Private customers Business customers
Save 10 % on domains  Code: domainsale · valid until Oct 11, 2026

Privacy policy

This English version is a translation provided for convenience. Only the German version is legally binding.

The privacy policy of MainHoster.de:

Controller

The controller responsible for the processing of personal data on this website and in the customer interface is:

Address of MainHoster.de

Contact details of MainHoster.de

 

Data protection

Your data is safe with MainHoster.de: the operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.

As a rule, our website can be used without providing personal data. Insofar as personal data (for example name, address or email addresses) is collected on our pages, this is always done on a voluntary basis as far as possible. This data will not be passed on to third parties without your express consent.

Please note that data transmission over the internet (e.g. when communicating by email) can have security gaps. Complete protection of data against access by third parties is not possible.

 

Consent-based cookies (cookie notice)

Services that are not strictly necessary - in particular our chat, tracking and marketing tools - are only loaded after you have expressly consented via our cookie notice (Art. 6 (1) (a) GDPR, Section 25 (1) of the German Telecommunications Digital Services Data Protection Act, TDDDG). If you decline, these services are not loaded and do not set any cookies. We store your choice in a technically necessary first-party cookie ("mh_consent", lifetime 180 days) so that the notice does not reappear on every page view. You can withdraw or adjust your consent at any time with effect for the future via the "Cookie settings" link in the page footer.

 

Use of HubSpot (chat, web analytics & CRM)

On the basis of your consent, we use HubSpot, a service for live chat, web analytics and customer relationship management (CRM). The provider within the EU is HubSpot Ireland Limited, Ground Floor, Two Dockland Central, Guild Street, Dublin 1, Ireland; the parent company is HubSpot, Inc., 2 Canal Park, Cambridge, MA 02141, USA.

For this purpose, HubSpot sets cookies (including "__hstc", "hubspotutk", "__hssc", "__hssrc" and "__cf_bm", which is set by the HubSpot infrastructure) and processes usage and communication data - such as your truncated IP address, browser and device information, the pages visited and, if you use the chat, the messages you enter. This data is used to process your enquiries, evaluate the use of our website and improve our offering.

Data may be transferred to the USA in the process. This is based on the standard contractual clauses of the EU Commission and - insofar as the provider is certified - the EU-US Data Privacy Framework. The legal basis for processing is your consent pursuant to Art. 6 (1) (a) GDPR and Section 25 (1) TDDDG, which you can withdraw at any time with effect for the future. Further information can be found in HubSpot's privacy policy at https://legal.hubspot.com/privacy-policy.

 

Microsoft Clarity (web analytics)

On the basis of your consent, we use Microsoft Clarity, a web analytics service of Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; the parent company is Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA.

Microsoft Clarity sets cookies (including "_clck", "_clsk", "CLID", "ANONCHK", "MUID", "SM") and creates anonymised heatmaps and recordings of usage behaviour (e.g. mouse movements, clicks, scrolling) on our website. Entries in form fields are masked by default. The data is used exclusively to analyse and improve the usability of our website.

Data may be transferred to the USA in the process. This is based on the standard contractual clauses of the EU Commission and - insofar as the provider is certified - the EU-US Data Privacy Framework. The legal basis for processing is your consent pursuant to Art. 6 (1) (a) GDPR and Section 25 (1) TDDDG, which you can withdraw at any time with effect for the future. Further information can be found in Microsoft's privacy statement at https://privacy.microsoft.com/en-us/privacystatement and specifically on Clarity at https://learn.microsoft.com/en-us/clarity/faq.

 

Google Ads conversion tracking

On the basis of your consent, we use Google Ads conversion tracking ("gtag.js"), a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; the parent company is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

If you reach our website via a Google ad, Google sets cookies (including "_gcl_au") and processes usage data - such as your IP address, browser and device information, the click on the ad and a conversion triggered by you (e.g. a completed sign-up or contact request). This data is used to statistically evaluate and bill the effectiveness of our advertisements. We only receive aggregated statistics and cannot identify individual users.

