A client emails at nine on a Monday to say their site is down. It is down because your provider suspended it at three in the morning, after a compromised contact form spent the night sending forty thousand emails.
You have ten minutes to decide three things. Whether you can keep the site offline while you clean it up. Whether you can charge for the hours it takes. And what you owe this client for the outage. All three are answerable in seconds if your terms exist, and arguable for weeks if they don’t.
That is what this page is for: three short documents — service terms, an acceptable use policy, an exit policy — most of whose content isn’t yours to invent. It is decided by the account you already bought. How to start a reseller hosting business is the whole picture; this is the paperwork chapter, and it takes an afternoon.
If you already have something in writing — a retainer, a proposal, a contract — this is about what to add, not what to replace (should web designers resell hosting to their clients is the wider version of that question). If you have nothing, read straight through. If you’re still working out what you’ve bought, what is reseller hosting comes first.
Table of Contents
- The short answer: three documents, one afternoon
- Why terms matter more for a small host than a big one
- The rule that shapes everything: you can’t promise more than you’re given
- Your terms of service, clause by clause
- Your acceptable use policy
- Suspension and termination: the section you’ll actually use
- What happens when they leave
- Backups: the promise to get right
- Data protection and the client who sends you a DPA
- Making it stick: acceptance, versions and changes
- Do you need a lawyer?
- Mistakes worth avoiding
- Frequently asked questions
The short answer: three documents, one afternoon
- You need three things in writing: service terms (what you do, what it costs, how it ends), an acceptable use policy (what may not go on the server), and an exit policy (what your client gets back, and when). They can live on one page under three headings.
- Most of the acceptable use policy isn’t yours to write. Your provider has already decided what can run on the account. Your job is to pass that down accurately, and add anything you personally won’t host.
- Never promise more than your provider promises you — on uptime, on backups, on support hours, on resources.
- The clause you will use most is suspension. Write one you will actually use, then use it.
- Two pages beats twenty. A document you have read and will apply beats a template you haven’t.
Some of this can wait a fortnight. If your only hosted site is your own, write it before client two rather than tonight; and if you bill hosting inside a retainer you may not need a separate document at all, since a schedule added to the agreement you have can do the job — hosting inside a retainer or billed separately sets out what it has to settle.
Two things can’t wait at any number of clients: knowing what your provider forbids, and being able to take a backup yourself.
Why terms matter more for a small host than a big one
A large provider’s terms are written to survive tens of thousands of customers and the disputes that come with them. Yours are written for one person deciding alone, at speed, usually about someone they know and would rather not upset. That is why copying theirs fits so badly — and why your document’s real job is to have made those decisions before the moment arrives.
The four moments your terms exist for
| The moment | What you have to answer in minutes | The clause that answers it |
|---|---|---|
| A client stops paying | How long before I suspend, and does anything get deleted? | Payment, suspension, data retention |
| A client’s site does something your provider won’t tolerate | Can I take it down right now, without asking them first? | Acceptable use, immediate suspension |
| A client wants to leave | What do I hand over, how fast, and at what cost? | Exit policy |
| A client asks for something you never agreed to | Is that included? | Scope, support expectations, entitlements |
Now the part the template sellers leave out. Terms are not armour. A client determined to argue will argue. What a document reliably does is stop you improvising under pressure — and improvising is how a small host ends up refunding a month, restoring a backup they never promised, and losing the client anyway.
Your real protection is four things: choosing clients carefully, being able to take a backup, making sure the client owns their domain, and having read the rules of the account you resell. Paperwork is one of the four, not a substitute for the other three.
The rule that shapes everything: you can’t promise more than you’re given
As a reseller you sit between two agreements: you accepted one when you bought the plan, and you are about to write the other. If the second is more generous than the first, you are personally funding the difference.
This is not a technicality. At every reseller provider, the account holder is responsible for what their clients do: the provider has a contract with you and no relationship with them. Resource warnings, abuse notices and suspension notices arrive in your inbox. Cleanup fees, where they exist, are billed to you. And the rules about what may run on the account apply to every cPanel account you create, whether or not the person renting it has heard of them.
Providers say this plainly in their own documents. ChemiCloud’s policies put it about as directly as it can be put: for resold accounts, the reseller is the one contacted, and the reseller is responsible for working with their customer to resolve the problem. Worth reading not because it is unusual — it isn’t — but because it is the document your own terms have to match, and it takes ten minutes.
Nobody will check that you have written anything. Most providers, ChemiCloud included, leave it entirely up to you — and then hold you responsible when something happens. That is the argument for writing the documents, not against it.

