Lastation LLC, Privacy Policy
Effective Date: 11/13/2025
Lastation is committed to protecting your privacy. We collect and store only the information necessary to provide our services.
We take your privacy seriously and are committed to protecting your personal information. This Privacy Policy explains what data we collect, how we use it, and the choices you have.
In summary:
- We do not sell, rent, or trade your personal data to third parties. We also do not "sell" or "share" personal information for cross-context behavioral advertising as defined by the CCPA/CPRA in relation to Lastation. When you interact with third-party content such as embedded YouTube videos, those third parties may collect and use information under their own privacy policies, which may include advertising in their own services.
- We aim to collect only the minimum data necessary to provide, secure, and improve our service.
- We do not train AI models on your messages, files, or any other content you create or share.
- You can delete your data(account) by request.
- We handle personal data in line with applicable privacy laws, such as GDPR in the EEA/UK and CCPA/CPRA in California, based on your location and use of our services.
- We log limited feature usage and operational events to keep the service reliable and secure. We do not use this data for behavioral advertising or cross-site tracking.
- We may use your data to access information from third-party services (e.g., VRChat) to provide our features, but we do not share your data with those services for advertising purposes.
This summary is provided for convenience. You should read the full policy below to understand how we handle your information.
1. Who We Are
We are Lastation LLC, a American limited liability company (Organization Number SOSID: 2972216). We operate the Lastation platform and related services.
We were initally just a small world development community bt in the span of a few months blew up into a large commmunity and eventually a company.
We collect information in three main ways: (1) information you provide to us, (2) information we collect automatically, and (3) information we receive from other sources.
2.1 Information You Provide to Us
This includes:
- Account information: Email address, username, date of birth.
- Government-issused ID or similar documents: If you choose to verify your age, This information is soley used for age verification and is deleted immediately after the verification process is complete.
- Content and communications: Messages, files, images, voice and video communications (where supported), community information, reactions, and profile data (such as avatar, bio, and other information you choose to display).
- Support and correspondence: Information you provide when you contact our support team or interact with customer service, including the content of messages, attachments, and any additional details you choose to provide.
- Payment information: If you purchase premium features (Such as https://vrchat.lastation.tech), payment processing is handled securely by PayPal. We do not store your full payment card details. PayPal provides us with limited information necessary to record and manage your purchases (for example, billing country, partial card details, payment status, and timestamps).
We do not require you to provide special categories of personal data (such as information about your health, religion, or political beliefs). If you choose to share such information in your messages or profile, you do so at your own discretion.
2.2 Information We Collect Automatically
When you use our services, we automatically collect certain technical and usage information, including:
- Device and technical information: IP address, browser type and version, operating system, device type, device identifiers, language settings, and similar technical data.
- Usage information: Information about how you interact with Lastation services, such as:
- pages and screens visited within the app or site;
- features used (for example, voice calls, file uploads, reactions);
- timestamps and duration of sessions;
- approximate counts and types of events (for example, messages sent, and other API endpoints), without reading message content for analytics;
- crash reports and performance metrics.
- Security and operational logs: Data generated by our systems to maintain security and reliability, such as:
- login attempts and authentication events;
- changes to account settings;
- rate limits, API errors, and system errors;
- IP-based signals related to spam, abuse, or unusual behavior.
We use this information to secure the service, detect and prevent abuse, improve performance, and understand which features are being used so we can prioritize support and improvements. We do not use this information for behavioral advertising or cross-site tracking.
2.3 Information From Other Sources
We may also receive information about you from:
- Other users: When other users mention you, send you messages, share content involving you, or otherwise interact with your account.
- Service providers: Limited operational information from our service providers, such as account data from VRChat, payment confirmations from PayPal, or security-related alerts from infrastructure providers.
- Public or third-party sources: In some cases, we may receive information from publicly available sources or trusted partners for security, anti-fraud, or compliance purposes (for example, checking whether an IP address is associated with known abuse).
We combine this information with the information we collect directly and automatically to help operate, secure, and improve our services.
3. ID Verification
Lastation provides adult only services in which we require 18+ verification to access more than just public facing information.
