30-day money-back guarantee · Free migration · 99.9% uptime SLA

Privacy Policy

What personal data we collect, why we collect it, and the choices you have.

Last updated October 8, 2026

1. Who we are and scope

Fonhost operates fonhost.com and the client area at billing.fonhost.com, and provides shared cPanel hosting, managed WordPress hosting and reseller hosting. We are the data controller for the personal data described here. Our registered office and registration details are published on this website. Contact support@fonhost.com with the subject line “Data protection request” for any privacy question, and abuse@fonhost.com for abuse or security reports. This policy covers our website, client area, support, billing and marketing. It does not cover the personal data you process inside the websites, databases and mailboxes you host with us: for that data you are the controller and we act only as your processor on your documented instructions, as explained on our GDPR and Data Processing page.

2. Personal data we collect

You give us: your name and company; email, phone and postal or billing address; your client area username, a hashed password and two-factor state; billing records and payment metadata such as the last four card digits, card brand, transaction reference and whether a payment succeeded; the domains and settings on your account; your support tickets and any attachments you send us; and your marketing preferences. Full card numbers, CVV codes and full bank details are entered on the payment processor’s own systems and are never transmitted to or stored on our servers.

We collect automatically: IP address, browser and device type, the pages you request, timestamps and results; login and failed-authentication events, firewall and abuse-detection output; and the resource, error and availability metrics we need to run and support the platform.

We receive from others: from payment processors and acquirers, the outcome of a transaction, a chargeback or a refund and the fraud signals returned with it; from fraud and sanctions screening services, risk scores and whether the details supplied matched; from registrars and registries, registration outcomes, verification status and the public WHOIS records for your domain; and from a partner who introduced you, the details needed to set up your account. We do not collect special category data, and our Services are not directed at children.

3. Purposes and legal bases

PurposeLegal basis
Creating and administering your account, provisioning hosting, registering domains and delivering supportPerformance of a contract
Taking payment, issuing invoices, handling refunds and chargebacks, and keeping accounting recordsPerformance of a contract; legal obligation
Preventing fraud, abuse, spam and attacks, and keeping the platform safeLegitimate interests; legal obligation where a report must be made
Monitoring availability, capacity and performance and diagnosing faultsLegitimate interests
Service notices about maintenance, outages, renewals, price changes and legal termsContract; legal obligation; legitimate interests
Marketing and newsletters about our hosting servicesConsent, or a soft opt-in where local law permits it for existing customers
Improving our website, products and supportConsent for optional analytics cookies; legitimate interests for aggregate measurement
Establishing or defending legal claims and answering lawful requests from authoritiesLegal obligation; legitimate interests
Answering a sales enquiry you startedSteps taken at your request before a contract; legitimate interests

Where we rely on legitimate interests we have balanced them against your rights, and you may ask us for that assessment. Where we rely on consent you may withdraw it at any time, without affecting processing already carried out.

4. Cookies

Essential cookies keep you logged in, protect forms against cross-site request forgery, remember your theme and cookie choice, and route requests to a healthy server. Optional analytics cookies, set only if you accept them, tell us which pages are read. You can accept, reject or change optional cookies at any time from the cookie preferences control or the banner, and blocking essential cookies will stop you logging in or completing an order. The full list, with names and lifetimes, is in our Cookie Policy.

5. Sharing and sub-processors

We never sell, rent or trade your personal data, and we do not share it with advertising networks or data brokers. We share it only with the providers we need to run the service: datacenter and infrastructure providers that host the servers and encrypted backup storage; payment processors and acquirers; domain registrars and registries, which receive the registrant data required to register and renew a domain and publish part of it in public WHOIS records as registry policy requires; email delivery providers that send account, invoice, security and marketing mail; support, helpdesk and monitoring tooling providers; fraud prevention and security services; our professional advisers; and authorities or rights holders where the law or a valid legal claim requires disclosure. Every processor is bound by a written contract to act only on our documented instructions, apply appropriate security measures, keep the data confidential, help us with data subject requests and breach notification, and delete or return the data when the engagement ends. Our current sub-processor list is on the GDPR and Data Processing page, and we notify customers before adding a new one. If we merge with or are acquired by another organisation, data may transfer to the successor under this policy.

6. International transfers

Our team, servers and providers may be in more than one country, so your data may be processed outside the country you live in. Where we transfer personal data out of the European Economic Area, the United Kingdom or Switzerland we rely on an appropriate safeguard: an adequacy decision for the destination country, or the approved standard contractual clauses or equivalent UK addendum with a transfer risk assessment and additional technical measures such as encryption in transit and at rest. You can request a copy of the safeguard by contacting support@fonhost.com. Where you choose a server location at checkout we store your Service data in that region, except for control, billing and backup copies held elsewhere under those safeguards.

