Last updated: June 14, 2026
Privacy Policy
The Coin Shop LLC, doing business as CoinWebHosting (“CoinWebHosting,” “we,” “us,” or “our”), respects your privacy. This Privacy Policy describes how we collect, use, disclose, retain, and protect information when you visit coinwebhosting.com, use our customer portal, or purchase and use our web hosting services (the “Service”).
This Policy applies to information we process as a service provider / business. It does not govern websites operated by our hosting customers; each customer is responsible for their own site privacy practices and visitor notices.
By using the Service, you acknowledge this Policy. If you disagree, do not use the Service.
1. Information we collect
1.1 Information you provide
- Account data: contact name, business name, email address, portal password (stored hashed), phone if provided, primary domain, plan, template selection, and support messages.
- Billing data: billing address and payment method details are collected and processed by Stripe. We receive tokens/IDs, subscription status, invoices, and limited card metadata (e.g., last four digits, brand) — not full card numbers on our servers.
- Communications: email, phone, and portal correspondence with our team.
- Identity verification: information we may request to investigate fraud, abuse, or payment disputes.
1.2 Information collected automatically
- Website/portal logs: IP address, user agent, browser type, pages viewed, referring URL, timestamps, and session identifiers.
- Hosting operations: server, FTP/SFTP, cPanel, database connection, and mail transfer logs generated in the normal course of providing hosting.
- Security data: failed login attempts, malware/abuse signals, and DDoS mitigation metadata.
- Cookies & similar technologies: session cookies to keep you logged into the portal and basic site preferences. See Section 8.
1.3 Information we do not intentionally collect
We do not intentionally collect sensitive categories such as government ID numbers, precise geolocation for marketing, health data, or payment card numbers (Stripe handles cards). Do not send sensitive data in unsecured support tickets if not required.
2. How we use information (purposes & legal bases)
We use personal information to:
- Provide, provision, operate, and maintain hosting accounts, email, SSL, templates, and portal features (contract).
- Process payments, renewals, refunds where applicable, and billing disputes (contract / legal obligation).
- Communicate about service, DNS, security, and policy updates (contract / legitimate interests).
- Provide customer support and improve documentation (contract / legitimate interests).
- Detect, prevent, and respond to abuse, fraud, spam, malware, AUP violations, and network attacks (legitimate interests / legal obligation).
- Comply with law, enforce our Terms, respond to lawful requests, and report CSAM to NCMEC and authorities (legal obligation).
- Protect rights, safety, and property of CoinWebHosting, customers, and the public (legitimate interests).
Where consent is required by law (e.g., certain marketing emails), we will obtain it separately.
3. How we disclose information
We do not sell your personal information and we do not share it for cross-context behavioral advertising as defined under U.S. state privacy laws.
We may disclose information to:
- Service providers / subprocessors that help us run the Service under contractual confidentiality and security obligations, including payment processing (Stripe), server/cPanel infrastructure, email routing, security tools, and backup systems.
- Affiliates such as SpotPro when you bundle or link products under your plan.
- Professional advisors (lawyers, accountants, insurers) under confidentiality duties.
- Law enforcement, regulators, courts, and rights holders when we believe disclosure is required by law, subpoena, court order, abuse complaint, DMCA notice, or to protect safety and rights — including CSAM reports.
- Business transfers in connection with merger, financing, acquisition, or sale of assets, subject to notice where required.
- With your direction when you ask us to share information or integrate a third-party service.
4. Customer-hosted content and email
Files, databases, and mailboxes on your hosting account are under your control. We do not routinely monitor private content but may access or disclose it when necessary to operate the Service, investigate abuse or security incidents, respond to legal process, enforce our Terms (including prohibitions on adult/pornographic content and illegal material), or protect our network.
You are the data controller for personal information your websites and mailboxes collect from your visitors and recipients. You must provide appropriate privacy notices and lawful bases for that processing.
5. Retention
- Active accounts: account and billing records retained while the account is open and as needed to provide the Service.
- Closed accounts: billing/tax records typically retained up to 7 years where required; hosting files deleted after termination per our Terms.
- Logs: server and security logs retained for a limited operational period (often days to months), then rotated or deleted unless needed for an investigation.
- Backups: may persist for a limited time after deletion before overwrite.
- Legal holds: data may be kept longer when required by litigation, investigations, or law.
6. Security
We implement reasonable administrative, technical, and physical safeguards appropriate to a shared hosting provider, including access controls, hashed passwords, TLS for our website, and industry-standard server practices. No system is perfectly secure; we cannot guarantee absolute security or that third parties will not unlawfully intercept data.
You are responsible for securing your CMS, plugins, weak passwords, world-readable files, and outdated software on your account.
7. Data breach notification
If we become aware of a security incident compromising personal information we hold as a business, we will investigate and provide notices required by applicable law, which may include email or website posting.
8. Cookies and tracking
We use cookies and similar technologies primarily for:
- Essential cookies: portal session authentication (e.g., PHP session ID).
- Functional cookies: remembering basic UI preferences where implemented.
We do not operate a third-party advertising pixel network on coinwebhosting.com as of the date above. If we add analytics or marketing tags later, we will update this Policy.
You can control cookies through browser settings; disabling essential cookies may prevent portal login.
We do not respond to “Do Not Track” browser signals because there is no uniform industry standard.
9. Your privacy rights (U.S. states)
Residents of California, Virginia, Colorado, Connecticut, Utah, and other states with consumer privacy laws may have rights to:
- Know/access the categories and specific pieces of personal information we hold about you;
- Correct inaccurate information;
- Delete personal information (subject to exceptions);
- Obtain a portable copy of certain data;
- Opt out of “sale” or certain targeted advertising — we do not sell personal information;
- Limit use of sensitive personal information where applicable;
- Non-discrimination for exercising privacy rights.
To submit a request, email info@spotpro.us with subject “Privacy Request,” your account email, and the right you wish to exercise. We will verify your identity (and authority if acting for a business) before responding. You may designate an authorized agent where permitted by law.
California residents may also contact us to learn how we handle Shine the Light / sharing disclosures; we do not share personal information with third parties for their direct marketing in the traditional sense described by California Civil Code § 1798.83.
10. International users
CoinWebHosting is based in the United States and our infrastructure is primarily U.S.-located. If you access the Service from outside the U.S., you understand that information may be processed in the U.S. and other countries whose laws may differ from yours. We do not intentionally market the Service to the EEA/UK as a localized offering; if EU/UK data protection law applies to you, contact us to discuss lawful transfer mechanisms.
11. Children’s privacy
The Service is not directed to children under 13 (or 16 where applicable), and we do not knowingly collect personal information from children. If you believe a child provided us information, contact us and we will delete it where appropriate. CSAM is reported as described in our Terms.
12. Marketing communications
We may send service-related and occasional promotional emails about CoinWebHosting or related products. You can opt out of promotional emails via the unsubscribe link or by contacting us. Transactional and legal notices may still be sent while you have an account.
13. Third-party links and services
Our site links to third parties (Stripe checkout, cPanel, SpotPro, registrars, etc.). Their privacy practices are governed by their own policies. We are not responsible for third-party sites you operate on your hosting or embed on your pages.
14. Changes to this Policy
We may update this Privacy Policy from time to time. The “Last updated” date will change when we do. Material changes may be communicated by email or portal notice. Continued use after the effective date constitutes acceptance.
15. Contact
Privacy inquiries & rights requests:
- The Coin Shop LLC (CoinWebHosting)
- 9937 E Grand River Ave, Brighton, MI 48116
- Email: info@spotpro.us (subject: Privacy Request)
- Phone: +1 248 446-1445