Web Shopping Systems Logo
21st golden anniversary
Hacking Websites Security – How to Fix & Prevent 3

Hacking Websites Security – How to Fix & Prevent 3





Hacking Websites: DDoS Attack

Distributed Denial of Service (DDoS) is associated with brute force attacks and other attack types so that log data becomes impractical amid investigations. Typically, hacking websites with DDoS attacks is not to attain entry but to disable the web site and/or web server.

Hacking websites denial of service attack imageFor instance, an attacker can directly hit your application barrier by flooding your website with an excessive number of requests, more than the server can handle. This can cause your website to be inaccessible. Furthermore, a Layer 7 assault can impose even more harm with constant polling data that contain fraudulent transactions.

How to Avoid DDoS Attack

It is almost unfeasible to shield from such an attack with standard means. In this scenario, there are no security issues being utilized. These requests are not malevolent. With more requests, it is a challenge to tell the difference between real requests and ill-intentioned ones.

Your options are limited if you cannot use a DDoS protection service, and they are different with each case. Taking in all the traffic by expanding network and server resources to harbor all the extra traffic until the attack lessens or can be isolated is your best option.

An attack on your website is bound to happen sooner or later. Approaching situations carefully and using sensible measures can protect you when it involves problems with internet security. Be sure to have an adequate restoration plan for complete compromise or absolute loss.



Hacking Websites: Spam and Phishing

Unsolicited email messages, or spam, is an old but relevant security issue. Spam has been around almost since the internet was started. Today, people regularly get these unsolicited emails in their email inboxes. Email spoofing is another form of SPAM. This gives the spammer the opportunity to send their own emails from your inbox. This can cause harm to your domain’s email reputation – which then leads to an immediate blacklisting. You will also receive error messages for each spoofed email..

Hacking Websites Security Phishing Attack ImagePhishing is different. Hackers send emails that look like they’re from a known organization. They try to trick the recipient into clicking on a link in the email – which can cause damage all by itself. The link usually takes you to a fake web page designed to look like a legitimate website. The spammers hope that you will fill out forms that will give them your personal information so they can steal your identity or log into your existing accounts.

How to Avoid SPAM and Phishing

Do not trust unsolicited emails. You should make it a habit not to click on links in unsolicited email. Most email software will show you the real link URL simply by hovering over the link without clicking. Never trust email attachments in unsolicited email. You should check attached files with your antivirous software before opening.




Hacking Websites: Virus Infection and Malware

Hacking websites with various types of malwareWhen hacking websites, malware is sometimes used to gather information about websites and their vulnerabilities. Malware is a shortened version of malicious software. Malware placed in a workstation can encode information for ransomware purposes, and it can even record keystrokes to seize passwords. Generally, hackers will use malware to extend entry to your website or give entry to others on the same system.

It is imperative to discover which internet security issue caused a breach before any malware sanitization or recovery.

How to Avoid Malware

On workstations, be cautious about what you download. Utilize antivirus software to locate and carefully eradicate malware. Maintain antivirus applications with updates and patches as indicated by the manufacturer. Users should not have administrative entry. Preserve backups to reinstate the workstation if compromised.




Hacking Websites: Data Breach

A data breach is unauthorized access to information on a computer system. The unauthorized user could’ve gained access through one of many routes. They could have an administrators login credentials, they could’ve found an unknown weakness in your system that allows access to users, they can hack the web server and create their own login. They can hack an insecure web form and have the database supply access information.

It is possible for a hacker to have access to your system and leave few to no signs that they’ve visited your server. The “good” hackers will know that secrecy is key and it allows them to steal information indefinitely.

How to Avoid a Data Breach

Hacking websites, at this stage, is usually performed by hackers that are quite skilled at maintaining stealth. It can be very difficult to address this security issue. A number of systems will automatically record session data from your prior visit. Check this data when available and be aware of activity that is unfamiliar.

Open-source applications and mainstream content management operations provide access alerts automatically or via plugins. Other plugins automatically process the monitoring of your website data for any new inclusions or changes. If you use these tools often, you can notice malicious activity. Discovering issues early gives you the opportunity to prevent data breach.



Hacking Websites: Ransomware Attack

Hacking websites with a ransomware attack is designed to obtain absolute control of vital information on your computer systems. The objective of a ransomware attack is to maintain control of your data until you pay for the key that will give you the ability to recover your data. Hacking Websites Security Ransomware Attack imageThey then demand payment in exchange for the decoding key you need to access the files. The hacker often downloads your data and threatens to publicize important information if you do not comply with their demands.

How to Survive a Ransomware Attack

Backups are the answer to this problem. Frequent backups of the entire website as well as incremental database backups will keep you from falling victim to this attack. Be sure to keep your backups in a location separate from the web server. iThemes BackupBuddy can help you create incremental and full backups quickly and easily. WebShoppingSystems.com Fully Managed WordPress Hosting includes BackupBuddy as part of its Perfect WordPress System.



Hacking Website Security – How to Fix & Prevent 2

Hacking Website Security – How to Fix & Prevent 2





When Do You Have A Website Security Problem?

When you have issues with the security in your systems, it means that your systems are vulnerable and at risk. Anything in your system can have vulnerabilities, and hackers can exploit this to inflict harm to data or systems. For example, there could be a vulnerability in the software, servers, or your customers’ private information. Website security to stop hackingEven if a hacker has not taken advantage of a vulnerability in your system, the vulnerability still exists and can allow an attack to occur. If there is a problem with the security in your systems, it should be addressed immediately. Website security breaches are inevitable, so it is important to put forth effort to find these vulnerabilities.

The links at the top of this page identify the most common types of hacking and website security problems.  Visit any link above to learn about hacking and how to protect your website, data and business reputation against hacking. To get information about the security of your website visit the free website security checker at Sucuri. Only a full website security audit will give you the most information about potential problems with your website.



Website Security: Authentication Issues and Weak Passwords

Basic website security demands that every password should be complex and have an adequate length. At minimum, a secure password should contain 18 characters – the longer it is, the better. While complexity is good, password length enhances security. A good password includes upper case and lower case letters, numbers, and symbols. Your password should not use the same character consecutively more than two times.

Website security authentication

How to Avoid Authentication Issues

Wherever available, make use of two-factor authentication. Doing so can protect a login even if the true password is retrieved or guessed. On top of that, change your passwords often. Do this every sixty or ninety days. Never use the same password or the username as a password.



Website Security: No Backups

Having a restoration plan in place if a total loss occurs is paramount to website security. Do frequent backups and maintain sufficient backup retention policies to ensure this. Back Ups are often the easiest way to restore your website after a malicious attack.

How to Prevent Lack of Back Ups

Every situation will warrant a different solution. Listed below are three backup best practices.

Retention: Preserve as many past backups as you can in the event that a website is compromised. The more backups you have, the better. It is a good practice to store your back ups away from the live server. If the live server is hacked, you won’t run the risk of losing your back ups in the hack.

Scope: Ensure that the backups are sufficient enough to recover all aspects of your website.

Scheduling: Have an adequate backup schedule. It will frequently record backups to stay up to date, but not so often that it negatively affects website function.



Website Security: Insider Threat

As discussed in social engineering, you cannot depend on your ability to judge a person’s character to maintain your protection. Treachery can come from within. An attacker can be anyone you consider to be trustworthy – like an employee. They can inflict severe damage to your organization.

How to Avoid Insider Threat

Other than running background checks on employees, you can also limit users’ access inside the company – and provide only the minimum level of access to accomplish tasks given.

An ill-natured insider wants to remain unknown. Create precise logins for each employee with the relevant authorizations necessary to complete their duties. Dispose of these logins when it is no longer needed.

It should be mandatory for staff to stay up to date with the most efficient security practices. Unattended workstations in your office should remain locked with a secure password.



Website Security: Not Updating or Patching Frequently

Outdated and unpatched systems are one of the most frequently imposed on security issues. Security issues are often the catalyst for a program update.  Although frequent updates can be bothersome they are necessary. There are hacker circles where software vulnerabilities are shared for future use and exploit.  There is automated hacking software with databases full of known vulnerabilities to be exploited.

