Shared Hosting Backup Policies: What to Check Before Signing Up

Published on January 07, 2026 in Shared Hosting

Shared Hosting Backup Policies: What to Check Before Signing Up
Shared Hosting Backup Policies: What to Check Before Signing Up — Hosting Captain

Shared Hosting Backup Policies: What to Check Before Signing Up

By : Billy Wallson January 07, 2026 9 min read
Table of Contents

Why Shared Hosting Backup Policies Deserve Your Full Attention Before You Sign Up

A shared hosting backup policy is the safety net that determines whether a server crash, a malware infection, an accidental file deletion, or a rogue plugin update translates into an hour of inconvenience or a permanent loss of years of content, customer data, and search engine rankings. Yet most people evaluating shared hosting plans fixate on storage gigabytes and bandwidth labels while skipping over the backup section of the terms of service entirely—a decision that has cost real businesses their entire web presence with no recovery path when the worst happened. Shared hosting environments, by their architectural nature as multi-tenant platforms where hundreds of websites coexist on a single physical machine, are exposed to risks that isolated hosting tiers like VPS and dedicated servers do not face: a neighboring account's compromised WordPress installation can trigger a server-wide malware cleanup that sweeps your files into quarantine, a filesystem corruption on the shared storage volume can silently damage databases across every account on that node, and a provider's backup infrastructure failure—which occurs more often than any hosting company's marketing copy would suggest—can mean that the daily backups you assumed were running simply do not exist when you file a restoration request. This guide examines every dimension of shared hosting backup policies with the scrutiny they deserve, from automated backup frequency and retention windows to restoration fees and what is actually included in the backup scope, so that the plan you sign up for includes a backup policy you can genuinely rely on when you need it.

What makes backup policies particularly treacherous in the shared hosting market is that marketing language deliberately blurs the line between a provider's internal disaster recovery backups—snapshots taken to restore the entire server in the event of hardware failure, which are not available for individual account restoration—and per-account backups that you as a customer can access, download, and restore through your control panel. When a shared hosting plan advertises "daily backups included," the statement is technically true in many cases but operationally meaningless if those backups are stored on the same physical server as your live data, retained for only 24 hours before rotation, or accessible only through a paid restoration service that costs $25 to $75 per incident. A shared hosting plan with a genuinely robust backup policy is easily worth an extra $3 to $5 per month compared to a cheaper plan with opaque or minimal backup coverage, because the cost of a single data recovery incident—hiring a developer to rebuild lost pages, re-entering customer orders from paper records, or attempting forensic data recovery from a corrupted database—dwarfs years of that price difference. HostingCaptain has reviewed the backup policies of every major shared hosting provider and distilled the findings into the checklist and comparison framework below, so you can evaluate any plan's backup terms against objective criteria rather than relying on the provider's own description of how "comprehensive" or "enterprise-grade" their backup solution is.

The shared hosting backup landscape in 2026 has improved meaningfully from the state of affairs five years ago, when automated backups were a premium add-on that many entry-level plans excluded entirely, but the improvements are unevenly distributed and many budget providers still treat backups as an afterthought. The rise of NVMe storage, which we examined in our guide to shared hosting disk space, has made backup operations faster and less disruptive to live server performance, and the broader industry shift toward JetBackup as a cPanel-integrated backup management tool has given end users direct control over backup generation, download, and restoration without filing a support ticket. At the same time, the increasing complexity of modern websites—database-driven CMS platforms like WordPress, e-commerce stores with real-time inventory tracking, membership sites with user-generated content—means that a backup that captures only files and neglects databases, or one that backs up databases but skips email accounts, is no longer sufficient to restore a site to full operational status. The sections that follow break down every component of a shared hosting backup policy with enough specificity that you can open any provider's terms of service, knowledge base, or pre-sales chat window and ask the exact questions that separate marketing claims from contractual guarantees.

Automated vs. Manual Backups: The Operational Gap That Matters

The first and most fundamental distinction in shared hosting backup policies is between automated backups—scheduled, hands-off, provider-initiated snapshots that occur on a fixed calendar cadence without any action required from you—and manual backups, which you must trigger yourself through the control panel, an FTP download of your file structure, or a phpMyAdmin export of your database. Automated backups are the baseline of a responsible backup strategy because they remove the single largest point of failure in data protection: human forgetfulness. A website owner who intends to run a manual backup every Friday will, at some point, miss a Friday—during a holiday week, while traveling, during an illness, or simply because the reminder slipped below the threshold of competing priorities—and the backup gap that results is precisely the window during which a catastrophic failure will choose to strike. Automated backups scheduled by the provider eliminate this risk, provided the automation is actually functioning and the resulting backup archives are being written to a storage destination that is separate from the live server.

