← All guides

What does my hosting provider store about website visitors?

Even if PHP or a CMS does not store an IP, web servers, reverse proxy, WAF, DDoS protection or the host may keep their own logs. This processing may serve a legitimate security purpose. For “We don’t save!” The type of data, purpose, access and retention period are therefore documented separately for each level.

Check

Ask the host specifically about access, security, proxy and DDoS logs as well as their retention periods and document the information.

Principle

“We don’t save!” does not evaluate whether an IP address becomes visible during technical communication, but rather whether this results in unnecessary persistent storage, recognition or sharing.

Related guides

Sources and verification

This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.

Important: IP processing is not IP storage

An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.

↑