AAHost

Legal

Privacy Policy

How AHost collects, uses and protects personal data under the IT Act, 2000 and DPDP Act, 2023 — cookies, sharing, retention, your rights and grievance contact.

This Privacy Policy explains what personal data AHost collects, why we collect it, and the choices you have. It is written in line with the Information Technology Act, 2000, the rules made under it, and the Digital Personal Data Protection Act, 2023 ("DPDP Act").

Data we collect

Information you give us

  • Account details — name, email address, phone number and password (stored only as a secure hash).
  • Billing details — billing address, state and, if you provide it, your GSTIN, used to issue GST invoices.
  • Domain contact details — registrant, administrative and technical contacts required by domain registries.
  • Support conversations — tickets, messages and attachments you send us.

Information collected automatically

  • Security and usage logs — IP address, browser and device information, login times and actions taken in your account. We use these to protect your account, investigate abuse and keep an audit trail.
  • Cookies and local storage — see "Cookies" below.

Information from others

  • Payment partner — Razorpay tells us whether a payment succeeded and gives us a reference number. We never receive or store your full card or bank details.
  • Referrals — if you sign up through a friend's referral link, we record which account referred you.

How we use your data

  • To create and manage your account and provide the services you order.
  • To register domains and issue SSL certificates, which requires sharing contact details with registries, registrars and certificate authorities.
  • To process payments, issue GST invoices and meet tax and accounting obligations.
  • To send service emails such as order confirmations, renewal reminders, security alerts and support replies. You can turn off optional notifications in your dashboard; essential service and security emails cannot be turned off.
  • To detect and prevent fraud, abuse and security incidents, including referral abuse.
  • To comply with law, court orders and lawful requests from authorities.

We do not sell your personal data.

Who we share data with

  • Domain registries and registrars, including NIXI for .in domains and ICANN-accredited registrars for generic domains, as required to register and manage domains. Public WHOIS/RDAP data is limited where the registry allows privacy.
  • Certificate authorities, for SSL validation.
  • Payment processors (Razorpay) to collect payments.
  • Infrastructure and email providers that host our systems and deliver our emails, under contracts that require them to protect your data.
  • Resellers — if you buy through a reseller, that reseller can see the account and order details needed to serve you.
  • Authorities, where we are legally required to disclose information.

Cookies

We use a small number of cookies and browser storage items:

NamePurposeDuration
Session cookiesKeep you signed in and protect forms against forgeryUntil you log out or the session expires
ahost_refRemembers the referral code from a friend's invite link so you both get credit30 days
Theme setting (local storage)Remembers whether you chose light, dark or system themeUntil you clear it

We do not use advertising or cross-site tracking cookies.

How long we keep data

We keep account data while your account is active. After closure we keep invoices and transaction records for as long as tax law requires (generally at least eight years), and security logs for a limited period. Domain records are kept as required by registry rules.

Security

Passwords are hashed, sensitive credentials are encrypted at rest, connections use HTTPS, and staff access is limited and logged. You can protect your account further with two-factor authentication. No system is perfectly secure; if a breach affects your data we will notify you and the authorities as the law requires.

Your rights

Subject to the DPDP Act and other applicable law, you can:

  • access a summary of the personal data we hold about you;
  • correct or update inaccurate data (most details can be edited directly in your dashboard);
  • ask us to erase data we no longer need to keep;
  • withdraw consent for optional processing, such as marketing emails;
  • nominate another person to exercise your rights in case of death or incapacity;
  • raise a grievance with us, and if unresolved, with the Data Protection Board of India.

To exercise these rights, email support@ahost.in.

Grievance officer

In line with the IT Act, 2000 and the DPDP Act, 2023, you can contact our Grievance Officer at support@ahost.in with the subject line "Grievance". We will acknowledge your complaint within 24 hours and aim to resolve it within 15 days.

Children

Our services are not intended for anyone under 18, and we do not knowingly collect data from children.

Changes to this policy

We may update this policy as our services or the law change. We will announce material changes by email or in your dashboard.

Last updated 11 Oct 2026