7. Retention

CategoryRetention
Account, identity and contact recordsWhile the Account is active, plus 24 months after closure
Invoices, payment and accounting recordsThe period required by the tax and accounting law that applies to us, typically 6 to 10 years
Support tickets and email36 months from closure of the ticket
Website, security and access logsUp to 12 months; longer where abuse or fraud evidence is under investigation
Service and usage telemetryUp to 13 months, aggregated where possible
Blocked or fraudulent order records24 months
Marketing consent and unsubscribe recordsUntil consent is withdrawn, plus 24 months

Customer files, databases and mailboxes are kept while the Service is active and then deleted on the schedule in the Terms of Service, normally within 30 days of termination, with courtesy backups following their own cycle. Where a legal hold, dispute, abuse investigation or regulatory requirement applies we keep the relevant data until that matter closes, and then delete it.

8. Security

Our measures include encryption in transit (TLS 1.2 or better, with HSTS) for our website, client area, control panel and mail; encryption at rest for backups with separate credentials; salted one-way password hashing, so we can never read your password; role-based internal access on a least-privilege basis with no shared admin logins; mandatory multi-factor authentication for staff who can reach customer systems, and optional MFA for you; firewalling, rate limiting, brute-force and intrusion detection, malware scanning and a web application firewall; 24/7 monitoring with administrative actions logged; and a documented incident response procedure. No system is perfectly secure, so use a strong unique password, enable MFA, keep your own site, themes and plugins updated, and tell us immediately if you suspect a compromise.

9. Data breaches

If a personal data breach is likely to risk your rights, we will contain it, assess the risk, notify the relevant supervisory authority without undue delay and within 72 hours where the law requires it, and notify affected customers and individuals without undue delay where the risk is high, explaining what happened, what data was involved, what we have done and what you should do. We keep a record of every breach and our response. Where we act as your processor, we notify you without undue delay so you can meet your own obligations.

10. Your rights

Depending on where you live you have the right to access your data and information about how we use it; to rectify inaccurate or incomplete data; to erasure, which is not absolute because we must keep records the law requires, such as invoices; to restrict processing while a question is resolved; to portability of the data you gave us in a structured, machine-readable format; to object to processing based on legitimate interests and at any time to direct marketing; to withdraw consent as easily as you gave it; and to complain to the supervisory authority in the country where you live, work or where the alleged breach occurred. To exercise a right, open a ticket or email support@fonhost.com with the subject line “Data protection request”. We may ask you to confirm your identity, usually by replying from the address on your Account, so we never disclose data to the wrong person. There is no fee for a normal request, and we respond within one month, extended by up to two further months for a complex or repeated request, telling you why within the first month. You can also correct your details, change your marketing preferences and close your Account directly in the client area.

11. Marketing and automated decisions

Service messages (invoices, renewal reminders, maintenance and security notices, and replies to your tickets) are part of running your Account and cannot be opted out of while you hold one. Marketing email is separate: unsubscribe from the link in every message or from your client area preferences, and we will act promptly and within the period the law allows. We do not use automated decision-making or profiling to make decisions with legal or similarly significant effects: no automated process terminates your Service, refuses you service permanently or sets your price. We do use automated tools to score new orders and payment attempts for fraud, to scan mail and files for spam and malware, to rate-limit automated traffic, and to segment customers on aggregate data only. A human reviews any flag before significant action is taken, and you may ask us to explain or reconsider a decision at support@fonhost.com.

12. Children

Our Services are for adults and businesses and are not intended for anyone under 18. We do not knowingly collect personal data from children; if you believe a child has given us data, contact support@fonhost.com and we will delete it promptly. If you host a website aimed at children, you are the controller of the data it collects and are responsible for any parental consent and age verification the law requires.

13. Changes and contact

We may update this policy to reflect changes in our Services, providers, security practices or the law. The current version is always published here with an effective date, and where a change materially affects how we use your data or your rights we give reasonable advance notice by email and in the client area. If we intend to use your data for a new purpose that needs consent, we ask for it first. For any privacy question or request use support@fonhost.com (subject line “Data protection request”), or a billing ticket from the client area; abuse and security incidents go to abuse@fonhost.com; sales questions to sales@fonhost.com; and postal enquiries to the registered office address published on this website. If you are not satisfied with our response you may complain to the supervisory authority in the country where you live, work, or where the alleged breach took place.

Ready to launch? We will move your website for free.

Pick a plan, and our migration team takes care of the rest - files, databases, email and DNS - usually within one business day.