24/7 Support Online

Privacy Policy

How We Collect, Use, Protect & Share Your Personal Data

Last Updated: June 2025  |  Version 2.1  |  Compliant with Indian IT Act 2000

1. Introduction & Commitment

Our commitment to your privacy and data protection

At GoHostBiz, we take your privacy seriously. This Privacy Policy explains in comprehensive detail how we collect, use, store, process, share, and protect your personal information when you visit our website, register an account, purchase our services, or otherwise interact with us.

We are committed to protecting your personal data in accordance with applicable Indian laws, including the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules), and other relevant data protection regulations.

Our Privacy Promise

  • We will never sell your personal information to third parties
  • We will never share your data except as explicitly described in this policy
  • We will always protect your data with industry-standard security measures
  • We will always be transparent about what data we collect and why
  • We will respect your rights regarding your personal information

Data Controller Information

Data Controller: GoHostBiz
Contact Person: Data Protection Officer (DPO)
Address: Harinagar, Karbala ke pass, Thakurganj, Chowk, Lucknow, Uttar Pradesh, India – 226003
Email: gohostbiz@gmail.com
Phone: +91 9598587318

2. Our Privacy Principles

The core principles that guide our data handling practices

GoHostBiz adheres to the following fundamental privacy principles in all our data processing activities. These principles form the foundation of our approach to protecting your personal information:

🔍
Transparency

We clearly inform you what data we collect, why we collect it, and how we use it. No hidden data collection practices.

🎯
Purpose Limitation

We collect data only for specific, legitimate purposes and never use it in ways incompatible with those purposes.

📦
Data Minimization

We collect only the minimum amount of personal data necessary to provide our services and fulfill our obligations.

Accuracy

We take reasonable steps to ensure your personal data is accurate, complete, and kept up to date.

⏱️
Storage Limitation

We retain your data only as long as necessary for the purposes for which it was collected.

🔒
Security & Integrity

We implement appropriate technical and organizational measures to protect your data against unauthorized access, loss, or damage.

3. Information We Collect — Overview

Categories of data we collect and process

We collect various types of information to provide, maintain, and improve our services. This information can be categorized into four main groups:

Personal Information

Information that identifies you as an individual

  • Full legal name
  • Email address
  • Phone number
  • Billing/Postal address
  • Government ID (if required for verification)
Technical Information

Automatically collected when you interact with our services

  • IP address
  • Browser type & version
  • Operating system
  • Device information
  • Login timestamps
Financial Information

Payment-related data for transaction processing

  • Payment method details
  • Transaction IDs
  • Invoice & billing records
  • GST number (if applicable)
Usage Information

Data about how you use our services

  • Support ticket history
  • Service usage patterns
  • Resource consumption data
  • Website interaction analytics

4. Personal Information — Detailed Breakdown

What personal data we collect, when, and why

Data Element When Collected Purpose Legal Basis
Full Name Account registration, checkout Account identification, billing, legal compliance, support communication Contractual necessity, legal obligation, legitimate interest
Email Address Account registration, checkout, newsletter signup Account management, service notifications, support communication, marketing (with consent) Contractual necessity, consent, legitimate interest
Phone Number Account registration, checkout Account verification, support communication, WhatsApp support, urgent notifications, 2FA Contractual necessity, legitimate interest
Billing Address Checkout, invoice generation GST invoice compliance, payment verification, legal records Legal obligation (GST laws), contractual necessity
GST Number Checkout (business customers) GST-compliant invoicing, input tax credit Legal obligation (GST Act)
Company Name Checkout (business customers) Business account management, billing Contractual necessity
IP Address All website visits, logins Security monitoring, fraud prevention, access logs, geolocation for compliance Legitimate interest, legal obligation
Government ID Specific verification requirements Identity verification (if fraud suspected), legal compliance Legal obligation, legitimate interest

Sensitive Personal Data

Under the Indian SPDI Rules, "sensitive personal data or information" includes passwords, financial information (bank account, credit/debit card details), physical/physiological/mental health conditions, sexual orientation, medical records, and biometric information. GoHostBiz does not collect or store sensitive personal data beyond what is strictly necessary for payment processing. We do NOT collect health data, biometric data, or genetic data.