Manual backups, however, are not obsolete or without value; they serve as a critical complement to automated backups by giving you control over the timing, content, and destination of a backup operation. Before performing a major WordPress core update, migrating to a new theme, installing a plugin with database schema changes, or running a bulk content import, a manual backup created immediately before the operation provides a rollback point that an automated daily backup—which may have run 23 hours ago and missed all the content changes you made today—cannot offer. Manual backups also allow you to store a copy of your site on your local computer, an external hard drive, or a personal cloud storage account like Google Drive or Dropbox, creating an off-provider copy that survives even if your hosting account is suspended, terminated, or caught in a billing dispute. The most responsible shared hosting users adopt a layered approach: they rely on the provider's automated backups for daily protection against routine failures, they create manual backups before any significant site change, and they periodically download a full account backup to local storage as an air-gapped disaster recovery copy. Our Black Friday deals guide notes that many providers bundle enhanced backup features—extended retention, increased frequency, off-server storage—into promotional plan upgrades, making the discount season an opportune time to secure better backup coverage at the same price point.

The practical difference between a provider that offers automated backups and one that expects you to handle backups manually becomes starkly apparent during an incident. With automated backups in place and accessible through the control panel, recovering from a malware infection or a broken update is typically a 10-minute process: log into the control panel, select the most recent clean backup from the restore interface, confirm the restoration target (files only, databases only, or full account), and wait for the restore job to complete. With manual backups only, the same incident requires you to have a recent backup file available, upload it to the server through FTP or the control panel's restore interface, extract archives, import databases through phpMyAdmin, and manually verify that every component—WordPress core files, theme files, plugin directories, uploads folder, database tables—restored correctly, a process that can consume hours and introduce configuration errors that break the site in subtle ways that may not surface for days. When evaluating a shared hosting plan, look for the specific phrase "automated daily backups" in the feature list rather than "backup tools available" or "backup-ready," which are weasel words that indicate the infrastructure exists but the scheduled execution does not.

Shared Hosting Backup Policies: What to Check Before Signing Up — Hosting Captain
Illustration: Shared Hosting Backup Policies: What to Check Before Signing Up
Backup Frequency and Retention: Daily, Weekly, and the Retention Calendar That Defines Your Recovery Window

Backup frequency—how often a new backup snapshot is created—and retention—how long each backup snapshot is preserved before it is rotated out and permanently deleted—are the two parameters that define your recovery point objective (RPO), which is the maximum amount of data you could lose in a worst-case failure scenario. A provider that creates daily backups and retains them for seven days gives you a rolling window of seven restore points, each spaced 24 hours apart, meaning the oldest data you can recover is one week old and the most recent data you can recover is up to 24 hours old. If your site is primarily content-driven—blog posts published a few times per week, static pages that change infrequently—a daily backup with seven-day retention is adequate for most scenarios. If your site processes transactions, accepts user registrations, or hosts a forum or membership area where data changes multiple times per hour, even a 24-hour backup gap can represent a meaningful loss of user-generated content, and you should seek providers that offer more frequent backup intervals—every 6 hours, every 4 hours, or in some premium configurations, hourly—with correspondingly structured retention calendars.

Retention depth beyond the daily rolling window is what allows you to recover from problems that are not immediately detected. A malware infection that was introduced through a plugin update three weeks ago may not manifest symptoms—defacement, SEO spam injection, redirects to phishing sites—until the attacker activates the backdoor, by which time the seven-day rolling backup window has rotated past the clean version of your site and every available restore point contains the compromised code. Providers that offer weekly or monthly retention points in addition to daily snapshots—for example, daily backups retained for 30 days plus weekly backups retained for 90 days—give you the ability to reach back in time and recover a version of your site from before the infection took root. This extended retention is particularly valuable for sites that are not monitored daily by a technical administrator, because the longer the gap between when a problem is introduced and when it is discovered, the deeper your retention calendar needs to reach to find a clean restore point. HostingCaptain recommends that any shared hosting plan you consider for a business website include at minimum 14 days of daily retention and at least one monthly snapshot retained for 90 days; plans that offer only 24 to 72 hours of retention are designed for server failure recovery, not for customer-accessible restoration, and should be treated as having no functional backup policy for your purposes.

The storage capacity allocated to your backups is a separate constraint from the retention calendar and one that is often hidden in the fine print. A provider may advertise 30 days of daily backups but quietly cap the total backup storage at 5 GB or 10 GB, a limit that a moderately sized WordPress site with a 2 GB media library and a 500 MB database will exhaust within a few backup cycles, at which point older backups are pruned regardless of the advertised retention period. If your site's total size—files plus databases—is 3 GB and daily backups consume approximately 3 GB each without deduplication or incremental capture, a 30 GB backup storage allocation would hold roughly 10 restore points, not 30, because each backup is a full copy rather than an incremental delta. Providers that use JetBackup with incremental backup capabilities, or that implement block-level deduplication at the storage layer, can offer dramatically longer retention windows within the same storage budget because each daily backup stores only the blocks that changed since the previous backup. When researching a shared hosting plan, inquire explicitly about total backup storage allocation and whether backups are full or incremental; a provider whose support team cannot answer these questions clearly is unlikely to have engineered their backup infrastructure with the care that reliable data protection demands.

