On this page
This Privacy Policy explains what personal data OffshoreServ collects, why, how long we keep it, and the choices you have. We built the service to need as little of your data as possible, so this policy is short on collection and clear on limits. We follow the structure of the EU General Data Protection Regulation because it is a good standard, even where we operate outside the EU.
1. Who is responsible (controller)
The data controller is the operating entity stated in our Terms of Service.
2. Data we collect
We collect only what we need to provide and bill the service:
- Email address
- Your login and the only account identifier. It can be a private or disposable address. We never send email to it, for marketing or anything else: replies, service notices and legal notices appear in your client area.
- Login and security data
- Your password, stored only as an Argon2id hash, and your
two-factor secret, encrypted, if you turntwo-factor authentication on. - Sessions and security log
- For each session and security event (such as a
sign-in or a password change): a summary of the browser and operating system, and the country as reported by Cloudflare. Never your IP address. - Balance ledger and
top-ups - Every credit and debit on your balance and, for each
top-up , the coin, the amount, the deposit address, and the transaction ID, so we can credit your payment. - Service records
- Your plans, their configuration, the IP addresses assigned to your servers, and your renewals.
- Referral codes
- Your own referral code and, if you signed up through another customer's referral link, that customer's code.
- Messages and requests
- The content of the tickets and requests you send from the client area (server actions, payment reports, and withdrawals with the wallet address you give).
- Form
anti-abuse data - A salted hash of the IP address used to submit a form, kept briefly to
rate-limit abuse. It is a hash, not a stored IP.
We have no email address, so no email metadata reaches us. We do not enrich or
3. Data we never collect
To be equally clear about what we do not do:
No KYC . We never ask for your name, postal address, phone number, or identity documents.- No traffic logging or inspection. We do not run deep packet inspection, we do not scan the content of your server, and we do not keep records of what your server sends or receives.
- No IP addresses with your account. Sessions and the security log keep only the browser summary and the country.
- No tracking cookies and no analytics. We run no analytics, no ads, and no
third-party trackers. The only cookie is one strictly necessary session cookie, set when you sign in (HttpOnly, Secure, SameSite=Lax). - Nothing loaded from third parties on public pages. The
sign-up andsign-in forms load Cloudflare Turnstile, aprivacy-friendly check that you are human; no other page loads anything from a third party. - No IP addresses in our web access logs. Server access logs for this website are kept without IP addresses.
4. Purposes and legal bases
We process the data above for these purposes, on these legal bases (using GDPR terms):
| Purpose | Data used | Legal basis |
|---|---|---|
| Provide and manage your services | Email, service records | Performance of a contract |
| Secure your account | Login and security data, sessions and security log | Performance of a contract and legitimate interests |
| Take payment and keep accounts | Balance ledger, | Contract and legal obligation |
| Credit referral commission | Referral codes, orders and renewals | Legitimate interests |
| Support and communication | Messages, service records | Contract and legitimate interests |
| Prevent abuse of our forms and network | Salted IP hash, Turnstile check | Legitimate interests |
| Comply with valid legal orders | Whatever the order compels | Legal obligation |
5. How long we keep data
We keep each type of data only as long as its purpose requires, then delete it.
- Email address and login data
- Until you close your account, plus up to
30 days in backups. - Sessions
- Deleted
7 days after they expire or you sign out, and at once when you close your account. - Security log
180 days , and deleted at once when you close your account.- Balance ledger,
top-up and service records - As long as accounting law requires, up to a maximum of
7 years ; after you close your account, they are kept without your email. - Messages and support requests
12 months .Rate-limit IP hashes- At most
1 hour . - Website access logs (without IP addresses)
14 days .
You can close your account from the client area (Security) once nothing is running on it. Closing it removes your email address and login data, and deletes your sessions and security log; backups age out within
6. Sharing your data
We do not sell your data and we do not share it for advertising.
- No ad networks or data brokers. Ever.
- Legal orders only. We disclose data to an authority only when a valid order from a court competent in the location where the server runs compels us, and only to the extent it compels. See our
law-enforcement guidelines. - Payment gateway. Crypto payments go through a payment gateway that generates the deposit address and watches the blockchain. It receives the amount, the coin, and a random payment reference, never your email or account details.
- Cloudflare Turnstile. The
sign-up andsign-in forms use Cloudflare Turnstile to keep bots out. It runs only on those forms. - Service providers. Where a supplier (for example a data center) is strictly necessary to run the service, they process only what the service requires and are bound to protect it.
- No profiling. We do not profile you or make automated decisions that produce legal or similarly significant effects for you.
7. How we protect data
We keep the data we hold to a minimum, which is the strongest protection of all. In addition:
- Passwords are stored only as Argon2id hashes, and
two-factor secrets are encrypted. - Anything sensitive can be encrypted with our PGP key before you paste it in a ticket.
- Access to account and billing systems is limited to staff who need it.
- Account, billing, and service records are held on systems under our control. We take no card payments, so no card processor ever sees them.
- We do not retain the raw material, such as your traffic or IP address, that would make a breach damaging.
No system is perfectly secure, but by collecting little we make sure there is little to lose.
Your data is processed on systems we control, and the location of your service determines where your server itself sits. Access to account and billing data is restricted to the small number of staff who need it to run the service and support you, and they are bound to keep it confidential. We do not transfer your personal data to advertising partners or data brokers under any circumstances.
8. Your rights
You can exercise the following rights:
- Access: ask what data we hold about you.
- Export: receive a copy of your account and service records.
- Deletion: delete your account and the data tied to it, subject to accounting records we must keep and the backup window in section 5.
- Correction: update your email or service details.
Much of this you can do yourself in the client area, without asking anyone: view your account, services and payments, export your transactions as CSV from Billing, and close your account from Security once nothing is running on it. Closing it deletes your login data; accounting records are kept without your email, as section 5 explains.
Because we hold no identity documents, we act on a request about an account only when we can confirm that it comes from the account holder. We respond within
You may also object to processing based on legitimate interests and, where a supervisory authority has jurisdiction over the operating entity or your service, you have the right to lodge a complaint with it. We would appreciate the chance to resolve your concern first.
9. Children
Our services are for adults and are not directed at children. We do not knowingly collect data from children. Because we require no identifying information, we cannot assess age, so we rely on customers to meet the minimum age required to enter a contract in their jurisdiction.
10. Changes to this policy
If we change this policy, we update the date at the top. For material changes that affect how we handle your data, we give notice at least
11. Contact
Support: tickets from the client area for customers with an active dedicated or GPU server, as how support works explains. We have no email address. The controller is the operating entity stated in our Terms of Service.
Customers with an active dedicated or GPU server can ask us by ticket from the client area. To send something sensitive, encrypt it with our PGP key first.