Skip to content
Zenith Hosting
Back to home

Privacy Policy

Last updated June 10, 2026

This policy explains what information we collect, how we use and share it, and the choices and rights you have. In short: we use your information to run and secure the Service, we do not sell it, and we do not train AI models on the private content of the data you host with us.

1. Overview

This Privacy Policy explains how Zenith Hosting (“Zenith”, “we”, “us”, or “our”) collects, uses, shares, and protects information when you use the Zenith website at zenith.hosting and our hosting, deployment, migration, and intelligence services (together, the “Service”). It should be read together with our Terms of Service.

By using the Service, you agree to the practices described in this policy. If you do not agree, please do not use the Service.

2. Who we are and how to contact us

Zenith Hosting is an independent business based in Australia that operates the Service for customers worldwide, including in the United States and Europe. For any privacy question or request, or to exercise your rights, contact us at [email protected]. We act as the controller of the personal data we process about you for our own purposes, and as a processor for the data you host within the apps you deploy on the Service. Where the law requires us to appoint a representative for a region such as the European Union or the United Kingdom, we will do so and update this policy.

3. Information we collect

Information you provide

  • Account information: your name, email address, username, and a securely hashed password when you register.
  • Sign-in via Google or GitHub: if you choose to sign in with a third-party provider, we receive basic profile information from that provider, such as your name, email address, and account identifier, in accordance with your settings with them.
  • Billing information: your payments are processed by Stripe. We do not store full payment-card numbers. We receive limited details such as your billing country, the last digits and brand of your card, and your subscription and payment status.
  • Hosted content and business data: the data, files, and content within the apps you deploy, and any data you migrate to or from other services using the Service (“Your Content”).
  • Communications: the information you include when you contact us or request support.

Information we collect automatically

  • Usage and device data: such as your IP address, browser and device type, the pages and features you use, actions you take, referring pages, timestamps, and deployment and resource metrics.
  • Cookies and similar technologies: used to keep you signed in and to understand and improve how the Service is used. See “Cookies and analytics” below.
  • Security and approximate location data: including information from anti-abuse checks (for example, our captcha provider) and an approximate location derived from your IP address.

4. How we use your information

We use the information we collect to:

  • provide, operate, maintain, and improve the Service, including deploying, hosting, scaling, networking, and securing your workloads;
  • create and manage your account and authenticate you;
  • process payments, billing, and usage metering;
  • send transactional and service messages, such as verification emails, receipts, security alerts, and notices about changes to the Service or our terms;
  • provide intelligence and related features to you, as described in “Intelligence and AI features” below;
  • secure the Service, prevent fraud and abuse, enforce our Terms of Service, and protect the rights and safety of Zenith, our users, and the public;
  • understand how the Service is used and develop new features and improvements;
  • respond to your enquiries and provide support;
  • comply with our legal obligations.

5. Intelligence and AI features

A core part of the Service is the ability to connect your deployed apps and business data to intelligence and agentic features. To provide these features, we may access, process, and aggregate Your Content and related usage data, so that the Service can surface insights, answer questions, and perform actions across the software you run with us.

We do not train our or any third party’s general-purpose AI models on the private content of Your Content. We may use aggregated or de-identified data that does not identify you or your business to operate, secure, evaluate, and improve the Service and its features. Where intelligence features use third-party AI providers, we share only the data needed to perform the requested task and select providers that do not use that data to train their models.

7. Cookies and analytics

We use cookies and similar technologies. Strictly necessary cookies keep you signed in and keep the Service secure and functional; these cannot be switched off without breaking the Service. We also use product-analytics technologies, provided by PostHog, to understand how the Service is used and to improve it. You can control non-essential cookies through your browser settings and, where offered, in-product controls. Disabling some cookies may affect how the Service works.

8. How we share information

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We share information only as described here:

  • Service providers (sub-processors): trusted vendors that process data on our behalf to run the Service, under contracts that require them to protect it. These currently include: Stripe (payments), Resend (transactional email), Cloudflare (anti-abuse and network security), Google and GitHub (sign-in, where you use them), PostHog (product analytics), our cloud and Kubernetes infrastructure providers (hosting and compute), and AI model providers used to power intelligence features. We may add or change sub-processors as the Service evolves.
  • Legal and safety: where we reasonably believe it is necessary to comply with the law, a legal process, or a lawful request, to enforce our terms, or to protect the rights, property, or safety of Zenith, our users, or others.
  • Business transfers: in connection with a merger, acquisition, financing, reorganisation, or sale of assets, in which case your information may be transferred as part of that transaction.
  • With your direction or consent: including data you choose to send to a third-party service through the Service.

9. International data transfers

We operate globally, and your information may be stored and processed in Australia, the United States, the European Union, and other countries where we or our service providers operate. These countries may have data protection laws that differ from those in your country. Where we transfer personal data across borders, we rely on appropriate safeguards where required, such as the European Commission’s Standard Contractual Clauses, to protect your information.

10. Data retention

We keep your information for as long as your account is active and as needed to provide the Service, and afterwards for as long as necessary to comply with our legal obligations, resolve disputes, prevent fraud and abuse, and enforce our agreements. After your account is closed, we may delete or de-identify your information, although copies may persist in routine backups for a limited period before being overwritten.

11. Security

We use reasonable technical and organisational measures designed to protect your information, including encryption in transit, access controls, and isolation between customer workloads. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. The Service is offered as an open alpha; you are responsible for keeping your credentials confidential and for maintaining your own backups of data you consider important. If we become aware of a security incident affecting your personal data, we will notify you where required by law.

12. Your privacy rights

Depending on where you live, you may have some or all of the following rights regarding your personal data. To exercise any of them, contact us at [email protected]. We will respond as required by applicable law and may need to verify your identity first.

European Economic Area and United Kingdom

You may have the right to access your personal data; to have it corrected or erased; to restrict or object to its processing; to data portability; and to withdraw consent where processing is based on consent. You also have the right to lodge a complaint with your local data-protection supervisory authority.

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing without a lawful basis. If you believe such a decision has been made about you, contact us to request human review.

California

You may have the right to know what personal information we collect, use, and disclose; to access and delete it; to correct it; and to be free from discrimination for exercising your rights. We do not sell your personal information and do not share it for cross-context behavioural advertising. You may use an authorised agent to make a request on your behalf.

Other regions

If you are elsewhere, including Australia, you may have similar rights under your local law, such as the right to access and correct your personal information. Contact us and we will help you exercise the rights available to you.

13. Children’s privacy

The Service is not directed to children under 13, and you must be at least 13 (or older where your jurisdiction requires) to use it. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us at [email protected] and we will take appropriate steps to delete it.

14. Third-party software and links

The Service lets you deploy and use software created by third parties, and may link to third-party sites and services. We do not control these and are not responsible for their privacy practices. Your use of third-party software and the data you process within it are governed by the terms and privacy policies of the relevant providers, which we encourage you to review.

15. Changes to this policy

We may update this Privacy Policy at any time. When we do, we will update the “Last updated” date at the top of this page, and the updated policy takes effect when posted. For material changes, we will make reasonable efforts to notify you by reasonable means, which may include email, a banner or notice in your dashboard, or an in-product notification. Your continued use of the Service after the changes take effect constitutes your acceptance of the updated policy.

16. Contact us

If you have any questions or requests about this Privacy Policy or how we handle your information, contact us at [email protected].