5. Technical Information — Automatically Collected

Data collected automatically when you use our services

When you visit our website or use our services, certain technical information is automatically collected through server logs, cookies, and similar technologies. This information is essential for service delivery, security, and improvement:

5.1 Server Log Data

Our servers automatically record information when you access our website or services, including:

  • IP Address: Your public IP address at the time of access
  • Timestamp: Date and time of each request/visit
  • Request Details: Pages visited, files accessed, API calls made
  • Referrer URL: The website from which you arrived (if any)
  • User Agent: Browser type, version, and operating system
  • Response Status: HTTP status codes indicating success or errors
5.2 Device & Browser Information

We collect information about the device and browser you use to access our services to ensure compatibility and optimize your experience:

  • Browser type and version (Chrome, Firefox, Safari, etc.)
  • Operating system (Windows, macOS, Linux, Android, iOS)
  • Screen resolution and viewport size
  • Device type (desktop, tablet, mobile)
  • Language preferences
  • Timezone settings
5.3 Usage Analytics

We use analytics tools to understand how our services are used. This helps us improve our platform:

  • Pages visited and time spent on each page
  • Features and tools used within the control panel
  • Navigation patterns and user flow
  • Error encounters and bug reports
  • Performance metrics (page load times, server response times)

Analytics data is typically aggregated and anonymized and does not personally identify you.

5.4 Hosting Service Usage Data

When you use our hosting services, we collect operational data necessary for service provision:

  • Resource usage (CPU, RAM, disk space, bandwidth consumption)
  • Inode count and file system usage
  • Database sizes and query counts
  • Email account configurations and usage
  • FTP and control panel login activity
  • Scheduled task (cron job) execution logs

6. Financial & Payment Information

How we handle your payment data

We Do NOT Store Full Payment Details

GoHostBiz does not store your complete credit card numbers, debit card numbers, UPI PINs, net banking credentials, or full bank account details on our servers. All payment processing is handled by PCI-DSS compliant third-party payment gateways (Razorpay, PayU, Instamojo, etc.). We only store:

  • Transaction reference IDs
  • Last 4 digits of card number (for identification purposes)
  • Payment method type (UPI, card, net banking, wallet)
  • Payment amount, date, and status
  • UPI ID / email associated with payment (for refund processing)
Payment DataStored by GoHostBiz?Stored by Payment Gateway?
Full Card Number (16 digits)NO Not storedYES Encrypted per PCI-DSS
Card Expiry DateNO Not storedYES Encrypted per PCI-DSS
CVV/CVC CodeNO Not storedNO Not stored (one-time use)
Card Holder NameNO Not storedYES For fraud checks
UPI IDYES For refundsYES Transaction record
Transaction IDYES For billing recordsYES Transaction record
Payment Amount & DateYES For invoicingYES Transaction record

7. How We Use Your Data

Purposes for which your information is processed

We use your personal information for the following specific purposes. We do not use your data for any purpose not listed here without your explicit consent:

7.1 Service Provision & Account Management
  • Creating, maintaining, and managing your GoHostBiz account
  • Provisioning, configuring, and delivering the hosting services you purchased
  • Processing your orders, payments, and invoices
  • Providing access to control panels, dashboards, and account management tools
  • Verifying your identity to prevent unauthorized access and fraud
  • Communicating service-related updates, maintenance schedules, and technical notifications
7.2 Customer Support & Communication
  • Responding to your support tickets, queries, and requests via all channels
  • Providing technical assistance and troubleshooting
  • Sending service expiry reminders, renewal notices, and invoice communications
  • Notifying you of changes to our terms, policies, or services
  • Sending security alerts and important account notifications
7.3 Service Improvement & Analytics
  • Analyzing usage patterns to improve our services and user experience
  • Monitoring server performance and resource utilization
  • Identifying and fixing bugs, errors, and technical issues
  • Conducting customer satisfaction surveys and feedback collection
  • Developing new features and services based on usage trends
7.4 Security & Fraud Prevention
  • Detecting, preventing, and investigating fraudulent transactions
  • Monitoring for unauthorized access attempts and security breaches
  • Enforcing our Terms of Service and Acceptable Use Policy
  • Protecting our infrastructure against DDoS attacks, malware, and abuse
  • Complying with legal obligations and law enforcement requests
7.5 Marketing & Promotional Communications
  • Sending promotional offers, discounts, and new service announcements (only with your consent)
  • Informing you about upgrades, addons, and complementary services
  • Sharing newsletters, blog posts, and educational content
  • Inviting you to participate in referral programs or loyalty rewards

Opting Out of Marketing

You can unsubscribe from marketing communications at any time by:

  • Clicking the "Unsubscribe" link in any marketing email
  • Updating your communication preferences in the Client Area
  • Contacting our support team with an opt-out request

Even after opting out of marketing, you will continue to receive essential service-related communications (invoices, renewal notices, security alerts) that are necessary for your account.

