provider mappings and routing rules;
- provider identifiers and provider-service identifiers;
- order records;
- order status;
- quantities;
- links and submitted order parameters;
- Retry, Failover, Completion, Refill, Cancel, and GetStatus records;
- operational and processing history;
- payment events;
- user balances;
- refunds;
- known fees and payment-related records;
- support tickets and customer-service history;
- reports, adjustments, and analytics configurations;
- provider and payment-gateway credentials;
- API keys, tokens, webhook secrets, and connection details;
- Public API activity;
- audit logs and administrative actions;
- plan type and account status;
- order and service usage counts;
- quota and limit status;
- additional usage purchases;
- billing-cycle information;
- panel activity, inactivity, archival, reactivation, and scheduled-deletion records;
- Powered by Nova Panel attribution status;
- referral identifiers, referral clicks, registrations, and related attribution records where referral functionality is enabled.
Some platform data may include personal data relating to a customer’s:
- staff;
- contractors;
- customers;
- panel users;
- support contacts;
- other end users.
In most cases, this information is processed on the customer’s behalf.
Nova Panel may automatically collect:
- IP address;
- browser type and version;
- device type;
- operating system;
- language;
- approximate region;
- referring pages;
- navigation events;
- login events;
- authentication events;
- security events;
- audit logs;
- identifiers stored in cookies or similar technologies;
- error, performance, and diagnostic information;
- date, time, and duration of activity;
- API request metadata;
- domain and DNS diagnostics;
- system status and usage events;
- referral and attribution events.
Nova Panel may receive information from:
- a business or team administrator who invites you;
- authentication providers where external sign-in is enabled;
- providers, gateways, and integrations connected by a customer;
- payment processors regarding payment status;
- hosting, analytics, monitoring, support, or security providers;
- referral or business partners where disclosure is authorized;
- domain and DNS infrastructure providers;
- public sources where lawful.
3. How Personal Data Is Used
Nova Panel may use personal data to:
- provide, configure, maintain, and support the Service;
- review demo, setup, onboarding, contact, and integration requests;
- create and manage accounts;
- authenticate users;
- manage permissions and access;
- create and provision panels;
- verify custom domains;
- configure DNS and SSL;
- determine whether the User Dashboard and customer-facing ordering functions may be activated;
- onboard customers;
- assess migration or integration requirements;
- process configured orders;
- perform routing, Retry, Failover, Completion, synchronization, Refill, Cancel, and related workflows;
- operate provider and payment integrations;
- calculate operational reports and recorded margin based on available data;
- measure plan usage;
- count customer orders and services;
- determine quota and limit status;
- process additional usage purchases;
- administer Free and paid plans;
- determine whether a Free panel remains active;
- send inactivity, archival, deletion, quota, domain, billing, and security notifications;
- archive, reactivate, delete, or anonymize inactive Free panels;
- operate Powered by Nova Panel attribution;
- attribute referrals, registrations, and related rewards where referral functionality is enabled;
- communicate about accounts, security, incidents, updates, billing, and support;
- process subscription and usage payments;
- maintain transaction records;
- monitor performance;
- diagnose errors;
- improve the Service;
- prevent fraud, abuse, duplicate-account creation, limit circumvention, unauthorized access, and security threats;
- enforce agreements and acceptable-use rules;
- comply with legal obligations and valid legal requests;
- send marketing communications where permitted and subject to your choices;
- establish, exercise, or defend legal claims.
4. Legal Bases
Where applicable law requires a legal basis, Nova Panel relies on one or more of the following:
Processing necessary to:
- provide requested access;
- create and operate an account;
- provision a panel;
- verify a domain;
- provide onboarding and support;
- process billing;
- operate integrations;
- provide the Service.
Processing necessary to:
- secure the Service;
- administer accounts;
- manage usage and panel lifecycle;
- prevent fraud and abuse;
- improve the Service;
- understand product usage;
- promote Nova Panel;
- operate referrals and attribution;
- protect Nova Panel, customers, and users.
These interests are relied upon only where they are not overridden by individual rights.