All software should be updated when a security vulnerability is found. Very popular software like WordPress, must be updated frequently. Because it is very popular; it is popular to hackers and requires a development team to maintain. The hacker does not care why you need the software, they only care that they can get into it and/or break the software …sometimes for nothing more than bragging rights.

WebShoppingSystems.com Fully Managed WordPress Hosting relieves you of this responsibility. All updates are performed automatically so that you never have to worry about security problems.



Website Security: Sensitive Data Leak

Data leaks are similar to ransomware. They can contain classified intellectual property like source code or have consumer information. If it is confidential, it is automatically a target for hackers. Oftentimes, this information is well guarded. Compromise generally happens via other techniques like social engineering or insider threats.

How to Avoid Sensitive Data Leak

Sensitive information should be kept behind login restrictions and network security. Control the number of users approved for entry. Make certain that all user entry is protected with multi-factor authentication and solid passwords wherever possible and that users modify these passwords often. A secure maintained email platform will clear away suspicious links and phishing. Additionally, limit physical entry to vital systems.



Hacking: Cross-Site Scripting (XSS) Attack

JavaScript and other browser-side scripting languages are generally used to update page content with external data like revenue-generating advertisements, social media feeds, and current market data.

To attack your customers by manipulating your site as a means to administer unwanted advertisements or malware, hackers use XSS. Your organization’s reputation can suffer as a result, and you may lose the trust of your consumers.

How to Avoid Cross Site Scripting

Modify security programs on your website to restrict images and Uniform Resource Locators (URLs) remote scripts to only your realm, as well as whatever external URLs you need. This can prevent several XSS attacks.

The majority of XSS attacks depend on the website formulator having done nothing to intercept it. You are able to alleviate these website security issues with input sterilization by duly escaping HTML tag characters if you are a developer. Deterrents can give a great deal of protection.



Hacking: Social Engineering (Plain Old Fraud and Deception)

Social engineering is the lies, fraud, and deceit people will use against your web system and personnel. People will call and try to gain access through tricking you or your personnel into believing that they’re someone they’re not. There is almost no limit to the amount of deceit used by hackers. Below is a list of the trickery that is very common. People have called and claimed to be the following:

  • Our Banker
  • Our New Vendor
  • Utility Company
  • Police Department
  • Fire Department
  • Our CEO and other high ranking personnel of our business

They usually call with the most urgent situations. We’ve heard such things as “we’re a new vendor and haven’t been paid in 60 days. You need to pay us today to avoid ruining your credit.” We’ve also received the super urgent “we’re going to disconnect your phone service for non-payment.” These are just a few of the scams designed to make you move urgently and hopefully before thinking.

Hackers will use trickery and bribery against your personnel to gain access to your systems. If they can convince someone to “try their excellent, new software” then that’s potential access to your systems. If your personnel can be convinced to shut down the web security for “systems testing” then all the more easier their hacking becomes. They will pretend to be your customer needing help with their account. They will try to have your personnel give them sensitive data like credit card numbers.

There shouldn’t be any credit card numbers to give since they’re not supposed to be stored on web enabled computers. If you’re ever audited by your merchant processor or Visa/Mastercard and credit card numbers and/or credit card security codes are found in your computer – not only will you be fined heavily but other problems will soon follow. You could  lose your merchant account, be banned from processing credit cards in the future, and you would open yourself up to all sorts of financial liabilities if found to be the cause or contributor to identity theft.

Social engineering attacks can have disastrous ramifications. The reason for this is because the individuals who initiate these attacks are skillful at trickery and coercion. A number of them posses several years of experience and an arsenal of highly polished characters. It is imperative that you do not depend on your ability to judge someone’s character.

How to Prevent a Social Engineering Attack

Teach your personnel to be suspicious of the following scenarios

  • People who get highly agitated at security questions.
  • Threats of a law suit if you don’t follow their instructions immediately.
  • People who have the solution to a problem that you can’t verify exists.

Your organization should set policies that define methods of verifying your customers. If a customer refuses to follow your verification requirements then don’t give them any information. If a person insists that they are someone you do business with then let them know that you’ll call them back at their publicly listed number or the number you have on file for them.



Hacking Website Security – How To Fix & Prevent 1

Hacking Website Security – How To Fix & Prevent 1





Introduction

Hacking website securityFor hackers, hacking your website security is done for something as small as bragging rights to something as large as identity theft and theft of  financial information. There are many types of hacking. Computer hacking has similarities to hacking a web server, however, the focus of this document is hacking of websites. While a number of online applications and websites have protection, they are still susceptible to website security problems and hostile attacks. This can occur with any website or online application even with something like an internet bank or a web store  for a small neighborhood business.

Some websites and online applications become targets because of how well-known they are and some become targets because of their vulnerability. Smaller systems are easy targets for hackers, even if they do not hold private data. There are hacking websites that do nothing but share information about insecurities in various software and at various websites. There is no shortage of people who want to be hackers. There are hacking camps that teach others how to circumvent website security and hack websites.

Most people see website security as a defensive barrier encircling a single site and/or server, which can simply be reinforced or ignored. A better, more factual viewpoint is that every computerized protection measure is a blanket of security. If you input more layers, then it is more likely that your data will remain safe and untouched. Adding layer after layer may appear unnecessary but doing so makes it more efficient. It is better to assume that every layer you add will be breached.



Hacking: Brute Force Attack

Brute force attack lock imageA brute force attack consists of the hacker attempting to use several password guesses in a variety of combinations until one of them grants access. Basically, it is akin to someone trying to open a combination padlock by inputting multiple numeric combinations until one works.



How to Avoid a Brute Force Attack

Several applications and content management systems (CMS) contain software that oversees website security and monitors excessive login failures. Some provide a plugin system that shows this data and allows you to block and unblock users and/or IP addresses. These plugins and software are efficient defenses against brute force attacks, as they heavily restrict the number of guesses permitted.

The WebShoppingSystems.com Fully Managed WordPress Hosting prevents this type of hacking using the iThemes Security Pro premium plug in. iThemes Security Pro prevents this type of attack and many others.




Hacking: Code Injection (Remote Code Execution)

SQL injection attack on codeTo start with a code injection a hacker will test the areas of your website that collects user input – namely a search box, contact form, or data-entry field. After trial and error, the attacker gains knowledge of which fields can be manipulated to give access to unintended data on the server.

Here is an example: A hacker will enter a variety of database commands into a search field. If your website’s search function gives un-sanitized data access to the database query then the hacker can be successful in extracting unexpected data from your database.



How to Prevent a Code Injection Attack

Maintain frequent updates with security patches when it involves development platforms, CMS, or any framework. It is highly advised that, when data processing, the best practices are followed in regards to sterilization. It does not matter if it is minimal, all user input should be checked to be sure that it is the anticipated.data type.

Programmers that create the code that processes your data are responsible for sanitizing and validating all incoming data. Sanitizing data has to do with removing known characters used in hack attempts. Validation has do with using the programming to verify that you have received the expected data type. For example, if you expect to receive an email address then the programming should check that the data is in the format of an email address.



Hacking: Credential Stuffing Attack

Hackers will abuse the re-use of passwords throughout a number of accounts. This is called credential stuffing, and it is a general term given to hackers who do this. There is no doubt that, if hackers have one of your account passwords, they will use that password to attempt to log into countless of other services.

How to Avoid Credential Stuffing

Never use the same password or username for different services. Web users should maintain a password book to track the credentials of each service they use. This is the most efficient way to prevent this security issue. What also helps is multi-factor authentication. Two factor authentication is very common now. This type of security uses a password and live authorization from the owner of the login information. This maintains a secure login even if the main password is frail.



