In short
- We collect what we need to run your account, bill you, register your domains and keep our network safe — nothing more.
- We do not sell your personal data or use it for third-party advertising.
- Domain registrations require us to share your contact details with registrars and registries, and some of it may be published in WHOIS unless privacy protection is on.
- Card and UPI details are handled by our payment providers; we never see or store full card numbers.
- You can access, correct or ask us to delete your data, subject to legal record-keeping duties.
1. Who we are
HostEthical ("HostEthical", "we") decides how and why your personal data is processed when you use our website and services, and acts as the data fiduciary for that data under the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 and rules made under them.
For data stored inside your services — for example the visitors to your website or the contents of your mailboxes — you are in control. We process that data only on your instructions in order to provide the service.
2. What we collect
Information you give us
- Account details: name, email address, password (stored only as a one-way hash), phone number and two-factor authentication settings.
- Billing details: company name, postal address, country and tax identifiers such as a GSTIN, and the history of your orders, invoices and payments.
- Domain contact details: the registrant, administrative and technical contacts required by registries.
- Support conversations: the content of tickets, emails and any files you attach.
Information collected automatically
- Technical and security data: IP addresses, browser and device type, sign-in times and actions taken in your account, used to secure your account and detect fraud and abuse.
- Service data: configuration of your domains, DNS records and services, and operational logs from our infrastructure.
Information from others
- Payment providers tell us whether a payment succeeded and give us a transaction reference. They do not share your full card or bank details with us.
- Registrars and registries send us the status of your domains and any verification or dispute notices.
3. How we use it
- To create and secure your account and provide the services you order — the legal basis is our contract with you.
- To issue invoices, collect payment, and meet tax and accounting obligations.
- To register, renew and transfer domains as required by registry and ICANN rules.
- To send service messages such as renewal reminders, security alerts and maintenance notices. These are not marketing and you can't opt out of them while you have active services.
- To prevent fraud, spam and abuse, and to investigate reports made to admin@hostethical.com.
- To send occasional product news, only if you have opted in. You can unsubscribe at any time.
- To comply with law, including lawful requests from government authorities and directions issued by CERT-In.
4. Domain registrant data
When you register or transfer a domain, the contact details on your billing profile (or the details you supply for that domain) are sent to the domain registrar and to the registry operating the extension. For generic extensions, ICANN requires registrars to keep this data, to escrow a copy with an approved provider, and to make some of it available through WHOIS / RDAP lookup services.
Where the registry allows it, WHOIS privacy replaces your personal details in public lookups with those of a privacy service. Some extensions — including several country-code extensions — do not permit privacy services. Even with privacy enabled, registries and registrars may disclose your details to law enforcement, to dispute-resolution providers, or to parties with a legitimate interest as their policies allow.
5. Who we share it with
We share personal data only with organisations that help us deliver the services, and only what each one needs:
- Domain registrars and registries — to register and manage your domains.
- Payment gateways and banks — to process card, UPI, net banking and bank-transfer payments and to prevent payment fraud.
- Infrastructure providers — data-centre, cloud and network providers that host our platform and your services, and DNS providers that serve your zones.
- Certificate authorities — to validate domains and organisations and issue SSL certificates.
- Email delivery and support tooling — to send you transactional emails and handle support conversations.
- Professional advisers and authorities — our auditors and lawyers, and government or law-enforcement bodies where disclosure is required by law or necessary to protect our users or network.
Our processors are bound by contract to use the data only to provide their service to us and to protect it. If our business is sold or merged, data may transfer to the new owner under the same protections.
6. Where data is processed
We aim to store core account and billing data in India. Some providers — for example registries for generic extensions, certificate authorities or international payment networks — process data in other countries. Where data leaves India we rely on the safeguards in our contracts with those providers and transfer it only as permitted under Indian law.
7. How long we keep it
- Account data: for as long as your account is open, and for a limited period afterwards to handle queries and disputes.
- Invoices and payment records: for at least eight years, as required by Indian tax and accounting law.
- Domain records: for the period required by ICANN and registry agreements, which can extend beyond the life of the registration.
- Security logs and subscriber records: for the periods required by applicable directions, including those issued by CERT-In.
- Data inside cancelled services: deleted after the service is terminated; backups expire on their normal rotation.
8. How we protect it
We use encryption in transit (TLS) for our website and APIs, encrypt sensitive fields such as service passwords and authorisation codes at rest, store account passwords only as salted hashes, restrict staff access on a need-to-know basis, and offer two-factor authentication on every account. No system is perfectly secure; if a breach affects your personal data we will notify you and the relevant authorities as the law requires.
9. Cookies
We use essential cookies to keep you signed in, remember your cart, and protect forms against cross-site request forgery. These are required for the site to work. We do not use third-party advertising cookies. If we introduce analytics, we will update this policy and, where required, ask for your consent first.
10. Your rights
Subject to the law, you can:
- ask for a summary of the personal data we hold about you and how we use it;
- correct or update it — most details can be changed directly in Profile & billing;
- ask us to delete it once it is no longer needed for the services or required by law;
- withdraw consent you have given, for example for marketing emails;
- nominate someone to exercise these rights on your behalf in the event of death or incapacity; and
- raise a grievance with us, and if you are not satisfied, with the Data Protection Board of India.
Email admin@hostethical.com from the address on your account to make a request. We may need to verify your identity first and will respond within the time required by law.
11. Grievance officer
In accordance with the Information Technology Act, 2000 and the rules made under it, our grievance officer is:
[Name], HostEthical
Email: admin@hostethical.com
Address: [registered address]
We acknowledge grievances within 24 hours and aim to resolve them within 15 days.
12. Changes to this policy
We will update this page when our practices change and revise the "last updated" date above. If a change materially affects how we use your data, we will tell you by email before it takes effect.