Off the server
A backup stored on the same machine as the site is not a backup. If the disk fails or the server is compromised, both copies go together.
Backups
Buyers compare hosting on disk space and bandwidth. Almost nobody asks what happens the day the site has to come back from nothing.
Not "do you take backups" — almost everyone says yes. Ask how far back they go, whether the database is included, how long a restore takes, and whether anyone has ever performed one. The answers are usually less reassuring than the marketing.
Plenty of hosting terms describe backups as a courtesy with no guarantee of availability or completeness. That is a reasonable position for them to take and a bad one for you to depend on.
Disk failure is the story people imagine and the least likely cause. The real ones are mundane: an update that broke something subtly, a page deleted by accident, a compromised plugin quietly injecting content, or a staff member overwriting the wrong file. Each of those needs a copy from before — which means retention matters as much as frequency.
Backups belong with maintenance and hosting, because the same person should be responsible for taking them, verifying them, and using them under pressure.
Four rules
A backup stored on the same machine as the site is not a backup. If the disk fails or the server is compromised, both copies go together.
Automated, so the frequency matches how often your content changes rather than how often somebody remembers.
Half a backup is not useful. The database without the uploads, or the uploads without the database, will not bring a site back.
Verification means performing a restore and confirming the result — the only way to know a backup works is to use it.
Straight answers
Many do, and their terms often say the backups are provided as a courtesy with no guarantee. Read them. Where a host does keep backups, they are frequently retained for a short window and restored only on request — which is not helpful if you need last Tuesday.
Retention is set to what you need. Longer retention matters more than people expect, because some problems — a bad edit, a slow-moving compromise — are only noticed weeks later.
Hardware failure is the least common cause. In practice it is a bad update, a deleted page, a compromised plugin, or somebody overwriting the wrong thing. Ransomware and hosting-account disputes are the ugly cases.
Usually yes, provided we can get appropriate access. It works better when we run the hosting, but it is not a requirement.
Start here
If you're not certain, that's worth resolving while it's a question rather than an emergency.