Privacy Policy
This policy describes the personal data we collect, the purposes for which it is processed, the parties to whom it is disclosed, and the rights available to you.
Last updated: 25 August 2026
1. Scope
This Privacy Policy describes how one9x ("we", "us", "our") collects, uses, stores and discloses personal data in connection with this website and the hosting services we provide (the "Services"). It does not apply to websites published by our customers on the platform, which are controlled by the customers who deployed them and are subject to their respective privacy notices. Where we process visitor data on a customer's behalf, we do so as that customer's processor under the terms of our Data Processing Addendum.
2. Personal Data We Collect
- Account data
- Your email address and a hashed password, together with a name and organisation if provided. This data is required to create and operate your account, authenticate you, and communicate with you about the Services.
- Content you deploy
- The files constituting your websites and the domains you connect. We store and serve this content in order to provide the Services.
- Site access logs
- One record per request to a website hosted on the platform: visitor IP address, timestamp, requested path, user agent, bytes transferred and response status. Query strings are removed before the record is written. These logs are used to serve traffic, apply rate limits, investigate abuse and diagnose faults, and are retained as described in Section 8.
- Security and audit records
- Sign-ins and failed sign-in attempts, issuance and revocation of API tokens, administrative actions on your account, and staff access to internal tooling, each recorded with the actor, action, source IP address and timestamp.
- Operational logs
- Diagnostic records generated by our systems, such as deployments, certificate renewals and errors. These concern the platform and rarely contain personal data.
- Billing records
- The plan purchased, the date and amount of each transaction, the currency, and the payment gateway's transaction reference. Invoices are retained as required by tax law.
3. Storage and Location
Account data, deployed content and the logs described above are stored in India. Backups are maintained at a second location, also in India. Payment card data is the one category that does not pass through our systems: it is collected directly by our payment gateways, in a form they serve and control, as described in Section 4.
4. Personal Data We Do Not Collect
We do not receive or store your card details. Payments are collected in a form served directly by our payment gateway. That form may sit on the gateway's own page or be embedded in ours; either way it is served, controlled and read only by them. Your card number, CVV and PIN are entered on the gateway's systems and do not reach ours; we receive only a transaction reference, the amount, and the payment status.
We do not sell personal data. This website carries no advertising and no third-party trackers.
5. Website Analytics
Page views on this website are measured using a self-hosted analytics instance at
analytics.one9x.com. No data is transmitted to any third-party analytics
provider. The instance sets no cookies, assigns no persistent
identifier and builds no individual profile; the data recorded is aggregate in nature —
page, approximate region, device class and referring site.
6. Disclosure of Personal Data
Personal data is disclosed to the following recipients:
- Razorpay and Cashfree, payment gateways authorised by the Reserve Bank of India, for the collection of payments and the processing of reversals. They receive your name, email address, payment instrument and transaction amount directly from you on their own checkout pages, and act as independent data fiduciaries in respect of that data.
- Our email service provider, which receives your email address for the delivery of transactional mail: verification, password reset, billing and service notices. We do not send marketing email through it.
- Let's Encrypt (Internet Security Research Group), which receives the domain names you connect in order to issue the TLS certificates that serve them. Issued certificates are published to public Certificate Transparency logs, as is standard for all certificate authorities.
- Government agencies and courts, where disclosure is required by a lawful order, and only to the extent so required.
7. Cookies
This website sets no cookies. The dashboard sets a single cookie that maintains your signed-in session; it is strictly necessary for the operation of the Services and carries no profiling data.
8. Retention of Personal Data
The retention periods below are those enforced by our systems. Where a period is prescribed by law, the applicable provision is stated; our obligation to erase personal data under the Digital Personal Data Protection Act, 2023 is subject to retention required by such other law.
- Operational logs — 7 days
- No statutory minimum applies; retained only as long as needed for diagnostics.
- Site access logs — 180 days
- Retained for a rolling 180 days within India, as required by the directions issued by CERT-In under section 70B of the Information Technology Act, 2000.
- Security and audit records — 365 days
- Retained for one year to permit the investigation of security incidents.
- Account and subscriber records — 5 years after cancellation
- Retained as required by the CERT-In directions, which oblige hosting providers to maintain subscriber records for five years after cessation of service.
- Site content — until deleted by you
- Deleted with the site or account, subject to a short backup window before backups roll off.
- Invoices and tax records
- Retained for the periods prescribed by applicable tax law.
9. Your Rights
Under the Digital Personal Data Protection Act, 2023, you are a Data Principal and may exercise the following rights in respect of the personal data we hold about you. Requests should be sent to contact@one9x.com from the email address registered on the account.
- Access (s.11) — to obtain a summary of the personal data we hold about you, the processing activities undertaken, and the parties to whom it has been disclosed.
- Correction and completion (s.12) — to have inaccurate or incomplete personal data corrected or completed.
- Erasure (s.12) — to have your personal data erased. Deletion of your account removes your websites from the platform; data listed in Section 8 as subject to a statutory retention period is retained only for that period.
- Grievance redressal (s.13) — to complain to our Grievance Officer, whose details appear in Section 10, prior to approaching the Data Protection Board of India.
- Nomination (s.14) — to nominate, in writing, a person to exercise these rights on your behalf in the event of death or incapacity.
Requests are answered within 15 days. If you are not satisfied with the outcome, you may approach the Data Protection Board of India.
10. Grievance Officer
In accordance with Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and section 13 of the Digital Personal Data Protection Act, 2023, the Grievance Officer for one9x is:
- Name
- Raman Kumar
- grievance@one9x.com
Complaints are acknowledged within 24 hours and disposed of within 15 days of receipt. Please include the URL or account concerned and the relief sought.
11. Security
Passwords are stored in hashed form. Traffic to the platform is served over HTTPS. Production systems are reachable only over a private network, and access to them is restricted to named individuals.
No system is perfectly secure. In the event of a personal data breach affecting you, we will notify you and the relevant authorities as required by applicable law.
12. Changes to this Policy
This policy may be updated as the Services evolve. The date at the top of this page reflects the most recent revision; material changes are notified by email.
13. Contact
Questions or requests concerning your personal data may be addressed to contact@one9x.com, or see the Contact page.