9. Data Sharing & Disclosure

Who we share your data with and under what circumstances

GoHostBiz does not sell, rent, trade, or lease your personal information to third parties. We only share your data in the following limited circumstances:

9.1 Service Providers & Business Partners

We share data with trusted third-party service providers who help us operate our business. These providers are contractually bound to protect your data and use it only for the specific services they provide to us:

Provider CategoryExamplesData SharedPurpose
Payment Gateways Razorpay, PayU, Instamojo Name, email, payment amount, transaction details Processing payments, refunds, and payment verification
Domain Registrars ResellerClub, LogicBoxes Name, email, phone, address (for WHOIS) Domain registration as required by ICANN
Data Center / Server Providers Upstream infrastructure providers Account data on provisioned servers Physical server hosting and network connectivity
Communication Tools WhatsApp Business API, Email services Phone number, email address Support communication and notifications
Analytics Providers Google Analytics, internal tools Anonymized usage data, IP address Website analytics and service improvement
9.2 Legal & Regulatory Disclosures

We may disclose your personal data when required by law or when we believe in good faith that disclosure is necessary to:

  • Comply with a legal obligation, court order, or government request
  • Respond to lawful requests by public authorities, including law enforcement and national security agencies
  • Protect and defend the rights, property, or safety of GoHostBiz, our customers, or the public
  • Detect, prevent, or address fraud, security, or technical issues
  • Enforce our Terms of Service or other agreements
  • Report illegal activities or content to appropriate authorities

Government & Law Enforcement Requests

In compliance with the Indian Information Technology Act, 2000 and the SPDI Rules, GoHostBiz may disclose personal information to government agencies mandated under law to obtain such information for the purposes of verification of identity, prevention, detection, investigation, prosecution, and punishment of offences. Any such disclosure will be made only upon receipt of a valid, legally-compliant written request from an authorized government body.

9.3 Business Transfers

In the event of a merger, acquisition, reorganization, sale of assets, or bankruptcy, your personal data may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our website of any change in ownership or use of your personal data, as well as any choices you may have regarding your data.

10. Third-Party Services & Links

Important information about services provided by other companies

Our website, control panel, and services may contain links to third-party websites, plugins, and applications. Clicking those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy practices.

Important Notice About Third-Party Services

  • When you leave our website or use third-party services, we encourage you to read the privacy policy of every website you visit
  • Third-party plugins, themes, or software you install on your hosting account may have their own data collection practices
  • Payment gateways have their own privacy policies governing how they handle your financial data
  • GoHostBiz is not responsible for the data practices of third-party services accessed through your hosting account

Some specific third-party services we use and links to their privacy policies:

11. Data Security Measures

How we protect your personal information

GoHostBiz implements comprehensive technical, administrative, and physical security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. Our security practices are designed in accordance with the ISO/IEC 27001 framework and the Reasonable Security Practices and Procedures prescribed under the Indian IT Act.

11.1 Technical Security Measures
  • Encryption in Transit: All data transmitted between your browser and our servers is encrypted using TLS 1.3 (Transport Layer Security) with strong cipher suites
  • Encryption at Rest: Sensitive data stored in our databases is encrypted using AES-256 encryption
  • Firewall Protection: Enterprise-grade firewalls (hardware and software) protect our network perimeter
  • DDoS Mitigation: Automated DDoS detection and mitigation systems protect against volumetric and application-layer attacks
  • Intrusion Detection: IDS/IPS systems monitor network traffic for suspicious activity 24/7
  • Malware Scanning: Regular automated scanning for malware, viruses, and malicious code
  • Secure Authentication: Support for two-factor authentication (2FA), strong password policies, and brute-force protection
  • Regular Updates: All server software, operating systems, and applications are regularly patched and updated
11.2 Administrative Security Measures
  • Access Control: Strict role-based access controls limit employee access to personal data based on job requirements and the principle of least privilege
  • Employee Training: All employees receive mandatory data protection and privacy training
  • Confidentiality Agreements: All employees, contractors, and third-party providers sign confidentiality and data protection agreements
  • Audit Logs: Comprehensive logging of all access to personal data and administrative systems
  • Regular Audits: Periodic security audits and vulnerability assessments by internal and external teams
  • Incident Response: Documented incident response plan for handling security breaches
11.3 Physical Security Measures
  • Data Center Security: Our servers are housed in Tier III data centers with 24/7 security personnel, biometric access controls, and CCTV surveillance
  • Restricted Access: Only authorized personnel have physical access to server infrastructure
  • Environmental Controls: Fire suppression systems, climate control, and redundant power supplies protect physical infrastructure

No Absolute Security Guarantee

While we implement industry-best security practices, no method of electronic storage or transmission over the Internet is 100% secure. We cannot guarantee absolute security of your data against all possible threats. In the event of a security breach, we will promptly notify affected users and relevant authorities as required by applicable law.

