HF-LGL-02 · PRIVACY POLICY
Privacy Policy
EFFECTIVE
2026-07-16
This policy explains what data Hostfluency collects, why, where it lives, and who else touches it. We keep client data on hardware we own — our own North American infrastructure behind Cloudflare’s global edge — we use exactly three outside processors, and we don’t sell anything to anyone. It’s a short list because we like it that way.
Last updated July 16, 2026 · Version 1.0 · Governed by the laws of California, United States
§1The short version
We’re a hosting company, not an ad network. The whole policy below boils down to six sentences:
- We collect the minimum we need to run your hosting and bill you.
- We never sell your data, and we don’t run advertising or cross-site trackers.
- Your hosted data lives on hardware we own— our own North American infrastructure behind Cloudflare’s global edge.
- Exactly three outside companies touch any of your data: Stripe, Resend, and Cloudflare (see §4).
- Backups are daily and kept for 30 days.
- Want to see, fix, export, or delete your data? Email [email protected] (see §8).
§2What we collect
We collect five kinds of information, and nothing speculative:
- Account details — your name, email address, and billing address, so we know who you are and where to send invoices.
- Billing status — Stripe handles your card entirely; we see only the card’s last four digits, its expiry, and whether a charge succeeded. Full card numbers never touch our systems.
- Correspondence — emails and portal messages you exchange with us, kept so support has context and promises stay on the record.
- Technical logs — server and request logs (including IP addresses) and uptime metrics, used for security and troubleshooting, and kept for about 30 days.
- Your hosted content — the site itself, which we store because hosting it is the job. We don’t mine it, analyse it, or peek at it beyond what operating and supporting it requires.
§3How we use it
We use the information in §2 to:
- operate and maintain your hosting,
- bill you and keep required financial records,
- answer your support requests,
- send transactional email — invoices, outage notices, maintenance windows, renewal reminders. No marketing blasts; we don’t even have a mailing list to sell you into,
- detect and prevent abuse, fraud, and attacks on the platform, and
- comply with legal obligations, such as tax record-keeping.
What we don’t do: sell your data, share it with advertisers, build profiles of you, or use your hosted content for anything other than hosting it.
§4Who touches your data — the three processors
We use exactly three outside services, each for one job. If this list ever grows, this policy will change and you’ll get an email about it.
Each processor handles data under its own published privacy policy, and each may process data in its own operating regions — see §5.
§5Where your data lives
Your hosted site — files, database, and backups — lives on hardware we own and operate— our own North American infrastructure behind Cloudflare’s global edge. It is not scattered across anonymous cloud regions; we can point at the hardware.
Two honest caveats. First, traffic to your site passes through Cloudflare’s global network, which is what keeps it fast and shielded. Second, Stripe and Resend operate largely in the United States, so billing records and transactional emails are processed there. We chose each of these deliberately, and we keep the list short on purpose.
§6Backups and retention
- Site backups — taken daily, retained 30 days, then overwritten in rotation.
- Technical logs — kept for about 30 days, then deleted.
- Account and billing records — kept while your account is active, and invoices for up to 7 years afterwards, because tax law requires it.
- After cancellation — your site data leaves the backup rotation and is permanently deleted within 30 days of your service ending (see the Terms, §7).
§8Your rights
Under applicable privacy law — and under our own sense of decency — you can ask us at any time to:
- see the personal information we hold about you,
- correct anything inaccurate,
- export your data — including a full copy of your hosted site, and
- delete your personal information, subject only to what the law requires us to keep (such as invoices, per §6).
Email [email protected]. You’ll typically hear back the same business day, and we’ll complete the request within 30 days. If you’re not happy with how we handle it, you can escalate to the privacy regulator that applies where you live.
§9Security
Everything is served over TLS, the platform sits behind Cloudflare’s DDoS protection, our systems are patched as part of routine maintenance, and access to client data is tightly restricted. Collecting minimal data (§2) is itself a security measure: what we don’t hold can’t leak.
If a breach ever affects your data, we will tell you promptly and in plain language — what happened, what was touched, and what we’re doing about it — and notify regulators where the law requires.
§10Changes and contact
If we change this policy in any way that matters — new processor, new data category, new retention period — we’ll email you before the change takes effect. Quiet edits to fix typos don’t count as changes that matter.
Questions about privacy, or anything in this document: [email protected].