About this policy
This policy explains what Hostinium for Information Technology LLC — "Hostinium", "we" or "us" below — does with personal data. It covers this website, the client area at hostinium.com/billing, the assistant built into every page, and the services we sell: Linux and Windows hosting, domains, SSL certificates, email and security add-ons, website design and e-commerce, SEO and marketing, and accounting software.
We are a limited liability company registered in Wyoming, United States, and this policy is written under US law. Where the GDPR or the UK GDPR applies to you, the GDPR page sets out the extra rights and commitments that come with it, and this policy still applies alongside it.
Two different relationships run through this policy, and it is worth separating them at the start:
- Your data. The account, billing and support information you give us. For that we are the controller: we decide what is collected and why, and this policy describes it.
- Data you store on our servers. Your visitors, your customers, your mailing list, the contents of your databases. For that you are the controller and we are the processor: we hold it and protect it, and we do not decide what happens to it. That side is covered on the GDPR page and in the terms of service.
What we collect
We ask for what an order needs and little else. In practice that is:
- Account details — your name, company name, email address, phone number and postal address. These create your account, identify you when you contact support, and reach you when a service needs attention.
- Billing details — your billing address, the services on your account, invoices, renewal dates and payment records. Card details are entered at checkout and handled by the payment provider that processes the transaction.
- Domain registration details — the registrant name, address, email and phone number a domain registration requires. ICANN rules say this must be accurate, and it is passed to the registrar and the registry that operate your extension.
- What you send us — support and billing tickets, WhatsApp messages, emails, and anything you attach to them. Screenshots and log files often contain more than people expect, so send only what the problem needs.
- Server and technical logs — our web servers and the client area keep standard access logs: IP address, date and time, the page or file requested, browser type and language, and the page that referred you. We use them to run the platform, find faults and investigate abuse.
- Content on your hosting account — your files, databases and mailboxes. We do not read them as a matter of course. Staff open them only to deliver a service you asked for, to fix a fault, or where a law or a court order requires it.
What we do not collect. We do not ask for your date of birth, gender, income or interests. We do not buy personal data from data brokers, we do not build advertising profiles, and we do not track you across other websites. If a form on this site or in the client area asks you for something this section does not describe, it is a mistake: tell us and we will take it out.
Why we use it
Every use below is tied to running the service you bought:
- to set up, run, renew and support your services, and to take payment for them;
- to reach you about your account — order confirmations, invoices and renewal reminders, planned maintenance, technical notices and security announcements. These are part of the service and cannot be switched off while you hold an account;
- to keep the platform secure: rate limiting, abuse investigation, blocking attacks and spam;
- to meet legal and registry obligations, including ICANN domain rules, tax and accounting records, and lawful requests from authorities;
- to improve what we sell, by looking at where things fail and what people ask for;
- to send you offers and product news, only where you have asked for them.
For customers in the EU and the UK, the legal bases are: performance of a contract for everything in the first two points; our legitimate interest in a secure, working platform for the third and the fifth; a legal obligation for the fourth; and your consent for the last, which you can withdraw at any time.
Cookies, analytics and advertising
This website sets no advertising cookies. There are no ad-network tags, no retargeting pixels, no cross-site trackers and no third-party analytics scripts on these pages. Nothing you do here feeds an advertising profile, and we run no marketing campaigns built on your browsing. Web fonts are served from our own servers, so opening a page sends nothing to a font provider.
Two things do store data in your browser, and neither of them is an advertising cookie:
- The assistant conversation is kept in your browser tab's session storage, so the panel still holds your chat when you move between pages. That copy is cleared when you close the tab or press New chat. The messages themselves are also sent to our server and on to the assistant's provider, so that an answer can be written — the section below sets out every step.
- The client area is separate billing software at hostinium.com/billing. It sets a session cookie when you sign in, because keeping you signed in is not possible without one.
We sell no personal information and share none for advertising, so a Global Privacy Control or Do Not Track signal has nothing here to opt out of. If we ever add analytics to this site, this section is where it will be named, before it ships.
The Hostinium assistant
The assistant answers questions about plans, prices and services. It reaches you in two places: the panel that opens from the Ask buttons, and the box at the top of the home page where you describe your project and it recommends a plan. Both send what you type to the same place. Here is exactly what happens to it.
- Your question goes to Google. The text you type is sent to our server, which passes it to Google's API together with the earlier turns of that same conversation and our plan catalog, so that the gemini-3.8-flash model can write the answer. Each request carries its own history and asks for no server-side conversation record, so Google holds no running transcript of your chat. We use Google's paid API, where Google does not use your questions or the answers to improve or train its products. It does keep a short-lived log of both, for the single purpose of detecting abuse of its own service. Its API terms set both out in full.
- Nothing identifies you. We send no name, no email address, no account number and no advertising identifier, because the assistant is not connected to your account. It cannot see your services, your invoices or your tickets, and it cannot place an order.
- We store no conversations. Your messages and the answers are not written to a database or a log file on Hostinium's servers. Our server keeps one thing: a short-lived count in memory of how many requests have come from an IP address recently, so that nobody can flood the assistant. It holds no message text and does not survive a restart.
- The conversation lives in your tab. It is held in your browser's session storage until you close the tab, or until you press New chat. Close the tab and our copy and yours are both gone; the only thing that outlives it is Google's short abuse-detection log, described above. The home page box keeps nothing at all: its answer is on screen and nowhere else.
Because your question leaves our servers to be answered, treat the assistant as a public conversation: do not type passwords, card numbers or anything confidential into it. For anything tied to your account, open a ticket in the client area or message a person on WhatsApp at +1 202 505 2888, where we can identify you properly.
