---
title: "Privacy Policy: What We Store and for How Long"
description: "What OffshoreServ collects and never collects: an email address, billing and service records. No KYC, no tracking cookies, no analytics."
url: https://offshoreserv.com/privacy-policy
lang: en
updated: 2026-09-27
source: HTML page at the url above (canonical); this is its Markdown version
---

Legal & privacy

# Privacy Policy

What OffshoreServ collects and what it never collects: an email address, billing and service records, with no KYC, no tracking cookies, and no analytics.

Updated 27 September 2026 7 min read All services, all 7 jurisdictions

Key points

- The only personal detail we require is an email address, which can be disposable.
- We do not log or inspect your server traffic, and we store no IP address with your account.
- This website sets no tracking cookies: the only cookie is your session, once you sign in.
- We keep data only as long as each purpose needs, then delete it.
- We share data only when a valid local court order compels us, never with ad networks.
- Crypto payments settle on public blockchains, which are visible to everyone.

Version 1.2[How support works](https://offshoreserv.com/contact)

This Privacy Policy explains what personal data OffshoreServ collects, why, how long we keep it, and the choices you have. We built the service to need as little of your data as possible, so this policy is short on collection and clear on limits. We follow the structure of the EU General Data Protection Regulation because it is a good standard, even where we operate outside the EU.

## 1. Who is responsible (controller)

The data controller is the operating entity stated in our [Terms of Service](https://offshoreserv.com/terms).

## 2. Data we collect

We collect only what we need to provide and bill the service:

- **Email address**: Your login and the only account identifier. It can be a private or disposable address. We never send email to it, for marketing or anything else: replies, service notices and legal notices appear in your client area.
- **Login and security data**: Your password, stored only as an Argon2id hash, and your two-factor secret, encrypted, if you turn two-factor authentication on.
- **Sessions and security log**: For each session and security event (such as a sign-in or a password change): a summary of the browser and operating system, and the country as reported by Cloudflare. Never your IP address.
- **Balance ledger and top-ups**: Every credit and debit on your balance and, for each top-up, the coin, the amount, the deposit address, and the transaction ID, so we can credit your payment.
- **Service records**: Your plans, their configuration, the IP addresses assigned to your servers, and your renewals.
- **Referral codes**: Your own referral code and, if you signed up through another customer's referral link, that customer's code.
- **Messages and requests**: The content of the tickets and requests you send from the client area (server actions, payment reports, and withdrawals with the wallet address you give).
- **Form anti-abuse data**: A salted hash of the IP address used to submit a form, kept briefly to rate-limit abuse. It is a hash, not a stored IP.

We have no email address, so no email metadata reaches us. We do not enrich or cross-reference your data with outside sources, and we do not build a profile of you from it.

## 3. Data we never collect

To be equally clear about what we do *not* do:

- **No KYC.** We never ask for your name, postal address, phone number, or identity documents.
- **No traffic logging or inspection.** We do not run deep packet inspection, we do not scan the content of your server, and we do not keep records of what your server sends or receives.
- **No IP addresses with your account.** Sessions and the security log keep only the browser summary and the country.
- **No tracking cookies and no analytics.** We run no analytics, no ads, and no third-party trackers. The only cookie is one strictly necessary session cookie, set when you sign in (HttpOnly, Secure, SameSite=Lax).
- **Nothing loaded from third parties on public pages.** The sign-up and sign-in forms load Cloudflare Turnstile, a privacy-friendly check that you are human; no other page loads anything from a third party.
- **No IP addresses in our web access logs.** Server access logs for this website are kept without IP addresses.

## 4. Purposes and legal bases

We process the data above for these purposes, on these legal bases (using GDPR terms):

| Purpose | Data used | Legal basis |
| --- | --- | --- |
| Provide and manage your services | Email, service records | Performance of a contract |
| Secure your account | Login and security data, sessions and security log | Performance of a contract and legitimate interests |
| Take payment and keep accounts | Balance ledger, top-up records | Contract and legal obligation |
| Credit referral commission | Referral codes, orders and renewals | Legitimate interests |
| Support and communication | Messages, service records | Contract and legitimate interests |
| Prevent abuse of our forms and network | Salted IP hash, Turnstile check | Legitimate interests |
| Comply with valid legal orders | Whatever the order compels | Legal obligation |

## 5. How long we keep data

We keep each type of data only as long as its purpose requires, then delete it.

