Service Terms

BITFOO LLC · Version 1.0 · Effective

Guide to the document

In Plain Language

A short summary of what follows. It is here to help you understand these terms, not to replace them.

  • Your plan's specifics live on its product page. These terms say who is responsible for what. The numbers — cores, storage, mailboxes, bandwidth — are in the Service Description for whatever you bought, so we can improve plans without rewriting contracts.
  • Shared hosting is managed by us. We keep the platform standardized and current, which means we control software versions. Backups are included and you can restore them yourself, free.
  • Virtual servers are yours to run unless you bought a managed plan. On an unmanaged server you have root, and everything above the hypervisor is your responsibility — updates, security, firewall, applications.
  • Snapshots are not backups. A snapshot lives on the same infrastructure as your server. If that infrastructure fails, so does the snapshot. Backups are a separate product stored separately, and we strongly recommend them.
  • SSL certificates come with obligations that aren't ours to waive. You generate your own private key, you complete validation, and if the key is ever compromised you must tell us immediately — the certificate authority has 24 hours to revoke it. Every domain on a certificate is also published permanently to public logs.
  • If you bring your own IP space, we need proof it's yours. We announce it from our network, so a false announcement is our problem, not just yours.
  • Suspension works differently per service. On shared hosting, everything stops — including your email. On a virtual server, it's powered off and your data stays intact.
  • If you resell, your customers depend on your account staying current. Suspending a reseller account takes every account beneath it offline. Make sure your own terms tell your customers what that means.

This summary is not part of these terms and has no legal effect. The numbered sections below are the actual terms, and they govern in full.

The service terms

Part 1 — General

1. About These Terms

1.1 These Service Terms form part of our Terms of Service and apply to shared web hosting, virtual private servers, SSL/TLS certificates, and IP address announcement services provided by BITFOO LLC (“Bitfoo,” “we,” “us”).

1.2 Domain registration is governed by our separate Domain Registration Agreement and is not covered here.

1.3 Where the numbers live. These terms set out responsibilities and rules. The specifications of each service — resource allocations, quantities, limits, retention periods, and included features — are set out in the Service Description for that service. Where a Service Description is silent on something, it is not included.

1.4 Descriptions of what is included. Where these terms describe what a service includes, that describes our standard offering for that type of service. Where the Service Description for a particular plan says otherwise, the Service Description prevails. This lets us offer plans with different feature sets without changing these terms.

1.5 Our Terms of Service, Acceptable Use Policy, and Refund and Cancellation Policy apply in full. Where these Service Terms conflict with the Acceptable Use Policy, that Policy prevails.

2. Provisioning

2.1 Most services are provisioned automatically once payment is received and any required checks are complete. We do not guarantee a provisioning timeframe. Automated provisioning can fail, and some services require review before activation.

2.2 Services in a restricted category under the Acceptable Use Policy are not provisioned until approval is granted.

2.3 We may require identity or business verification before activating a service.

2.4 Location. Where a service is offered in more than one location, you select the location when you order. We will not move your service to a different country without telling you. Where a location becomes unavailable, we will contact you before making any change.

3. Credentials and Access

3.1 You are responsible for securing all credentials associated with your services, including control panel logins, administrative and root passwords, SSH keys, and API tokens.

3.2 Where we provide initial credentials, we provide them once, through your client portal or to your account email address. Change them promptly. We are not responsible for the consequences of credentials that remain unchanged or are shared.

3.3 We may reset credentials without notice where necessary to secure a service, our platform, or another client.

3.4 You are responsible for everything done using your credentials, whether by you or by anyone else.

4. Migrations

4.1 We may offer assistance migrating services to us. Whether migration assistance is included, and its scope, is stated in the applicable Service Description or agreed in writing.

4.2 Migrations are provided on a reasonable-efforts basis and are not guaranteed. Success depends on factors outside our control, including access to your source provider, the configuration and condition of the source environment, undocumented dependencies, and third-party software.

4.3 You remain responsible for verifying that a migration completed correctly, and for maintaining your own backup of the source environment until you have done so. Do not cancel your previous service until you are satisfied.

