Jump to Document Section
- 01 Scope & Privacy Principles
- 02 Information We Collect
- 03 Purpose & Legal Basis of Processing
- 04 Data Classification & Retention Matrix
- 05 Technical Security & Encryption
- 06 Sub-processors & Third-Party Sharing
- 07 Your Statutory Privacy Rights
- 08 Cookie & Session Tracking Policy
- 09 Data Residency & Cross-Border Transfers
- 10 Grievance Officer & Formal Contact
Privacy & Data Protection Policy
This document governs customer relationships, platform usage, and operational guarantees provided by MeraHost. Please review these terms thoroughly. Continued use of MeraHost infrastructure constitutes full acceptance.
Executive Summary & Key Commitments
- Zero Selling or Monetization: We never sell, rent, trade, or monetize your personal data or browsing history to third-party ad networks or data brokers.
- Data Minimization: We only collect information strictly required to provision compute infrastructure, issue valid tax invoices, and prevent malicious abuse.
- Statutory CERT-In & DPDP Alignment: Our log retention strictly satisfies Indian CERT-In cybersecurity directives and Digital Personal Data Protection Act (DPDP) 2023 mandates.
- Complete Control: You have full rights to request an export of your account records or request total deletion upon account closure and service termination.
Scope & Core Privacy Principles
MeraHost (“we”, “us”, or “our”) is dedicated to safeguarding the privacy and digital autonomy of our website visitors, registered clients, and domain registrants (“Customer”, “you”). This Privacy Policy explains our practices regarding the collection, storage, processing, and protection of personal data across our web domains, customer dashboard (account.merahost.org), and managed compute nodes.
Our data handling operations are built upon four fundamental principles:
- Transparency: We clearly communicate what data is gathered and why, with no hidden behavioral trackers.
- Purpose Limitation: Personal data is processed exclusively for the specific infrastructure services contracted.
- Security by Default: High-grade transport layer security (TLS 1.3), role-based sysadmin access, and continuous automated auditing.
- Regulatory Compliance: Strict compliance with the Digital Personal Data Protection Act (DPDP), 2023 (India), CERT-In security directives, and global data privacy standards including GDPR principles.
Information We Collect
Depending on how you interact with MeraHost, we collect the following categories of information:
- Account Identification Data: Full legal name, verified email address, physical mailing address, primary telephone number, and company name (if registering an enterprise account).
- Billing & Transactional Records: Tax identifiers (such as GSTIN), invoice histories, transaction IDs, payment method tokens, and currency preferences. Note: MeraHost does not store raw credit card numbers or banking CVVs; payment processing is handled via tokenized PCI-DSS Level 1 compliant gateways.
- Technical Infrastructure Telemetry: Public IP addresses, browser user-agent strings, reverse DNS lookups, authentication timestamps, and administrative panel audit logs.
- Domain WHOIS Data: Registrant contact details required by ICANN and national registry operators (such as .IN Registry / NIXI) to establish legal domain ownership.
Purpose & Legal Basis of Processing
We process your data under clear, lawful bases under applicable data protection statutes:
- Contractual Performance: To provision web hosting environments, configure DNS zones, allocate NVMe storage, and provide active 24/7 technical helpdesk assistance.
- Statutory Compliance: Issuance of valid tax invoices complying with Indian GST laws, compliance with CERT-In cybersecurity directives, and adherence to ICANN WHOIS accuracy guidelines.
- Security & Threat Defense: Defending against brute-force intrusion, preventing distributed denial of service (DDoS) campaigns, and blocking phishing attacks via Imunify360.
- Service Notifications: Dispatching essential transactional communications such as maintenance advisories, invoice delivery, SSL expiration alerts, and domain renewal reminders.
