Acceptable Use Policy
The short version: host websites, keep it legal, keep it yours, and don't make the platform worse for the people you're sharing it with. The longer version is below, written to be read rather than survived.
Last updated August 2026
Who this applies to
This Acceptable Use Policy (“AUP”) applies to everyone who uses a Rack1 Networks hosting account, including your customers, your colleagues and anyone you give access to. If you host sites on our platform on behalf of other people, you are responsible for what they do with the space you give them.
Most of it comes down to one principle: don't do anything that makes the platform worse for someone else. On our shared plans that also means using the account for hosting websites; on plans with resources reserved for you alone there is more room to move, and we say so where it matters.
If something you want to do isn't obviously covered here, ask us at support@rack1.net before you do it. We'd much rather have a two-minute conversation than a suspension.
Legal content only
You may only use your account for content and activity that is lawful in the United States and in any jurisdiction where your content is published or accessed. You must not use Rack1 Networks to store, publish, transmit or link to:
- Content that is illegal, or that promotes or facilitates illegal activity
- Child sexual abuse material, or any content sexualising minors. This results in immediate termination and a report to the appropriate authorities, with no notice and no refund
- Content that harasses, threatens, defames or incites violence against any person or group
- Malware, ransomware, exploit kits, phishing pages, credential-harvesting forms or fraudulent “lookalike” sites impersonating another business
- Content designed to deceive people into transferring money or handing over personal information
- Material that violates export controls, sanctions or other applicable trade regulations
We do not moderate accounts proactively and we are not in the business of policing opinions. We do act on credible reports, and we comply with lawful requests from competent authorities.
Content standards
Anything you publish must be accurate where it states facts, genuinely held where it states opinions, and lawful in the United States and in any country where it is published or accessed. In addition to the illegal material listed above, the following must not appear on our platform:
- Defamatory material about any person or organisation
- Obscene, offensive, hateful or deliberately inflammatory material
- Pornography and sexually explicit material
- Material that promotes violence, or promotes discrimination based on race, sex, religion, nationality, disability, sexual orientation or age
- Material that infringes copyright, database right or trade mark
- Material likely to deceive, or that misrepresents your identity or your affiliation with someone else
- Material that breaches a legal duty owed to a third party, such as a duty of confidence
- Material that threatens, abuses, invades privacy, or causes needless anxiety or inconvenience
- Material that gives the impression it comes from us when it does not
- Material that advocates, promotes or assists any unlawful act
We do not vet sites before they go live and we are not in the business of policing opinions. We act on credible reports, and on anything a competent authority requires us to act on.
Copyright and intellectual property
You must own, license or otherwise have authorisation for everything you publish. Specifically, you must not use your account to host or distribute:
- Copyrighted material of any kind, including software, films, music, books, images, fonts, courses and stock assets, unless you hold the rights or a licence that permits it
- Cracked, pirated or keygen-modified software, or tools whose purpose is circumventing licensing
- Counterfeit goods, or trade marks and branding you are not authorised to use
- Content that has been scraped wholesale from another site and republished as your own
We respond to properly formed copyright complaints. Send notices to abuse@rack1.net with enough detail to identify the material, the work it infringes, and your authority to act. We will pass complaints on to the account holder and may remove content or suspend an account where a complaint is credible and unresolved.
What your storage is for
On our shared platform plans, which means Static, Basic Shared, Accelerated and WordPress Optimized, your storage allocation is for files that are part of a website you are serving from your account: pages, templates, images, downloads your visitors actually download, databases, email and the backups we take for you.
On those plans it is not general-purpose cloud storage, and the following are not permitted:
- Using your account as a backup target, file archive, sync destination or personal cloud drive
- Storing media libraries, disk images, virtual machine images or archives that aren't served by your website
- Storing content for a site hosted somewhere else, or hot-linking your Rack1 storage from an external platform to avoid paying for that platform's storage or bandwidth
- Bulk storage of content that no visitor ever requests
- Files that are neither reachable over the web nor required for your site to function. Material stored outside your web root, or otherwise hidden from visitors, may be removed without notice
The reasoning is straightforward: on a shared platform, storage that isn't serving websites still consumes disk, backup capacity and I/O that other customers' sites need. Keeping non-website data off those plans is part of how we keep them fast and priced the way they are.
