Privacy Policy

Last updated 11 August 2026

This explains what we collect when you use Plysk, why we collect it, and what you can ask us to do about it. It is written to be read rather than to be impressive. If anything here is unclear, ask us before you assume what it means.

1. Who we are

Plysk is a website builder operated by Plysk LLC, a Wyoming limited liability company, registered at 30 N Gould St Ste N Sheridan, Wyoming 82801. For the personal data described in this notice, Plysk LLC is the data controller — it decides what is collected and why.

There is one exception, and it matters: for the information your own website visitors send you through a form on your site, you are the controller and we act on your instructions. Section 8 covers that.

2. The short version

  • We collect what running the service requires: your account details, your billing record, the content of your site, and operational logs.
  • We do not sell personal data, and we have never done so.
  • We run no advertising trackers. Our public pages use Google Analytics, and only if you agree — we ask before it loads anything, refusing takes one click, and the site behaves identically either way.
  • The signed-in application carries no analytics at all, and neither do the websites we publish for our customers.
  • We do not read the contents of your mailboxes, except where you ask us to look at a specific problem or the law compels us.
  • Your data is stored in the United States.
  • You can ask for a copy of your data, or ask us to delete it, by emailing office@plysk.com.

3. What this notice covers

It covers plysk.com, the builder you sign into, and the hosting that serves your published site. It sits alongside our Terms of Service, which govern the service itself.

It does not cover the websites our customers build. If you have arrived here from someone else's site that happens to be hosted on Plysk, that site's owner decides what they collect from you, and their own privacy notice applies — not this one.

4. What we collect

Account information

Your email address, a hashed version of your password, the name you give your workspace, and the plan you are on. We never store your password itself.

Billing information

Your subscription status, plan history, and the identifiers our payment provider gives us so we can match a payment to your account. Card numbers are entered on the payment provider's own checkout and never reach our servers — we cannot see them.

Your site content

Everything you put into the builder: text, images, page structure, and the settings that describe your site. If you have connected a domain, the contact details required to register it — ICANN requires those to be accurate, and the registry receives them.

Images you upload are checked automatically for illegal and explicit content before they are stored. The check is carried out by Google Cloud Vision, which receives the image and returns a rating. It is sent nothing about you or your account — not your email, not your site, not your plan — and no person at Plysk sees the image as part of this check. We keep the rating alongside the image so we can show why something was refused.

Form submissions from your visitors

If your site has a contact form, what your visitors type into it is stored so you can read it. See section 8.

Mailboxes

If your plan includes email on your domain, the mail platform stores your messages so it can deliver them. We can see that a mailbox exists and how much it is sending; we do not read its contents in the ordinary course of running the service.

Operational logs

Our servers record requests: IP address, timestamp, the page or endpoint, the response, the browser's user-agent string, and an error trace when something breaks. This is how we keep the platform up and work out what went wrong when it is not.

Analytics, on our public pages only

If you accept the analytics question, Google Analytics records which of our public pages you looked at, roughly where in the world you are (derived from a shortened IP address, which we do not store in full), and general information about your browser and device. It does not receive your name, your email or anything you have typed. If you decline, none of this is collected — and it is never collected inside the signed-in application.

Correspondence

When you email us, we keep the email and our reply, so the next person who helps you has the context.

5. Where it comes from

Almost all of it comes from you directly — you type it in when you register, build your site, or write to us. The rest is generated automatically as you use the service (logs), or comes back to us from a provider acting on your instruction: the payment provider confirms a subscription, the registrar confirms a domain, the mail platform reports a mailbox.

We do not buy personal data, and we do not enrich your record from third-party sources.

6. Why we use it, and our legal basis

Where the GDPR applies, we need a lawful basis for each use. Ours are these:

  • To provide the service you signed up for — creating your account, storing and publishing your site, registering domains, running mailboxes, taking payment. Basis: performance of a contract with you.
  • To keep the platform working and secure — logging, monitoring, rate limiting, investigating abuse, blocking attacks. Basis: our legitimate interest in running a service that stays up and is not used to harm people.
  • To contact you about your account — renewals, failed payments, expiring domains, security notices, material changes to our terms. Basis: performance of a contract, and our legitimate interest in reaching you about things that affect you. These are not marketing and you cannot unsubscribe from them while you have an account.
  • To meet legal and financial obligations — keeping billing records, responding to lawful requests, complying with ICANN rules for domains. Basis: legal obligation.
  • To keep the platform lawful and safe — checking uploaded images for illegal and explicit material before they are published on our infrastructure. Basis: legitimate interest in not hosting that material, and legal obligation where the law requires us to act on what is found.
  • To improve Plysk — understanding which features are used and where people get stuck. Inside the signed-in application this comes from our own logs, not a tracking product. Basis: legitimate interest.
  • To measure our public pages — which pages visitors read, how they found us, and whether the site persuades anyone to sign up. Google Analytics, on the public pages only, and only after you accept. Basis: consent, withdrawable at any time by clearing this site's data.
  • To send you optional product email, if you have asked for it. Basis: consent, withdrawable at any time.

Where we rely on legitimate interest, we have considered whether it is fair to you, and you can object — see section 14.

7. Cookies

We use as few as the service can function with. There are three kinds:

  • Your session. When you sign in we set an HttpOnly cookie holding a signed token. It is what keeps you signed in, it cannot be read by JavaScript, and signing out invalidates it.
  • Preferences. Small values that remember choices such as your theme, and your answer to the analytics question below.
  • Analytics, only if you agree. Google Analytics cookies, set on our public pages when you accept. They record which pages are visited and how people arrive; they do not follow you to other websites.

