1. Who we are and scope
Virtualizor is a product of Softaculous Ltd. This Cookie & Tracking Policy applies to browsing and forms on this marketing website (for example Virtualizor.com marketing pages built from this project).
It does not fully describe cookies inside the Virtualizor control panel after install, Softaculous billing/client center logins, community forums, demo panels, or third-party sites linked from here. Those services have their own technical stacks and notices.
2. What cookies and similar technologies are
We use “cookies and similar technologies” to mean:
- HTTP cookies set by our domain or by third parties we load.
- Browser localStorage / sessionStorage used by our own scripts (this site relies on localStorage for theme and consent choice).
- Scripts and embeds that may set their own cookies or process your IP address and browser data when they load (fonts, maps, analytics, CDNs).
Some items below are not classic cookies but still involve personal data or device storage, so we list them for honesty.
3. Legal bases (GDPR, UK GDPR, ePrivacy / PECR)
Where the EU GDPR or UK GDPR applies, we process personal data related to cookies and tracking as follows:
- Strictly necessary storage (for example remembering your cookie choice, or a theme preference you set): may be processed without consent under ePrivacy/PECR-style “strictly necessary” / service delivery rules, and as legitimate interests or contract-related processing where appropriate. You can still clear browser data at any time.
- Non-essential analytics: only with your consent (GDPR Art. 6(1)(a)), given via the cookie banner when analytics is configured. Until you accept, analytics scripts are not loaded and analytics_storage remains denied.
- Marketing email: only with your consent when you deliberately subscribe (and, where required, confirm via double opt-in). Consent must be freely given, specific, informed, and unambiguous. Pre-ticked boxes are not used.
This page is informational. It is not legal advice for your own business. Hosting providers using Virtualizor remain responsible for their own compliance with end-customer data.
4. What this site uses (truthful inventory)
The following describes the current marketing-site implementation in this codebase. Names and keys match the source.
4.1 First-party storage we control
| Name / key | Type | Purpose | Required? | Duration |
|---|---|---|---|---|
theme |
localStorage | Stores light, dark, or system appearance so the UI does not flash the wrong theme. | Functional preference (not advertising) | Until you clear site data or change theme |
vz_cookie_consent |
localStorage | Remembers whether you chose Accept analytics or Essential only, so the banner does not reappear every page load. | Strictly necessary to honor your choice | Until you clear site data or use Reset preferences below |
vz_newsletter_intent |
localStorage (optional) | Stores only a non-identifying flag that you completed the subscribe form flow on this browser (not your email address). Used to avoid repeating success UI noise. Does not subscribe you by itself. | Optional, functional | Until cleared |
We do not store your email address in localStorage or cookies for the newsletter. If a live subscription backend is connected, your email is sent only to that endpoint over HTTPS when you submit the form with consent checked. If no backend is connected, the form will tell you honestly that online subscribe is not available and will not pretend you were added to a mailing list.
4.2 What we do not claim
- We do not run advertising pixels or ad personalization on this marketing site by default.
- We do not sell personal information for money.
- We do not load Google Analytics unless a GA4 Measurement ID is configured and (when consent is required) you accept analytics.
- We do not treat “Essential only” as analytics consent.
- We do not use the newsletter form as a hidden analytics or profiling tool beyond optional event names if analytics is already consented.
5. Optional analytics (Google Analytics 4)
Analytics is controlled in assets/js/combined.js (window.VZ_SITE):
MEASUREMENT_ID- GA4 ID shaped likeG-XXXXXXXX. If this is empty, no gtag script is loaded and no Google Analytics cookies are set by us.REQUIRE_CONSENT- whentrue(default), the cookie banner is shown until you choose. Analytics loads only after Accept analytics.
When analytics is active after consent, Google may set or read cookies / storage typical of GA4 (for example identifiers used to distinguish sessions and measure page views and events such as CTA clicks). We request IP anonymization where supported by the configuration. Google acts as a processor / independent controller of its telemetry depending on your agreement with Google; see Google Privacy Policy and your GA4 property settings.
Default consent mode values before accept: analytics and ads storage denied. Reject keeps GA off (no gtag network request from our loader when you never accepted).
6. Third-party services that may receive data
Even without analytics, loading this site may cause your browser to contact third parties for assets. Those parties may process technical data (IP address, user-agent, referrer, request URL). We list them so this policy is not incomplete:
| Service | When it loads | Why | Notes |
|---|---|---|---|
| Google Fonts | Most pages (stylesheet link) | Load Inter typeface | Request to Google may include your IP. See Google policies. We may self-host fonts later to reduce this. |
| unpkg CDN (Feather icons) | Pages that include the icon script | UI icons | CDN may log technical request data. |
| Google Maps embed | Contact page map iframe only | Show Softaculous office location | Google may set cookies or process location/IP for the embed. Not controlled by our cookie banner. |
| Google Analytics 4 / Google Tag Manager endpoints | Only if Measurement ID is set and analytics accepted | Traffic and CTA measurement | Optional; consent gated when REQUIRE_CONSENT is true. |
| Outbound links (docs, trial, demos, Softaculous clients, social) | When you click them | Product docs, trial, demos, accounts | Those sites apply their own cookies and policies after you leave. |
7. Email subscribe / newsletter
The footer “Subscribe” band is a marketing email signup for Virtualizor news, product updates, tips, and related Softaculous product information for hosting providers.