4.4 We are not liable for data loss, downtime, configuration differences, or business interruption arising from a migration.

5. Changes to Services

5.1 We may change the composition of a service — including the software, platform components, and infrastructure used to deliver it — where the change is like-for-like or an improvement. We will give notice where the change is likely to be noticeable.

5.2 Where a change materially reduces what you purchased, we will treat it as a material change under our Terms of Service, give at least 30 days’ notice, and you may cancel before it takes effect.

5.3 Changes required for security, or by a supplier or by law, may be made immediately, with notice as soon as practicable.

6. Beta and Preview Services

6.1 We may offer services or features labelled beta, preview, early access, or similar. These are provided “as is,” without any warranty or availability commitment, may change or be withdrawn at any time, and are not covered by any Service Level Agreement.

6.2 Do not use a beta service for anything you cannot afford to lose. Data in a beta service may be deleted when the beta ends.

7. Resource Limits

7.1 Resource limits applicable to your service are stated in its Service Description.

7.2 Where you approach or exceed a limit, we may throttle the service, and where the excess is sustained we will contact you and recommend a more suitable plan. We would rather move you to the right product than restrict the one you have.

7.3 Where a Service Description provides for charges above an allowance, those charges apply as stated there.

8. Availability

8.1 These terms set out what a service includes and who is responsible for it. They do not create any uptime or availability commitment. Availability commitments and service credits apply only where a Service Level Agreement is published and referenced in your Service Description. See our Terms of Service.

8.2 Nothing in these terms limits our right to take protective action, perform maintenance, or suspend a service as set out in our Terms of Service and Acceptable Use Policy, and action taken under those provisions is not a failure to provide the service.

9. Programmatic Access

9.1 Where we make an application programming interface available to you, this Section applies. API access is not included with every service, and where it is available it is stated in the Service Description.

9.2 Credentials and tokens issued to you are yours to secure, on the same terms as any other credential under Section 3. You are responsible for everything done using them, including by automated systems you build or authorize.

9.3 We may apply rate limits, quotas, and restrictions on which operations are available. We may change them where necessary to protect the platform.

9.4 We may suspend or revoke a token immediately and without notice where it is being misused, where it is generating load that threatens the platform or other clients, or where we believe it has been compromised.

9.5 Our Acceptable Use Policy applies in full to anything done through an API.

Part 2 — Shared Web Hosting

Reseller hosting is covered separately in Part 6.

10. What Shared Hosting Includes

10.1 Control panel. Shared hosting is provided with the DirectAdmin control panel. Access details are provided on provisioning.

10.2 Included, subject to the limits in your Service Description:

  • Email mailboxes, with webmail, IMAP, and POP access

  • Databases

  • Subdomains, addon domains, and parked domains

  • FTP and SFTP accounts

  • SSH access

  • Scheduled tasks (cron)

  • The Softaculous application installer

10.3 DNS hosting is included. We provide authoritative DNS for domains hosted with us, managed through your control panel. Point your domain at the nameservers given in your welcome email.

10.4 Free TLS certificates are included. Shared hosting includes automatically issued and renewed domain-validated certificates at no charge. These secure your site and require no action from you. They are issued by a third-party certificate authority and are subject to that authority’s terms, and we do not guarantee their continued availability on the same basis. Paid certificates offering organization or extended validation, or a certificate authority warranty, are available separately — see Part 4.

10.5 IPv6 availability on shared hosting is as stated in your Service Description.

10.6 Dedicated IP address. Shared hosting uses a shared IP address by default. A dedicated IP is available as a paid add-on.

11. Platform Management and Software Versions

11.1 We manage the shared hosting platform and are responsible to you for it. The platform — the operating system, web server, database server, control panel, and mail services — is maintained on current, supported software and is not configured by you.

11.2 We determine which software versions are available to your account, and maintain a standardized platform. This is a deliberate security decision: a standardized, current platform is materially easier to keep secure than one carrying arbitrary legacy configurations. Platform-level maintenance, upgrades, and security work are carried out on our schedule, not on request.