Backup Storage Locations: On-Server, Off-Server, and the Geography of Data Survival

The physical location where backup data is stored is the single most overlooked dimension of shared hosting backup policies and the one that most directly determines whether your backups survive the same incident that took down your live site. Backups stored on the same physical server as your live data—a practice that is distressingly common among budget shared hosting providers—protect against exactly one failure mode: accidental file deletion or user error that does not affect the underlying storage hardware. They provide zero protection against a server power supply failure that corrupts the storage volume, a data center fire or flood, a ransomware attack that encrypts the entire server including the backup directory, or a provider-level administrative error that wipes the wrong disk array. A backup that lives on the same spinning platter or NVMe drive as the data it is backing up is not a backup in any meaningful engineering sense; it is a convenience copy that will disappear simultaneously with the primary data when a hardware-level failure occurs.

Off-server backup storage—where backup archives are written to a physically separate storage node, often in a different rack, and ideally in a different data center or at least a different fire suppression zone within the same facility—is the minimum acceptable standard for a backup policy that offers genuine disaster recovery capability. Most reputable shared hosting providers in 2026 store backups on dedicated backup servers or network-attached storage appliances that are connected to the hosting infrastructure through a private management network rather than the public internet, ensuring that backup traffic does not consume the bandwidth allocated to your website's visitors. Some providers go further and replicate backups to a secondary data center in a different geographic region—for example, primary hosting in Dallas with backups replicated to a facility in Phoenix or Ashburn—creating geographic redundancy that protects against regional disasters like hurricanes, earthquakes, or extended power grid failures. This geographic separation typically adds cost to the provider's infrastructure and is therefore more common on mid-tier and premium shared plans than on entry-level offerings, but the protection it provides is worth inquiring about during the plan evaluation process.

The storage technology underlying the backup destination also matters for restoration speed and reliability. Backups stored on traditional RAID-protected hard drive arrays are vulnerable to the same bit rot and silent data corruption that affects any long-term magnetic storage, and a backup archive that has developed corruption on disk will fail to restore—or worse, restore successfully with corrupted data that propagates errors into your live site—when you need it. Backups stored on object storage platforms with erasure coding (like those built on Ceph or MinIO) or on ZFS-based storage appliances with checksumming and self-healing capabilities provide stronger integrity guarantees because the storage layer actively detects and corrects data corruption without requiring the backup application to implement its own integrity verification. HostingCaptain's evaluation of shared hosting backup infrastructure considers not just whether off-server storage is used but what storage technology backs it, what filesystem integrity mechanisms are in place, and whether the provider performs regular test restores to validate that backup archives are actually recoverable—a practice that distinguishes backup systems that work in theory from those that have been proven to work in practice.

The Restoration Process: How You Actually Get Your Data Back When Things Go Wrong

A backup policy is only as good as the restoration process that turns a backup archive into a functioning website, and the ease, speed, and cost of that restoration process vary dramatically across shared hosting providers. The ideal restoration workflow is self-service through the control panel: you log in, navigate to the backup section, select the date and time of the backup you want to restore, choose whether to restore files, databases, or both, and click a button that queues the restore job. Within minutes—or at most an hour for very large accounts—your site is reverted to the selected restore point, and you can verify the result immediately by visiting your domain. This self-service model, typically powered by JetBackup, Acronis Backup, or a proprietary control panel integration, is the standard that HostingCaptain considers table-stakes for any shared hosting plan in 2026; if you must open a support ticket and wait for a human to perform the restoration on your behalf, the provider's backup infrastructure is not customer-facing, and you should factor that operational friction into your evaluation.

Restoration fees are where backup policies transition from protective to predatory, and they represent one of the most common hidden costs in the shared hosting industry. A provider that advertises "free daily backups" but charges $25 to $75 per restoration incident is not offering free backups; they are offering free backup storage with a paywall in front of the only operation that gives that storage value. These fees are sometimes disclosed in the terms of service under a section titled "Restoration Services" or "Data Recovery," but they are almost never mentioned in the plan comparison table or the marketing feature list where consumers make their purchasing decisions. Some providers waive the restoration fee if the data loss was caused by a provider-level incident—server hardware failure, storage array corruption, data center outage—but charge the fee if the restoration is requested due to customer error, malware infection, or third-party software failure. Others charge the fee universally, framing it as a service cost for the administrative labor involved in performing the restoration. Before signing up for any shared hosting plan, ask the provider's pre-sales team directly: "If I need to restore my website from your automated backups, what is the exact cost per restoration, and is the restoration process self-service through the control panel or do I need to submit a support ticket?" A provider that cannot give a clear, written answer to this question within one business day is not one whose backup claims you should trust.