Data may be transferred to the USA in the process. This is based on the standard contractual clauses of the EU Commission and - insofar as the provider is certified - the EU-US Data Privacy Framework. The legal basis for processing is your consent pursuant to Art. 6 (1) (a) GDPR and Section 25 (1) TDDDG, which you can withdraw at any time with effect for the future. Further information can be found in Google's privacy policy at https://policies.google.com/privacy.

 

Google reCAPTCHA

To protect our forms (e.g. sign-up, contact, partner programme, cancellation) against misuse and spam, we use "reCAPTCHA v3". The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. reCAPTCHA evaluates various characteristics of your usage (including IP address, time spent, mouse and keyboard input) in order to distinguish automated entries from human ones. Data may be transmitted to Google in the process, including to the USA (basis: standard contractual clauses, where applicable the EU-US Data Privacy Framework).

The legal basis is our legitimate interest in preventing spam and misuse and in the security of our systems (Art. 6 (1) (f) GDPR). Further information can be found in Google's privacy policy at https://policies.google.com/privacy and at https://policies.google.com/terms.

 

Web analytics with Matomo (cookieless)

For the statistical evaluation of the use of our website, we use Matomo, an open-source web analytics software. We operate Matomo ourselves on a server in Germany (matomo.mainhoster.de) - no data is transmitted to third parties and no data is transferred to third countries.

We deliberately operate Matomo "cookieless": no cookies are set. Your IP address is anonymised (truncated) before processing, so that no conclusions can be drawn about your person. Only pseudonymous usage data is recorded, such as the pages accessed, the approximate location (based on the truncated IP address), browser type and device, the time spent and the previously visited page. This data is used exclusively to measure reach and improve our offering.

The legal basis is our legitimate interest in a data-minimising statistical analysis and optimisation of our offering (Art. 6 (1) (f) GDPR). Since Matomo is operated cookieless and with an anonymised IP address, no consent is required for this.

You can object to future recording by Matomo at any time. To do so, tick the following checkbox to set the opt-out:

 

Customer account and contract processing

To register a customer account, we collect first name, last name, username, email address and a password. We do not store the password in plain text. To protect the sign-up form, we use Google reCAPTCHA (see above).

While you use the customer account, we process the data required to perform the contracts: booked services and their terms, top-ups, credit movements and payment method, orders and receipts, support tickets including their content, and the system messages we send you by email. We only process content that you store on your services (such as files on web hosting, a VPS or a game server) insofar as this is technically necessary to operate the service.

The legal basis is the performance of the contract or the implementation of pre-contractual measures (Art. 6 (1) (b) GDPR), and for the retention of accounting records our legal obligation (Art. 6 (1) (c) GDPR). We store the data for as long as your customer account exists. After the account is deleted, we delete the data unless retention obligations under commercial or tax law prevent this; we block such data for any other use until the retention periods expire.

 

Cancellation form

Via the form "Cancel contracts here", you can cancel contracts without logging in. In doing so, we process first and last name, email address, optionally your username, the name of the contract, the type and desired date of cancellation, the reason in the case of an extraordinary cancellation, and the date, time and IP address of receipt. The details are sent by email to our support team, and you receive a confirmation of receipt. To protect against misuse, we use Google reCAPTCHA (see above).

The legal basis is the performance of the contract (Art. 6 (1) (b) GDPR) and our legal obligation to confirm receipt of a cancellation and to be able to prove it (Art. 6 (1) (c) GDPR, Section 312k BGB). We retain the data for as long as it is needed as proof of the cancellation.

 

Payment processing with PayPal

If you top up credit via PayPal or activate automatic renewal for a service, which runs via PayPal, you will be redirected to PayPal. The provider is PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg.

In doing so, we transmit the amount, currency and an order reference to PayPal. From PayPal we receive the confirmation of payment, the transaction number and the name and email address of your PayPal account; for automatic renewal, also its status. We do not have access to your bank or card details at PayPal. PayPal also processes the data under its own responsibility, for example for fraud prevention and credit checks, and may transfer it to third countries such as the USA.

The legal basis is the performance of the contract (Art. 6 (1) (b) GDPR). Further information can be found in PayPal's privacy statement at https://www.paypal.com/de/legalhub/paypal/privacy-full.