11.3 We will move the platform off software versions that are end-of-life or no longer receiving security updates. We give notice before a change likely to affect your site, and where practicable we allow a period during which you can select an older supported version for your account.

11.4 We do not maintain end-of-life software on request. If your application requires a version we no longer support, a virtual server is the appropriate product, and we will help you move.

11.5 You remain responsible for your own applications, themes, plugins, and code, including keeping them updated and secure. Software installed through Softaculous is your responsibility once installed.

12. Backups on Shared Hosting

12.1 Backups are included with shared hosting. Frequency, retention, and storage location are stated in the Service Description.

12.2 Restores are self-service through your control panel, and free of charge.

12.3 Backups are a convenience, not a guarantee. We do not warrant that any backup will be complete, current, uncorrupted, or restorable, and you remain responsible for maintaining your own independent copies of anything you cannot afford to lose. See our Terms of Service.

12.4 Backups are deleted when your service is terminated, on the timeline in our Terms of Service.

13. Email on Shared Hosting

13.1 Email is included with shared hosting. Mailbox counts and storage are stated in the Service Description.

13.2 Outbound sending limits are stated in the Service Description, and the Acceptable Use Policy governs what you may send. SPF and DKIM are required for outbound mail.

13.3 Important — use an independent address for your account. If your hosting is suspended, your email stops working with it (see Section 14). We recommend the email address on your Bitfoo account is one that does not depend on your hosting with us, so that you continue to receive billing and service notices.

13.4 We cannot guarantee delivery. Whether a message you send arrives is decided by the receiving mail provider, not by us. Delivery depends on your sending practices, your domain’s reputation, your authentication records, the content of your messages, and the policies of providers we have no relationship with. We provide the means to send mail; we do not and cannot guarantee that any message will be delivered, or that it will not be classified as spam. We will investigate delivery problems that originate on our side.

13.5 Mailboxes are not an archive. We recommend keeping local copies of anything important.

14. Suspension of Shared Hosting

14.1 Where shared hosting is suspended — for non-payment, under the Acceptable Use Policy, or otherwise — the entire account is suspended. This is how the control panel works and it cannot be applied selectively.

14.2 This means that during a suspension: your website is unavailable, your email stops sending and receiving, FTP and SSH access are disabled, databases are inaccessible, and scheduled tasks do not run. Mail sent to your addresses during a suspension may be rejected or lost.

14.3 Visitors to a suspended site see a suspension notice page.

14.4 Your data is retained during suspension and is not deleted until termination, on the timeline in our Terms of Service.

Part 3 — Virtual Private Servers

15. Managed and Unmanaged

15.1 Virtual servers are unmanaged by default. A service is managed only where its Service Description says so.

15.2 On an unmanaged server, you are responsible for everything above the virtual hardware, including:

Responsibility Unmanaged
Virtual hardware, hypervisor, host network Bitfoo
Operating system installation Bitfoo provides templates; you choose and deploy
Operating system updates and patching You
Security configuration and hardening You
Firewall configuration You
Control panel installation and licensing You
Web server, database, and application software You
Application-level support You
Monitoring You
Response to compromise of your server You
Backups You, using our backup product or your own

15.3 Managed services. Where a service is managed, the Service Description states exactly which of the responsibilities above we assume. Anything not listed there remains yours. Management scope varies by product and we do not imply a level of management that a Service Description does not state.

15.4 Custom arrangements. Where we agree a bespoke arrangement, its scope is set out in writing with you and takes precedence over this Section for that service.

15.5 Our general support obligations — responding to platform issues, network problems, and faults on our side — apply to every service regardless of management level.

16. Root Access and Control

16.1 You receive full root or administrative access to unmanaged servers.

16.2 On managed services, whether you also hold root access depends on the service and is stated in its Service Description. Where we hold exclusive administrative control, changes you make outside agreed channels may void what we can support or guarantee.

16.3 We may access a virtual server where necessary to investigate abuse, respond to a security incident, comply with a legal obligation, or perform work you have requested. See our Acceptable Use Policy.

