What we handle, and what's yours
Hosting, SSL, and backups are ours. Passwords and who has a key are yours.
Overview
There's no server to rent, no software to install, and no security updates to keep on top of. Hosting is part of your plan and it's fully managed — the parts of running a website that used to need a developer on call simply aren't your job here.
That leaves a short list of things that genuinely are yours: your password, who you've given access to, and keeping a copy of anything you'd hate to lose. This guide covers both halves.
What's handled for you
None of the following needs setting up, buying, or renewing:
- Hosting — your site is served from a network with locations around the world, so it loads quickly wherever your visitor is.
- SSL — every site gets a certificate and HTTPS on every page, on from day one. It renews itself.
- Software updates — the platform is patched and updated underneath you, with nothing to approve.
- Backups — your site's data is backed up on a regular schedule so a bad day can't become a lost business.
- Traffic protection — the usual background noise of the internet, from bots to floods of junk requests, is filtered before it reaches your site.
Images are optimised and pages are cached for you too, which is most of what a “speed up my site” checklist would otherwise ask you to do by hand.
Your password and sign-in
The most likely way anyone gets into your site is not a clever attack on us — it's a password you also used somewhere else that has since been breached.
Use a password that's only for this account, at least eight characters and ideally much longer. You can change it any time from Settings, under Account in the side navigation.
Adding a second step
Account settings also lets you choose how your sign-in is verified — a code from an authenticator app on your phone, or a code sent to your email.
The authenticator app is the stronger of the two, because it doesn't depend on your email account staying safe. If you sell anything, or if anyone else has access to your site, it's worth the two minutes it takes to set up.
- In the side navigation, under Account, open Settings.
- Find the sign-in verification section.
- Choose the authenticator app and follow the prompts to enrol, or choose email codes if you'd rather.
Who has a key
Every person with access to your site is a way in, so the useful habit is giving each one the least access that lets them do their job. There are five roles:
- Owner — full control, including billing, members, and transferring or deleting the site.
- Admin — manage all content and members, but can't transfer or delete the site.
- Editor — create, edit, and publish content, and work orders and customers. No members, no settings.
- Contributor — edit content, but changes go through the review flow instead of publishing live.
- Read Only — see the dashboard, change nothing.
Nobody can grant a role above their own, so an Admin can add another Admin but not an Owner. Manage all of this in your site's Settings, under Access & legal, on the Staff & permissions card.
When someone leaves
Removing someone from Staff & permissions takes away their access to that site immediately. It doesn't delete their account, which may still be on other sites you own — so if a person is leaving entirely, check each site.
This is the one piece of security housekeeping that gets forgotten, and it's the one that matters most. A former contractor with a live login is a bigger risk than any password.
Trying things safely
If you want to rework a page — or try a whole seasonal look — make a version rather than experimenting on the live site. A version is a private sandbox copy with its own pages, visible only to people who can already see your site, and it can't be found or bought from.
A version is a copy taken at a moment in time, not a running backup. Changes you make to the live site afterwards don't flow into it.
Versions are on the Versions card in your site's Settings, under Access & legal. How many you can keep at once comes from your plan.
Frequently asked questions
No — hosting is included in every plan, along with SSL and the security updates underneath it. There's nothing separate to buy or renew.
Yes, on a regular schedule. If something goes badly wrong, get in touch and we'll help — restoring from a backup is something we do for you rather than a button in your dashboard.
You can export your content — products, customers, orders, and more — as spreadsheets from their own pages. That's the copy worth keeping somewhere of your own, especially before a big import.
No. Everything under your site is patched and updated for you, with nothing to approve and no plugins to keep current.
Included on every site and every page, and it renews itself. There's nothing to buy or install.
Yes. In Settings under Account, choose how your sign-ins are verified — a code from an authenticator app, or a code by email. The app is the stronger option.
Remove them from Staff & permissions on each site they had access to. Their account still exists, so removing them from one site doesn't remove them from the others.
Not a public one. If your site seems down, check it in a different browser or on mobile data first — that rules out your own connection — and then contact us.
Junk and abusive traffic is filtered before it reaches your site, as part of the hosting. It isn't something you configure.
On managed infrastructure with locations around the world, so pages are served from somewhere near your visitor. There's no server of your own to choose, size, or maintain.