Cookie Notice

This Cookie Notice describes how and why Web Shopping Systems, Inc. and our subsidiaries (“we,” “us” or “WSS”) use cookies, web beacons, pixels, tags, scripts and other similar technologies in the course of our business, including through websites and apps that link to this Cookie Notice. It also explains your rights to control our use of these tracking technologies. For additional information about our privacy practices, please review our Privacy Notice.

WHAT ARE COOKIES?

Cookies are small data files placed on your computer or other internet-enabled device that enable our features and functionality. They allow us to record information when you visit or interact with our websites, products and services (collectively, our “Websites”). Other tracking technologies, such as web beacons and pixels work similarly to cookies, placing small data files on your device that monitor your Website activity.

HOW DO WE USE COOKIES?

We use cookies and other tracking technologies to make our Websites easier to use and to better tailor them to your interests and needs. We use the information we obtain from cookies and other tracking technologies to carry out profiling activities in order to learn more about you and offer you tailored advertising based on your behavior on our Websites. We also use these technologies to compile information that allows us to better understand our customers and visitors.

WHAT KINDS OF COOKIES AND TRACKING TECHNOLOGIES DO WE USE?

PERSISTENT AND SESSION COOKIES

We use two categories of cookies: Persistent cookies and session cookies. Persistent cookies are cookies that help us recognize you. They are stored on your device in between browser sessions, allowing us to remember your preferences and actions across multiple sites and on multiple visits. Session cookies expire at the end of your browser session, allowing us to link your actions during a particular browsing session.

THIRD PARTY COOKIES

In addition to the first party cookies set by us, we also allow third parties to set cookies on our Websites.  Third parties may use cookies, web beacons, pixels, tags, scripts and other similar tracking technologies to enable the third party’s features or functionalities to be provided through the Website you are using. The third party setting these cookies can recognize your device both when it visits our Website and when it visits certain other websites or services. For example, our paid endorsers, or affiliates, may use third party cookies to identify you as a referral so they can be compensated if you sign up for services from us as a result of visiting one of our paid endorsers. For example, third party vendors such as Google may use cookies or other device identifiers to provide you with targeted advertisements based on your past visits to our Website.

CROSS-DEVICE TRACKING

We perform cross-device tracking which allows us to provide more relevant advertising to you on multiple devices. We do this by identifying browsing activity on your smartphones, tablets, desktop computers and other devices connected to the same IP address or logged into the same account to better understand the products and services that might be of interest to you.

LOCAL STORAGE OBJECTS

We also use Local Storage Objects (LSOs), such as HTML5, to, among other things, optimize screen presentation, video and other preference information.

GOOGLE ANALYTICS

We use Google Analytics which is a web analytics tool that helps us understand how users engage with our Websites. Like many services, Google Analytics uses first-party cookies to track user interactions as in our case, where they are used to collect information about how users use our Website. This information is used to compile reports and to help us improve our Websites. The reports disclose website trends without identifying individual visitors.

WHY DO WE USE COOKIES?

We use the following types of cookies for the reasons described below.  These cookies may be set by us or a third party service provider to perform the functions described below:

    • Required: These cookies and tracking technologies are required to help our websites work correctly.  For example, these cookies allow you to navigate our Website and use essential features, including secure areas and shopping baskets.
    • Analytics: These cookies and tracking technologies help us understand how customers and visitors interact with our Websites.  They provide us with information about areas of our Websites visited, time spent on our Websites, transactions performed, and any error messages you receive.  These cookies allow us to improve the performance of our Websites.  They may collect your IP address but only for the purpose of identifying general locations of visitors and identifying fraudulent or spam traffic.
    • Functional: These cookies and tracking technologies allow our Websites to remember choices you make to give you better functionality and a personalized experience.  For example, when you select a specific currency on one of our Websites, we will remember your currency selection when you return.
    • Advertising: These cookies and tracking technologies allow us to deliver content, including advertisements, relevant to your specific interests.  This content may be delivered on our Websites or on third party websites or services.  They allow us to understand and improve the relevancy of our advertisements.  They may track personal information, including your IP address.

HOW CAN I CONTROL COOKIES?

If you visit our Websites from the European Union and/or the European Economic Area, only required cookies, as described above, will be used on our Websites by default. Other cookies and tracking technologies will only be used when you consent by visiting each Website’s Cookie Management Center at http://preferences-mgr.truste.com/, where available.

Where you visit our Website from outside Europe, all cookies and similar tracking technologies described above will be used by default. If you would prefer not to receive personalized ads based on your browser or device usage, you may generally express your opt-out preference to no longer receive tailored advertisements.  Please note that you will continue to see advertisements, but they will no longer be tailored to your interests.

If you opt out of receiving certain cookies from us, your web browser will be associated with a generic “opt-out” cookie, which will prevent us from associating any non-personal information with your browser.  Our “opt-out” cookie has no expiration date. Since this program is cookie-based, you may need to opt out again if you do any of the following:

    • Delete your cookies;
    • Block cookies, including third party cookies;
    • Switch internet browsers;
    • Change computers; or
    • Upgrade your web browser.

Internet browsers allow you to change your cookie settings via the “options’ or “preferences” menu in your browser. Please note that if you set your browser to refuse or block all cookies, certain features or functionalities of our Websites will be limited or unavailable to you.

Some internet browsers include the ability to transmit “do not track” signals. Because no industry standard has yet been developed with respect to “do not track,” our Websites do not currently process or respond to such “do not track” signals.

Some internet browsers may offer their own management tools for removing HTML5 and other Local Storage Objects.

You can opt out of Google’s use of cookies or device identifiers without affecting how you visit or use our Website. For more information on opting out of Google’s use of cookies across all websites you use, visit this Google page: https://adssettings.google.com/authenticated. To provide you with more choice on how your data is collected by Google Analytics, Google has developed an opt-out browser add-on, which is available at https://tools.google.com/dlpage/gaoptout and enables you to opt out of being tracked by Google Analytics.

To learn how to manage privacy and storage settings for Flash cookies, visit http://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager07.html.

Further information about deleting and blocking cookies can be found at http://www.allaboutcookies.org.

Further information about our advertisers’ use of cookies can be found at:

HOW CAN I GET FURTHER INFORMATION?

If you have any questions about our use of cookies or other tracking technologies, please email us at privacy@webshoppingsystems.com or contact our Data Protection Officer at P.O. Box 6013 Moreno Valley, CA 92554.

 

Terms of Service

General Terms of Service

These Terms of Service (the “Agreement”) are an agreement between Web Shopping Systems, Incorporated (“WSS”, “us”, “our”, or the “Company”) and you (“User” or “you” or “your”). This Agreement sets forth the general terms and conditions of your use of the products and services made available by WSS and of the WebShoppingSystems.com website (collectively, the “Services”). By using the Services, you agree to be bound by this Agreement. If you do not agree to abide by the terms of this Agreement, you are not authorized to use or access the Services.

Additional Policies and Agreements

Use of the Services is also governed by the following policies, which are incorporated by reference. By using the Services, you also agree to the terms of the following policies.

Additional terms may also apply to certain Services and are incorporated by reference herein as applicable. For example, if you register a domain name with us, then the Domain Registration Agreement will also apply to you and would be incorporated herein.

