Privacy Policy

PRIVACY POLICY — "CLOUDFLARE DNS & SSL" PLESK EXTENSION

Last updated: 19 July 2026

This Privacy Policy explains what data the "Cloudflare DNS & SSL" Plesk extension
(the "Software") processes, where it goes, and what leaves your server. Ege Hosting
("Vendor", "we") designed the Software to keep your credentials and DNS data on
your own server and in your own third-party accounts.


1. WHAT THE SOFTWARE STORES ON YOUR SERVER

1.1. Cloudflare API token — supplied by each reseller, stored per reseller and
     ENCRYPTED AT REST using Plesk's own cryptography (pm_Crypt). It is readable
     only by the reseller who entered it and by server administrators through the
     normal Plesk privilege model. It is never written to logs and never passed on
     a command line.

1.2. Cloudflare Account ID (optional) and a timestamp of the last successful token
     verification.

1.3. Per-domain preferences (for example, whether Cloudflare proxying is enabled
     for that domain).

1.4. Issued TLS certificates and their private keys, produced by the ACME client
     and imported into Plesk's certificate repository, stored on your server.


2. WHAT THE SOFTWARE SENDS, AND TO WHOM

2.1. To Cloudflare (api.cloudflare.com), using YOUR token: requests to verify the
     token, list your zones, and read/create/update/delete DNS records for your own
     domains. This is the core function you invoke.

2.2. To Let's Encrypt (via the ACME protocol): certificate signing requests and the
     temporary _acme-challenge TXT validation records required to prove control of
     your domain. The challenge records are created at Cloudflare and removed after
     validation.

2.3. To the Vendor: NOTHING about your domains, tokens, or DNS. The only optional
     contact with the Vendor is an update check (see Section 3).

We, the Vendor, never receive your Cloudflare token, your DNS records, or your
certificates. That data flows only between your server and the services you connect.


3. UPDATE CHECK

3.1. The Software may request a small version file from the Vendor's website over
     HTTPS to tell you whether a newer version exists. This request carries only
     what any HTTPS request carries (e.g. your server's IP address, as seen by the
     web server). It contains no domain names, tokens, or personal data.

3.2. The update check only reports availability; it never downloads or installs
     anything automatically.


4. THIRD-PARTY COMPONENTS

4.1. The first time you issue a certificate, the Software downloads the open-source
     ACME client "acme.sh" from its official distribution point over HTTPS and runs
     it locally on your server. Its network activity is limited to Let's Encrypt and
     Cloudflare as described above.


5. DATA RETENTION AND REMOVAL

5.1. All data in Section 1 remains on your server until you remove it (disconnect a
     token, delete a record, or remove a certificate).

5.2. Uninstalling the Software stops the automation and removes its scheduled task
     and DNS backend registration. It does not delete your stored tokens, your
     Cloudflare records, or your issued certificates, so that removing the extension
     never silently destroys data you rely on. You can remove those yourself.


6. THIRD-PARTY SERVICES' OWN POLICIES

Your use of Cloudflare and Let's Encrypt is subject to their respective privacy
policies and terms. The Vendor is not affiliated with either service.


7. CONTACT

Ege Hosting
Website: https://egehosting.com