This does not apply to plans with resources reserved for your account alone, such as Managed Cloud when it launches. On those plans there is no shared pool to protect, so you may use the storage for general file storage, bulk uploads of content unrelated to a website, and archival or backup data, within the storage and bandwidth allowance published on your plan.
The rest of this policy still applies on every plan, including those ones. In particular, whatever you store must be lawful and yours to store, you may not resell or sub-divide the space to third parties, and you may not operate a public file-sharing, file-dropping, torrent-seeding or paste service from it.
No reselling or sub-dividing
Your plan is for hosting your own sites and sites you manage on behalf of clients. You must not:
- Sub-divide your storage, bandwidth, databases, mailboxes or other allocations and sell, rent or otherwise supply them to third parties as a hosting service
- Offer accounts, control panel access, FTP/SFTP accounts or web space to the public, whether paid or free
- Operate a “free hosting”, shell, tunnelling, proxy or VPN service from your account
- Resell email accounts or use your mailbox allocation as a mail service for unrelated third parties
To be clear about what is fine: hosting websites you build and manage for your clients is absolutely permitted and is exactly what our larger plans are for. Building sites for clients is a normal business. Selling raw hosting allocation out of your account is not.
Resource use and abusive scripts
Our platform is shared, and Rack1 Burst exists precisely so that legitimate traffic spikes are handled automatically rather than punished. What we do act on is code and behaviour that consumes resources disproportionately or harms other customers. You must not run:
- Scripts that consume excessive CPU, memory, disk I/O or database capacity on a sustained basis, including runaway loops, unbounded recursion and badly written cron jobs
- Sustained use of a disproportionate share of a shared server. As a working guide, more than 10% of a server's processing capacity held continuously is disproportionate. Short spikes are what Rack1 Burst is for and are not what this rule is aimed at
- Unattended server processes, persistent background daemons or long-running listeners
- Web spiders, crawlers, indexers or automated scraping tooling
- IRC servers, bouncers or bots
- BitTorrent clients, trackers, seedboxes or any peer-to-peer file-sharing system
- Game servers and voice servers
- Proxy sites, anonymisers, tunnelling or VPN services
- Remote file-hosting services, file-dropping sites or paste services
- Self-hosted cloud storage and sync platforms, such as ownCloud, Nextcloud, Pydio or SparkleShare
- Scheduled tasks set up outside the control panel, or scheduled to run more often than the panel permits
- Cryptocurrency mining, distributed computing clients, or any workload whose purpose is consuming compute rather than serving a website
- Brute-force tooling, port scanners, packet floods, stress-testing tools or anything designed to probe or overwhelm a third party
- Software with known unpatched security vulnerabilities, including out-of-date WordPress cores, themes and plugins, where those vulnerabilities are being actively exploited
Where a script is simply inefficient rather than malicious, our first step is normally an email explaining what we're seeing and what would fix it. Where an account is actively degrading the platform or attacking someone else, we may suspend first and explain afterwards.
Rack1 Burst allocates additional compute during genuine traffic spikes at no extra cost. It is not a licence to run permanently oversized workloads on an undersized plan, and it does not change the bandwidth allowance published on your plan.
Email, spam and messaging
Unsolicited bulk email is prohibited without exception, whether it is sent through our mail servers, through a script on your account, or from elsewhere while advertising a site hosted with us. You must not:
- Send unsolicited bulk or commercial email, SMS or messages of any kind
- Mail to purchased, harvested, scraped or otherwise non-consenting lists
- Forge headers, spoof sender addresses or disguise the origin of a message
- Operate open relays, open proxies or unsecured mail forms that third parties can abuse
- Run mailing lists without a working unsubscribe mechanism and a record of consent
- Send mail advertising a site hosted on our platform from any other provider in a way that violates that provider's rules (“spamvertising”)
Sending volume is subject to reasonable rate limits to protect platform deliverability for everyone. If you're planning a large legitimate campaign, use a dedicated bulk email provider. It's better for your deliverability as well as ours.