Account Eligibility

By registering for or using the Services, you represent and warrant that:

      • You are eighteen (18) years of age or older. The Services are intended solely for Users who are eighteen (18) years of age or older. Any registration, use of or access to the Services, by anyone under eighteen (18) is unauthorized and is a violation of this Agreement.
      • If you use the Services on behalf of another party you agree that you are authorized to bind such other party to this Agreement and to act on such other party’s behalf with respect to any actions you take in connection with the Services.
      • It is your responsibility to provide accurate, current, and complete information on the registration forms, including an email address that is different from the domain you are signing up under. If there is ever an abuse issue or we need to contact you, we will use the primary email address we have on file. It is your responsibility to ensure that the contact information for your account, including any domain accounts is accurate, correct and complete at all times. WSS is not responsible for any lapse in the Services, including without limitation, any lapsed domain registrations due to outdated contact information being associated with the domain. If you need to verify or change your contact information, you may utilize the WSS Billing and Support Portal to update your contact information. Providing false contact information of any kind may result in the termination of your account. In dedicated server purchases or certain other cases, you may be required to provide government issued identification and possibly a scan of the credit card used for verification purposes. Failure to provide the information requested may result in your order being denied.
      • You agree to be fully responsible for all use of your account and for any actions that take place through your account. It is your responsibility to maintain the confidentiality of your password and other information related to the security of your account.
      • Any dedicated IP order in addition to those provided with a hosting package may be subject to IP justification. IP justification practices are subject to change to remain in compliance with the policies of the American Registry for Internet Numbers (ARIN). We reserve the right to deny any dedicated IP request based on insufficient justification or current IP utilization.
      • The Service and any data you provide to WSS is hosted in the United States (U.S.) unless otherwise provided. If you access the Service from outside of the U.S., you are voluntarily transferring information (potentially including personally identifiable information) and content to the U.S. and you agreeing that our collection, use, storage and sharing of your information and content is subject to the laws of the U.S., and not necessarily of the jurisdiction in which you are located.

Transfers

Our Transfers Team will make every effort to help you move your website to us. We do not make any guarantees regarding the availability, possibility, or time required to complete an account transfer. Each hosting company is configured differently, and some hosting platforms save data in an incompatible or proprietary format, which may make it extremely difficult, if not impossible, to migrate some or all account data. In some cases we may not be able to assist you in a transfer of data from an old host. Please contact a member of our Transfers department to receive a price quote. In no event shall WSS be held liable for any lost or missing data or files resulting from a transfer to or from WSS. You are solely responsible for backing up your data in all circumstances.

WSS Content

Except for User Content (as defined below), all content made available through the Services, including images made available through website builder tools provided by WSS (the “Licensed Images”), designs, templates, text, graphics, images, video, information, software, audio and other files, and their selection and arrangement, and all software used to provide the Services (collectively with the Licensed Images, “WSS Content”), are the property of WSS or its licensors. No WSS Content may not be modified, copied, distributed, framed, reproduced, republished, downloaded, scraped, displayed, posted, transmitted, sold or exploited for any purpose in any form or by any means, in whole or in part, other than as expressly permitted in this Agreement. You may not, directly or indirectly, reverse engineer, decompile, disassemble, or otherwise attempt to derive source code or other trade secrets from any WSS Content.

To the extent applicable, you are granted a limited, revocable, non-sublicensable, license to use the Licensed Images solely in connection with the Services. You are prohibited from using any Licensed Images: (i) with pornographic, defamatory, or unlawful content or in such a manner that infringes upon any third party’s trademark or intellectual property rights; (ii) as a trademark, service mark, or logo; and (iii) portraying any person depicted therein (a “Model”) in a way that a reasonable person would find offensive, including but not limited to depicting a Model: (a) in connection with pornography, “adult videos”, adult entertainment venues, escort services, dating services, or the like; (b) in connection with the advertisement or promotion of tobacco products; (c) as endorsing a political party, candidate, elected official, or opinion; (d) as suffering from, or medicating for, a physical or mental ailment; or (e) engaging in immoral or criminal activities.

Any use of WSS Content, other than as specifically authorized herein, is prohibited and will automatically terminate your rights to use the Services and any WSS Content. All rights to use WSS Content that are not expressly granted in this Agreement are reserved by WSS and WSS’s licensors.

User Content

You may be able to upload, store, publish, display and distribute information, text, photos, videos, emails, and other content on or through the Services (collectively, “User Content”). User Content includes any content posted by you or by users of any of your websites hosted through the Services (“User Websites”). You are solely responsible for any and all User Content and any transactions or other activities conducted on or through User Websites. By posting or distributing User Content on or through the Services, you represent and warrant to WSS that (i) you have all the necessary rights to post or distribute such User Content, and (ii) your posting or distribution of such User Content does not infringe or violate the rights of any third party.Solely for purposes of providing the Services, you hereby grant to WSS a non-exclusive, royalty-free, worldwide right and license to: (i) use, reproduce, publicly perform, publicly display, modify, translate, excerpt (in whole or in part), publish and distribute User Content; and (ii) make archival or back-up copies of User Content and User Websites. Except for the rights expressly granted herein, WSS does not acquire any right, title or interest in or to the User Content, all of which shall remain solely with you.

WSS exercises no control over, and accepts no responsibility for, User Content or the content of any information passing through WSS’s computers, network hubs and points of presence or the Internet. WSS does not monitor User Content. However, you acknowledge and agree that WSS may, but is not obligated to, immediately take any corrective action in WSS’s sole discretion, including without limitation removal of all or a portion of the User Content or User Websites, and suspend or terminate any and all Services without refund if you violate the terms of this Agreement. You hereby agree that WSS shall have no liability due to any corrective action that WSS may take.

Compliance with Applicable Law

You agree to comply with all applicable laws, rules, and regulations, including without limitation all local rules where you reside or your organization is location regarding User Content, User Websites, online activities, email and your use of the Services. More specifically, but without limitation, you agree to comply with all applicable laws regarding the transmission of technical data exported to or from the United States or the country in which you reside. The Services are controlled and operated by us from our offices within the United States (although we may share data
with third parties around the world to assist us in providing the Services as further described in our Privacy Notice)
and we make no representation that the Services are appropriate or available for use in other locations. Those who access the Services from other locations do so at their own initiative, risk, and are fully responsible for compliance with all applicable laws in those locations. We do not offer the Services where prohibited by law.

For the purposes of European Directive 95/46/EC, the General Data Protection Regulation 2016/679) (“GDPR”) and any applicable national implementing laws in your jurisdiction, and with respect to your subscribers’ or customers’ personal
data, you acknowledge and agree that you are the Controller (as that term is defined in the GDPR), and we are a Processor (as that term is defined in the GDPR) insofar as you may store personal data through your use of our Services only as permitted and subject to the terms of this Agreement. You also acknowledge and agree that you are responsible for complying with all obligations of a data controller under applicable law (including the GDPR).

To the extent the GDPR applies to you, you represent and warrant that in using our Services, you will clearly describe in writing how you plan to use any personal data collected and you will ensure you have a legitimate legal basis to transfer such personal data to us and that you have the necessary permission to allow us to receive and process (e.g., store) such personal data on your behalf. The additional data processing terms set forth here shall apply where you are a Controller subject to the GDPR.

Third Party Products and Services

    • Third Party Providers
      WSS may offer certain third-party products and services. Such products and services may be subject to the terms and conditions of the third-party provider. Discounts, promotions and special third party offers may be subject to additional restrictions and limitations by the third-party provider. You should confirm the terms of any purchase and the use of goods or services with the specific third-party provider with whom you are dealing.WSS does not make any representations or warranties regarding, and is not liable for, the quality, availability, or timeliness of goods or services provided by a third-party provider. You undertake all transactions with these third-party providers at your own risk. We do not warrant the accuracy or completeness of any information regarding third-party providers. WSS is not an agent, representative, trustee or fiduciary of you or the third-party provider in any transaction.
    • WSS as Reseller or Licensor
      WSS may act as a reseller or licensor of certain third-party services, hardware, software and equipment used in connection with the Services (“Non-WSS Products”). WSS shall not be responsible for any changes in the Services that cause any Non-WSS Products to become obsolete, require modification or alteration, or otherwise affect the performance of the Services. Any malfunction or manufacturer’s defects of Non-WSS Products, either sold, licensed or provided by WSS to you will not be deemed a breach of WSS’s obligations under this Agreement. Any rights or remedies you may have regarding the ownership, licensing, performance or compliance of any Non-WSS Product are limited to those rights extended to you by the manufacturer of such Non-WSS Product. You are entitled to use any Non-WSS Product supplied by WSS only in connection with your use of the Services as permitted under this Agreement. You shall make no attempt to copy, alter, reverse engineer, or tamper with such Non-WSS Product or to use it other than in connection with the Services. You shall not resell, transfer, export or re-export any Non-WSS Product, or any technical data derived therefrom, in violation of any applicable law, rules or regulations.
    • Third Party Websites
      The Services may contain links to other websites that are not owned or controlled by WSS (“Third Party Sites”), as well as articles, photographs, text, graphics, pictures, designs, sound, video, information, and other content or items belonging to or originating from third parties (“Third Party Content”). We are not responsible for any Third Party Sites or Third Party Content accessed through the Services. Third Party Sites and Third Party Content are not investigated, monitored or checked for accuracy, appropriateness, or completeness by us. If you decide to access Third Party Sites or to access or use any Third Party Content, you do so at your own risk and you should be aware that our terms and policies no longer govern. You should review the applicable third party’s terms and policies, including privacy and data gathering practices of any website to which you navigate.