Processing based on consent where consent is requested, including for:
- certain marketing communications;
- optional cookies;
- certain optional integrations.
Processing required to comply with:
- law;
- tax requirements;
- accounting requirements;
- sanctions;
- regulatory obligations;
- valid legal requests.
Processing necessary to:
- prevent harm;
- prevent fraud;
- prevent misuse;
- investigate security incidents;
- enforce agreements;
- establish or defend legal claims.
Where Nova Panel processes personal data on behalf of a customer, the customer is responsible for identifying its own lawful basis and providing required notices to its staff, customers, and users.
5. Customer Data and Processing Roles
“Customer Data” means information submitted to or processed through the Service by or for a Nova Panel customer.
Customers control the purposes and configuration of Customer Data they submit to the Service.
Customers are responsible for:
- determining whether they may lawfully collect and use the data;
- providing required privacy notices;
- obtaining required consents or other lawful grounds;
- responding to requests from their staff, customers, and users;
- configuring access appropriately;
- configuring retention appropriately;
- exporting information they wish to retain;
- requesting deletion where applicable;
- ensuring that links, order data, user records, and support communications are processed lawfully.
Nova Panel processes Customer Data according to:
- the customer’s instructions;
- Service configuration;
- applicable agreements;
- applicable data-processing terms;
- legal requirements.
Production onboarding involving personal data may require acceptance of additional data-processing terms before data is imported or processed.
6. Provider Credentials and Sensitive Configuration Data
Provider API keys, payment-gateway credentials, access tokens, webhook secrets, and similar configuration data are used to operate integrations configured by a customer.
Nova Panel does not use these credentials to contact or market to a customer’s users.
Customers should provide only credentials that:
- they own;
- they are authorized to use;
- may lawfully be provided to Nova Panel.
Customers should rotate or revoke credentials when access should end.
Access to credentials and sensitive configuration data is restricted to the extent reasonably necessary to:
- operate integrations;
- secure the Service;
- diagnose technical problems;
- provide authorized support.
Provider and payment credentials may be encrypted or otherwise protected according to the technical requirements of the relevant integration.
Because Nova Panel must send certain credentials to third-party APIs, some credentials must remain technically recoverable by authorized Service components.
7. Payments
Payments may be processed by independent payment processors.
Nova Panel may receive:
- transaction identifiers;
- payment status;
- amount and currency;
- billing contact information;
- limited payment-method information;
- subscription status;
- purchased usage capacity;
- payment failure and refund information.
Nova Panel does not intend to store complete payment-card numbers or card security codes.
Payment processors handle payment data according to their own:
- privacy notices;
- terms;
- security requirements.
Nova Panel customers may also connect their own payment gateways for payments made by their panel users. Those payment gateways are selected and controlled by the customer.
8. Cookies and Similar Technologies
Nova Panel may use:
- essential cookies for authentication;
- security cookies;
- session-management cookies;
- preference cookies;
- cookies required for core functionality;
- analytics technologies to understand use and performance;
- support technologies to provide chat or customer assistance;
- referral and attribution technologies;
- marketing technologies where implemented and legally permitted.
Where consent is legally required, non-essential cookies will not be used until the required choice is provided.
You can control cookies through:
- available consent controls;
- browser settings;
- device settings.
Disabling essential cookies may prevent parts of the Service from working correctly.
10. International Data Transfers
The Service may involve processing in countries other than the country where an individual is located.
Those countries may have different data-protection laws.
Where required, Nova Panel will use an available legal mechanism for international transfers, such as:
- contractual protections;
- legally recognized transfer clauses;
- consent where valid;
- another lawful transfer basis.
11. Data Retention
Nova Panel retains personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including:
- providing the Service;
- account administration;
- support;
- security;
- fraud prevention;
- billing;
- legal obligations;
- dispute resolution;
- enforcement.
Unless a longer period is required or justified:
- demo, setup, contact, onboarding, and application submissions may be retained for up to 24 months after the last relevant interaction;
- account and subscription information may be retained during the account relationship and for up to 24 months afterward;
- support communications may be retained for up to 24 months after resolution;
- security and audit logs may be retained for up to 12 months;
- billing and transaction records may be retained for the period required by applicable tax, accounting, and legal obligations;
- deleted production data may remain in protected backups for up to 90 days;
- marketing contact information may be retained until unsubscribe, objection, invalidation, or prolonged inactivity.
