Your terms and your acceptable use policy are the documents you reach for on the worst day: a client whose site is compromised, a dispute over a refund, a request to host something you would rather not. Written before you need them, they turn arguments into references.
This is not legal advice, and a lawyer should see the final version. What follows is what actually gets used.
Two documents, two jobs
Terms of service covers the commercial relationship: what you provide, what it costs, how it renews, how either side ends it.
Acceptable use policy covers what may run on the server: prohibited content, resource limits, what happens when a site misbehaves.
Keep them separate. The AUP is the one you cite when suspending an account, and it is easier to point at when it is not buried inside billing terms.
Say what happens when a site is compromised
The clause you will use most, and the one whose absence causes the worst conversations.
State plainly that you may suspend an account immediately if it is sending spam, serving malware, or attacking other systems, before contacting the client, because the damage is ongoing and shared by every account on the server.
Then state what the client must do to be restored: the entry point closed, software updated, passwords changed.
A client who agreed to that at signup reacts entirely differently from one meeting it for the first time while offline. Handling an abuse report explains the process the clause authorises.
Define resource limits in words, not just numbers
Disk and bandwidth figures are in the package. The AUP is where you say what happens when a site consistently exceeds what a shared plan can give.
Avoid "unlimited" entirely. Every unlimited offer has a fair use clause, and the gap between the headline and the clause is where disputes live. A generous specific number is more honest and easier to enforce.
Say what you do first, contact them, discuss an upgrade, and what you do if that goes nowhere. A client throttled without warning is a complaint; one who had two conversations first is an upgrade.
Backups: say what you actually provide
The clause that prevents a genuinely bad day.
If your backups are a courtesy instead of a service, say so explicitly, and say that the client is responsible for their own copies. If you do guarantee backups, state the frequency, the retention, and how a restore is requested.
What you must not do is leave it vague. A client who lost a year of work and believed you had nightly backups is a dispute you cannot win on goodwill. There is more on making the promise deliverable before you make it in WHM backup strategy.
Support: scope and hours
What is included, what is chargeable, and when you answer.
The line most resellers need is between hosting support and site support: a broken server is yours, a broken plugin is theirs. Without that written down, every WordPress question becomes your unpaid job.
State response targets you can actually meet, not aspirational ones. "Within one business day" that you hit beats "within one hour" that you miss.
Refunds and cancellation
Whether there is a money-back period and what it excludes: domain registrations almost always, since you cannot get that money back either.
Notice period for cancellation, and what happens to data afterwards: how long you keep it, and when it is deleted. What to Do When a Client Leaves goes into doing that cleanly.
Be clear that a client's data is theirs and will be provided on request. Whatever the invoice situation, withholding it is a position you do not want to defend.
Prohibited content, specifically
A short list beats a long one. Illegal material, spam operations, phishing, malware distribution, and content that would get your server null-routed by your upstream.
Then a general clause for anything that puts the server or your relationship with your provider at risk; you cannot enumerate everything, and you need the discretion.
Note that your own upstream provider's AUP applies to you, and therefore to your clients. You cannot permit what your provider forbids, so read theirs before writing yours.
Price changes and renewals
How much notice before a price rises, and whether existing clients keep their rate.
Say when renewal invoices are issued and when auto-renewal charges. The most common billing complaint is a charge that arrived without warning, and it is entirely preventable by saying "we invoice 14 days before renewal" and doing that.
Make them agree to it, and keep the version
A policy nobody accepted is hard to enforce. A checkbox at signup, recording the date and the version they agreed to, is enough for most purposes.
Keep old versions. When a dispute concerns something that happened last year, the terms that applied then are the ones that matter, and "we changed it since" is not a defence you want to rely on.
Give notice before changes take effect rather than updating silently.
Write it in plain language
Terms copied from a large provider are written for a different business and full of clauses that do not apply to you. Clients do not read them, and you will not remember what they say.
Short, specific, readable. Then have a lawyer check it in your jurisdiction, because consumer law sets minimums you cannot contract out of, and a clause that is unenforceable is worse than none: it undermines the parts that are. Reseller best practices covers the operational habits these documents support.