Prohibited Persons (Countries, Entities, And Individuals)

The Services are subject to export control and economic sanctions laws and regulations administered or enforced by the United States Department of Commerce, Department of Treasury’s Office of Foreign Assets Control (“OFAC”), Department of State, and other United States authorities (collectively, “U.S. Trade Laws”). You may not use the Services to export or reexport, or permit the export or reexport, of software or technical data in violation of U.S. Trade Laws. In addition, by using the Services, you represent and warrant that you are not (a) an individual, organization or entity organized or located in a country or territory that is the target of OFAC sanctions (including Cuba, Iran, Syria, North Korea, or the Crimea region of Ukraine); (b) designated as a Specially Designated National or Blocked Person by OFAC or otherwise owned, controlled, or acting on behalf of such a person; (c) otherwise a prohibited party under U.S. Trade Laws; or (d) engaged in nuclear, missile, chemical or biological weapons activities to which U.S. persons may not contribute without a U.S. Government license. Unless otherwise provided with explicit written permission, WSS also does not register, and prohibits the use of any of our Services in connection with, any Country-Code Top Level Domain Name (“ccTLD”) for any country or territory that is the target of OFAC sanctions. The obligations under this section shall survive any termination or expiration of this Agreement or your use of the Services.

Account Security and WSS Systems

It is your responsibility to ensure that scripts/programs installed under your account are secure and permissions of directories are set properly, regardless of the installation method. When at all possible, set permissions on most directories to 755 or as restrictive as possible. Users are ultimately responsible for all actions taken under their account. This includes the compromise of credentials such as user name and password. You are required to use a secure password. If a weak password is used, your account may be suspended until you agree to use a more secure password. Audits may be done to prevent weak passwords from being used. If an audit is performed, and your password is found to be weak, we will notify you and allow time for you to change or update your password before suspending your account.

The Services, including all related equipment, networks and network devices are provided only for authorized customer use. WSS may, but is not obligated to, monitor our systems, including without limitation, to ensure that use is authorized, to facilitate protection against unauthorized access, and to verify security procedures, survivability, and operational security. During monitoring, information may be examined, recorded, copied and used for authorized purposes. By using the Services, you consent to monitoring for these purposes.

Any account found connecting to a third party network or system without authorization from the third party is subject to suspension. Access to networks or systems outside of your direct control requires the express written consent of the third party. WSS may, at our discretion, request documentation to prove that your access to a third party network or system is authorized.

Any account which causes us to receive an abuse report may be terminated and/or have access to services suspended. If you do not remove malicious content from your account after being notified by WSS of an issue, we reserve the right to leave access to services disabled.

WSS reserves the right to migrate your account from one data center to another in order to comply with applicable data center policies, local law or for technical or other reasons without notice.

HIPAA Disclaimer

We are not “HIPAA compliant. You are solely responsible for any applicable compliance with federal or state laws governing the privacy and security of personal data, including medical or other sensitive data. You acknowledge that the Services may not be appropriate for the storage or control of access to sensitive data, such as information about children or medical or health information. WSS does not control or monitor the information or data you store on, or transmit through, the Services. We specifically disclaim any representation or warranty that the Services, as offered, comply with the federal Health Insurance Portability and Accountability Act (“HIPAA”). Customers requiring secure storage of “protected health information” as defined under HIPAA are expressly prohibited from using the Services for such purposes. Storing and permitting access to “protected health information” is a material violation of this Agreement, and grounds for immediate account termination. We do not sign “Business Associate Agreements” and you agree that WSS is not a Business Associate or subcontractor or agent of yours pursuant to HIPAA. If you have questions about the security of your data, you should contact info@WebShoppingSystems.com.

Compatibility with the Services

You agree to cooperate fully with WSS in connection with WSS’s provision of the Services. It is solely your responsibility to provide any equipment or software that may be necessary for your use of the Services. To the extent that the performance of any of our obligations under this Agreement may depend upon your performance of your obligations, WSS is not responsible for any delays due to your failure to timely perform your obligations.

You are solely responsible for ensuring that all User Content and User Websites are compatible with the hardware and software used by WSS to provide the Services, which may be changed by WSS from time to time in our sole discretion.

You are solely responsible for backing-up all User Content, including but not limited to, any User Websites. WSS does not warrant that we back-up any User Content, and you agree to accept the risk of loss of any and all User Content.

Billing and Payment Information

It is your responsibility to ensure that your payment information is up to date, and that all invoices are paid on time. You agree to pay for the Services in advance of the time period during which such Services are provided. Subject to applicable laws, rules, and regulations, payments received will be first applied to the oldest outstanding invoice in your billing account.

Unless otherwise provided, you agree that until and unless you notify WSS of your desire to cancel the Services, you will be billed on an automatically recurring basis to prevent any disruption to your Services, using your credit card or other billing information on file with us.

Listed fees for the Services do not include any applicable sales, use, revenue, excise or other taxes imposed by any taxing authority. Any applicable taxes will be added to WSS’s invoice as a separate charge to be paid by you. All fees are non-refundable when paid unless otherwise stated.

Late Payment.

All invoices must be paid within ten (10) days of the invoice due date. Any invoice that is outstanding for more than ten (10) days may result in the suspension or termination of Services. Access to the account will not be restored until payment has been received. If you fail to pay the fees as specified herein, WSS may suspend or terminate your account and pursue the collection costs incurred by WSS, including without limitation, any arbitration and legal fees, and reasonable attorneys’ fees. WSS will not activate new orders or activate new packages for customers who have an outstanding balance on their account. Dedicated servers are subject to being reclaimed and all content deleted if you fail to make a timely payment. If you make a late payment we do not automatically reactivate the dedicated servers. Contact WSS directly after you make a late payment to reactivate the dedicated server.

Domain Payments.
It is solely your responsibility to notify WSS’s Billing department by calling 1-844-866-4466 after purchasing a domain. Domain renewal notices are provided as a courtesy reminder and WSS is not responsible for a failure to renew a domain or a failure to notify a customer about a domain’s renewal. Domain renewals are billed and renewed thirty (30) days before the renew date.

It is a violation of this Agreement for you to misuse or fraudulently use credit cards, charge cards, electronic funds transfers, electronic checks, or any other payment method. WSS may report any such misuse or fraudulent use, as determined in WSS’s sole discretion, to governmental and law enforcement authorities, credit reporting services, financial institutions and/or credit card companies.

Invoice Disputes.
You have ninety (90) days to dispute any charge or payment processed by WSS. If you have any questions concerning a charge on your account, please reach out to our billing department for assistance.

Payment Card Industry Security Standard Disclaimer.
WSS complies with the Payment Card Industry Security Standard (“PCI Standard”) in connection with the collection and processing of our customer’s data and billing information. However, you are solely responsible for the security of the data and billing information on your User Website. WSS does not monitor User Websites for PCI compliance and we are not able to verify whether a User Website complies with the PCI Standard.

Money-Back Guarantee.

Dedicated Servers.
There are no refunds on dedicated servers. The thirty (30) day money-back guarantee does not apply to dedicated servers.