Limited information may be retained longer where necessary to:
- prevent fraud;
- prevent repeated Free Plan abuse;
- enforce account limits;
- resolve disputes;
- comply with law;
- establish or defend legal claims.
Free panels are subject to an activity-based retention policy.
A Free panel may be archived after 14 consecutive days without Qualifying Activity.
Qualifying Activity may include:
- a sign-in by the panel owner;
- a sign-in by an authorized administrator;
- a meaningful configuration or content change;
- creation of a customer order;
- a valid user registration or account event;
- a valid payment event;
- a valid support event;
- a legitimate authenticated Public API request;
- another genuine business or administrative action recorded by the Service.
The following do not normally count as Qualifying Activity:
- automated provider synchronization;
- automated GetStatus checks;
- health checks;
- monitoring requests;
- scheduled system jobs;
- search-engine crawlers;
- bots;
- artificial traffic;
- background processing of previously created orders.
When a Free panel is archived:
- the customer-facing panel may become unavailable;
- the User Dashboard may become unavailable;
- users may no longer be able to create new orders;
- Public API order creation may be disabled;
- Guest Checkout may be disabled;
- provider and payment integrations may be paused;
- background jobs may be stopped or limited;
- the owner may retain limited access to reactivate, upgrade, export, or manage the panel.
Nova Panel may delay archival where necessary to:
- complete existing orders;
- process pending payments;
- resolve disputes;
- investigate fraud or security incidents;
- comply with legal requirements.
If a Free panel is not reactivated within 30 days after archival, Customer Data associated with that panel will be deleted or anonymized from active production systems.
This may include:
- panel settings;
- panel content;
- users;
- user profiles;
- balances;
- services;
- categories;
- provider mappings;
- order data;
- payment-related panel records;
- tickets;
- support history;
- reports;
- integration configuration;
- other panel-specific Customer Data.
Deletion of panel data does not necessarily delete:
- the panel owner’s Nova Panel account;
- billing records;
- transaction records;
- security logs;
- audit records;
- anti-fraud records;
- abuse-prevention records;
- referral records;
- legally required records;
- support communications that must be retained.
Deleted panel data may remain in protected backups for up to 90 days and will be deleted or overwritten through the normal backup cycle.
Backup copies are not generally available for individual restoration.
Paid panels are not archived or deleted solely due to inactivity while the applicable paid subscription remains active.
12. Data Export, Deletion, and Account Closure
Available export tools and formats depend on:
- the relevant data type;
- product configuration;
- account status;
- release stage;
- technical availability.
Customers should export any information they wish to retain before:
- canceling an account;
- closing an account;
- allowing a Free panel to remain archived;
- reaching a scheduled deletion date;
- ending access to the Service.
For an inactive Free panel:
- the panel may be archived after 14 consecutive days without Qualifying Activity;
- supported reactivation or export may remain available during the 30-day archival period;
- if the panel is not reactivated, Customer Data will be deleted or anonymized from active systems after that period.
Once deletion from active systems has occurred, the data may no longer be recoverable.
Deletion from active systems does not immediately remove information from protected backups.
Backup copies:
- remain protected;
- are not used for ordinary production purposes;
- are deleted or overwritten through the normal backup cycle;
- may remain for up to 90 days.
Certain account, security, billing, support, anti-fraud, referral, and legally required records may remain after panel deletion.
Where access is terminated because of unlawful activity, fraud, a security risk, or a legal requirement, export or reactivation access may be restricted or unavailable.
Where technically available, supported Customer Data may remain exportable for up to 30 days after termination of a paid account.
13. Security
Nova Panel uses administrative, technical, and organizational measures designed to protect personal data against:
- unauthorized access;
- loss;
- misuse;
- alteration;
- destruction;
- disclosure.