We operate a zero-tolerance policy on unsolicited bulk email. An account found sending it may be suspended or terminated immediately and without notice. If your activity causes any of our IP addresses or mail servers to be added to a blocklist, we may pass on the reasonable costs of getting them removed, and the account will stay suspended until the problem is resolved.
Security and your responsibilities
You are responsible for the security of your own site and credentials:
- Keep applications, themes, plugins and dependencies updated. Our WordPress plans include staging environments so you can test updates before they go live
- Use strong, unique passwords and don't share account credentials
- Don't attempt to access another customer's account, data or processes, or probe the platform for vulnerabilities without our written permission
- Don't attempt to circumvent resource limits, quotas, security controls or account isolation
- Tell us promptly at support@rack1.net if you believe your account has been compromised
If a site on your account is compromised and is being used to attack, defraud or spam others, we may suspend it to stop the harm and then work with you to clean it up.
Bandwidth and fair use
Every plan has a published monthly bandwidth allowance, printed on its plan page. That figure covers content delivered to your visitors, including content served from our edge network.
Static, Basic Shared, Accelerated and WordPress Optimized
If your site has a good month and goes a little over, we will do our best to absorb it. We do not believe in punishing customers for their site doing well, and a spike in traffic is usually good news rather than a billing event.
- Minor or occasional excesses are absorbed at our discretion and at no charge to you
- If the excess becomes substantial or persistent, we will contact you first
- Where additional bandwidth is charged, it will be at a rate not exceeding $0.10 per GB
- In most cases a larger plan costs less than the overage would, and we will tell you when that is true rather than quietly billing you
Plans with reserved resources
Plans that reserve resources for your account alone, such as Managed Cloud when it launches, do not get the discretionary absorption above. Bandwidth used beyond the monthly allowance on those plans is billed at a flat $0.10 per GB.
On every plan
- $0.10 per GB is the only bandwidth charge there is. There is no multiplier, no premium tier of traffic and no separate charge for content served from the edge
- We will always contact you before charging for bandwidth, and you will always have the option to move to a plan that fits instead
- Bandwidth consumed by activity prohibited elsewhere in this policy, such as file distribution, hot-linked external storage or abusive scripts, is not fair use and may be restricted immediately rather than billed
How we enforce this
Our strong preference is always to talk to you first. In practice that means:
- We contact you. For most issues, such as an inefficient script, storage being used the wrong way or an out-of-date plugin, you'll get an email explaining what we're seeing and what needs to change, with a reasonable window to fix it.
- We may restrict narrowly. If something is actively harming the platform or others, we may limit or disable the specific script, process or site involved while we sort it out with you.
- We may suspend. For serious or unresolved violations, or where content is clearly illegal, the account may be suspended.
- We may terminate. For severe violations such as child sexual abuse material, fraud, phishing, attacks on third parties or repeated breaches, the account may be terminated immediately without refund.
Alongside those steps we may also remove or edit the offending material, issue a formal warning, disclose your identity and other information to law enforcement or another competent authority where the law requires or permits it, and take legal proceedings to recover the reasonable costs we incur as a result of the breach.
Failure to comply with this policy is a material breach of our Terms of Service. We decide whether a breach has occurred, and we will explain our reasoning if you ask.
Reporting abuse
To report content or activity on our platform that you believe breaches this policy, email abuse@rack1.net. Please include:
- The full URL or domain concerned
- What you believe the violation is
- Any relevant evidence: email headers, log excerpts, timestamps with time zone, screenshots
- How we can contact you if we need more information
We review every report we receive. We may pass the substance of your report on to the account holder in order to resolve it.
Changes to this policy
We may update this policy as the platform, the law or the abuse landscape changes. Material changes will be posted here with an updated date, and where the change meaningfully affects how you use your account we'll let existing customers know by email.
This policy forms part of our Terms of Service.
Questions about any of this?
We'd rather explain a policy than enforce one you didn't understand. Ask us.