Managed Shared, VPS and Reseller Services.
WSS offers a thirty (30) day money-back guarantee for WSS’s managed shared, VPS, and reseller hosting services only. Subject to the terms described in Section 13 below, if you are not completely satisfied with these hosting services and you terminate your account within thirty (30) days of signing up for the Services, you will be given a full refund of the amount paid for hosting. This money-back guarantee only applies to fees paid for hosting services and does not apply to domains, administrative fees, install fees for software or other setup fees, or to any fees for any other additional services.

Cancellations and Refunds.

Payment Method
No refunds will be provided if you use any of the following methods of payment: bank wire transfers, Western Union payments, checks and money orders. If you use any of these payment methods, any applicable credit will be posted to your hosting account instead of a refund.

Money-Back Guarantee
If an account with a thirty (30) day money-back guarantee is purchased and then cancelled within the first thirty (30) days of the beginning of the term (the “Money-Back Guarantee Period”), you will, upon your written request to the WSS Support Team (the “Refund Request”) within thirty (30) days of such termination or cancellation (“Notice Period”), receive a full refund of all shared, VPS and reseller hosting fees previously paid by you to WSS for the initial term (“Money-Back Guarantee Refund”); provided that such Money-Back Guarantee Refund shall be due to you only upon your compliance with, and subject in all respects to the terms and conditions of this Section. Requests for these refunds must be made in writing to the WSS Support Team. Refunds will only be issued for shared, VPS and reseller hosting services and will not include domains, administrative fees, install fees for software or other setup fees, nor will they include any fees for any other additional services. Money-Back Guarantee Refunds will not accrue, and shall not be paid under any circumstances if you do not provide the applicable Refund Request within the Notice Period.

Refund Eligibility.
Only first-time accounts are eligible for a refund. For example, if you’ve had an account with us before, canceled and signed up again, or if you have opened a second account with us, you will not be eligible for a refund. Violations of this Agreement will waive your rights under the refund policy.

Non-refundable Products and Services.
There are no refunds on dedicated servers, administrative fees, domain names and install fees for software.

Cancellation Process.
You may terminate or cancel the Services by giving WSS written notice via the customer portal. In such event: (i) you shall be obligated to pay all fees and charges accrued prior to the effectiveness of such cancellation and (ii) WSS may, in our sole discretion, refund all pre-paid fees for hosting services for the full months remaining after the effectiveness of such cancellation (i.e. no partial month fees shall be refunded) less any setup fees, applicable taxes and any discount applied for prepayment, provided that you are not in breach of this Agreement. Once we receive your cancellation notice and have confirmed all necessary information with you via email, we will inform you in writing (typically email) that your account has been canceled. Your cancellation confirmation will contain a ticket/tracking number in the subject line for your reference and for verification purposes. You should immediately receive an automatic email with a tracking number stating that “Your request has been received….” WSS will confirm your request and process your cancellation shortly thereafter. If you do not hear back from us, or do not receive the automatic confirmation email within a few minutes after submitting your cancellation form, please contact us immediately via phone at: 1-844-866-4466..

We require all cancellations to be done through the online system in order to (a) confirm your identity, (b) confirm in writing that you are prepared for all of your files and emails to be removed, and (c) document the request. This process aims to reduce the likelihood of mistakes, fraudulent/malicious requests, and to ensure that you are aware that your files, emails, and account may be removed immediately and permanently after a cancellation request is processed.

Cancellations for shared and reseller accounts will be effective on the account’s renewal date. Cancellations for dedicated and VPS accounts will be effective immediately.

Domain
Domain renewals are billed and renewed thirty (30) days before the renewal date. It is your responsibility to notify WSS’s Billing department by calling 1-844-866-4466 to cancel any domain registration at least thirty (30) days prior to the renewal date. No refunds will be given once a domain is renewed. All domain registrations and renewals are final.

Domain Name Fees
If your plan includes a free domain name and you cancel within 1 year, our standard fee of $19.99 for the domain name (and any applicable taxes) (the “Domain Name Fee”) will be deducted from your refund.

Foreign Currencies.
Exchange rate fluctuations for international payments are constant and unavoidable. All refunds are processed in U.S. dollars and will reflect the exchange rate in effect on the date of the refund. All refunds are subject to this fluctuation and WSS is not responsible for any change in exchange rates between the time of payment and the time of refund.

Termination
WSS may terminate your access to the Services, in whole or in part, including deletion or confiscation of all files, content, and/or domain name registrations, without notice in the event that: (i) you fail to pay any fees due hereunder to WSS; (ii) you violate the terms and conditions of this Agreement; (iii) your conduct may harm WSS or others, cause WSS or others to incur liability, or disrupt WSS’s business operations (as determined by WSS in its sole discretion); (iv) you are abusive toward WSS’s staff in any manner; or (v) for any other lawful reason, including to comply with applicable law, or as otherwise specified in this Agreement. In such event, WSS will not refund to you any fees paid in advance of such termination, and you shall be obligated to pay all fees and charges accrued prior to the effectiveness of such termination.

UPON TERMINATION OF THE SERVICES FOR ANY REASON, USER CONTENT, USER WEBSITES, AND OTHER DATA WILL BE DELETED.

Resource Usage

Shared Hosting

Acceptable Use Policy 

Disk space is intended for use in accordance with WSS’s Acceptable Use Policy and limited to web files, active email and User Website content only. Shared hosting space may not be used for storage, including without limitation, of media, emails, as offsite storage of electronic files, or FTP hosts. WSS expressly reserves the right to review every shared account for excessive usage of CPU, disk space and other resources that may be caused by a violation of this Agreement or the Acceptable Use Policy. WSS may, in its sole discretion, terminate access to the Services, apply additional fees, or remove or delete User Content for those accounts that are found to be in violation of WSS’s terms and conditions.

Excessive Server Resources

Use of WSS’s resources must be consistent with a shared hosting environment and must otherwise comply with this Agreement. Accounts with a large number of files (inode count in excess of 200,000) can have an adverse effect on server performance. Similarly, accounts with an excessive number of database tables (in excess of 5000 database tables) or an excessive database size (in excess of 10GB total database usage or 5GB database usage in a single database) negatively affect the performance of the server. In the event that you exceed these amounts, WSS may request that you reduce the number of files/inodes, database tables, or total databases to ensure optimal server performance. WSS reserves the right to terminate your account, with or without notice, for excessive use of resources that result in a degradation of server performance or the Services.

Bandwidth Usage

With the exception of resellers and buck-a-roo hosting, shared servers are not limited in their bandwidth allowance. Resellers are subject to the terms of the plan they purchased and usage information can be viewed in the control panel.

Virtual Private Servers (VPS) and Dedicated Servers Usage.

Dedicated and VPS usage is limited by the resources allocated to the specific plan you purchased.

Uptime Guarantee
If your shared or reseller server has a physical downtime that falls short of the 99.9% uptime guarantee, you may receive one (1) month of credit on your account. This uptime guarantee does not apply to planned maintenance. Approval of any credit is at the sole discretion of WSS and may be dependent upon the justification provided. Third party monitoring service reports may not be used for justification due to a variety of factors including the monitor’s network capacity/transit availability. The uptime of the server is defined as the reported uptime from the operating system and the Apache Web Server which may differ from the uptime reported by other individual services. To request a credit, please contact our Billing department by calling 1-844-866-4466 with justification within thirty (30) days of the end of the month for which you are requesting a credit. Uptime guarantees only apply to shared and reseller solutions. Dedicated servers are covered by a network guarantee in which the credit is prorated for the amount of time the server is down which is not related to our uptime guarantee.

Reseller Terms and Client Responsibility

Resellers shall ensure that each of their clients complies with this Agreement.

Resellers are responsible for supporting their clients. WSS does not provide support to clients of WSS’s resellers. If a reseller’s client contacts WSS, WSS reserves the right to place a reseller client account on hold until the reseller can assume responsibility for the reseller’s client. All support requests must be made by the reseller on its client’s behalf for security purposes.