Measures may include:
- access controls;
- authentication;
- role-based permissions;
- logging;
- encryption;
- secret-management controls;
- secure development practices;
- backups;
- monitoring;
- network protections;
- incident-response procedures.
The measures used depend on:
- the sensitivity of the data;
- the relevant risk;
- the product configuration;
- the release stage.
No online service can guarantee absolute security.
You are responsible for:
- using strong credentials;
- protecting API keys and tokens;
- enabling available security features;
- restricting team access;
- removing access when it is no longer required;
- promptly reporting suspected compromise.
14. Security Incidents
Nova Panel will investigate confirmed security incidents and take reasonable steps to:
- contain them;
- remediate them;
- reduce further risk.
Where required by applicable law or contract, affected customers or authorities will be notified within the applicable timeframe.
Suspected security issues may be reported to [email protected].
15. Marketing Communications
Nova Panel may send:
- product news;
- educational content;
- invitations;
- updates;
- promotional messages;
where permitted by law.
You may unsubscribe using:
- the link in a marketing email;
- available account controls;
- a request sent to Nova Panel.
Unsubscribing from marketing does not stop necessary:
- account communications;
- security communications;
- billing communications;
- domain notices;
- quota notices;
- archival and deletion notices;
- operational service communications.
Where required, marketing consent is collected separately from acceptance of the Terms of Service.
16. Your Privacy Rights
Depending on applicable law, you may have rights to:
- request access to personal data;
- correct inaccurate or incomplete information;
- request deletion;
- restrict processing;
- object to processing;
- receive certain data in a portable format;
- withdraw consent where processing is based on consent;
- object to direct marketing;
- complain to a competent data-protection authority.
To exercise a privacy right, contact [email protected].
Nova Panel may request additional information to verify:
- identity;
- account ownership;
- authority to act on behalf of another person or business.
Some rights are subject to legal exceptions.
Where Nova Panel processes data on behalf of a customer, a request may be:
- directed to that customer;
- handled with that customer’s assistance.
17. Automated Operational Processing
Nova Panel and Nova Connect may use automated rules to:
- route orders;
- select providers;
- perform Retry;
- perform Failover;
- create Completion processing;
- synchronize provider data;
- calculate reports;
- issue alerts;
- detect errors;
- measure plan usage;
- count orders and services;
- determine quota status;
- restrict new order creation when a plan allowance is unavailable;
- verify custom-domain status;
- restrict customer-facing order creation where a required custom domain is not connected or verified;
- determine Free panel inactivity;
- schedule panel archival;
- schedule panel-data deletion;
- restore functionality after reactivation;
- detect duplicate accounts or suspected limit circumvention;
- attribute referrals.
These functions are intended to support business and account operations.
They are not designed to make decisions producing legal or similarly significant effects about individual people.
Customers may contact support if they believe that:
- usage was measured incorrectly;
- a panel was restricted incorrectly;
- a domain was not recognized correctly;
- a Free panel was archived incorrectly;
- a panel was scheduled for deletion incorrectly.
18. Children’s Privacy
The Service is intended for business users and is not directed to children.
Nova Panel does not knowingly collect personal data directly from children through account-registration or marketing forms.
If you believe that a child has provided personal data directly to Nova Panel, contact [email protected].
19. Third-Party Services and Links
The Service may contain links to or integrations with third-party services.
These may include:
- providers;
- payment gateways;
- authentication providers;
- domain registrars;
- analytics providers;
- support tools;
- other external services.
Their privacy practices are governed by their own:
- privacy notices;
- terms;
- agreements.
Nova Panel is not responsible for independent third-party privacy practices.
Customers should review third-party policies before enabling an integration.
20. Changes to This Privacy Policy
Nova Panel may update this Privacy Policy to reflect changes in:
- the Service;
- Free or paid plan operation;
- domain requirements;
- panel-lifecycle rules;
- vendors;
- security practices;
- legal requirements;
- data-processing practices.
The updated version will state a new effective date.
Where required, additional notice of material changes may be provided through:
- the Service;
- email;
- the Admin Dashboard;
- another appropriate communication channel.
21. Contact Us
Privacy questions and requests may be sent to:
Email: [email protected]