50% off your first month on monthly billing, for new customers, with code See the plans
HostCrafter
Get started

Privacy policy

What we collect, why we collect it, and who else sees it. The honest answer is: as little as we can get away with — and here is the part that is not zero.

Last updated 29 August 2026

What we collect

  • Account details — your name, email, phone and billing address. We need these to invoice you and to know who we are talking to.
  • Payment details — handled by our payment provider. Card numbers never reach our servers and we never see them. We do keep a reference the provider gives us, so we can match a payment to an invoice and send a refund back to the right place.
  • Order records — what you bought, when, from which IP address, and the domain names on the account.
  • Server logs — IP address, time and page for requests to your sites and to our panel. These are how we investigate an outage or an attack, and how we count your traffic.
  • Support conversations — so the next person who helps you can read what already happened.
  • Website analytics — how people arrive at hostcrafter.com and which pages they read. This is about our marketing website, not about your websites or their visitors.

What we do not do

We do not sell your data. We do not share it for advertising. We do not build a profile of you to target you with anything. We do not read your website content, your database or your email except when you ask us to look at something, or when we are legally required to.

We do not put analytics, advertising or tracking of any kind onto your websites. What runs on your site is what you installed.

Cookies and analytics on this website

This website sets a small number of cookies of its own: your chosen currency, your billing term, and whether you prefer the light or dark theme. The client area uses a session cookie to keep you signed in. None of those follow you anywhere else.

We also use Google Analytics to understand how people find this website and which pages are actually useful. It tells us that a page was read, roughly where in the world the reader was and what brought them here. We use it to decide what to write and what to fix. IP addresses are handled by Google, and Google sets its own cookies when it runs — its practices are described in Google's privacy policy.

We use Google Search Console for the same reason on the other side: it shows us which searches bring people here. It reports on our pages, not on individual people.

If you would rather not be counted, a browser that blocks analytics, or Google's own opt-out add-on, will keep you out of it, and nothing on this site works any worse for it.

Cloudflare, in front of this website

hostcrafter.com is served through Cloudflare, which sits between your browser and our server. It makes the site faster for people far from our machines and it absorbs attacks before they reach us. Every request to this website therefore passes through Cloudflare's network and it sees the request — your IP address, the page, your browser — as part of delivering it. Cloudflare also sets a cookie of its own to tell real visitors from automated ones.

This is about our website. Your own websites are a separate matter: they are served through our own CDN, which runs on machines we operate rather than a third party's network. A visitor's request to your site may therefore be answered by one of our edge servers instead of the machine your site lives on. It is still us, still under this policy, and no other company is introduced by it. If you would rather your site was served only from its own node, ask support and we will turn the CDN off for it.

The companies that help us run this

We are small, so some of the machinery is bought rather than built. Each of these sees only what its job requires, and none of them is allowed to use what it sees for anything else:

  • Our payment providers — to take payments and send refunds.
  • Our email provider — to deliver invoices, alerts and replies.
  • The datacentres that house the servers.
  • Cloudflare, Google Analytics and Google Search Console — as described above.
  • Monitoring and server-management services — see the next paragraph.

We use external monitoring and management tools to watch our servers and, where necessary, to operate them: uptime and performance monitoring, error and log collection, alerting, and remote administration. A hosting company that did not use these would find out about an outage from its customers, which is not a service we are willing to sell. From time to time we may also engage a specialist provider to help operate or repair a server.

What we hold ourselves to, when any of that happens:

  • They get the narrowest access that does the job, and only for as long as the job takes.
  • They are there to run the infrastructure. Access to a server is not permission to read your website's content, your database or your email, and it is not used for that.
  • They are bound by a contract with confidentiality obligations, and they are not permitted to use anything they see for their own purposes.
  • Access is logged, and it is removed when the work is finished.

We will also disclose data where the law requires it, and we will tell you if we are allowed to.

Where it lives

Your websites and their data sit on our hosting node in Europe (France). Account and billing records are held on our control-plane server. Backups stay in the same region as the site they came from. If we add nodes in other regions we will say so here, and your data stays in the region your site was created in unless you ask us to move it.

Some of the services above operate outside India and outside the EU, so the limited data each one handles crosses borders as part of doing its job.

What we keep after you leave, and why

Most of it goes. Your site files, your databases and your backups are deleted 14 days after an account ends. Server logs rotate within weeks.

Two things outlive the account, and we would rather explain them than leave you to find out:

  • Billing records. Invoices, payments and tax records are kept for as long as Indian tax and company law requires us to keep them. We do not get to delete these on request.
  • A refund record. Our refund policy gives one refund per customer, ever. A rule like that only works if closing the account does not erase the fact that a refund was made — so when we refund someone we keep a small record of it, mostly as one-way fingerprints of the email address, phone number, domains, payment reference, billing country and order IP, alongside the date and amount. A fingerprint can answer “have we seen this before?” and cannot be turned back into your personal details. We keep it for five years and then delete it.

We also keep a record of accounts closed for abuse, for the same reason and for the same period: so that the account we removed for hosting a phishing page does not simply come back under a new email address.

Indian data-protection law allows personal data to be kept beyond its original purpose where that is needed to meet a legal obligation or to prevent fraud. Those are the two reasons above, and we hold ourselves to keeping the smallest thing that does the job.

Your rights

Email [email protected] to get a copy of what we hold, correct it, or have it deleted. We acknowledge within 24 hours and answer within 30 days, and we will not charge you for it.

Two honest limits. Deleting your data means closing your account — we cannot run hosting for someone we hold no record of. And the billing records and the refund record described above are the exceptions: we will tell you exactly what is left and why, but we cannot delete them on request.

If you are not satisfied with how we handled a privacy request, write to [email protected], and you retain the right to complain to the data-protection authority in your country.