Resellers are also responsible for all content stored or transmitted under their reseller account and the actions of their clients. WSS will hold any reseller responsible for any of their client’s actions that violate the law or this Agreement.

WSS is not responsible for the acts or omissions of our resellers. The reseller hereby agrees to indemnify WSS from and against any and all claims made by any User arising from the reseller’s acts or omissions.

WSS reserves the right to revise our Reseller Program at any time. Changes shall take effect when posted online or on any subsequent date as may be set forth by WSS.

Resellers in the WSS Reseller Program assume all responsibility for billing and technical support for each of the Users signed up by the reseller.

Shared (non-reseller accounts)
Shared accounts may not be used to resell web hosting to others. If you wish to resell hosting you must use a reseller account.

Dedicated Servers
WSS reserves the right to reset the password on a dedicated server if the password on file is not current so that we may do security audits as required by our datacenter. It is your responsibility to ensure that there is a valid email address and current root password on file for your dedicated server to prevent downtime from forced password resets. WSS reserves the right to audit servers as needed and to perform administrative actions at the request of our datacenter. Dedicated servers are NOT backed up by us. It is your responsibility to maintain backups. Dedicated servers that have invoices outstanding for more than ten (10) days may be subject to deletion which will result in the loss of all data on the server. WSS will not be liable for any loss of data resulting from such deletion.

Appointment Booking

If you elect to use WSS’s Appointment Booking Service (“Booking”) to schedule appointments through the User Website, you acknowledge that you are responsible for managing and fulfilling your appointments and service offerings. BOOKING IS PROVIDED ON AN “AS-IS” AND “AS-AVAILABLE” BASIS AND WSS MAKES NO WARRANTIES THAT THE SERVICE WILL PERFORM IN AN ERROR-FREE AND UNINTERRUPTED MANNER. WSS HEREBY EXPRESSLY DISCLAIMS ANY LIABILITY FOR LOSS OF PROFITS OR BUSINESS RESULTING FROM YOUR USE OF BOOKING.

Email Marketing

If you elect to use the email marketing feature (“Email Marketing”), your use of Email Marketing shall be governed by the Constant Contact Website and Products Terms and Conditions of Use (the “Email Marketing Terms”). To the extent there is any conflict between the Email Marketing Terms and this Agreement, the Email Marketing Terms shall control solely with respect to your use of Email Marketing.

Store

If you elect to use WSS e-commerce store Services (“Store”) for selling any of your products and/or services (“Store Content”), you are solely responsible for any and all Store Content and any transactions or other activities conducted on or through the Store. Your Store activities are your responsibility and WSS disclaims any and all liability related to any Store Content. You represent and warrant to WSS that (i) you have all necessary rights to post or distribute such Store Content, and (ii) your Store Content does not infringe or violate the rights of any third party.

You acknowledge and agree that WSS may, but is not obligated to, monitor your Store and may take any corrective action in WSS’s sole discretion, including without limitation removal of all or a portion of the Store Content, and suspension or termination of any and all Services without refund of any pre-paid fees. You hereby agree that WSS shall have no liability due to any corrective action that WSS may take, including without limitation suspension or termination of your Store.

You acknowledge and agree that you are solely responsible for your compliance with the following:

    • all applicable laws and regulations related to the Store and any Store Content including any related consumer, data privacy, and e-commerce laws;
    • taxes and fees associated with the Store, including taxes related to purchase or sale of products and services in connection with the Store;
    • customer service for the Store, including any inquiries, concerns, warranties you may offer, or claims and complaints relating to the Store;
    • fulfillment and the delivery of Store Content to your customers; and
    • visibility for all terms and policies that may apply, including but not limited to privacy policies, cookie policies, return policies, and any offered warranties.
    • Your Store Content is subject to WSS’s Acceptable Use Policy. In the event you violate this policy, WSS reserves the right to, at any time and in our sole discretion, without notice, suspend and disable access, or remove your Store and/or Store Content without any liability to you or your customers, including without limitation, any loss of profits, revenue, data, goodwill, or other losses except where prohibited by law.

LogoMaker

If you elect to use WSS’s LogoMaker Service (“LogoMaker”) to create a logo or design for your use, you acknowledge that LogoMaker uses certain elements, including colors, fonts, icons, and other designs. These elements are also made available to other Users and, as such, any logo created by LogoMaker may be similar or identical to logos created by other Users who use LogoMaker. LOGOS CREATED BY LOGOMAKER ARE PROVIDED ON AN “AS-IS” AND “AS-AVAILABLE” BASIS AND WEBSITE BUILDER MAKES NO WARRANTIES THAT THE LOGOS DO NOT INFRINGE THE INTELLECTUAL PROPERTY RIGHTS OF ANY THIRD PARTY. It is your responsibility to determine (a) whether any logo created by LogoMaker is subject to any third party rights and (b) whether you may use and/or register your logo as a trademark.

You may not assign or resell your LogoMaker logo to any third party, and you may not challenge the use or registration of any other logo created by LogoMaker on behalf of another User.

WordPress Plugins

If you install or use WordPress plugins operated by Automattic on your hosting account (including, for example, Jetpack), you also acknowledge and agree to (1) the WordPress.com Terms of Service located at (https://en.wordpress.com/tos/) which apply to your use of all Automattic products and services; and (2) the Automattic Privacy Policy located at (http://automattic.com/privacy/), including without limitation, Automattic’s collection of data as described therein.

Price Change
WSS reserves the right to change prices or any other charges at any time. We will provide you with at least thirty (30) days notice before charging you with any price change on any annual or longer term plans. It is your sole responsibility to periodically review billing information provided by WSS through the user billing tool or through other methods of communication, including notices sent or posted by WSS.

Coupons
Discounts and coupon codes are reserved for first-time accounts or first-time customers only and may not be used towards the purchase of a domain registration unless otherwise specified. If you have previously signed up using a particular domain, you may not sign up again for that domain using another coupon at a later date. Any account found in violation of these policies will be reviewed by our sales department and the appropriate charges will be added to the account. Coupon abuse will not be tolerated and may result in the suspension or termination of your account. All coupons and discounts are only valid towards the initial purchase and do not affect the renewal or recurring price.

Limitation of Liability
IN NO EVENT WILL WSS ITS DIRECTORS, EMPLOYEES OR AGENTS BE LIABLE TO YOU OR ANY THIRD PERSON FOR ANY INDIRECT, CONSEQUENTIAL, EXEMPLARY, INCIDENTAL, SPECIAL OR PUNITIVE DAMAGES, INCLUDING FOR ANY LOST PROFITS OR LOST DATA ARISING FROM YOUR USE OF THE SERVICES, OR ANY USER CONTENT, USER WEBSITES OR OTHER MATERIALS ACCESSED OR DOWNLOADED THROUGH THE SERVICES, EVEN IF WSS IS AWARE OR HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
NOTWITHSTANDING ANYTHING TO THE CONTRARY CONTAINED HEREIN, WSS’S LIABILITY TO YOU, OR ANY PARTY CLAIMING THROUGH YOU, FOR ANY CAUSE WHATSOEVER, AND REGARDLESS OF THE FORM OF THE ACTION, IS LIMITED TO THE AMOUNT PAID, IF ANY, BY YOU TO WSS FOR THE SERVICES IN THE THREE (3) MONTHS PRIOR TO THE INITIAL ACTION GIVING RISE TO LIABILITY. THIS IS AN AGGREGATE LIMIT. THE EXISTENCE OF MORE THAN ONE CLAIM HEREUNDER WILL NOT INCREASE THIS LIMIT.

Indemnification
You agree to indemnify, defend and hold harmless WSS, our affiliates, and their respective officers, directors, employees and agents (each an “Indemnified Party” and, collectively, the “Indemnified Parties”) from and against any and all claims, damages, losses, liabilities, suits, actions, demands, proceedings (whether legal or administrative), and expenses (including, but not limited to, reasonable attorney’s fees) threatened, asserted, or filed by a third party against any of the Indemnified Parties arising out of or relating to (i) your use of the Services, (ii) any breach or violation by you of this Agreement; or (iii) any acts or omissions by you. The terms of this section shall survive any termination of this Agreement.