 

Payment processing with Paysafecard

If you top up credit via Paysafecard, you enter the PIN code of your Paysafecard during the payment process. The payment is processed by the Paysafe group as the provider of Paysafecard. In doing so, we transmit the amount, currency and an order reference and receive the confirmation of payment. We do not store the PIN code. Paysafe also processes the data under its own responsibility, for example for fraud prevention.

The legal basis is the performance of the contract (Art. 6 (1) (b) GDPR). Further information can be found in Paysafecard's privacy notice at https://www.paysafecard.com/de-de/datenschutzmitteilung/.

 

Payment by bank transfer

For a top-up by bank transfer, we process the details your bank transmits to us with the payment, in particular name, IBAN, amount and payment reference, in order to allocate the payment to your customer account. The legal basis is the performance of the contract (Art. 6 (1) (b) GDPR) and our statutory retention obligation (Art. 6 (1) (c) GDPR).

 

Payment processing with Stripe

For payments by credit card (Visa, Mastercard, Maestro) and via Google Pay and Apple Pay, we use the payment service provider Stripe. The provider for customers in the European Economic Area is Stripe Technology Europe Limited, 25/28 North Wall Quay, Dublin 1, Ireland.

When you make a payment, the data required for processing is transmitted to Stripe, in particular name, email address, invoice amount and currency, as well as the payment data entered during the payment process. You enter your full card details exclusively with Stripe; they are processed by Stripe and are not available to us. Stripe processes the data to carry out the payment and for fraud prevention and may pass it on to affiliated companies of the Stripe group as well as to the credit institutions and card organisations involved. Data may be transferred to third countries, in particular the USA, in the process (basis: standard contractual clauses, where applicable the EU-US Data Privacy Framework).

The legal basis is the performance of the contract or the implementation of pre-contractual measures (Art. 6 (1) (b) GDPR) and our legitimate interest in secure payment processing free of misuse (Art. 6 (1) (f) GDPR). Further information can be found in Stripe's privacy policy at https://stripe.com/privacy.

 

Supporter pages

Customers can create a public supporter page through which other people can buy credit for their customer account. If you make a support payment there, we process the following data:

  • your email address (mandatory, for the receipt and queries about the payment),
  • optionally your name,
  • optionally a nickname and a message to the page owner,
  • amount, time and payment method as well as the transaction data transmitted by the payment service provider,
  • a hash value of your IP address to detect misuse and to enforce the daily limits.

The page owner only sees the nickname and the message. We do not pass on your email address, name or payment data to them. Your details are not displayed publicly on the supporter page. We delete the hash value of the IP address after 30 days. We retain the remaining payment data for as long as retention obligations under commercial and tax law apply.

To protect against automated entries and misuse, we use Google reCAPTCHA on the supporter page (see the section "Google reCAPTCHA"). The payment itself is processed by the respective payment service provider; for credit card, Google Pay and Apple Pay, this is Stripe (see the section "Payment processing with Stripe").

The legal basis is the performance of the contract with you (Art. 6 (1) (b) GDPR), for the retention of payment data our legal obligation (Art. 6 (1) (c) GDPR), and for misuse detection, IP hash and reCAPTCHA our legitimate interest in secure, fraud-free processing (Art. 6 (1) (f) GDPR). Nickname and message are voluntary.

 

Access, deletion, blocking

You have the right at any time to free information about your stored personal data, its origin and recipients and the purpose of the data processing, as well as a right to rectification, blocking or deletion of this data. For this purpose, and for any further questions on the subject of personal data, you can contact us at any time at the address given in the legal notice.

 

Cookies

Some of our web pages use so-called cookies. Cookies do not harm your computer and do not contain viruses. Cookies serve to make our offering more user-friendly, effective and secure. Cookies are small text files that are stored on your computer and saved by your browser.

Most of the cookies we use are so-called "session cookies". They are automatically deleted at the end of your visit. Other cookies remain stored on your device until you delete them. These cookies enable us to recognise your browser on your next visit.

You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be limited.