HostCore LogoBack to hostcore.co

Legal

Privacy Policy

Last updated: August 25, 2026

On this page

#Introduction

This policy explains how HostCore Limited, a company incorporated in New Zealand (HostCore, “we”, “us”), collects and handles personal information. It forms part of our Terms of Service.

#Who this policy covers — and who it doesn't

This policy applies to:

  • Tenants — the businesses (and the individuals within them) who register for and use HostCore; and
  • Visitors to hostcore.co and our public sites.

It does not cover End Customers — the customers of stores operated by our tenants. If you are an End Customer of a store powered by HostCore, the store owner is responsible for your personal information; their privacy policy applies, and you should contact them directly. We process End Customer data only on tenants’ behalf as described in our Data Processing Addendum (hostcore.co/legal/data-processing).

For the personal information this policy covers, HostCore is the “agency” under the New Zealand Privacy Act 2020 and, where the EU/UK GDPR applies, the controller.

#Information we collect

  1. Account and registration information.
    Your name, business name, email address, country, and password (stored hashed). If you select an indicative plan at sign-up, we record that selection.
  2. Billing information (paid plans).
    When paid plans launch, subscription and invoicing records. Subscription payments will be processed by Stripe; your card details are collected and stored by Stripe, not by HostCore, and Stripe’s own privacy policy applies to that processing.
  3. Payment gateway credentials.
    Tenants supply their own payment-provider credentials (e.g. Stripe restricted API keys, PayPal API credentials) to enable payments on their stores. These are business credentials rather than personal information in most cases, but we treat them with heightened protection regardless: encrypted at rest, used solely to provide the Services, and deleted within 30 days of account termination.
  4. Usage and technical data.
    Logs (IP address, browser/user-agent, timestamps, pages and API endpoints accessed) and diagnostic and error data (error reports are sanitized before leaving our systems). Store analytics (for example sales, orders, and churn metrics for your stores) are a service feature computed from your own store’s data and processed on your behalf as described in the Data Processing Addendum; HostCore itself accesses that data only in aggregated, de-identified form across the platform (for example, platform-wide totals used in marketing).
  5. Communications.
    Support requests, bug reports, feedback, and emails you exchange with us. Support tickets are handled in our own in-house system. If you choose to link your Discord account, ticket messages can be synced with Discord for your convenience; this is optional, requires you to manually link your account, and involves storing your Discord account identifier and sharing synced messages with Discord. Emails we send you are delivered via Google Workspace.
  6. Website data.
    We do not run third-party analytics, advertising trackers, or marketing pixels on our websites or in the Services. Our sites and the Services are served through Cloudflare, which processes visitor connection data (such as IP addresses) to provide content delivery and security, and we use Cloudflare Turnstile to protect sign-up, login, and similar forms from automated abuse.

We collect this information directly from you and automatically through your use of the Services. We do not buy personal information from data brokers.

#How we use information

We use personal information to:

  • provide, operate, secure, and support the Services (including authenticating you, processing gateway credentials, and delivering webhooks and notifications);
  • send you account and service communications — service notices, security alerts, invoices, changes to terms, and the end of the Founding Access period — and occasional product announcements (typically a few per year), each of which includes a working unsubscribe for the non-essential ones;
  • monitor, debug, and improve the Services, including through aggregated and de-identified analytics;
  • detect and prevent fraud, abuse, and security incidents; and
  • comply with legal obligations and enforce our Terms.

Where the GDPR applies, our legal bases are: performance of our contract with you (service provision, account communications); our legitimate interests (security, product improvement, business operations — balanced against your rights); consent (marketing, where required); and legal obligation.

#How we share information

We do not sell personal information. We share it only with:

  • Service providers — OVH (infrastructure hosting in Australia, the United States, and the European Union); Cloudflare (content delivery, security, Turnstile bot protection, and encrypted backup storage); Google (Google Workspace, for email we send you); Sentry (error tracking — error reports are sanitized before transmission); and Discord (only if you opt into ticket syncing). Where tenants configure their own providers (for example their own SMTP or email API credentials, or their own CAPTCHA keys for their stores), those providers act for the tenant, not for HostCore;
  • Stripe — when paid plans launch, to process your subscription payments (Stripe acts as an independent controller for payment processing);
  • Professional advisers (lawyers, accountants) under confidentiality;
  • Authorities where required by law, or where necessary to protect the rights, safety, or property of HostCore, our tenants, or others; and
  • A successor entity in connection with a merger, acquisition, or sale of assets — in which case this policy continues to apply to information transferred.

#International transfers

We are a New Zealand company with infrastructure in Australia, the United States, and the European Union; personal information may also be accessed from New Zealand for administration and support. New Zealand holds a European Commission adequacy decision. Where information covered by the GDPR is transferred to a jurisdiction without an adequacy decision (including the United States), we rely on appropriate safeguards as described in our Data Processing Addendum.

#Retention

We keep personal information for as long as your account is active and as needed afterwards for the purposes above. Specifically:

  • account data and Tenant Data: deleted following the 30-day post-termination export window in our Terms, subject to residual copies in backups, which are retained for no more than 30 days (full backups run daily, with continuous database backups; all expire within 30 days);
  • gateway credentials: deleted from active systems within 30 days of termination;
  • records we must keep by law (e.g. tax and accounting records): for the legally required period, typically 7 years in New Zealand.

#Security

We protect personal information with measures appropriate to an early-access service, including encryption in transit (TLS), encryption at rest for gateway credentials and other sensitive values, access controls, and network isolation between tenant stores. No internet service can guarantee absolute security; our Terms describe our breach-notification commitment.

#Your rights

Under the New Zealand Privacy Act 2020, you may request access to and correction of your personal information. Complaints may be made to us first, and to the Office of the Privacy Commissioner (privacy.org.nz).

Where the GDPR or UK GDPR applies to you, you additionally have rights to erasure, restriction of processing, data portability, and objection (including to direct marketing), and the right to lodge a complaint with your supervisory authority.

To exercise any right, contact legal@hostcore.co. We will respond within the timeframes required by applicable law (20 working days under the Privacy Act; one month under the GDPR). Note that requests concerning End Customer data must go to the relevant store owner; where such a request reaches us directly, we will refer it to them.

Our privacy officer for the purposes of the Privacy Act 2020 can be reached at legal@hostcore.co.

#Cookies

We use only cookies that are required for the Services to function: session and authentication cookies (including access and refresh tokens) and cookies set by Cloudflare for security and bot protection (including Turnstile). We do not use advertising, analytics, or cross-site tracking cookies.

#Children

The Services are business tools and are not directed at children. We do not knowingly collect personal information from anyone under 18. Contact us if you believe we have.

#Changes to this policy

We may update this policy. Material changes will be notified by email or dashboard notice at least 30 days before taking effect, consistent with our Terms. The date at the top reflects the current version.

#Contact

Privacy contact: legal@hostcore.co

General support: support@hostcore.co

Link copied to clipboard