Arbitration
By using the Services, you hereby submit to the exclusive jurisdiction of the American Arbitration Association (“AAA”) in connection with any dispute relating to, concerning or arising out of this Agreement. The arbitration will be conducted before a single arbitrator chosen by WSS and will be held at the AAA location chosen by WSS in California. Payment of all filing, administrative and arbitrator fees will be governed by the AAA’s rules, unless otherwise stated in this paragraph. In the event you can demonstrate that the costs of arbitration will be prohibitive as compared to the costs of litigation, WSS will pay as much of your filing, administrative, and arbitrator fees in connection with the arbitration as the arbitrator deems necessary to prevent the arbitration from being cost-prohibitive. The arbitration before the AAA shall proceed solely on an individual basis without the right for any claims to be arbitrated on a class action basis or on bases involving claims brought in a purported representative capacity on behalf of others. The Federal Arbitration Act, and not any state arbitration law, governs all arbitration under this paragraph. All decisions rendered by the arbitrator will be binding and final. The arbitrator’s award is final and binding on all parties. The arbitrator’s authority to resolve and make written awards is limited to claims between you and WSS alone. Claims may not be joined or consolidated unless agreed to in writing by all parties. No arbitration award or decision will have any preclusive effect as to issues or claims in any dispute with anyone who is not a named party to the arbitration. If you initiate litigation or any other proceeding against WSS in violation of this paragraph, you agree to pay WSS’s reasonable costs and attorneys’ fees incurred in connection with our enforcement of this paragraph.

Independent Contractor
WSS and User are independent contractors and nothing contained in this Agreement places WSS and User in the relationship of principal and agent, partners or joint venturers. Neither party has, expressly or by implication, or may represent itself as having, any authority to make contracts or enter into any agreements in the name of the other party, or to obligate or bind the other party in any manner whatsoever.

Governing Law; Jurisdiction
Any controversy or claim arising out of or relating to this Agreement, the formation of this Agreement or the breach of this Agreement, including any claim based upon an alleged tort, shall be governed by the substantive laws of the State of California. The United Nations Convention on Contracts for the International Sale of Goods does not apply to this Agreement.

Disclaimer
WSS shall not be responsible for any damages your business may suffer. WSS makes no warranties of any kind, expressed or implied for the Services. WSS disclaims any warranty of merchantability or fitness for a particular purpose, including loss of data resulting from delays, delivery failures, wrong deliveries, and any and all service interruptions caused by WSS or our employees.

Backups and Data Loss
Your use of the Services is at your sole risk. WSS’s backup service runs once a week and overwrites any of our previous backups. Only one week of backups are kept at a time. This service is provided only to shared and reseller accounts as a courtesy and may be modified or terminated at any time at WSS’s sole discretion. WSS does not maintain backups of dedicated accounts. WSS is not responsible for files and/or data residing on your account. You agree to take full responsibility for all files and data transferred and to maintain all appropriate backup of files and data stored on WSS’s servers. Any shared account using more than 20 gigs of disk space will be removed from our off site weekly backup with the exception of databases continuing to be backed up. All data will continue to be mirrored to a secondary drive to help protect against data loss in the event of a drive failure.

Limited Warranty
THE SERVICES PROVIDED UNDER THIS AGREEMENT ARE PROVIDED ON AN “AS IS” AND “AS AVAILABLE BASIS.” EXCEPT AS EXPRESSLY PROVIDED IN THIS SECTION, WSS AND OUR AFFILIATES, EMPLOYEES, AGENTS, SUPPLIERS AND LICENSORS DISCLAIM ALL WARRANTIES OF ANY KIND, INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT, FOR THE SERVICES PROVIDED HEREUNDER. WSS AND OUR AFFILIATES, EMPLOYEES, AGENTS, SUPPLIERS AND LICENSORS MAKE NO REPRESENTATIONS OR WARRANTIES (I) THAT THE SERVICES WILL BE UNINTERRUPTED, ERROR FREE OR COMPLETELY SECURE; (II) AS TO THE RESULTS THAT MAY BE OBTAINED FROM THE USE OF THE SERVICES; OR (III) AS TO THE ACCURACY, RELIABILITY OR CONTENT OF ANY INFORMATION PROVIDED THROUGH THE SERVICES. WSS AND OUR AFFILIATES, EMPLOYEES, AGENTS, SUPPLIERS AND LICENSORS ARE NOT LIABLE, AND EXPRESSLY DISCLAIMS ANY LIABILITY, FOR THE CONTENT OF ANY DATA TRANSFERRED EITHER TO OR FROM USERS OR STORED BY USERS ON OR THROUGH THE SERVICES. THE TERMS OF THIS SECTION SHALL SURVIVE ANY TERMINATION OF THIS AGREEMENT.

Disclosure to Law Enforcement
WSS may disclose User information to law enforcement agencies without further consent or notification to the User upon lawful request from such agencies. We cooperate fully with law enforcement agencies.

Entire Agreement.
This Agreement, including documents incorporated herein by reference, supersedes all prior discussions, negotiations and agreements between the parties with respect to the subject matter hereof, and this Agreement constitutes the sole and entire agreement between the parties with respect to the matters covered hereby.

The headings herein are for convenience only and are not part of this Agreement.

Changes to the Agreement or the Services

WSS may modify, add, or delete portions of this Agreement at any time. If we have made significant changes to this Agreement, we will post a notice on the WSS website for at least thirty (30) days after the changes are posted and will indicate at the bottom of this Agreement the date of the last revision. Any revisions to this Agreement will become effective when posted unless otherwise provided. You agree to any modification to this Agreement by continuing to use the Services after the effective date of any such modification.

WSS reserves the right to modify, change, or discontinue any aspect of the Services at any time.

Severability
If any provision or portion of any provision of this Agreement is found to be illegal, invalid or unenforceable by a court of competent jurisdiction, the remaining provisions or portions (unless otherwise specified) thereof shall remain in full force and effect.

Waiver
No failure or delay by you or WSS to exercise any right or remedy hereunder shall operate as a waiver thereof, nor shall any single or partial exercise of any right or remedy preclude any other or further exercise of any right or remedy. No express waiver of, or assent to, any breach of or default in any term or condition of this Agreement by any party hereto shall constitute a waiver of, or an assent to, any succeeding breach of or default in the same or any other term or condition hereof.

Assignment; Successors
You may not assign or transfer this Agreement or any of your rights or obligations hereunder, without the prior written consent of WSS. Any attempted assignment in violation of this Agreement shall be null and void and of no force or effect whatsoever. WSS may assign our rights and obligations under this Agreement and may engage subcontractors or agents in performing our duties and exercising our rights hereunder, without the consent of User. This Agreement shall be binding upon and shall inure to the benefit of the parties hereto and their respective successors and permitted assigns.

Force Majeure
Neither party is liable for any default or delay in the performance of any of its obligations under this Agreement (other than failure to make payments when due) if such default or delay is caused, directly or indirectly, by forces beyond such party’s reasonable control, including, without limitation, fire, flood, acts of God, labor disputes, accidents, acts of war or terrorism, interruptions of transportation or communications, supply shortages or the failure of any third party to perform any commitment relative to the production or delivery of any equipment or material required for such party to perform its obligations hereunder.

Third-Party Beneficiaries
Except as otherwise expressly provided in this Agreement, nothing in this Agreement is intended, nor shall anything herein be construed to confer any rights in any person other than the parties hereto and their respective successors and permitted assigns. Notwithstanding the foregoing, user acknowledges and agrees that any supplier of a third-party product or service that is identified as a third-party beneficiary in the service description, is an intended third-party beneficiary of the provisions set forth in this Agreement as they relate specifically to its products or services and shall have the right to enforce directly the terms and conditions of this Agreement with respect to its products or services against user as if it were a party to this Agreement.

This file was last modified: August 28, 2022.