PRIVACY & DATA BOUNDARIES

What GreatHosts itself stores — and what it does not.

This page describes the GreatHosts.biz website, Sales Boost and public agent/MCP layer. It supplements, but does not replace, the contractual privacy and service terms presented for hosting, domains and payment processing.

Site-specific privacy baseline reviewed: 3 October 2026
Payments

GreatHosts does not receive or store payment-card credentials. Payment authorization is handled by the upstream payment provider during the human checkout flow.

Checkout recovery

Only when the customer opts in, Sales Boost may temporarily retain encrypted email, username, locale, checkout progress and resumable configuration for up to 7 days. Passwords, payment credentials, EPP codes and API credentials are not retained for recovery.

Operational records

Successful-order metadata may be retained for up to 14 days. Sanitized API warning/failure incident records may be retained for up to 60 days for reliability diagnostics.

Reach and agent metrics

GreatHosts keeps limited aggregate counters for selected search, referral and agent-tool activity. The GreatHosts measurement layer does not retain raw IP addresses, raw referrer URLs, raw user-agent strings or tracking cookies for these aggregate counters.

Public MCP tools

The public agent platform exposes public hosting facts and read-only lookups. It does not expose private customer accounts, payment credentials or authentication secrets. Short-lived rate-limit keys are pseudonymous keyed hashes rather than stored raw network addresses.

Checkout drafts

A prepared checkout draft uses a browser URL fragment, which is not sent to the web server as part of the HTTP request and is removed after the form consumes it. Draft transport rejects passwords, payment data, EPP codes, API keys and other secrets.

Your choices

  • You can use the site without opting in to checkout-recovery follow-up.
  • Necessary cookies support site and checkout operation; optional analytics remains subject to the site cookie choice.
  • Do not send passwords, private keys, payment credentials or API secrets through ordinary support messages or agent prompts.

Contractual service privacy and terms

Hosting, domain registration, billing and payment processing can involve the upstream service provider. The applicable contractual terms, cancellation/refund policy and provider privacy policy remain available from the GreatHosts Terms page and the final checkout policy links.