17. Operating Systems and Deployment

17.1 We provide a selection of operating system templates.

17.2 Custom installation media. You may upload and boot your own installation media, subject to the following:

  • Media size limits are stated in the Service Description.

  • We may require your account to be in good standing before enabling this, and may decline a request.

  • We do not support operating systems installed from custom media. Our support covers the virtual hardware, the network, and the console — not an operating system we do not provide.

  • We may remove stored media, and may decline to boot media that appears malicious, unlawful, or likely to compromise our platform.

  • Our Acceptable Use Policy applies in full to whatever you run.

17.3 Licensing is your responsibility. Where an operating system or application requires a licence, you must hold a valid one. We do not supply licences for anything you install yourself, and we may require evidence of licensing.

17.4 Microsoft Windows. We do not supply Windows licences. You may install Windows using your own licence, but only where that licence is eligible for use on a hosting provider’s multi-tenant infrastructure. Not every Windows licence qualifies — retail, OEM, and volume licences without active Software Assurance generally are not eligible, and eligible licences carry minimum core-count and client access licence requirements.

By installing Windows you confirm that your licensing is valid for this use, and you are solely responsible for compliance. We may require evidence and may remove or suspend a deployment we reasonably believe is not properly licensed. We cannot advise you on Microsoft licensing — take your own advice before you deploy.

17.5 You may reinstall or rebuild your server at any time from your control panel. Rebuilding destroys all data on the server. We cannot recover data lost to a rebuild.

17.6 SSH keys stored in your control panel account may be deployed automatically on build and rebuild.

18. Console Access

18.1 Browser-based console access is available, which connects to your server’s virtual display independently of its network configuration. This is the appropriate tool when you have locked yourself out, misconfigured a firewall, broken SSH, or need to intervene during boot.

18.2 Console sessions are not encrypted. Console access is intended for recovery and troubleshooting. Enable it when you need it and disable it when you are finished, and take that lack of encryption into account when deciding what to type into it.

18.3 Rescue and recovery media may be mounted through your control panel to boot a server into a recovery environment.

19. Snapshots and Backups — Different Things

19.1 A snapshot is not a backup. This distinction matters and clients are frequently caught by it.

19.2 Snapshots capture the state of your server at a point in time and are stored on or alongside the infrastructure hosting your server. They are intended for short-term rollback — before an upgrade, a configuration change, or a risky deployment. If the underlying infrastructure fails, your snapshots are affected too. Snapshot allowances and retention are stated in the Service Description.

19.3 Backups are stored separately from the infrastructure hosting your server and are designed to survive its failure.

Backups are an optional paid add-on, subscribed alongside your server and billed on the same cycle. Frequency, retention, and restore method are stated in the add-on’s Service Description.

If you cancel the backup add-on, backup creation stops immediately and existing backups are deleted at the end of the paid period. If your server is terminated, associated backups are deleted on the timeline in our Terms of Service. Retrieve anything you need before either happens.

19.4 If your data matters, take backups. Snapshots alone are not a disaster recovery strategy, and we will not be able to help you if the only copy of your data was a snapshot on failed infrastructure.

19.5 While a backup or snapshot operation is running on a server, power operations such as reboot, shutdown, reinstall, and rebuild may be temporarily unavailable until it completes. A minimum interval may also apply between manual backup or restore operations.

19.6 Section 12.3 and our Terms of Service apply equally here: backups and snapshots are a convenience, not a guarantee, and you remain responsible for your own independent copies.

20. Processor Allocation

20.1 Virtual servers are offered on shared-processor and dedicated-processor tiers. Which tier applies to your service is stated in its Service Description.

20.2 On a shared-processor tier, processor capacity is shared between servers on the same host. This suits typical workloads with variable demand, and it is what makes those tiers affordable. We plan capacity to keep shared hosts comfortably provisioned — we would rather run more hosts than degrade the ones we have — but sustained heavy use by one server still affects its neighbours.