Data Classification & Retention Matrix
Below is our transparent data classification, purpose, and statutory retention schedule:
| Data Category | Specific Purpose | Retention Duration | Governing Requirement |
|---|---|---|---|
| Client Account Records | Account identity, portal access, support tickets | Active tenure + 30 days post-cancellation | Contractual Fulfillment & Support |
| Invoices & Fiscal Ledger | Statutory accounting, tax filings, audits | 8 Years from transaction date | Indian Income Tax & GST Acts |
| Network & Firewall Logs | Forensic tracking, intrusion defense, anti-abuse | 180 Days | Indian CERT-In Cybersecurity Directives |
| Automated Backup Archives | Disaster recovery & website restoration | Rolling 30-day snapshot window | MeraHost Platform Continuity SLA |
| Domain Registry WHOIS | TLD ownership allocation & registry records | Duration of active domain registration | ICANN & NIXI Registry Guidelines |
Technical Security & Encryption Safeguards
We deploy enterprise-grade defense-in-depth security measures to protect customer data against unauthorized access, alteration, disclosure, or destruction:
- Transit Encryption: All communications with MeraHost properties and customer control panels are strictly secured with TLS 1.3 / HTTPS encryption, enforced with strict HTTP Strict Transport Security (HSTS) headers.
- Data at Rest: Core database stores, backup snapshot archives, and sensitive configurations are stored on encrypted NVMe arrays.
- Perimeter Defense: Real-time heuristic malware scanning via Imunify360, ModSecurity web application firewalls (WAF), automated brute-force IP rate limiting, and multi-gigabit edge DDoS mitigation.
- Access Control: Administrative access to bare-metal hypervisors is restricted to authorized senior sysadmins using cryptographic SSH keys and hardware MFA.
Sub-processors & Third-Party Disclosures
MeraHost engages verified third-party service providers (“Sub-processors”) solely to execute specific technical and transactional operations:
- Payment Gateways: Razorpay, Stripe, and PayPal process credit cards, NetBanking, and UPI transactions under strict PCI-DSS compliance.
- Domain Registries & ICANN: Registry operators (e.g. Verisign for .com, NIXI for .in) receive registrant data necessary to allocate legal domain delegation.
- Tier-IV Datacenter Facilities: Physical hardware housing in Mumbai (India) and Amsterdam (Netherlands) with biometric physical controls and ISO 27001 certification.
- Legal Mandate Exceptions: We disclose data to law enforcement agencies only when presented with a valid court order, search warrant, or binding statutory directive issued by competent Indian judicial authorities.
Your Statutory Privacy Rights
In accordance with the Indian Digital Personal Data Protection Act, 2023, and applicable global privacy standards, you hold the following rights:
- Right to Access & Portability: You may view or export your personal information, active services, invoices, and support history directly from the client area at any time.
- Right to Rectification: You may update outdated contact details, phone numbers, or corporate addresses via your profile dashboard.
- Right to Erasure (“Right to be Forgotten”): Upon complete cancellation of active services and settlement of outstanding invoices, you may request the permanent deletion of your account credentials and personal records.
- Right to Withdraw Consent: You may opt out of non-essential product advisories at any time (essential transactional and security alerts will continue for active accounts).
To exercise any statutory privacy right, please submit an authenticated ticket via the Billing & Privacy Desk.
Cookie & Session Tracking Policy
MeraHost employs minimal, privacy-respecting cookies:
- Essential Session Cookies: Used to maintain authenticated user sessions in the client area and preserve your active shopping cart.
- Security & CSRF Tokens: Unique, cryptographic tokens designed to protect web forms against Cross-Site Request Forgery (CSRF) attacks.
- Preference Cookies: Storing currency selection (INR vs. USD) and theme preferences (dark mode).
We do not embed third-party surveillance cookies, advertising beacons, or commercial data-tracking pixels on our website.
Data Residency & Cross-Border Transfers
MeraHost operates redundant enterprise datacenter footprints:
- India Region (Default): Primary compute nodes, NVMe storage pools, and client data are maintained in our Tier-IV Mumbai facility, ensuring compliance with Indian data sovereignty principles.
- European Region (Optional): For clients requiring European Union data residency under GDPR Article 44–50, dedicated servers and VPS instances may be provisioned in our Amsterdam (Netherlands) datacenter.
Grievance Officer & Formal Privacy Contact
If you have questions, inquiries, or grievances regarding this Privacy Policy or our data handling practices, our designated compliance desk can be reached at:
Attention: Grievance Officer
Email: support@merahost.org
Portal: account.merahost.org/contact.php
Response Commitment: Formal written acknowledgement within 24–48 hours; resolution within statutory 15 days.