12. Data Retention Policy

How long we keep your personal data

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. When your data is no longer needed, we securely delete or anonymize it.

Data CategoryRetention PeriodBasis for Retention
Account Information Duration of account + 2 years after closure Legal obligations, dispute resolution, record-keeping
Hosting Content & Data Duration of active service + backup retention period (see Backup Policy) Service provision, then permanent deletion
Financial/Transaction Records 8 years from transaction date Legal requirement under Indian tax laws (Income Tax Act, GST Act)
Support Tickets & Communication 3 years from last interaction Customer service improvement, dispute resolution
Server Logs 30–90 days (rotating) Security monitoring, debugging
Analytics Data 26 months (anonymized) Long-term trend analysis
Marketing Consent Records Duration of consent + 3 years after withdrawal Proof of consent for compliance

Data Deletion After Account Closure

When you close your GoHostBiz account or your services are terminated:

  • All your hosted content (websites, databases, emails, files) is permanently deleted after the applicable backup retention period
  • Your account profile is deactivated but retained for legal and record-keeping purposes
  • Financial records are retained for the statutory period required by Indian tax laws
  • You can request earlier deletion of non-mandatory personal data by contacting our DPO

13. Your Data Protection Rights

Rights you have regarding your personal information

Under applicable data protection laws, you have the following rights regarding your personal data. GoHostBiz is committed to honoring these rights:

Right to Access

You have the right to request a copy of the personal data we hold about you. We will provide this information in a structured, commonly used, machine-readable format.

How to exercise: Submit a data access request via support ticket or email to our DPO.

Right to Rectification

You have the right to correct any inaccurate or incomplete personal data we hold about you. You can update most information directly through your Client Area.

How to exercise: Update via Client Area → My Details, or contact support for assistance.

Right to Erasure

You have the right to request deletion of your personal data in certain circumstances (e.g., data no longer necessary, consent withdrawn, objection to processing). This is subject to legal retention requirements.

How to exercise: Submit a deletion request to our DPO with specific details of what data you want deleted.

Right to Restrict Processing

You have the right to request restriction of processing in certain situations (e.g., while we verify accuracy of disputed data, or if processing is unlawful but you oppose deletion).

How to exercise: Contact our DPO with your restriction request and justification.

Right to Data Portability

You have the right to receive your personal data in a portable format and, where technically feasible, have it transferred directly to another service provider.

How to exercise: Request data export via support ticket. We provide data in CSV/JSON format.

Right to Object

You have the right to object to processing based on legitimate interests or direct marketing. We will cease processing unless we demonstrate compelling legitimate grounds.

How to exercise: Contact our DPO specifying the processing you object to and your reasons.

Response Time for Rights Requests

We will respond to all data rights requests within 30 calendar days of receipt. In complex cases, this may be extended by an additional 30 days, in which case we will notify you of the extension and the reasons for the delay. We may need to verify your identity before processing your request to prevent unauthorized access to your data.

Limitations & Exceptions

Your data rights are not absolute and may be subject to limitations and exceptions under applicable law. For example:

  • We may retain data required for legal compliance even if you request deletion
  • We may refuse manifestly unfounded or excessive requests (or charge a reasonable fee)
  • Access requests that could compromise others' privacy may be partially restricted
  • Data portability applies only to data you provided and processed by automated means

14. Cookie Policy

How we use cookies and similar tracking technologies

Cookies are small text files placed on your device when you visit a website. They are widely used to make websites work efficiently and provide information to the website owners. GoHostBiz uses cookies and similar technologies (web beacons, pixels, local storage) for the following purposes:

Managing Your Cookie Preferences

You can control and manage cookies in the following ways:

  • Browser Settings: Most browsers allow you to block or delete cookies through their settings. Note that blocking essential cookies may prevent our website from functioning correctly.
  • Cookie Consent Banner: When you first visit our website, a cookie consent banner allows you to accept or decline non-essential cookies.
  • Google Analytics Opt-out: Install the Google Analytics Opt-out Browser Add-on.
  • Third-Party Opt-out: Visit Your Online Choices for EU-based opt-outs or DAA WebChoices for US-based opt-outs.