7.1 What you must do to subscribe
- Enter your email address deliberately.
- Tick the consent checkbox (unticked by default) confirming you want marketing emails and that you understand you can unsubscribe later.
- Submit the form.
That is opt-in consent, not forced consent bundled into unrelated account creation on this static page.
7.2 What happens technically (no lies)
- If
newsletterEndpointin site config is empty, no email is sent to our servers from this form. You will see a clear message that online subscribe is not connected, with alternative contact options. We will not show a fake “you are on the list” success state. - If
newsletterEndpointis set to a live form or ESP endpoint (for example a mailing provider or Softaculous backend), your email and a source label (marketing-site) are POSTed over HTTPS to that endpoint only after valid input + consent checkbox. - Where double opt-in is configured on the mailing provider (recommended for EU/UK), you must confirm via email before regular newsletters start. Until confirmation, you should not receive promotional bulk mail from that list.
- Optional analytics events (for example form submit) fire only if you already accepted analytics; they are not a substitute for email consent.
7.3 Data used for email marketing
- Email address you submit
- Consent timestamp / source (when the backend records them)
- Unsubscribe status and delivery logs held by the email provider
We use this only to send the types of messages described at signup, to maintain the list, prevent abuse, and honor opt-outs. We do not sell your email list.
7.4 How to stop emails
- Use the unsubscribe link in any marketing email (required for bulk commercial mail).
- Or email support[@]virtualizor[dot]com or sales[@]virtualizor[dot]com asking to be removed from marketing lists.
- Account notification preferences inside Softaculous/Virtualizor client systems (if you have an account) may control product/account mail separately from this marketing list.
Transactional or service messages (billing, license, security, support tickets) may still be sent when needed to provide a product you requested, even if marketing mail is stopped, where law allows.
8. Anti-spam and marketing email laws (summary)
We design the subscribe flow to support compliance with common regimes. Your region may add requirements. Summary only:
| Regime | How this site approaches it |
|---|---|
| EU GDPR + ePrivacy | Marketing email based on consent; clear purpose; withdraw anytime; no pre-ticked consent; prefer confirmed opt-in on the ESP when serving EU residents. |
| UK GDPR + PECR | Similar consent rules for electronic mail marketing to individuals; soft opt-in may apply only in narrow existing-customer cases handled outside this generic footer form (not claimed by this form). |
| US CAN-SPAM | Truthful subject/from lines on campaigns; physical postal address on commercial email; working unsubscribe honored promptly; no harvested addresses via this form. |
| Canada CASL | Express consent via this form when used for CEM; identification and unsubscribe in messages; implied consent not assumed from a mere site visit. |
| India DPDP and others | Purpose limitation and consent for marketing where required; contact channels to withdraw consent. |
| CCPA / CPRA (California) | We do not sell personal information for money. Analytics (if enabled) may involve "sharing" for cross-context behavioral advertising under some interpretations; you can refuse analytics via Essential only. Email signup is direct marketing with opt-out. |
9. How to manage or withdraw consent
- Browser controls: block cookies, clear site data, or use private mode.
- Google Analytics opt-out: browser add-ons and Google account ad settings may further limit Google measurement.
- Maps / fonts / CDNs: controlled by not loading those pages or by browser tracker blockers; not fully covered by our analytics banner.
- Email: unsubscribe link or contact support/sales as above.
10. Retention
- localStorage keys remain until you clear them or use Reset for consent.
- GA4 data is retained according to the retention setting in the Google Analytics property (configured by Softaculous when a property is active).
- Newsletter records are kept while you remain subscribed, then suppressed or deleted according to the mailing system and legal hold needs (for example proving prior consent or honoring suppression lists).
11. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, object, port data, or withdraw consent. For marketing-site and Softaculous/Virtualizor privacy requests, contact support[@]virtualizor[dot]com. You may also have the right to complain to a supervisory authority (for example an EU/UK data protection authority).
See also our Privacy Policy for broader product and website practices.
12. Children
This marketing site and Virtualizor products are aimed at businesses and professionals. We do not knowingly solicit personal data from children. If you believe a child provided data through this site, contact support so we can delete it where applicable.
13. Changes to this policy
We may update this page when the site’s real technology changes (new analytics vendor, self-hosted fonts, live newsletter endpoint, and so on). The “Last updated” date at the top will change. Material changes to analytics or email practices should also be reflected in the banner or subscribe UI.
14. Contact
Softaculous Ltd. / Virtualizor
- Privacy / support: support[@]virtualizor[dot]com
- Sales: sales[@]virtualizor[dot]com
- Contact page (includes office map embed)
Related: Privacy Policy · Terms of Use