The pass-through check
Open your provider’s terms, resource policy and backup section, put a blank page beside them, and work down this table before writing a word of your own.
| What your provider has already decided | Where to look | What your terms have to say |
|---|---|---|
| Prohibited content and activities | Terms of service, acceptable use | At least as restrictive. You may be stricter, never looser |
| Categories not permitted on reseller plans at all | Acceptable use, high-risk or regulated sections | Name them — and decline those clients before they sign |
| Outbound email sending limits | Resource or fair-use policy | The real numbers, per domain, per hour and per day |
| Per-account CPU, memory, process and inode limits | Resource policy | What “unlimited” does and doesn’t mean on your plans |
| Mailing list size and throttling rules | Resource policy | Whether you allow lists at all, and how big |
| Backup commitment (usually none) | Backups section | Never more than you receive |
| Uptime commitment and its remedy | Service agreement, SLA | Never better than the one above you |
| Non-payment: grace period, suspension, termination | Billing section | Your own ladder, finishing before theirs does |
| Notice they give you before changing their terms | Modifications clause | Your own change clause, at least as long |
An hour of reading settles most of what your documents need to say, and almost nobody does it first.
The SLA you can actually fund
This is where small hosts over-promise most often, usually because a prospect asked and a number sounded reassuring. Whatever uptime your provider commits to is your ceiling, not your floor. You are reselling their availability plus your own response time — and yours is worse than theirs, because you sleep.
Then look at the remedy upstream. It is almost always a service credit — free months of hosting — rather than cash, and usually has to be claimed inside a short window with evidence. Offer a client a cash refund for downtime and you are paying for it yourself, out of a margin never designed to carry it.
The shape that works for a one-person host is a target plus a commitment you control: the availability your provider commits to, and a promise about how fast the client hears from you and through which channel. That is worth more to them than a percentage they cannot verify. Handling downtime with a communication plan covers the part they actually judge you on.
Your terms of service, clause by clause
The checklist
This is the standalone version. If your hosting sits inside a retainer, the retainer article above covers the same ground from the other direction — you want one system, not two documents contradicting each other.
| Clause | What it settles |
|---|---|
| Who the parties are | That you are contracting as a business, whatever its size |
| What the service is | The plan, the resources, what’s included beyond the hosting |
| What isn’t included | Site changes, plugin work, content, third-party fees — the most argued-about line in the document |
| Price, billing cycle, renewal | When money moves, and what happens automatically |
| Price changes | That prices can change, with notice, at renewal |
| Late payment and suspension | The ladder: reminder, suspension, termination |
| Support expectations | Hours, channels, and a response time you can hold in a bad week |
| Availability | A target and a communication commitment, not a guarantee |
| Acceptable use | Incorporated by reference, or attached |
| Client responsibilities | Current contact details, software they install, their own users |
| Backups and restores | What you do, what you don’t, what a restore costs |
| Domain ownership | That the domain is theirs, registered in their name |
| Data and privacy | Where data sits and who else touches it |
| Notice periods, both directions | How either of you ends it |
| What happens at the end | Export window, format, cost, deletion date |
| Changes to these terms | How you notify, and when a change takes effect |
| Limits on what you’re liable for | The paragraph to have checked by someone qualified |
Four rows depend on decisions made elsewhere. The number in the price row comes from how to price reseller hosting plans. The price-change wording has a whole article behind it: raising hosting prices on existing clients. The entitlements in “what the service is” must match your published plans exactly — the trap in how many hosting tiers you should offer. And the support response time should come from what hosting support load actually looks like, not from optimism.
The four clauses small hosts leave out and regret
The immediate-suspension clause. Everything else in your terms is about notice periods. This one is the exception: the right to take a site offline with no warning when your provider demands it, when the site is attacking someone, or when it is serving malware. Without it you choose between breaching your own terms and losing the account. When a client site gets compromised is what happens next.
The cost-recovery clause. When a client’s site causes work you didn’t sell — a cleanup, an emergency migration, a day of abuse correspondence — nothing in a template lets you bill for it. State an hourly rate for work caused by a breach of these terms; what you can actually make reselling hosting is a fair check on what that hour is worth. You will rarely charge it, and it changes the conversation every time you mention it.
The contact-details clause. Sounds like filler. Quota warnings, abuse notices and suspension notices land on the address attached to the account, and your ability to act depends on reaching your client within hours. Make keeping a working address their obligation, and say what you may do when you can’t reach them.
The client-resale clause. Whether your client may host other people’s sites on the account they rent. Most small hosts never consider it, and the answer is almost always no: one client quietly reselling turns a book you understand into one you don’t. Your own version of that question is overselling and when it’s defensible.
Your acceptable use policy
Keep it separate, incorporated by reference. Your service terms are stable; your acceptable use policy changes whenever your provider’s rules do, and you want to update it without reopening the contract.
What your provider won’t allow anywhere
These are not matters of taste. Lists vary between providers, so check your own rather than trusting this one, but on shared and reseller infrastructure they usually cover:
- Anything unlawful — with the provider as sole judge of what qualifies. You inherit that judgement.
