Scope and responsibility
This Policy explains how TurbineWeb (“TurbineWeb”, “we”, “us”, or “our”) handles personal information when you browse this website, contact us, create an account, receive hosting services, or interact with billing and support. For customer content hosted on our infrastructure, the customer generally decides why that content is processed and TurbineWeb processes it to provide the contracted service.
Information we collect
Information you provide: your name, email address, company, account credentials, contact messages, quote requirements, billing details, invoice records, helpdesk tickets, support communications, and—when you order or transfer a domain—registrant name, organization, postal address, telephone number, domain preferences, and any required transfer authorization code.
Google sign-in information: if you choose Google authentication, we receive your Google account identifier, name, email address, and email-verification status. We do not receive or store your Google password.
Service information: hosting region, assigned IP addresses, service configuration and status, customer-visible service notes, account activity, technical requests, security events, resource use, and information needed to operate and support your service.
Basic technical information: IP address, browser or device type, timestamps, requested pages, and similar server-log data may be collected automatically for delivery, security, and troubleshooting.
How and why we use information
We use personal information to respond to enquiries; prepare quotes; create and secure accounts; provision, bill, maintain, and support Services; process and reconcile payments; detect abuse or fraud; keep business and tax records; enforce agreements; comply with law; and improve reliability and customer experience.
Where applicable, our legal bases include performing a contract or taking requested pre-contract steps, complying with legal obligations, protecting legitimate interests such as security and service improvement, and consent where the law requires it.
Retention and security
We retain account, service, and helpdesk information while an account is active and afterward only as reasonably necessary for legal, accounting, security, dispute, backup, and operational purposes. Contact enquiries that do not become customers are periodically reviewed and deleted when no longer needed. Domain transfer authorization codes and their pending contact payload are encrypted while awaiting paid submission and erased after the registrar accepts the request, or if the order is cancelled or fails. Used and expired authentication tokens are routinely removed, and successfully delivered or cancelled email-outbox records are removed after 90 days.
We use measures appropriate to the nature of the information, including password hashing, encrypted outbox content, server-side rich-text sanitization, access controls, encrypted transport, request validation, and restricted configuration. No online system can be guaranteed completely secure, so please use a unique password and notify us promptly of suspected compromise. Avoid placing passwords or highly sensitive secrets in helpdesk or service notes unless specifically instructed through an approved secure channel.
Your choices and rights
Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, or objection; withdraw consent; or complain to a data-protection authority. These rights may be limited by identity verification, legal obligations, and valid exceptions.
You may update basic account information by contacting us. We do not knowingly offer accounts to children under 18 or intentionally collect their personal information.
Contact and changes
To ask a privacy question or exercise a right, use our contact page or email billing@turbineweb.com. We may update this Policy as our services or legal obligations change. The effective date above identifies the current version.