Partial restoration capability—the ability to restore a single file, a single directory, a single database table, or a single email account without rolling back the entire account to a previous state—is a feature that most shared hosting users do not know to ask for but that dramatically changes the operational experience of using backups. A full account restoration overwrites everything: if you made changes to your theme's CSS yesterday, published three new blog posts this morning, and then discovered that a plugin update corrupted your media library, a full restore from last night's backup would revert the CSS changes and delete the new blog posts to recover the media library—a cure that is arguably worse than the disease. Partial restoration, which JetBackup supports natively for cPanel environments, allows you to browse a backup snapshot as if it were a file system, select exactly the files or database tables you want to recover, and restore only those items while leaving the rest of your live site untouched. This granularity is particularly important for e-commerce stores, membership sites, and multi-author blogs where different parts of the site change at different rates and a full rollback would destroy legitimate data to recover a single corrupted component. When evaluating backup policies, confirm not only that backups are taken but that partial restoration is supported and can be performed through the control panel without tier-2 administrative intervention.

What Is Actually Backed Up: Files, Databases, Emails, and the Gaps You Cannot Afford

The scope of a shared hosting backup—what data types, directories, and services are included in the backup snapshot and what is explicitly excluded—is where the gap between marketing claims and technical reality widens into a chasm that has swallowed entire businesses. A shared hosting account comprises multiple distinct data categories: website files (HTML, PHP, CSS, JavaScript, media uploads, theme and plugin files), databases (MySQL or MariaDB instances containing posts, pages, user accounts, e-commerce orders, form submissions, and configuration settings), email accounts (messages stored on the server via IMAP, address books, forwarders and filters), DNS zone files, SSL certificates, cron job definitions, and control-panel-level configuration like subdomain mappings and redirect rules. A backup that captures only the home directory files and skips the databases produces a restore that looks correct—your theme renders, your pages load—until a visitor clicks on any dynamic content and encounters a database connection error because the posts, products, and user accounts that populate those pages were never backed up and are now gone.

Database inclusion is the most common and most consequential gap in shared hosting backup policies, particularly on entry-level plans where the provider's automated backup script is a simple tar of the home directory with no MySQL dump step. The Mozilla web server documentation explains how web servers handle the boundary between static file serving and application-level processing, and that boundary is exactly where database-backed content lives—accessible to the web server but stored in a completely separate data engine that a file-level backup does not touch. A WordPress site stores every post, page, comment, user profile, plugin setting, and theme customization in its MySQL database; the files in the home directory are essentially the application framework that displays database content, and without the database, those files are an empty shell. When you evaluate a shared hosting plan, verify that the provider's backup scope explicitly includes MySQL and PostgreSQL databases, and ideally confirm that the database backup is performed using a native dump utility like mysqldump with the `--single-transaction` flag rather than a filesystem-level copy of the MySQL data directory, which can produce inconsistent backups if the database engine is actively writing transactions at the moment of the copy.

Email backup inclusion is a less frequently discussed but potentially devastating gap, especially for businesses that use their hosting account's built-in email service for customer correspondence, order confirmations, contract negotiations, and legal communications. Many shared hosting backup systems exclude the mail directory—typically `/home/username/mail/`—from automated backups because email storage can consume tens of gigabytes for accounts that use IMAP with long retention, and including those gigabytes in every daily backup would rapidly exhaust the backup storage allocation. A provider that excludes email from automated backups is making a rational infrastructure decision, but that decision must be disclosed and you must either arrange separate email backup (through an email client that downloads and archives messages locally, or through a third-party email backup service) or accept that server-side email data is not protected. The same consideration applies to ancillary data types: cron job definitions, SSL certificate private keys, custom PHP configuration overrides in php.ini or .user.ini files, and any data stored outside the standard home directory structure. A thorough backup policy evaluation includes asking the provider for a written list of what is excluded from automated backups, because exclusions are almost never advertised in the feature list and are typically discovered only after a restoration attempt fails to recover critical data.

Red Flags in Shared Hosting Backup Policies: The Warning Signs You Should Not Ignore

Certain patterns in a shared hosting provider's backup documentation, terms of service, or pre-sales communication should trigger immediate skepticism regardless of how attractive the plan's price or other features appear. The most significant red flag is the complete absence of backup information from the provider's public-facing website: if you cannot find a dedicated page, knowledge base article, or terms of service section that describes the backup frequency, retention period, storage location, restoration process, and any associated fees, the provider either does not have a defined backup policy or considers it too uncompetitive to publish. In either case, you are being asked to trust that backups exist and work without any verifiable evidence, and the history of the hosting industry is littered with providers whose "trust us" backup promises evaporated the moment a customer filed a restoration request. A legitimate hosting provider treats its backup infrastructure as a competitive differentiator and documents it with the same specificity as its server specifications and uptime guarantee.

Another red flag is language that conflates RAID redundancy with backups, such as "your data is protected by RAID-10 storage" or "our servers use redundant storage arrays." RAID (Redundant Array of Independent Disks) protects against physical disk failure by distributing data across multiple drives with parity or mirroring, ensuring that a single dead hard drive does not cause data loss or downtime. RAID is not a backup; it does not protect against accidental deletion, malware, filesystem corruption, application-level data corruption, or a server-level incident that destroys the entire RAID array. If a provider's answer to the question "what is your backup policy?" is a description of their storage hardware redundancy, they are either deliberately misleading you or do not understand the distinction themselves, and neither scenario inspires confidence. A genuine backup policy creates separate, restorable copies of your data that exist independently of the live storage system; RAID is a component of that live storage system, not a replacement for a backup architecture.

