Skip to main content
.com from $2.99 — free WHOIS privacy

Acceptable Use Policy

Last updated: August 19, 2026

Scope

Applies to every credential issued against an account — yours, your developer's, your agency's, and every downstream customer if you resell. The account holder answers for the traffic the account emits regardless of who initiated it.

The terms of service remain the operative contract. This document expands clause 4 of it and cannot extend what that clause already permits.

1. Prohibited outright

No appeal, no grace period, no discussion. Publishing any of the following terminates the account:

  • child sexual abuse material, in any quantity or format;
  • content inciting terrorism or violence toward a person or group;
  • credential-harvesting pages: fake logins, cloned banking, counterfeit checkouts;
  • malware, ransomware, exploit kits, breached credential dumps, stolen card data;
  • botnet command-and-control, and proxies knowingly carrying abuse;
  • material published without the rights it required, once a rights holder has substantiated that through the copyright and takedown policy;
  • pharmaceutical, weapons or gambling operations targeting jurisdictions that have not licensed them.

Lawful adult content is not prohibited. Age-gate it, keep it clear of outbound mail, and it is not our business.

2. Shared capacity

A shared plan allocates a generous slice of a machine and never the whole of it. One account saturating processor, memory, disk throughput or process count degrades every neighbour on that node, which is the entire reason a ceiling exists.

Workloads that belong on a VPS or dedicated hardware instead: media transcoding, crawlers and scrapers, cryptocurrency mining, public distribution mirrors, offsite backup targets for systems hosted elsewhere, and databases running continuous bulk operations. None of these are banned outright — they are simply the wrong product, and the conversation happens before anything is switched off.

Storage advertised as unlimited is unlimited for the websites on the plan. It is not general-purpose capacity.

3. Maintenance boundary

We maintain the operating system, web server and control panel. Everything installed above that line is yours. An unpatched extension is the single most common root cause of a compromised account here, and the outbound mail or defacement that follows is attributed to the account.

  • keep applications, themes and extensions current;
  • remove installers, database exports and .env files from web-accessible directories;
  • issue individual credentials and revoke them on departure;
  • report a suspected compromise immediately rather than after confirming it.

Scanning, probing or load-testing infrastructure you do not own requires written authorisation first. Testing your own site is fine, but notify us beforehand — the automated defences cannot distinguish your test from an attack.

4. Mail

Sending rules are held separately in the anti-spam policy, because the blast radius of getting mail wrong extends to every customer sharing an address range rather than stopping at the sender.

5. Enforcement

Proportionate, and almost always opening with a message:

  • Notice. The normal path. Most breaches are a compromised extension or a workload that outgrew its plan, and a message resolves them.
  • Isolation. Where harm is active — an outbound run, a live phishing page, a process consuming a node — that item or account is suspended pending the conversation.
  • Termination. Section 1 material, repeated breaches, and accounts unreachable while causing damage.

Unlawful material is removed without notice and reported where the law requires it. Nothing here obliges us to wait when waiting makes us party to the harm.

6. Challenging a decision

Reply to the suspension notice, or escalate through the complaints procedure. A suspension issued in error is reversed and the lost time credited.

7. Reporting

Use report abuse. The substance of a report reaches the account holder; your contact details do not travel with it unless you request that or a court compels it.

8. Contracting entity

HostingAlly operates as a trading name of Fairdeal Renovations Limited, a company registered in England and Wales under Company No. 15026869. Registered office: The Workspace Basildon, 7 High Pavement, Basildon, England, SS14 1EA. Questions to info@hostingally.com.