20.3 Where a service on a shared-processor tier sustains near-full processor use over an extended period, we will contact you and recommend a dedicated-processor tier. Our first response is an appropriate product, not a restriction. Where sustained use is materially degrading service for others and cannot be resolved, Section 7 and the Acceptable Use Policy apply.

20.4 On a dedicated-processor tier, allocated processor capacity is reserved for your service.

21. IP Addresses

21.1 The IPv4 and IPv6 addresses included with your virtual server are as stated in its Service Description.

21.2 Additional IPv4 addresses may be available subject to availability, and we may require justification of need before allocating them, consistent with registry policy and responsible address stewardship.

21.3 All addresses we assign remain under our control. No ownership or portability is granted or implied, and we may reassign or renumber where operationally required. See our Acceptable Use Policy.

21.4 Reverse DNS. You may set reverse DNS records for addresses assigned to you through your control panel.

The hostname you set must have a forward DNS record already resolving to that address. This is not optional — mail systems check that the round trip matches, and a record that fails it will hurt your deliverability rather than help it.

Records must not be deceptive, must not impersonate another organization, and must not be offensive. We review reverse DNS records and may reset or remove any that do not meet this standard, without notice where the record is deceptive or offensive.

21.5 DNS for virtual servers. Authoritative DNS for your own domains is not included with a virtual server. You may run your own nameservers or use a third-party DNS provider.

22. Network

22.1 Basic protection. Our network applies basic protective measures, including null-routing addresses under attack where necessary to protect the wider network. Null-routing means traffic to the affected address is discarded, and your service is unreachable while it is in place. See our Terms of Service and Acceptable Use Policy.

22.2 Enhanced DDoS protection is available as an add-on where offered. Basic null-routing is not a mitigation service and should not be relied on as one.

22.3 Port speeds and bandwidth allowances are stated in the Service Description.

23. Host Migrations

23.1 We may move a virtual server between physical hosts for maintenance, hardware replacement, or capacity balancing. We will give notice where practicable, and may act without notice where an emergency or a hardware failure requires it.

23.2 A migration normally involves a short interruption. We aim to minimize it.

24. Suspension of a Virtual Server

24.1 Where a virtual server is suspended, it is powered off and your data is retained. It is not deleted until termination, on the timeline in our Terms of Service.

24.2 You may not have control panel access to a suspended server. Retrieve anything you need before a suspension becomes a termination.

Part 4 — SSL/TLS Certificates

25. What We Provide

25.1 We resell certificates issued by third-party certificate authorities. We are not a certificate authority. Domain Validated, Organization Validated, and Extended Validation certificates are offered, including wildcard and multi-domain options, as stated in the Service Description.

25.2 The issuing certificate authority’s Subscriber Agreement applies to you directly. Certificate authorities are required by the industry rules governing publicly-trusted certificates to obtain an executed subscriber agreement before issuance, and to ensure it is enforceable against the applicant. You must accept it, we cannot accept it for you, and we cannot vary it. It applies in addition to these terms.

25.3 Certificate authorities may decline to issue, and may revoke, at their discretion and in accordance with their own policies and the industry rules they operate under. We do not control those decisions.

26. Your Key, Your Responsibility

26.1 You generate your own private key and certificate signing request. We do not generate private keys for you, and we do not hold your private key material.

26.2 Protect your private key. A private key that has been disclosed to, or accessed by, anyone unauthorized is compromised.

26.3 If you suspect key compromise, tell us immediately at support@bit.foo. Under the rules governing publicly-trusted certificates, a certificate with a confirmed compromised key must be revoked within 24 hours. We cannot meet that timeline if you do not tell us promptly. Other circumstances requiring revocation — including evidence of misuse or inaccurate information in a certificate — carry a five-day requirement.

26.4 You must also tell us promptly if information in an issued certificate becomes inaccurate, or if you no longer control a domain named in one.

27. Validation

27.1 Issuance requires you to complete validation steps set by the certificate authority. These may include publishing a DNS record, placing a file on a web server, or responding to a verification email, and for organization and extended validation, providing business documentation.