Restoration guarantees that are qualified out of existence are a subtler but equally dangerous red flag. Look for language like "we make every effort to back up customer data but cannot guarantee backup availability" or "backups are provided as a courtesy and are not guaranteed." These disclaimers, which appear in the terms of service of several well-known shared hosting providers, legally absolve the provider of any responsibility if backups are missing, corrupted, or incomplete when you need them. A provider that will not stand behind its backup infrastructure contractually is signaling that its backup infrastructure is not reliable enough to warrant a contractual commitment—and you should believe that signal. The strongest backup policies include a financially backed guarantee: if the provider's automated backups fail and you suffer data loss as a result, the provider offers account credits, free migration assistance, or in some cases direct compensation. While few providers offer this level of commitment, its presence is a powerful signal of infrastructure confidence, and its absence should be factored into your risk assessment alongside the plan's price and other features.

Finally, be wary of backup policies that are exclusively tied to the hosting control panel ecosystem in a way that locks you into the provider. A backup archive that can only be restored through the provider's proprietary control panel—and cannot be downloaded as a standard-format cPanel backup tarball, a zip archive of the home directory, or a SQL dump file—means that your backup data is only useful as long as you maintain an active, paid hosting account with that specific provider. If you decide to migrate to a different host, if your account is suspended due to a billing issue, or if the provider goes out of business, those backups become inaccessible. A properly portable backup policy allows you to generate and download a full account backup in a standard format that can be restored on any cPanel-based host, imported into any MySQL-compatible database server, and extracted on any Linux system with standard tools. Our VPS upgrade guide discusses the migration process in detail, and the portability of your backup archives is the single factor that determines whether a migration is a controlled, planned transition or a frantic scramble to extract data from a proprietary backup format under the pressure of an expiring hosting account.

Backup Policy Comparison Across Major Shared Hosts: What the Landscape Looks Like in 2026

The shared hosting backup policy landscape in 2026 spans a wide spectrum from providers that have invested heavily in customer-facing backup infrastructure to those whose backup capabilities remain essentially unchanged from the cPanel default configurations of a decade ago. At the upper end, providers like SiteGround, A2 Hosting, and KnownHost have built or integrated sophisticated backup platforms that offer daily automated backups with 30-day retention, off-server storage on dedicated backup infrastructure, self-service restoration through the control panel with partial restore capability, and on-demand backup generation that allows customers to create a backup snapshot at any time without waiting for the next scheduled window. These providers typically include backup functionality in all plan tiers—not as a paid add-on—and treat backup reliability as a core product feature rather than an ancillary service. SiteGround's backup system, for example, stores backups on a separate storage network with checksum verification and includes a backup restore tool accessible directly from the Site Tools control panel, with up to 30 restore points available for daily backups and the ability to restore individual files or database tables without a full account rollback.

In the mid-range, many shared hosting providers—including HostGator, Bluehost, and InMotion Hosting—offer automated backups with varying degrees of transparency, accessibility, and fee structures. These providers typically include some form of automated backup in their plans, but the details differ significantly: Bluehost includes daily backups only on its Choice Plus tier and above, leaving the Basic plan without automated backup coverage unless a paid backup add-on is purchased. HostGator provides weekly automated backups on its base shared plans, with daily backups reserved for higher-tier plans, and charges a restoration fee for each restore request processed by support staff. InMotion includes automated daily backups across all shared plans, stores them off-server, and provides JetBackup-powered self-service restoration, making it one of the stronger mid-range options for backup-conscious buyers at the time of writing. The key lesson from surveying the mid-range landscape is that backup features are not consistently correlated with plan price; a $4.99 per month plan from one provider may include stronger backup protections than a $9.99 per month plan from another, and the only way to know is to read the specific backup terms for each provider and plan tier you are evaluating.

At the lower end of the market, the budget shared hosting segment—plans priced below $3.00 per month, often from providers that compete primarily on price—frequently treats backups as either a premium add-on or an operational afterthought. It is common in this segment to find that automated backups are not included at all, that they are included only on an annual billing cycle and excluded from monthly plans, that they are retained for 24 to 48 hours with no extended retention, or that they are stored on the same server as the live data with no off-server replication. Some budget providers run a nightly backup job as part of their server administration but do not expose those backups to customers through the control panel, meaning the backup exists but requires a support ticket and potentially a fee to access. HostingCaptain's recommendation for budget-conscious site owners is to allocate a portion of the money saved on a low-cost hosting plan toward a third-party backup solution—a WordPress backup plugin with offsite storage to Dropbox or S3, or a manual monthly backup routine that downloads a full account archive to local storage—because the gap between the plan's backup coverage and what responsible data protection requires is too wide to leave unfilled.