3.1 Information Collected for Verification
If you choose to verify your age, we may temporarily collect:
- a photo or scan of a government-issued ID (such as a passport or driver’s license);
- a selfie image for facial comparison (where necessary to confirm authenticity); and
- limited metadata required to confirm age (for example, date of birth and document validity status).
We only collect the minimum information necessary to verify your age or identity status.
3.2 How Verification Is Processed
Age verification may be processed:
- internally by authorized Lastation staff.
3.3 Data Retention and Deletion
Government-issued ID documents and biometric comparison data (such as selfies used for verification):
- are used solely for the purpose of completing the verification process;
- are deleted promptly after verification is completed; and
- are not retained for ongoing profiling, advertising, or analytics.
We may retain a minimal verification record (for example, a flag indicating that age was successfully verified and the date of verification) to avoid repeated verification requests and to demonstrate compliance with legal obligations.
3.4 Security Measures
ID verification data is:
- transmitted using encrypted connections (TLS);
- stored temporarily using strong encryption at rest; and
- accessible only to authorized personnel on a strict need-to-know basis.
We implement technical and organizational safeguards to prevent unauthorized access, misuse, or disclosure during the verification process.
3.5 Refusal or Failure to Verify
If you decline to complete required ID verification:
- you may be unable to access certain age-restricted features; and
- in cases involving suspected age misrepresentation, your account may be restricted or suspended in accordance with our Terms of Service.
We aim to use the least intrusive method possible to verify age while meeting our legal and safety obligations.
4. How We Use Your Information
We use your information for the following purposes:
- To provide, operate, and maintain the Lastation platform and services.
- To create and manage your account.
- To deliver your messages, media, and other content to the intended recipients.
- To secure your account and prevent unauthorized access.
- To detect, investigate, and prevent abuse, fraud, spam, and violations of our terms or community guidelines.
- To send important service updates, security alerts, and administrative messages.
- To process payments, manage subscriptions, and handle financial transactions.
- To understand which features are used and how the service performs, so we can prioritize support, fix issues, and plan improvements.
- To comply with legal obligations and respond to lawful requests.
- To protect the safety, rights, and property of our users, the public, and Lastation.
We do not use your messages, files, or any other content you create or share on Lastation's services for targeted advertising or for training AI models.
4.1 Lawful Bases for Processing (GDPR)
If you are in the EEA, UK, or another jurisdiction with similar requirements, our legal bases for processing your personal data include:
- Contract necessity: We process data that is necessary to provide the services you have requested under our Terms of Service, such as processing requests, accessing content, maintaining your account, and providing support.
- Legitimate interests: We process data based on our legitimate interests, such as:
- securing the platform and preventing fraud and abuse;
- maintaining and improving service reliability and performance;
- understanding how features are used at an aggregate level; and
- communicating with you about changes to our services or policies. When we rely on legitimate interests, we balance our interests against your rights and expectations and implement safeguards to protect your privacy.
- Legal obligations: We process data when necessary to comply with legal obligations, such as:
- accounting, tax, and record-keeping;
- child protection and CSAM reporting obligations;
- responding to lawful requests from public authorities; and
- complying with applicable data protection, security, and consumer laws.
- Consent: In limited cases, we may rely on your consent, for example:
- where required to send certain types of optional communications; or
- where local law requires consent for specific processing or cookie use on our marketing site. Where we rely on consent, you can withdraw it at any time in your settings or by contacting us. Withdrawing consent does not affect the lawfulness of processing that took place before the withdrawal.
4.2 IP Address Geolocation
We may geolocate your IP address at a coarse level (city, state/region, and country) for the following purposes:
- providing security alerts when logins occur from new or unusual locations;
- showing you where your account is currently logged in for security monitoring;
- preventing fraud, detecting abuse, and protecting platform integrity;
- determining regional age requirements and access eligibility based on local laws; and
- meeting legal obligations related to export control and sanctions.
We use IP geolocation databases that run locally on our servers for internal platform functions.
5. Who We Share Information With
We do not sell your personal data. We share information only in the following limited circumstances:
5.1 When You Direct Us to Share
We share your information when you intentionally interact with Lastation services, for example:
- when you use Lastation's World Auth to other users;
- when you join Lastation's VRC Group;
- when you share content publicly or with specific groups;
- when your profile information is visible to others according to your settings; and
- when you choose to connect to or use integrations or third-party services (where available).