The first two are strictly necessary and need no permission. The third is why you see a banner on your first visit. Nothing analytical is stored until you press Accept — Reject is the default, it is the same size and shape as Accept, and choosing it does not degrade the site in any way. You can change your mind by clearing this site's data in your browser.

We run no advertising cookies, no session recording and no social media pixels anywhere. The signed-in application at /admin carries no analytics whatsoever, and neither do the websites we publish for our customers — those remain, as before, free of anything we have added.

Sites built by our customers can contain whatever their owners add, including embedded third-party content that sets its own cookies. That is the site owner's responsibility, not ours.

8. Data your own visitors give you

When someone fills in a form on a site you built with Plysk, you decide what that form asks for and what you do with the answers. In data protection terms you are the controller and we are your processor: we store the submissions so you can read them, and we do not use them for our own purposes.

That split has consequences for you:

  • You need your own privacy notice on your site, telling visitors what you collect and why.
  • You need a lawful basis for collecting it.
  • If a visitor asks you to delete their data, it is your obligation — you can delete submissions from your account, and we will help if you cannot.
  • Do not use forms to collect passwords, card numbers or government identification numbers. Our terms prohibit it.

We act on your documented instructions, keep the submissions confidential, apply the security measures in section 13, and use the same subprocessors listed in section 9. If you need a formal data processing agreement, email us and we will put one in place.

9. Who else sees it

We do not sell personal data and we do not share it for anyone else's marketing. We do use other companies to deliver parts of the service — hosting, the content delivery network, payments, domain registration, email, analytics and image checking — and each receives only what its role requires. Ask us at office@plysk.com if you want the current list.

We disclose information only:

  • when the law requires it, or to respond to a valid legal request — and we will tell you when we are permitted to;
  • to enforce our terms or protect the rights and safety of our customers, our visitors or us;
  • to professional advisers such as accountants and lawyers, under a duty of confidence;
  • to a buyer, if the business is ever sold or merged — you would be told before your data moved, and this notice would continue to apply until replaced.

10. Where it is stored

Our application database and file storage are in the United States. Published sites are copied to a content delivery network with servers worldwide,

The content on that network is your published website, which is public by design. Your account data, billing records and unpublished drafts stay in the United States.

11. International transfers

If you are in the European Economic Area, the United Kingdom or Switzerland, using Plysk means your personal data is transferred to the United States, which those regimes do not treat as offering equivalent protection by default.

We rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where relevant) with the providers in section 9, together with the technical measures in section 13. You can ask us for details of the safeguards that apply to a particular provider.

12. How long we keep it

  • Account and site content — for as long as your account is open. After you close it, we keep it briefly so it can be restored if you closed it by mistake, then delete it.
  • Billing records — for as long as tax and accounting law requires us to, which is longer than your account may last.
  • Form submissions — until you delete them or close your account.
  • Analytics — retained by Google for 14 months from a visitor's last activity, then deleted automatically. Aggregate reports built from it are not personal data and are kept indefinitely.
  • Correspondence — for as long as it is useful for support history, then deleted.
  • Domain registration records — for as long as ICANN and the registry require, which we do not control.

Backups are rotated, so deleted data can persist in a backup for a short period after it has gone from the live system.

13. How we protect it

  • Everything travels over TLS, including the sites we publish for you.
  • Passwords are stored as salted hashes, never in a form we could read.
  • Sessions use signed, HttpOnly cookies and can be revoked server-side.
  • Each customer's data is structurally separated so that a request made in one account cannot reach another's.
  • Access to production is limited to those who need it, over authenticated channels.

No service can promise perfect security, and we do not. If a breach affects your personal data and is likely to put you at risk, we will tell you and the relevant regulator within the time the law requires.

14. Your rights

Depending on where you live, you can ask us to do the following. We do not charge for it, and we answer within one month.

  • See it — get a copy of the personal data we hold about you.
  • Correct it — most of it you can edit yourself in your account; ask us for the rest.
  • Delete it — we will, unless we are legally required to keep something such as a billing record.
  • Take it elsewhere — receive it in a portable format, or have it sent to another provider.
  • Restrict or object — including objecting to anything we do on the basis of legitimate interest.
  • Withdraw consent — where consent is what we relied on, without affecting what was done before you withdrew it.

Email office@plysk.com. We may need to confirm who you are before we act, which protects you as much as us.

If you are asking about data held in someone else's site — a form you filled in — contact that site's owner, since it is theirs and not ours to give.

15. Marketing

We do not add you to a marketing list because you created an account. If we ever send product email, it will be because you asked for it, and every message will carry an unsubscribe link that works.

Service email is separate — renewals, failed payments, expiring domains, security notices. You will keep receiving those while you have an account, because not receiving them is worse for you than receiving them.

16. Children

Plysk is for adults running websites and businesses. It is not directed at children, and we do not knowingly collect data from anyone under 18. If you believe a child has given us personal data, tell us and we will delete it.

17. Automated decisions

We do not profile you or make decisions about you by automated means that produce legal or similarly significant effects. Automated systems do flag accounts for review — for suspected spam or abuse, for example — but a person decides what happens next, and you can ask us to explain and reconsider.

18. Changes to this notice

We will update this page as the service changes. If a change materially affects your rights or how we use your data, we will email you before it takes effect rather than quietly editing the page. The date at the top tells you when it last changed.

19. Contacting us and complaining

Any question about this notice, or any request under section 14: office@plysk.com.

If we have got something wrong, tell us first — we would rather fix it than have you escalate. You also have the right to complain to your local data protection authority, and in the EEA or UK you can do so in the country where you live or work.