27.2 You must complete validation promptly. Delay or failure to complete validation is the most common cause of a certificate not issuing, is not a fault in our service, and is not grounds for a refund.

27.3 CAA records. A Certification Authority Authorization record in your domain’s DNS can prevent a certificate authority from issuing. Check your CAA records if issuance fails unexpectedly.

27.4 Certificates cannot be issued for internal names, non-public hostnames, or private IP addresses.

28. Certificate Transparency — Your Domains Become Public

28.1 Publicly-trusted certificates are logged to Certificate Transparency logs, which are public, permanent, and searchable. This is mandatory under the rules governing publicly-trusted certificates and is not optional.

28.2 Every domain name included in a certificate is published. If you request a certificate for a hostname you consider confidential — an unreleased product, an internal-sounding subdomain, a client name — that hostname becomes publicly discoverable and cannot be removed.

28.3 A wildcard certificate publishes only the wildcard entry, which some clients prefer for this reason.

29. Installation, Reissuance, and Lifetime

29.1 Installation is your responsibility. Where we offer installation as a service, the fee is stated in the applicable Service Description. Installation on services or configurations we do not offer as a standard option may be quoted on request.

29.2 Reissuance is free and unlimited within the term of your certificate, subject to the certificate authority’s own requirements.

29.3 Certificate lifetimes are shortening. The maximum validity period for publicly-trusted certificates is being reduced in stages under industry rules, and will continue to fall. A multi-year certificate product is a prepaid entitlement to a series of shorter certificates, not a single certificate valid for the whole period. You will need to reissue during your term, and it is your responsibility to do so before expiry.

29.4 We will send renewal and expiry reminders to your account email address, but you are responsible for ensuring a valid certificate is installed and current.

30. Warranty and Termination

30.1 Certificates may carry a warranty from the issuing certificate authority. Any such warranty is the certificate authority’s, not ours, is subject to their terms and claims process, and we make no representation about it. Details are in the certificate authority’s documentation.

30.2 An issued certificate remains valid until it expires or the certificate authority revokes it. Terminating your Bitfoo services does not revoke it. We do not control revocation and do not undertake to revoke a certificate, and your obligations under Section 26 continue for as long as the certificate remains valid.

Part 5 — Announcing Your Own IP Address Space

31. Scope and Requirements

31.1 Where we agree to announce address space you hold, this Part applies in addition to our Acceptable Use Policy.

31.2 Minimum sizes. We announce a minimum of a /24 for IPv4 and a /48 for IPv6. Smaller prefixes are generally filtered by other networks and will not propagate reliably.

31.3 Before we announce, we require:

  • A Letter of Authorization naming Bitfoo and our autonomous system number, signed by the registered holder of the address space;

  • Verification of your holding against the relevant regional internet registry’s records;

  • A valid RPKI Route Origin Authorization authorizing our autonomous system number to originate the prefix; and

  • Appropriate internet routing registry objects for the prefix.

31.4 You must keep registry, RPKI, and routing registry records accurate and current for as long as we announce your space, and tell us before anything changes.

31.5 We may decline to announce any prefix, and may require additional verification.

32. Your Responsibilities

32.1 You may only ask us to announce address space you demonstrably control. Requesting announcement of space you are not authorized to announce is a serious violation of our Acceptable Use Policy and grounds for immediate termination without notice or refund.

32.2 You are responsible for abuse originating from your address space, and for its reputation. Where your space attracts abuse reports, blocklisting, or upstream complaints, we may cease announcing it.

32.3 Our Acceptable Use Policy applies in full to traffic to and from your space.

33. What We Do Not Guarantee

33.1 We control our announcement. We do not control whether other networks accept it. Propagation depends on upstream filtering policies, RPKI validation by third parties, routing registry data, and the configuration of networks we have no relationship with. We do not guarantee that your space will be reachable from any particular network.

33.2 We do not guarantee any particular routing path, latency, or performance for your space.

34. Ending an Announcement

34.1 Where you cancel or migrate away, we will agree a withdrawal date with you so that you can arrange alternative transit and avoid an outage. We would rather coordinate a clean transition than drop an announcement on a deadline.