Questions to Ask Before Signing Up: The Backup Policy Checklist

Armed with the framework established in the preceding sections, you can now approach any shared hosting provider's sales team, knowledge base, or terms of service with a structured set of questions that extract the information you actually need to evaluate their backup policy rather than accepting their marketing summary at face value. The following checklist organizes the essential questions by category and explains what a strong answer looks like versus what should give you pause.

Backup Automation and Frequency

The first set of questions establishes whether backups happen automatically and how often new restore points are created. Ask: "Are backups automated and scheduled, or do I need to trigger them manually?" A strong answer is a clear statement of automation with a specific frequency—"daily automated backups run every 24 hours" or "automated backups run every 6 hours." A weak answer is any variation of "backup tools are available in the control panel" or "you can create backups whenever you want," which describes manual backup capability rather than automated protection. Follow up with: "What exact time do backups run, and how long does the backup process typically take for an average shared hosting account?" The timing matters because a backup that runs during your site's peak traffic hours can compete for server I/O and CPU resources, slowing down your site for visitors during the backup window. Providers that schedule backups during off-peak hours—typically between 1:00 AM and 5:00 AM in the data center's local timezone—minimize this performance impact.

Retention and Storage Depth

Retention questions determine how far back in time you can reach to find a clean restore point. Ask: "How many days of daily backups are retained, and are weekly or monthly snapshots also kept?" A strong answer specifies a retention calendar like "daily backups retained for 30 days, weekly backups retained for 90 days" or provides a specific number of restore points with their spacing. A weak answer is vague language like "multiple restore points are available" or "backups are kept for a reasonable period," which gives you no actionable information about your recovery window. Also ask: "Is there a total storage cap on backup data, and what happens when my backup data exceeds that cap?" A transparent provider will state the cap—"10 GB of backup storage per account"—and explain whether older backups are pruned automatically or whether backup creation stops until you reduce your account size. A provider that cannot or will not specify a backup storage cap is likely either imposing a cap without disclosing it or has not engineered their backup system to handle growth predictably.

Backup Scope and Exclusions

Scope questions identify what is and is not protected. Ask: "Do your automated backups include MySQL databases, and are the database dumps created using mysqldump or a similar consistent-snapshot method?" A strong answer confirms both database inclusion and the use of a database-native dump tool that ensures transactional consistency. Also ask: "Are email accounts and email data included in the automated backups?" and listen carefully for the answer—many providers will confirm file and database backup but pause or redirect when asked about email specifically. If email is excluded, ask whether email data can be backed up manually and what the process is. Additionally, ask: "Are there any specific file types, directories, or data categories that are excluded from automated backups?" Error logs, cache directories, temporary files, and backup archives themselves are commonly and reasonably excluded, but you need to know the full list to assess whether any excluded category contains data you cannot afford to lose.

Storage Location and Redundancy

Storage location questions reveal whether your backups can survive the same incident that takes down your live site. Ask: "Are backup archives stored on the same physical server as my live hosting account, or on separate backup infrastructure?" A strong answer confirms off-server storage, ideally with geographic redundancy: "Backups are stored on dedicated backup servers in a separate rack, with replication to a secondary data center." A weak answer describes RAID or local disk redundancy without addressing physical separation from the live server. Follow up with: "Is backup storage replicated to a different geographic region or data center?" Geographic redundancy adds meaningful protection against facility-level disasters but is not universally offered, and its presence or absence should factor into your own risk tolerance and whether you need to supplement the provider's backups with your own offsite copies.

Restoration Process and Costs

Restoration questions are the most operationally consequential because they determine what actually happens when you need to use the backups. Ask: "Can I restore backups myself through the control panel, or do I need to submit a support ticket?" A strong answer describes a self-service restoration interface—JetBackup, Acronis, or a proprietary tool—that allows you to select a restore point and initiate restoration without human intervention. Also ask: "Is partial restoration supported? Can I restore a single file, a single database table, or a single email account without rolling back my entire account?" The answer to this question often reveals the sophistication of the backup platform; providers using modern backup management tools can support partial restoration, while those using legacy scripts typically cannot. Finally, ask the direct question: "What is the exact fee, if any, for a backup restoration, and under what circumstances is that fee waived?" Get this answer in writing—in a pre-sales ticket or a live chat transcript—because verbal assurances from sales representatives about free restorations have a way of disappearing when the billing department processes a restoration request six months later.

Backup Export and Portability

Portability questions protect your ability to leave the provider without losing your backup history. Ask: "Can I download a full account backup in a standard format—cPanel backup tarball, zip archive, or SQL dump—that can be restored on a different hosting provider?" A strong answer confirms downloadable backups in standard formats, ideally with the ability to generate and download a backup on demand through the control panel rather than waiting for the next scheduled backup window. A weak answer restricts backup data to the provider's own infrastructure with no export capability, which means your backup data is effectively held hostage as long as you remain a customer. Also ask: "Are there any limits on how many backup downloads I can perform per month?" Some providers throttle or charge for backup downloads to manage bandwidth consumption, and knowing the limits before you need to execute an emergency migration prevents a bottleneck at the worst possible moment.