In these cases, other users can see the information you choose to share, and they may further share or store it outside Lastation's services. We encourage you to be mindful about the content you share and with whom.
5.2 With Service Providers
We work with trusted third-party service providers who process data on our behalf to help us operate Lastation. These providers include:
Infrastructure and Data Storage
- Hg-Hosting – primary hosting of our servers.
- Backblaze – encrypted backups stored in Amsterdam, Netherlands.
- Bunny.net – content delivery network (CDN) for delivery and caching of user-generated.
Security and Safety
- Cloudflare – limited services, including:
- Turnstile CAPTCHA for bot prevention (primary CAPTCHA provider; see also hCaptcha below); and
- hCaptcha – backup CAPTCHA provider; users can choose hCaptcha instead of Cloudflare Turnstile for bot prevention challenges.
Observability and error reporting
- Sentry – application error monitoring. We send error and crash diagnostics directly to Sentry over HTTPS so we can investigate reliability and security issues. This may include stack traces, runtime metadata (for example browser, OS, and device details), release/build identifiers, and account identifiers associated with the active session (for example user ID, username, and email). We do not use this data for advertising, and routine error reports do not include private message content or uploaded file attachments.
Payment and Communications
- Stripe – payment processing for subscriptions and other purchases.
- PayPal – payment processing for subscriptions and other purchases.
- Sweego – transactional email services.
- Twilio – SMS-based account verification services.
- Fastmail – support email infrastructure.
Other Services
- Cloudflare – domain registration services.
Many of these providers (for example, HG-Hosting, Backblaze, Bunny.net, Cloudflare, Stripe, Sweego, Twilio, Fastmail, and PayPal) act as processors and process personal data only on our behalf, according to our instructions.
Other providers, such as Cloudflare Turnstile, and hCaptcha, may also process some data as independent controllers when you interact directly with their services (for example, when you complete a CAPTCHA). In those cases, your use of those services is also governed by their own terms and privacy policies.
Where required by law, we have data processing agreements and standard contractual clauses or equivalent safeguards in place with providers that process personal data on our behalf, and we take steps to minimize the amount of personal data shared with all providers.
5.3 When Required by Law or to Protect Rights
We may disclose your information if we reasonably believe it is necessary to:
- comply with a valid legal obligation, legal process, or enforceable governmental request;
- enforce our Terms of Service or other agreements;
- protect the safety, rights, or property of our users, the public, or Lastation; or
- detect, prevent, or otherwise address fraud, security, or technical issues.
Where legally permitted and appropriate, we will attempt to notify you before disclosing your information in response to legal requests, especially if the request concerns your account or content.
5.4 Business Transfers
If we are involved in a merger, acquisition, reorganization, sale of assets, or similar transaction, your information may be transferred as part of that transaction. We will continue to protect your information in accordance with this policy and will notify you of any significant changes to how your data is handled.
6. Data Storage and International Transfers
6.1 Where Your Data Is Stored
We store and process data in multiple locations in order to provide a reliable and performant service:
- Primary servers: HG-Hosting data center.
- Encrypted backups: Backblaze data center in Amsterdam, Netherlands.
- User-generated content CDN: Bunny.net edge locations worldwide.
6.2 International Data Transfers
Because we operate globally and use service providers located in different countries, your data may be transferred to and processed in countries outside your own, including the United States. These countries may have data protection laws that are different from the laws of your country.
Where required by law (for example, under GDPR), we ensure that appropriate safeguards are in place for international transfers, such as:
- standard contractual clauses approved by the European Commission or UK authorities;
- data processing agreements with appropriate security and privacy commitments; and
- additional technical and organizational measures, such as encryption and access controls.
We do not transfer your data to third parties for their own independent advertising or marketing purposes without your explicit consent.
7. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes described in this policy, to comply with legal obligations, to resolve disputes, and to enforce our agreements.