- Phishing, fraud and malware distribution, plus the categories every provider terminates immediately and without notice.
- Spam in all its forms, including advertising a hosted site with mail sent from somewhere else.
- Mining, torrents and file-sharing, public proxies and anonymising relays, game servers, and using an account as storage detached from a real website.
- Whole industries that shared and reseller infrastructure excludes and routes to a VPS or dedicated server with prior approval — adult content, gambling, forex, online pharmacies, escort services, crypto sites, self-hosted chat platforms.
That last group is a sales qualification list as much as a policy list: a client in one of those categories can’t go on a reseller plan at all, so you need to know before the proposal, not after the migration.
The technical limits your clients will actually hit
In rough order of how often they generate a ticket: outbound email sending caps, per domain and per hour; mailing list size limits and throttling rules; inode counts, the limit nobody has heard of and the reason a ten-year mail archive breaks a backup; database size and query guidelines; per-account CPU, memory and process limits; and minimum intervals between cron jobs. Fill in your provider’s numbers — don’t invent them and don’t copy someone else’s.
One point to make plainly, because it causes the worst arguments: these limits apply per hosted account, not to your plan as a whole. “Unlimited” describes how your provider bills you, not what one site can consume. Selling unlimited plans over an account with published per-site ceilings is the entitlement trap from how many hosting tiers you should offer, arriving in legal form.
What you additionally choose not to host
This is the discretionary part, and you are allowed to be stricter than your provider: stacks you can’t support, applications you don’t know, businesses whose support load you can’t carry, anything that would leave you arbitrating somebody else’s content.
Writing it down in advance is what makes a refusal professional rather than personal. You are allowed to decline a client; this is where you explain why, before it comes up.
Suspension and termination: the section you’ll actually use
Write it as a ladder, and arrange yours to finish before your provider’s does — their termination date is a cliff, and you want the account suspended with data intact when it arrives, not deleted.
Non-payment. Reminder, grace period, suspension with everything preserved, and a stated period before deletion. That is the clause; the process — the sequence, the tone, the conversation with someone whose business is on that site — is non-payment, suspensions and getting paid.
Breach of acceptable use. Notice, and a window to fix it, for anything that isn’t urgent.
Immediate, no notice. The short list from your provider’s rules, and it exists because your provider will act with or without you.
Two things to spell out. Say what happens to the data at each stage — the difference between suspended and deleted is the whole of your client’s anxiety, and answering it in advance removes a panicked phone call. And note that suspended accounts are often excluded from provider backups, so a long suspension can quietly destroy the restore point you were counting on: backups, and who’s responsible when a client deletes their site.
How this plays out upstream is better news than most people expect. When one hosted site becomes an abuse problem, providers generally suspend that single cPanel account rather than your whole plan, and the normal sequence is to notify you first and ask you to fix it. The blast radius is one client, and you get a window before anyone else acts.
That window is measured in hours, and using it depends on two clauses above: the right to act on the site immediately, and a contact method that reaches your client the same morning. Without them you spend the window asking permission — which is the clearest illustration of why this paperwork is operational rather than legal.
One awkward last thing: a suspension clause you won’t use is worse than no clause, because the first time you enforce it your client can point at every time you didn’t. If you’d never suspend a friend’s site over one late invoice, write what you will actually do instead.
What happens when they leave
Hosting inside a retainer or billed separately covers the three endings a hosted client can have and the transfer-out policy you write once and use forever; telling existing clients you’re taking over their hosting covers when to say it. What goes in the document is this:
- Notice period, both directions.
- What they receive — a full account backup any host can restore, including mail and databases. Name the kind of archive, not a product.
- How fast, in business days.
- What it costs. Free is cleanest and is worth more as a sales asset than it costs you. If you charge for hands-on migration help, the figure belongs here, not in the invoice that follows the request.
- How long the account stays live after notice, and the date the data is deleted.
- Who holds the domain — and it should be them, registered in their name. This is the single most common cause of an ugly ending.
- What you don’t hand over: your WHM, your reseller account, your tooling, and anything belonging to your other clients.
Performing the handover is a separate job from owing it — migrating client sites without downtime covers the mechanics, in both directions.
Volunteering all of this before anyone asks is a sales move, not a concession. The strongest objection to depending on one small supplier is the fear of being stuck, and this is the page a careful client actually reads before signing. Finding your first hosting clients makes the same argument from the sales side.
Backups: the promise to get right
Read what your provider commits to before you write a word of this. Provider backups are commonly described as existing for the provider’s own administrative purposes, explicitly not guaranteed, with the customer responsible for keeping their own copies. If you haven’t read that sentence in your provider’s terms, you are about to promise something somebody else has disclaimed.