Building Your Own Backup Layer: When the Provider's Policy Is Not Enough

Even the strongest shared hosting backup policy should be supplemented with a backup layer that you control independently, because no provider's backup infrastructure can cover every failure scenario and because the provider's incentives—to minimize support costs, to retain you as a customer, to avoid the infrastructure expense of extended retention—are not perfectly aligned with your interest in comprehensive, immediately accessible, portable data protection. A provider's backups protect against server-level failures, routine operational errors, and the types of incidents that the provider's support team is equipped to handle at scale. Your own independent backups protect against scenarios that fall outside the provider's scope: a billing dispute that results in account termination with no grace period for data extraction, a provider-level security breach that compromises the backup storage infrastructure, a provider acquisition or shutdown that gives customers 30 days to migrate with overloaded support queues, or simply the desire to test a migration to a VPS or a different shared host without relying on the current provider's tools and timelines.

For WordPress sites—which represent the majority of websites hosted on shared platforms—the independent backup layer can be implemented in under an hour using a plugin like UpdraftPlus, BackWPup, or Duplicator, each of which can be configured to create automated backups of both files and databases on a schedule you define and to upload those backup archives to remote storage destinations that you control: Google Drive, Dropbox, Amazon S3, Backblaze B2, Microsoft OneDrive, or an SFTP server. The annual cost of the remote storage for a typical shared-hosted WordPress site is under $15 for up to 10 GB on Backblaze B2, and the peace of mind of having a provider-independent, offsite, encrypted backup that you can restore to any hosting environment without involving your current provider's support team is disproportionate to that cost. Configure the plugin to run daily database backups and weekly or daily full file backups, set a retention policy that keeps at least four weekly full backups, and enable the plugin's integrity check feature if available to verify that backup archives are not silently corrupted. This independent layer does not replace the provider's backups; it complements them, creating the backup diversity that is the hallmark of a genuinely resilient data protection strategy.

For non-WordPress sites—static HTML sites, custom PHP applications, or sites built on CMS platforms like Joomla, Drupal, or Magento—the independent backup layer requires a bit more manual configuration but follows the same principles. Use the hosting control panel's backup tool to generate a full account backup (home directory plus databases plus email) on a weekly schedule, download that backup archive to your local computer or upload it to a personal cloud storage account, and set a recurring calendar reminder to ensure the routine does not lapse. cPanel's Backup Wizard and DirectAdmin's Backup/Restore tool both support generating and downloading full account backups through a browser interface, and most providers allow you to automate the generation side through cron jobs while still requiring a manual download step. Alternatively, if you have SSH access (increasingly common on shared hosting plans as providers adopt jailshell environments), a cron-driven shell script that runs mysqldump, tars the home directory, and uploads the result to a remote server via scp or rclone provides a fully automated independent backup pipeline that costs nothing beyond the remote storage. The specific implementation matters less than the principle: your data's survival should not depend entirely on a single provider's infrastructure, policies, and continued operation, and the modest effort required to establish an independent backup layer is the cheapest insurance policy you will ever buy for your website.

Frequently Asked Questions

What is a shared hosting backup policy, and why does it matter more than other plan features?

A shared hosting backup policy defines how your website's files, databases, and sometimes email data are copied and preserved by the hosting provider on a scheduled basis, including the frequency of those copies, how long they are retained, where they are stored, and how you can access them for restoration. It matters more than storage space or bandwidth because those resources can be upgraded incrementally as your site grows, but data that is lost due to an inadequate or nonexistent backup policy is gone permanently—there is no undo button, no support ticket that can recover a file that was never backed up, and no amount of plan upgrade that retroactively creates a backup of data that has already been deleted or corrupted. Every other feature of a hosting plan—speed, uptime, support quality, included email, SSL certificates—exists to serve and protect a website that is only as durable as its most recent verified backup, which is why backup policy evaluation should be the first filter you apply to any hosting plan comparison, not an afterthought checked after the price and disk space look attractive.

How can I tell if a provider's backup claims are real or just marketing language?

The most reliable method is to ask specific, technical questions through the provider's pre-sales support channel and evaluate the clarity, specificity, and promptness of the answers. A provider with a genuinely robust backup infrastructure will answer questions about backup frequency, retention depth, storage location, restoration process, and fees with precise details—numbers, product names like JetBackup or Acronis, storage infrastructure descriptions—rather than vague assurances. If the pre-sales team cannot answer backup-specific questions and escalates them to a technical team, note how long the escalation takes and whether the final answer contains the level of detail you would expect from a provider that has invested in its backup platform. Additionally, search for the provider's name alongside terms like "backup failure," "restoration fee," "lost data," and "backup not working" in web hosting forums, Reddit communities like r/webhosting, and review platforms like Trustpilot; real customer experiences with backup restoration—both positive and negative—are more informative than any policy document because they reveal how the backup system actually performs under the conditions that matter: when a customer needs their data back urgently.

What should I do if my shared hosting plan does not include automated backups?