34.2 Where we terminate for cause, or where continuing to announce would breach a legal obligation, expose us to liability, or damage our network’s reputation, we may withdraw the announcement immediately and without notice.

34.3 On withdrawal we will remove associated routing registry objects we created. Updating your own RPKI Route Origin Authorizations is your responsibility, and leaving one authorizing our autonomous system number after you have left may cause routing problems for you.

Part 6 — Reseller Hosting

35. What Reseller Hosting Is

35.1 Reseller hosting gives you a reseller account within our shared hosting platform, from which you create and manage hosting accounts for your own customers.

35.2 You control your reseller account through DirectAdmin. You create sub-accounts, set their resource allocations, and manage them yourself. We do not set allocations for your customers and do not manage your sub-accounts.

35.3 Reseller hosting may be offered by arrangement rather than as a listed product. Where it is, the specifics of your arrangement are as agreed in writing and stated in your Service Description.

35.4 Everything in Part 2 applies to your reseller account and to the accounts you create under it, including platform management and software versions (Section 11), backups (Section 12), email (Section 13), and suspension (Section 14).

36. Resources and Allocation

36.1 You buy a pool. Your reseller plan provides a total allocation of resources — storage, bandwidth, and any other limits stated in your Service Description. Sub-accounts you create draw on that pool.

36.2 You are billed for the pool, not per sub-account. How you divide it is your decision.

36.3 Over-allocation is your risk. You may allocate more to your sub-accounts in total than your pool actually contains, in the same way any host can. If your customers then use what you promised them, you will exhaust your pool, and the consequences fall on you and on them. We do not prevent this and are not responsible for it.

36.4 Where your pool is exhausted or exceeded, Section 7 applies. We will contact you and recommend a larger plan rather than restricting first, but sustained overuse may result in throttling.

37. Your Customers

37.1 Our Terms of Service and Acceptable Use Policy apply in full. You are responsible for your customers’ conduct as if it were your own, and you must maintain your own terms and acceptable use policy with them that are at least as protective as ours.

37.2 We have no relationship with your customers. We are not obliged to provide them support, accept instructions from them, or deal with them directly. Billing them, supporting them, and resolving their disputes are yours.

37.3 Suspension of your account suspends all of your customers. This follows from how the control panel works and cannot be applied selectively. If your reseller account is suspended — for non-payment, under the Acceptable Use Policy, or otherwise — every account beneath it goes down with it, including their websites, email, and databases.

Your customers will have no warning from us and no way to reach us. You should make sure your own terms tell them who to contact and what happens if your account lapses.

37.4 Where one of your customers violates our Acceptable Use Policy, we may act against that sub-account, against your reseller account as a whole, or both, at our discretion. Where the violation is contained and you are responsive, we would rather work with you than suspend everything.

37.5 On termination of your reseller account, data in all sub-accounts is deleted on the timeline in our Terms of Service. You are responsible for telling your customers and for giving them the opportunity to retrieve their data.

37.6 Contacting your customers. As a matter of practice we do not contact your customers. They are your relationships and we have no interest in interfering with them.

There is one exception. Where your reseller account is suspended, terminated, or abandoned, we may contact the customers whose services are affected to tell them what has happened, and we may offer them the opportunity to continue their service directly with us. We may do this whether or not you have been able to tell them yourself.

Doing so is not a breach of these terms and gives rise to no claim against us — including for interference with your business, loss of customers, loss of revenue, or loss of goodwill. Where a customer chooses to continue with us directly, that is a new relationship between them and us, and you have no interest in it.

We would always rather you resolved the situation and kept your customers. This exists so that people whose businesses are offline through no fault of their own have somewhere to go, not to compete with you.

37.7 You must not represent yourself as Bitfoo, as our agent, or as accredited by any body by which you are not accredited.

Contact

BITFOO LLC · 146 East King St, Unit #1283, Lancaster, PA 17602, United States

Support and service requests: support@bit.foo · Abuse: abuse@bit.foo · Legal: legal@bit.foo