7.1 Active Accounts
For active accounts, we generally keep your personal data for as long as you use Lastation services. This includes your linked accounts (Discord, VRChat, etc.), uploaded content, and other User Content while your account remains active, unless you delete specific content yourself.
7.2 Deleted Content
When you delete content:
- We remove them from our active systems within a reasonable period of time.
- Deleted data may remain in our backup systems and certain logs for a limited period before being permanently removed, except where we are required by law to retain specific data for longer.
For user-generated content cached on Bunny.net's edge network, we use Bunny.net's cache purge API to invalidate cached attachments as soon as possible after deletion. In practice, there may be short delays due to rate limits and global propagation.
7.3 Inactive Accounts and Account Deletion
We may delete accounts that are inactive for an extended period, and we also delete accounts when you request it or following certain enforcement actions, in line with our deletion procedures.
When an account is deleted:
- you lose access to the account and its associated data; and
- all account content is invalidated internally.
7.4 Logs and Security Data
Security logs, audit logs, and usage logs are retained only for as long as necessary for security, fraud prevention, troubleshooting, and compliance, and are then deleted or anonymized. We may retain certain logs longer where necessary to investigate security incidents, comply with legal obligations, or resolve disputes. Where relevant, we describe retention periods for particular types of data in our help articles.
8. Your Privacy Controls
You have several tools and settings to help you manage your data and privacy.
8.1 Requests over Discord
If you need specific data removed or modified without deleting everything:
- Access the "Contact-Staff" channel and open a Developer Ticket using the Discord account associated with your Lastation account.
- Clearly describe what you want us to do (for example, delete specific content, correct account information, or provide a data copy).
- We may ask for additional information to verify your identity and confirm that you control the account.
If you want a copy of your data before deleting content or your account, request an export first and wait for the export to complete.
8.2 Requests by Email
If you need specific data removed or modified without deleting everything:
- Email privacy@lastation.tech from the email address associated with your Lastation account.
- Clearly describe what you want us to do (for example, delete specific content, correct account information, or provide a data copy).
- We may ask for additional information to verify your identity and confirm that you control the account.
If you want a copy of your data before deleting content or your account, request an export first and wait for the export to complete.
9. Data Security
We implement technical and organizational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
These measures include:
- industry-standard encryption for data in transit (TLS);
- strong encryption for data at rest on our servers and backups;
- secure, professionally managed data centers with physical security controls;
- regular security updates, patch management, and infrastructure hardening;
- rate limiting, anomaly detection, and other protections against abuse and attacks;
- strict access controls so that only authorized staff can access user data, on a need-to-know basis and for limited purposes; and
- regular encrypted backups for disaster recovery.
No online service can guarantee perfect security. We work continuously to improve our security posture and reduce risks.
9.1 Data Breaches
If we become aware of a data breach that has a material impact on your personal data, we will:
- investigate and take appropriate remedial steps;
- notify you without undue delay when legally required; and
- notify relevant supervisory authorities when required by law.
Notifications will include information about what happened, what data may be affected, and steps you can take to protect yourself.
10. Your Privacy Rights
Depending on where you live, you may have certain rights regarding your personal data. These rights may include, for example under GDPR (EEA/UK) or CCPA/CPRA (California):
- Right of access: Request confirmation of whether we process your personal data and, if so, receive a copy.
- Right to rectification: Request correction of inaccurate or incomplete personal data.
- Right to deletion ("right to be forgotten"): Request deletion of your personal data in certain circumstances, for example where it is no longer necessary for the purposes for which it was collected.
- Right to restriction: Request that we restrict processing of your personal data in certain circumstances (for example, while we verify its accuracy or assess an objection).
- Right to object: Object to certain processing of your personal data, including processing based on legitimate interests, and we will consider your objection in line with applicable law.
- Right to data portability: Request a copy of certain personal data in a structured, commonly used, machine-readable format and ask us to transmit it to another controller where technically feasible.
- Right to withdraw consent: Where processing is based on your consent, you can withdraw that consent at any time. This will not affect the lawfulness of processing that took place before you withdrew consent.