Then write what you will do, in your own words, and make it something you control. Your own copies on a schedule you set, a paid backup add-on, or saying plainly that backups are the client’s responsibility and offering to help — all three are defensible. A guarantee resting on a system you don’t own is not.
Say what a restore costs and how long it takes, including whether the monthly price covers it. That request always arrives on the worst possible morning, which is not when you want to be inventing a policy.
Data protection and the client who sends you a DPA
Hosting someone’s website means holding data belonging to their customers, which is not the same as holding your client’s own files. Your terms should say where data is stored and who else has access to it — including, plainly, that the infrastructure comes from a named upstream provider.
Business clients, particularly in regulated fields, may send you a data processing agreement to sign. This is routine and not an accusation. Look first for your provider’s own: most publish one, and some cover resellers’ end clients as well as direct customers, which may already handle the infrastructure layer for you.
Worth checking rather than concluding: where the servers are, what your provider publishes about data handling, and whether anything in your own terms contradicts it. What the rules require of you specifically depends on where you and your clients are — a question for someone qualified rather than for this page.
Making it stick: acceptance, versions and changes
How agreement happens. In practice: a checkbox at signup, a link in the proposal, or a reply to an email. What matters more than the method is being able to show which version your client agreed to and when. Billing systems record that at order time, which is one of the quieter reasons to stop invoicing by hand eventually — WHMCS vs Blesta covers that decision.
Versioning. Date the document, number the version, keep the old ones. A one-line change log at the bottom costs nothing and settles arguments that would otherwise go nowhere.
The change clause. Your terms will change for two reasons: your business changes, and your provider’s change underneath you — usually with notice, by email or a posted announcement. Give your clients at least as much notice as you get, or you spend that gap stuck between two documents.
Where they live. A public URL, linked from your invoices and signup page — not a PDF attached to one email in 2024. If you run white-label, this is one of the places your own brand has to be consistent; white-label hosting covers where those seams show.
Do you need a lawyer?
For most small hosts the sensible split is this. Write the operational parts yourself — service description, price, support expectations, acceptable use, suspension, exit terms — because they encode decisions only you can make, and a lawyer would only ask you what you want them to say.
Then have the liability, warranty and dispute sections looked at by someone qualified where you are. That is where a confidently wrong sentence gets expensive, and where the right wording genuinely depends on your jurisdiction.
Four situations justify more than ten minutes of somebody’s time: clients who are consumers rather than businesses; clients in regulated industries; contracts big enough that a dispute would be worth someone’s while; and any client who sends you their own contract to sign.
A review of a short document costs less than most people expect, and far less than the first argument it prevents. This article describes what these documents usually contain and why — it isn’t legal advice, and the sections named above are the ones worth paying for.
Mistakes worth avoiding
- Copying another host’s terms without reading your own provider’s.
- Promising uptime, backups or support hours you don’t control.
- Describing plans as unlimited in your sales copy and limited in your terms.
- Writing a suspension clause you know you won’t use.
- Leaving the client’s domain registered in your name.
- No right of immediate suspension, so you breach your own terms to comply with your provider’s.
- Twenty pages for four clients — or a document nobody has read, including you.
- Terms that exist only as an attachment in an old email.
- Never updating them after your provider updated theirs.
Frequently asked questions
Do I legally need terms of service to resell hosting? Some providers require resellers to have their own client terms as a condition of the plan. Many don’t — but all of them hold you responsible for what your clients do. Nobody may be checking, and without terms you still have no stated basis to suspend an account, charge for a cleanup, or limit what you owe. Whether a law requires it depends on where you and your clients are.
Can I just copy another host’s terms of service? No, for a practical reason before a legal one: the parts that matter most are set by the account you bought, and they differ between providers. Copy someone else’s and you inherit their sending limits, prohibited categories and backup position, none of which describe your account. It is also someone else’s document.
What’s the difference between terms of service and an acceptable use policy? The terms are the deal; the acceptable use policy is the rules for what goes on the server. Keep them separate so you can update the second when your provider changes theirs, without reopening the first.
What uptime should I promise my hosting clients? Not more than your provider promises you. A target plus a response-time commitment you control is more honest, more useful and cheaper than a guaranteed percentage with a refund attached — the refund would come out of your own margin.
Your terms now say what happens when it ends. The next question is what “it” is: whether hosting sits inside a retainer or is billed separately, and which of the three endings a client actually gets. Hosting inside a retainer vs billed separately works through that, and it’s where the exit clauses above get used.
One thing worth checking before you commit to a provider: what you can promise your clients is bounded by what they promise you. Their acceptable use rules, their backup language and the notice they give before changing terms matter more than the headline rate.
Read those before signing up for a reseller hosting plan, not after your first client asks a question you can’t answer.


