Fusion Arc Hosting – Privacy Policy
Effective Date: 9-13-2025
1) Who We Are
Fusion Arc Hosting, a division of Fusion Arc Telecom LLC (“Fusion Arc,” “we,” “us,” “our”), provides web hosting and related services. This Privacy Policy explains how we collect, use, share, and secure personal information, and the choices you have.
This Policy is incorporated into our Terms of Service and applies to our websites, Client Area, and services.
2) Personal Information We Collect
We collect information directly from you, automatically from your device, and from service providers/partners.
2.1 Information you provide
- Identifiers & contact: first/last name, company, mailing address, email, phone.
- Billing & transactions: payment method details processed by our payment processors; invoice and transaction history.
- Verification (when required): government-issued ID or limited card scan for fraud prevention/order verification.
- Support content: tickets, chat messages, call recordings (where notified), attachments, server logs you share, login credentials you may share, other information you share to us.
- Account content: domains, DNS, hosting plan choices, server names, configuration preferences.
2.2 Information we collect automatically
- Device/usage: IP address, browser type/version, OS, device identifiers, pages viewed, timestamps, referring URLs, location, network or isp information.
- Security/operations: server events, error logs, authentication events, abuse indicators.
- Session analytics: session replay/heatmap data via analytics tools (e.g., Microsoft Clarity) to improve UX (payment fields and other sensitive inputs are masked/blurred).
2.3 Information from partners & vendors
- Payments: status/metadata from payment processors (e.g., success/decline, risk scores). Partners including Stripe or Paypal.
- Advertising & anti-fraud: ad platforms (Google, Microsoft, Meta, Reddit) and ClickCease provide campaign and click fraud signals.
- Datacenter & infrastructure providers: operational diagnostics (e.g., uptime, hardware status) tied to your services.
- Financial & legal professionals: limited details (e.g., transaction summaries) for accounting/audit/legal compliance.
2.4 Optional demographic info
- Age range, gender (optional) if you choose to provide it (used for aggregate analytics only).
We do not knowingly collect information from children under 13. Our services are for adults 18+ (see TOS).
3) How We Use Personal Information
- Provide & operate services: provisioning, DNS, server management, customer support.
- Billing & account: invoicing, collections, tax reporting, fraud prevention.
- Security & abuse mitigation: intrusion detection, malware scanning/quarantine, DDoS mitigation, account integrity checks.
- Communications: service notices, transactional emails, policy/price updates, and (where permitted) product updates/marketing (you can opt out).
- Analytics & improvement: site performance, usability testing (session replay/heatmaps), feature development.
- Advertising & attribution: measure/optimize campaigns; prevent click fraud.
- Legal compliance: sanctions screening (OFAC), lawful requests, enforcing our agreements.
4) Legal Bases (GDPR/UK GDPR)
Where applicable, we process data on these bases: contract (service delivery), legitimate interests (security, improvement, marketing to existing customers), consent (cookies/marketing where required), and legal obligations (tax, accounting, sanctions).
5) Cookies & Tracking
We use cookies, pixels, and similar technologies.
Categories:
- Essential: login/session, load balancing, security.
- Analytics: usage metrics, session replay (with sensitive fields masked).
- Marketing/ads: ad measurement and cross-context behavioral advertising.
- Functional: remembering preferences.
Consent & controls:
- Visitors in the EU/UK will see a cookie banner to Accept or Manage settings (enable/disable categories). We log consent choices.
- You can also manage cookies in your browser.
- We recognize Global Privacy Control (GPC) signals for opt-out of sale/share where required by law.
(For details, see our standalone Cookie Policy if provided.)
6) How We Share Information
We do not sell customer lists. We share information with:
- Service providers (processors):
- Datacenter/infrastructure partners (e.g., third-party facilities we lease/rent/colocate in) and storage/backup providers to host your data.
- Payment processors for payments, refunds, chargebacks.
- Email & communications tools for transactional mail and support.
- Analytics/session replay and advertising platforms (Google, Microsoft, Meta, Reddit) and ClickCease for click-fraud detection.
- Security/anti-abuse vendors (e.g., malware scanning, blacklisting).
- Professional advisors: licensed accountants/auditors/attorneys for tax and legal compliance (limited, need-to-know).
- Law enforcement & legal: when required by law, valid legal process, or to protect rights, property, users, or public safety (including emergencies involving harm or CSAM).
- Corporate transactions: in a merger, acquisition, financing, or sale of assets, subject to confidentiality and continued protection.
We also share limited “online identifiers” and internet activity with advertising/analytics partners, which may be considered a “sale” or “sharing” under some state privacy laws (see Section 10).
7) International Transfers
We may transfer/process data outside your country (including the U.S.). Where required, we use appropriate safeguards such as Standard Contractual Clauses (SCCs) and vendor risk assessments.