If your current or prospective shared hosting plan does not include automated daily backups, you have three options: upgrade to a plan tier that includes them, implement your own automated backup solution using the tools available within your hosting environment, or switch to a provider whose entry-level plans include backup coverage. The third-party backup approach is viable and, for many site owners, preferable because it gives you full control over backup scheduling, retention, and storage destination. For WordPress sites, install a backup plugin like UpdraftPlus, configure it to run daily backups to an offsite destination like Google Drive or Backblaze B2, and verify the first automatic backup completes successfully. For non-WordPress sites, use the control panel's cron job feature to schedule a script that creates a database dump and archives the home directory, then manually download the archive periodically or configure automatic upload to a remote storage service if your hosting environment supports the necessary tools. The critical point is to take action immediately; every day your site operates without a verified, restorable backup is a day when an incident could cause permanent data loss, and the probability of that incident occurring is not zero on any shared hosting platform.

Are paid backup add-ons from shared hosting providers worth the extra cost?

Paid backup add-ons—typically priced between $2 and $5 per month and marketed under names like "Automatic Backup Pro," "Site Backup," or "Advanced Backup"—are generally worth the cost if they add capabilities that meaningfully improve your recovery options beyond the free or included backup tier. The features to look for in a paid backup add-on include: increased backup frequency from daily to every 6 or 4 hours, which reduces your maximum data loss window from 24 hours to a fraction of a business day; extended retention from 7 or 14 days to 30 or 90 days, which allows recovery from problems discovered long after their introduction; off-server or offsite storage that protects against server-level failures; self-service restoration with partial restore capability; and the ability to generate and download on-demand backups in portable formats. If the paid add-on primarily offers the same daily backups that the base plan already includes but with slightly larger storage quotas or cosmetic control panel changes, the value proposition is weaker. Compare the cost and capabilities of the provider's paid backup add-on against the cost and capabilities of implementing your own independent backup layer—often the independent layer offers better portability and offsite storage for a comparable or lower total cost, and it remains with you if you switch hosting providers.

How does backup policy quality change when I upgrade from shared hosting to VPS?

When you upgrade from shared hosting to a VPS, the backup responsibility model fundamentally shifts from provider-managed to self-managed unless you specifically purchase a managed VPS plan that includes backup services. On an unmanaged VPS, the provider typically offers snapshot functionality—the ability to take a point-in-time image of your entire virtual server's storage volume—through the control panel or API, but those snapshots are a tool for you to use, not an automated service that runs on a schedule unless you configure the automation yourself. This shift can be jarring for site owners accustomed to shared hosting where backups "just happen" in the background, and it is one of the reasons that managed VPS plans and fully managed dedicated servers exist: they restore the provider-handled backup automation while delivering the resource guarantees and isolation of a virtualized or bare-metal environment. If you are considering a VPS upgrade and backup reliability is important to you, factor the cost of a backup automation solution—whether a server management panel with backup scheduling, a third-party backup service, or the labor cost of configuring and maintaining your own backup scripts—into the total cost of the upgrade. Our VPS hosting guide includes a full section on backup strategies for self-managed virtual servers, covering snapshots, offsite automation tools like BorgBackup and Restic, and the 3-2-1 backup rule applied to single-server environments.

What is the single most important thing to verify about a shared hosting backup policy before purchasing?

The single most important verification is whether you can independently download a complete, restorable copy of your website—files and databases—without relying on the provider's infrastructure, support team, or continued operation as a business. This verification takes the form of two specific questions: "Can I generate and download a full account backup through the control panel at any time, without filing a support ticket?" and "Is the downloaded backup in a standard, portable format that can be restored on a different hosting provider's servers?" If the answer to both questions is an unqualified yes, you have the escape hatch that protects you against every provider-side failure mode—billing disputes, provider bankruptcy, service degradation, platform lock-in—because you can take your data and leave at any time, on your own schedule, without negotiating with a support team that may or may not be motivated to facilitate your departure. If the answer to either question is no or is qualified with conditions, limitations, or fees, you are operating without the fundamental data portability that should be non-negotiable in any hosting relationship. At HostingCaptain, we consider backup portability to be as essential to a hosting plan as the server that serves the web pages, and we recommend that our readers apply this portability test to every hosting provider they evaluate, regardless of how attractive the plan's other features appear.

Billy Wallson

Billy Wallson

Senior Director

Billy Wallson is a senior operations director with over 15 years of experience scaling remote teams and implementing lean business strategies.

Frequently Asked Questions

This guide covers the practical decision points — pricing, performance, and when it makes sense for your situation — based on current 2026 data.
Pricing varies by provider and plan tier; see the cost breakdown section above for current ranges and what's actually included at each price point.
Look closely at uptime guarantees, renewal pricing (not just the first-year discount), and how responsive support actually is — all covered in detail in this article.

What Our Customers Are Saying

Trusted Technologies & Partners

  • Technology Partner
  • Technology Partner
  • Technology Partner
  • Technology Partner
  • Technology Partner
  • Technology Partner
  • Technology Partner
  • Technology Partner