15. Children's Privacy

Protection of minors' personal information

GoHostBiz's services are not directed at, intended for, or designed to attract individuals under the age of 18 years. We do not knowingly collect, solicit, or maintain personal information from anyone under the age of 18.

If We Discover Minor's Data

If we become aware that a person under the age of 18 has registered an account or provided personal information without verified parental consent, we will:

  • Immediately suspend the account
  • Delete all personal information associated with the account
  • Terminate all services without refund (as per Terms of Service age requirement)
  • Notify the parent or legal guardian if contact information is available

If you are a parent or guardian and believe that your child under 18 has provided us with personal information, please contact our Data Protection Officer immediately so we can take appropriate action.

16. Data Breach Notification Policy

How we respond to and notify about data breaches

In the unfortunate event of a data breach involving your personal information, GoHostBiz has established the following response and notification procedures:

  1. Immediate Containment: Upon discovery, we will immediately take steps to contain and mitigate the breach, secure affected systems, and prevent further unauthorized access.
  2. Investigation: We will conduct a thorough investigation to determine the scope, cause, and impact of the breach, including what data was affected and which individuals are impacted.
  3. Notification to Affected Users: If the breach poses a risk to your rights and freedoms, we will notify you without undue delay (and within 72 hours of becoming aware, where feasible) via email to your registered email address. The notification will include:
    • Nature and extent of the breach
    • Categories and approximate number of data records affected
    • Likely consequences of the breach
    • Measures we have taken or propose to take to address the breach
    • Measures you can take to mitigate potential adverse effects
    • Contact details for further information
  4. Notification to Authorities: Where required by applicable law, we will notify relevant data protection authorities and regulatory bodies.
  5. Documentation: We will maintain a comprehensive record of the breach, our response actions, and lessons learned to prevent future incidents.

17. International Data Transfers

Transfer of data across national borders

GoHostBiz is based in India and primarily stores and processes data on servers located in India. However, certain third-party service providers we use may process data in other countries. When we transfer personal data internationally, we ensure appropriate safeguards are in place to protect your data in accordance with this Privacy Policy and applicable law.

Safeguards for International Transfers

For international data transfers, we implement one or more of the following safeguards:

  • Transferring data only to countries deemed by relevant authorities to have adequate data protection laws
  • Entering into data processing agreements containing standard contractual clauses approved by relevant authorities
  • Ensuring recipients are certified under recognized data protection frameworks
  • Obtaining your explicit consent for specific transfers where required by law

18. Changes to This Privacy Policy

How we update and communicate changes

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational reasons. When we make changes, we will:

  • Update the "Last Updated" date at the top of this page
  • Post the revised policy on our website with a prominent notice
  • For material changes, send an email notification to all active account holders
  • For significant changes affecting your rights, provide at least 14 days' notice before changes take effect

Your continued use of our services after the effective date of any changes constitutes your acceptance of the revised Privacy Policy. We encourage you to review this policy periodically.

Policy Version History

VersionEffective DateSummary of Changes
v1.0January 2023Initial Privacy Policy
v1.1August 2023Added cookie policy details, updated third-party providers list
v2.0March 2024Major revision: Added data rights section, legal basis for processing, data breach policy
v2.1June 2025Updated data retention periods, added international transfer safeguards, refined cookie categories
Contact Our Data Protection Officer

If you have any questions, concerns, or wish to exercise your data protection rights, please contact our Data Protection Officer (DPO) through any of the following channels:

WhatsApp
+91 9598587318
Phone (DPO Direct)
+91 9598587318
Email (DPO)
gohostbiz@gmail.com Subject: "Attention: Data Protection Officer"

Harinagar, Karbala ke pass, Thakurganj, Chowk, Lucknow, Uttar Pradesh, India – 226003  ·  DPO Response Time: Within 48 hours

Grievance Redressal

If you are not satisfied with our response to your privacy concern, you have the right to lodge a complaint with the relevant data protection authority in your jurisdiction. In India, you may contact:

Grievance Officer (as per IT Act 2000):
Same as Data Protection Officer details above. All grievances will be acknowledged within 24 hours and resolved within 15 days.

© 2025 GoHostBiz. This Privacy Policy is effective from June 2025 and supersedes all prior versions.

?>