Acceptable Use Policy
Last updated: August 19, 2026
Scope
This covers every credential issued against an account: your own, your developer's, your agency's, and each downstream customer where you resell. Whatever traffic the account emits, the account holder answers for it, and it makes no difference who set that traffic in motion.
The terms of service remain the operative contract. What follows here expands clause 4 of those terms, and it cannot widen anything the clause already allows.
1. Prohibited outright
Nothing to appeal, no grace period, no conversation. Publish any of the following material and the account is terminated:
- child sexual abuse material, whatever the volume or the file format;
- content that incites terrorism, or violence against a person or a group;
- harvesting credentials: counterfeit sign-ins, cloned banking, fake checkout pages;
- malware, ransomware and exploit kits, dumps of breached credentials, stolen card data;
- botnet command-and-control, plus proxies knowingly carrying abusive traffic;
- material put online without the rights that were needed, where a rights holder has already substantiated that claim through the copyright and takedown policy;
- pharmaceutical, weapons and gambling operations aimed at jurisdictions which have issued them no licence.
Adult content that is lawful stays permitted. Put an age gate on it, keep it out of your outbound mail, and we take no interest.
2. Shared capacity
A shared plan hands you a generous slice of a machine, never the machine itself. Saturate the processor, the memory, disk throughput or the process count and every neighbour sitting on that node suffers for it. That is the whole reason a ceiling exists in the first place.
Some workloads belong on a VPS or on dedicated hardware rather than here: media transcoding, crawlers and scrapers, cryptocurrency mining, public distribution mirrors, offsite backup targets for systems hosted somewhere else, and databases grinding through continuous bulk operations. None of that is banned outright. It is simply the wrong product for the job, and we talk to you about it before anything gets switched off.
Unlimited storage covers the websites you host on that plan, nothing wider. Think of it as web space, not general-purpose capacity.
3. Maintenance boundary
The operating system, the web server and the control panel are ours to maintain. Anything installed above that line belongs to you. An extension left unpatched is the single most common root cause of a compromised account here, and whatever follows it, an outbound mail run or a defaced homepage, is attributed to the account.
- keep every application, theme and extension updated;
- remove installers, database exports and
.envfiles from web-accessible directories; - a separate login for each person, withdrawn when they leave;
- report any suspected compromise straight away, not after you have confirmed it.
Scanning, probing or load-testing infrastructure that is not yours requires written authorisation before you start. Testing your own site is fine. Tell us in advance though, because the automated defences have no way to tell your test apart from a genuine attack.
4. Mail
The rules covering outbound mail live in the anti-spam policy, because when outbound mail goes wrong the blast radius reaches every customer who happens to share an address range, rather than stopping neatly with whoever sent it.
5. Enforcement
Proportionate, and it nearly always begins with a message:
- Notice. The usual route. Most breaches turn out to be a compromised extension, or a workload that has outgrown its plan, and a message settles them.
- Isolation. Where the harm is live, meaning an outbound run, a phishing page still serving, a process eating a node, that item or that account gets suspended while the conversation takes place.
- Termination. Section 1 material, breaches that repeat, and accounts nobody can reach while damage continues.
Material that breaks the law comes down without notice, and gets reported wherever the law requires that. Nothing written here obliges us to wait, when waiting would make us party to the harm.
6. Challenging a decision
Answer the suspension notice, or take it further through the complaints procedure. Where a suspension was issued in error, we reverse it and credit the time lost.
7. Reporting
Use report abuse. What a report actually says reaches the account holder; your contact details do not travel alongside it unless you ask for that, or a court orders it.
8. Contracting entity
HostingAlly runs as a trading name belonging to Fairdeal Renovations Limited, a company registered in England and Wales under Company No. 15026869. Registered office: The Workspace Basildon, 7 High Pavement, Basildon, England, SS14 1EA. Questions to info@hostingally.com.