Who else sees your data
We do not sell personal data, and we do not share it for anyone else's marketing. Delivering the services does mean passing specific data to specific companies:
- Domain registrars and registries get the registration details for a domain you buy, because a domain cannot exist without them.
- Certificate authorities get the domain and contact details needed to issue an SSL certificate.
- Our data center partners host the servers your account runs on and therefore hold the data on them.
- The payment provider processes your card payment and sends us the result.
- Google receives assistant questions, as described above.
- WhatsApp carries the messages you choose to send us there, under its own operator's terms.
Each of these is used for that purpose and no other. Partners who handle personal data for us are either bound by data protection law themselves or by a contract with us that holds them to the standard on the GDPR page.
We also disclose data where the law compels us: a valid court order, a subpoena, a registry or regulator with the authority to ask, or an urgent situation involving someone's safety. Where we are allowed to tell you about such a request, we do.
Where your data is held
Hostinium is a Wyoming company, our billing system runs in the United States, and your data is held there and in the data centers that host your services.
If you are in the EU or the UK, that means your personal data is transferred to the United States. The legal basis for that transfer is the set of Standard Contractual Clauses issued by the European Commission, backed by an assessment of the safeguards behind them. The GDPR page explains how it works, and we can send you the documentation if your own compliance work needs it.
How long we keep it
- Account and billing records are kept while your account is open, and afterwards for as long as tax, accounting and company law require us to hold them.
- Tickets and messages stay with the account, so that the next person to help you can see what happened last time.
- Domain registration data lives with the registry for as long as the domain is registered, on its rules, not ours.
- Server backups are overwritten on a 30-day cycle. The backup policy is precise about what that means.
- Website and email files are removed from our servers when an account is cancelled. Download what you want to keep before the cancellation date.
- Assistant conversations are never stored by us at all. Google keeps its own short log of the questions and answers, to detect abuse of its service; that period is Google's, not ours.
When a retention period ends, the data is deleted. If you want the schedule for a particular record, ask and we will tell you what applies to it.
How we protect it
Traffic to this website and the client area is encrypted with TLS, so what you send is protected in transit. Access to customer data inside Hostinium is limited to the staff who need it to do a specific job, our servers sit behind firewalls and monitoring, and the credentials for third-party services stay on our servers rather than in anything your browser downloads.
Your side matters as much as ours. Keep your client area password and any API keys private, use a different password for your hosting than for anything else, and tell us within 24 hours if you think an account has been reached by someone who should not have it. On a shared computer, sign out before you walk away.
If a breach affects personal data we hold, we notify affected customers within 72 hours at the latest. The terms of service hold us to shorter deadlines still: one for the first alert, and one for each written report after it.
Your rights and choices
Whoever and wherever you are, you can ask us to:
- tell you what personal data we hold about you and why;
- give you a copy of it, in a form you can take elsewhere;
- correct anything that is wrong or out of date;
- delete data we no longer need to hold;
- stop or limit a particular use, including marketing;
- explain a decision we made about your account.
Most of this is faster to do yourself: your contact details, billing details and email preferences are all editable under My Details in the client area. For anything else, ask us using one of the routes at the bottom of this page. We do not charge for it, and where the law that applies to you sets a deadline for answering — one month under the GDPR and the UK GDPR — we work to it. We may ask you to confirm your identity first: not to slow you down, but because handing an account's data to the wrong person is the one mistake that cannot be undone.
Some rights have limits. We cannot delete billing records we are legally required to keep, or registration data a domain registry controls, and deleting account data usually means closing the service it belongs to.
If you are in California or another US state with a privacy law, you have the rights above under that law: to know, to access, to correct, to delete, and to opt out of the sale or sharing of personal information. We sell no personal information and share none for cross-context behavioral advertising, so there is nothing to opt out of. Using any of these rights never changes the price or the quality of your service.
If you are in the EU or the UK, the GDPR page lists your rights in full, including the right to complain to your national supervisory authority.
Emails you get from us
Service emails — order confirmations, invoices and renewal reminders, maintenance windows, technical notices, security announcements — go to every account holder. They are part of the service, and an account cannot opt out of them while it is open. Use an email address that a suspension of your hosting would not take offline.
Marketing email is different. Tips, offers and product announcements go only to people who have asked for them. Turn that consent on or off under My Details in the client area, or use the unsubscribe link in any such message. We do not pass your address to anyone else to market to you.
Children
Our services are sold to businesses and adults, and they are not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, tell us and we will delete it and close any account opened in their name.
Data you hold about other people
Your website, your databases and your mailboxes hold personal data about your own visitors and customers. You decide what is collected there and why, which makes you the controller of it; we hold it for you as the processor, on the terms in the terms of service and on the GDPR page.
That comes with obligations that are yours, not ours: publish your own privacy notice, collect only what you are allowed to collect, and answer the requests your users make to you. If one of your users contacts us directly about data on a site we host, we point them to you and let you know, because we cannot act on data we do not control.
Changes to this policy
The date at the top of this page is the version in force. When we change something that affects how your personal data is handled, we give at least 30 days' notice by email or in the client area before it takes effect, and the change never applies retroactively to data already collected. Smaller edits — a clearer sentence, a renamed page — are made with the date updated and nothing more.
Contacting us about your data
Three routes reach us, and any of them is enough to make a privacy request:
- WhatsApp — +1 202 505 2888, answered around the clock.
- Email — info@hostinium.com. Put "privacy request" in the subject line so it reaches the right person quickly.
- A ticket in the client area — hostinium.com/billing. This is the best route for anything about an account you already hold, because the request arrives already tied to your account.
Written notices go to Hostinium for Information Technology LLC, 30 N Gould St, Ste R, Sheridan, WY 82801, United States.
Questions
Questions about this policy? Message us on WhatsApp at +1 202 505 2888 or open a ticket in the client area.