8) Security
We use reasonable administrative, technical, and physical safeguards (TLS encryption in transit; access controls; network segmentation; vulnerability management). No method of transmission or storage is 100% secure.
9) Data Retention
We keep personal data only as long as necessary for the purposes stated and to meet legal, tax, and accounting obligations, then delete or anonymize it.
Typical periods (may vary by law/needs):
- Account profile & service metadata: life of account + 2 years.
- Invoices & tax records: 7 years from issuance.
- Support tickets/logs: 2–3 years after closure (longer if needed for security/legal).
- Verification documents: up to 2 years after verification or sooner if regulations allow.
- Backups: per our backup schedules (courtesy backups for shared/reseller; purchased backups for VPS/dedicated). Backups are purged on rotation and are deleted upon account termination per TOS.
10) Your Choices & Rights
10.1 Email preferences
- Manage marketing preferences via unsubscribe links or by contacting support. Transactional/service emails are required for service.
10.2 Cookie/Tracking choices
- Use the cookie banner (EU/UK) or browser settings. We honor GPC where required.
10.3 GDPR/UK GDPR rights (where applicable)
- Access/Portability (get a copy), Correction, Deletion, Restriction, Objection (including direct marketing), and Withdraw Consent.
- You may also lodge a complaint with your supervisory authority.
10.4 U.S. state privacy rights (e.g., CA/VA/CO/CT/UT)
Depending on your state:
- Know/Access: the categories and specific pieces of personal information we collected about you.
- Delete personal information (subject to exemptions).
- Correct inaccurate personal information.
- Opt-out of sale or sharing of personal information and targeted advertising.
- Limit use/disclosure of sensitive personal information (SPI) to what’s reasonably necessary (we only use SPI—like government ID for verification—strictly for security, fraud prevention, compliance, and do not use SPI for advertising).
- Appeal a decision if we deny your request (where applicable).
“Sale”/“Sharing” disclosure (CA/CPRA):
We may “share” (and in some cases be deemed to “sell”) limited identifiers and internet activity (e.g., IP, cookie IDs, page views) with ad/analytics partners for cross-context behavioral advertising and measurement. You can opt out (see below).
10.5 How to make a privacy request or opt-out
- Submit a ticket via our Contact/Client Area selecting Privacy Request, or
- Email privacy@fusionarchosting.com with your request and account email.
- For Do Not Sell or Share My Personal Information (ad/analytics opt-out), use the “Do Not Sell or Share” control in our site footer or email us.
- We will verify your identity (and, if applicable, your authorized agent) before fulfilling requests.
- Response timeframe: within 30 days (GDPR) or 45 days (U.S. state laws), with one extension where permitted.
11) Children’s Privacy
We do not knowingly collect personal information from children under 13 (COPPA). Our services are intended for adults 18+ (see TOS). If you believe a minor has provided data, contact us to remove it.
12) Do Not Track
Browsers may send Do Not Track (DNT) signals; there’s no industry standard for responding. We instead follow the choices you make in our cookie banner and honor Global Privacy Control (GPC) where required.
13) Third-Party Links
Our site may link to third-party websites. Their privacy practices are not controlled by us. Review their policies before providing information.
14) Subprocessors & Infrastructure
We rely on multiple third-party datacenter/infrastructure providers (including facilities we lease/rent/colocate in) and backup/storage providers to operate and secure your services. We also use payment, email/support, analytics/session replay, advertising, anti-fraud, and professional service providers. We contractually require them to protect personal information and use it only for our instructions.
We are not HIPAA compliant and do not sign Business Associate Agreements. Do not store Protected Health Information (PHI) on our services (see TOS).
15) Communications & Electronic Notices
By using our services you consent to receive electronic communications related to your account (service notices, invoices, policy updates). You can opt out of marketing emails at any time.
16) Changes to This Policy
We may update this Policy. We’ll post the new effective date and, for material changes, provide a prominent notice (e.g., banner, email, or Client Area notice). Continued use after the effective date means you accept the updated Policy.
17) Contact Us
Privacy Requests / Questions
privacy@fusionarchosting.com
or open a ticket via the Client Area (choose Privacy Request)
General Support
support@fusionarchosting.com
Mailing Address
Fusion Arc Hosting – A Fusion Arc Telecom LLC Company
PO Box 1766, Gypsum, CO 81637, USA
Required Disclosures (California/Colorado, etc.)
- California (CCPA/CPRA): You have the rights listed in Section 10.4. We do not discriminate for exercising privacy rights. We offer a Do Not Sell or Share mechanism for cross-context advertising.
- Colorado (CPA): You have rights to access, correct, delete, and opt out of targeted advertising/sale/profiling; we provide an appeals process if we deny your request (reply to our response stating “Appeal” and we’ll review).