- Rights under CCPA/CPRA (for California residents):
- right to know what personal information we collect, use, disclose, and share;
- right to delete personal information in certain circumstances;
- right to correct inaccurate personal information;
- right to opt out of the sale or sharing of personal information (we do not sell or share personal information for cross-context behavioral advertising in relation to Lastation); and
- right to be free from discrimination for exercising your rights.
10.1 Exercising Your Rights
You can exercise many of your rights directly through Discord and account settings (for example, export, deletion, and correction of certain information).
You can also contact us at privacy@lastation.tech to exercise your rights. When you do so:
- we may need to verify your identity (for example, by asking you to reply from your registered email or provide additional details);
- we will respond as required by applicable law (typically within 30 days, or up to 45 days where permitted and necessary); and
- if we cannot fully comply with your request (for example, due to legal obligations, technical limitations, or the rights of others), we will explain why and what options you still have.
You may also authorize an agent to submit requests on your behalf where permitted by law. We may require proof that the agent is validly authorized.
10.2 Complaints to Supervisory Authorities
If you are in the EEA, UK, or another jurisdiction with a data protection authority, you have the right to lodge a complaint with your local supervisory authority if you believe your privacy rights have been violated.
We encourage you to contact us first so we can try to resolve your concerns directly.
10.3 Automated Decision-Making
We use automated systems in certain limited ways that may affect your use of Lastation, such as:
- determining whether your approximate location is in a region where access to Lastation is permitted based on IP geolocation and applicable laws; and
- detecting potential fraud, spam, or abusive behavior.
These systems can influence, for example, whether you can access Lastation from a given region or whether certain actions are temporarily blocked while we investigate potential abuse.
Where applicable law (such as GDPR) grants you rights related to automated decision-making – such as the right to obtain human review, to express your point of view, or to contest certain decisions – you can contact us at privacy@lastation.tech. We will handle such requests in line with those laws and our legal obligations.
11. Cookies and Similar Technologies
11.1 Lastation Services
We do not use third-party advertising or tracking cookies for our own analytics or advertising in Lastation services. Any cookies we set are strictly necessary for the operation and security of the service. We also do not run advertising trackers or analytics SDKs in the app. Operational logging and limited feature-usage telemetry are stored server-side to keep the service reliable and secure and to understand which features are used. This server-side data is not used for advertising or cross-site profiling.
When you interact with embedded third-party content in the app (for example, a YouTube video or a CAPTCHA challenge), those third parties may set their own cookies or similar technologies under their own privacy policies.
11.2 Marketing Site
On our marketing website (lastation.tech):
- we set a single language-preference cookie to remember your language choice; and
- we do not use third-party advertising trackers or fingerprinting technologies.
If we introduce additional analytics on the site in the future, we will update this notice and, where required, seek your consent (for example, via a cookie banner or similar interface).
You can control cookie usage through your browser settings, which may allow you to block or delete cookies. Note that some site functionality may be affected if you disable cookies entirely.
12. Third-Party Services and Links
Lastation may contain links to third-party websites, services, or content (for example, VRChat, Discord, or other embedded content). When you use these features:
- we route requests through our servers where technically possible to reduce the amount of data sent directly from your device to third parties;
Third-party services may have their own privacy policies and data practices that are separate from ours. We are not responsible for the privacy practices, content, or security of third-party services, and we encourage you to review the privacy policies of any third-party services you use.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal obligations.
If we make significant changes, we will:
- provide at least 30 days' advance notice, where reasonably practicable, via email, in-app notifications, or notices on our website; and
- indicate the effective date at the top of this policy.
We maintain a changelog or archive of prior versions of this Privacy Policy for reference.
Your continued use of Lastation after the updated policy takes effect constitutes your acceptance of the changes. If you do not agree with the updated policy, you should stop using Lastation services and, if you wish, delete your account.
For account-related and privacy-related requests, you should contact us from the email address associated with your Lastation account wherever possible. This helps us verify your identity and protect your account.
Privacy and Data Protection Contact
- Email: privacy@lastation.tech
- Contact person: Drake, founder and LLC Member
- This is our primary contact point for privacy and data protection questions. We have not formally appointed a Data Protection Officer under GDPR.
You can use this address to exercise your privacy rights, ask questions about this policy, or raise concerns about how your data is handled.
General Support