Privacy Policy
The short version: we collect only what we need to run the service and bill you, we don't sell your data, and you can export or delete everything from your account at any time. The long version, below, says the same thing more carefully.
In this document
01Who we are
"HostingSimple", "we", "us", and "our" refer to Hosting Simple LLC, a limited liability company organised under the laws of the State of Delaware, United States, with registered office at 1209 N Orange Street, Wilmington, DE 19801. EIN 88-1234567. We operate the website hostingsimple.com and the hosting infrastructure connected to it. For the purposes of the EU/UK GDPR we are the data controller of your account data and a data processor for any personal data your end users send to a site hosted on our infrastructure.
02What we collect
We collect three categories of data:
- Account data — name, email address, postal address (for tax purposes), payment method last-4 (full card numbers never touch our servers; they live with Stripe), authentication credentials, two-factor secret.
- Service data — your sites, databases, files, backups, access logs, and any other content you upload to the service. We treat this as your property; we access it only on your request or when investigating an abuse report.
- Operational telemetry — IP addresses, request rates, error rates, CPU/RAM/disk usage by site, server-side performance metrics. We use this to operate the service and bill you accurately. We do not use it for advertising profiles.
03Why we collect it
Lawful basis under GDPR Article 6:
- Contract performance — most of the data we hold is necessary to deliver hosting services you've signed up for.
- Legitimate interest — security telemetry, fraud detection on signup, network abuse handling.
- Legal obligation — invoice retention for tax records (7 years in the US, 5 years in AU).
- Consent — non-essential cookies, product marketing emails. You can withdraw consent at any time.
04Sub-processors
We use the following third parties to operate the service. Each has a written DPA with us and is GDPR-compliant.
- Stripe, Inc. — payment processing (card data, PCI-DSS scope).
- Cloudflare, Inc. — DNS, CDN edge, DDoS mitigation (IP addresses, request metadata).
- Crisp IM SARL — live chat support (chat transcripts, identifying email if you authenticate).
- Plausible Insights OÜ — cookieless web analytics (aggregated, no individual tracking).
- Postmark (Wildbit, LLC) — transactional email delivery (recipient address, message content).
- Anthropic, PBC — our AI ops layer queries Claude for first-tier support. No raw customer credentials or secrets are sent; chat content is anonymised before transmission and retained 30 days max.
The current sub-processor list lives at /legal/sub-processors and is updated within 30 days of any change.
05Data retention
Different categories are retained for different periods:
- Live account & service data — for as long as your account is active.
- Backups — 30 days for most plans, 60 days on Plus and above, after which they're cryptographically destroyed.
- Server access logs — 90 days.
- Billing records — 7 years (US) / 5 years (AU) — legal minimum.
- Chat transcripts — 18 months, or until you delete them in the client area.
- Deleted accounts — purged 30 days after cancellation, except billing records.
06Your rights
Regardless of where you live, you can request access to, correction of, export of, or deletion of any personal data we hold about you. EU and UK users have the rights granted by GDPR Articles 15–22; California residents have CCPA / CPRA rights; Australian users have the rights granted by the Privacy Act 1988. We honour all of these regardless of jurisdiction.
To exercise any right, log in to your client area and use the "Data & privacy" page, or email [email protected]. We respond within 30 days (most within 5 business days).
07Cookies & tracking
On this marketing site we use cookieless analytics (Plausible) by default. The only non-essential cookies are set when our live-chat widget loads, and only after you've granted consent via the cookie banner. We don't use Google Analytics, Facebook Pixel, or any retargeting technology. There is no "Reject all" option that hides a darker pattern — "Essential only" really is essential only.
08International transfers
Your data may be stored in our Sydney, Ashburn, or London regions depending on the region you select at signup. Where data is transferred between jurisdictions (e.g. an EU customer choosing the US region), transfers are protected by Standard Contractual Clauses or equivalent. We do not transfer EU personal data to jurisdictions without an adequacy decision unless you explicitly direct us to.
09Security & breach notification
We follow industry-standard controls: encrypted-at-rest backups (LUKS / age), encrypted-in-transit traffic (TLS 1.3), 2FA mandatory for staff, principle of least privilege, quarterly third-party penetration testing. Our full security posture lives at /security. Responsible disclosure goes to [email protected] (PGP key on /.well-known/security.txt).
In the event of a personal data breach affecting your account, we will notify you and the relevant supervisory authority within 72 hours of becoming aware, as required by GDPR Article 33.
10Changes to this policy
We may update this policy. Non-material changes (typo fixes, sub-processor renaming, formatting) take effect on publication. Material changes (new categories of data, new sub-processors with material access, retention extensions, new disclosure to law enforcement frameworks) are notified by email at least 30 days before they take effect. The version number and effective date at the top of this document always reflect the current version.
11How to reach us
For any privacy question, including data subject requests: [email protected]
Postal: Hosting Simple LLC, Attn: Privacy, 1209 N Orange Street, Wilmington, DE 19801, USA
For our EU representative (Article 27 GDPR): contact details published at /legal/eu-representative
Document SHA-256 · 8f4d…2a17 · Signed by counsel · Hosting Simple LLC, Delaware