- **Email address and login data**: Until you close your account, plus up to 30 days in backups.
- **Sessions**: Deleted 7 days after they expire or you sign out, and at once when you close your account.
- **Security log**: 180 days, and deleted at once when you close your account.
- **Balance ledger, top-up and service records**: As long as accounting law requires, up to a maximum of 7 years; after you close your account, they are kept without your email.
- **Messages and support requests**: 12 months.
- **Rate-limit IP hashes**: At most 1 hour.
- **Website access logs (without IP addresses)**: 14 days.

You can close your account from the client area ( **Security**) once nothing is running on it. Closing it removes your email address and login data, and deletes your sessions and security log; backups age out within 30 days. Records we must retain for accounting are kept, without your email, until that obligation ends.

## 6. Sharing your data

We do not sell your data and we do not share it for advertising.

- **No ad networks or data brokers.** Ever.
- **Legal orders only.** We disclose data to an authority only when a valid order from a court competent in the location where the server runs compels us, and only to the extent it compels. See our [law-enforcement guidelines](https://offshoreserv.com/law-enforcement).
- **Payment gateway.** Crypto payments go through a payment gateway that generates the deposit address and watches the blockchain. It receives the amount, the coin, and a random payment reference, never your email or account details.
- **Cloudflare Turnstile.** The sign-up and sign-in forms use Cloudflare Turnstile to keep bots out. It runs only on those forms.
- **Service providers.** Where a supplier (for example a data center) is strictly necessary to run the service, they process only what the service requires and are bound to protect it.
- **No profiling.** We do not profile you or make automated decisions that produce legal or similarly significant effects for you.

> **Public blockchains.** Crypto payments settle on public blockchains. A transaction, its amount, its timing, and the wallet addresses involved are recorded on-chain and are visible to anyone, permanently. That is a property of the networks, not something we control. If you need stronger payment privacy, consider a privacy-preserving coin such as Monero. See [crypto payments](https://offshoreserv.com/crypto-payments).

## 7. How we protect data

We keep the data we hold to a minimum, which is the strongest protection of all. In addition:

- Passwords are stored only as Argon2id hashes, and two-factor secrets are encrypted.
- Anything sensitive can be encrypted with our [PGP key](https://offshoreserv.com/pgp) before you paste it in a ticket.
- Access to account and billing systems is limited to staff who need it.
- Account, billing, and service records are held on systems under our control. We take no card payments, so no card processor ever sees them.
- We do not retain the raw material, such as your traffic or IP address, that would make a breach damaging.

No system is perfectly secure, but by collecting little we make sure there is little to lose.

Your data is processed on systems we control, and the location of your service determines where your server itself sits. Access to account and billing data is restricted to the small number of staff who need it to run the service and support you, and they are bound to keep it confidential. We do not transfer your personal data to advertising partners or data brokers under any circumstances.

## 8. Your rights

You can exercise the following rights:

- **Access:** ask what data we hold about you.
- **Export:** receive a copy of your account and service records.
- **Deletion:** delete your account and the data tied to it, subject to accounting records we must keep and the backup window in section 5.
- **Correction:** update your email or service details.

Much of this you can do yourself in the client area, without asking anyone: view your account, services and payments, export your transactions as CSV from **Billing**, and close your account from **Security** once nothing is running on it. Closing it deletes your login data; accounting records are kept without your email, as section 5 explains.

Because we hold no identity documents, we act on a request about an account only when we can confirm that it comes from the account holder. We respond within 30 days. Note that we cannot delete public blockchain records, which are outside our control.

You may also object to processing based on legitimate interests and, where a supervisory authority has jurisdiction over the operating entity or your service, you have the right to lodge a complaint with it. We would appreciate the chance to resolve your concern first.

## 9. Children

Our services are for adults and are not directed at children. We do not knowingly collect data from children. Because we require no identifying information, we cannot assess age, so we rely on customers to meet the minimum age required to enter a contract in their jurisdiction.

## 10. Changes to this policy

If we change this policy, we update the date at the top. For material changes that affect how we handle your data, we give notice at least 30 days in advance in your client area and on this page, consistent with our [Terms of Service](https://offshoreserv.com/terms).

## 11. Contact

Support: tickets from the client area for customers with an active dedicated or GPU server, as [how support works](https://offshoreserv.com/contact) explains. We have no email address. The controller is the operating entity stated in our [Terms of Service](https://offshoreserv.com/terms).

**Questions about this page?**

Customers with an active dedicated or GPU server can ask us by ticket from the [client area](https://offshoreserv.com/account/support). To send something sensitive, encrypt it with our [PGP key](https://offshoreserv.com/pgp) first.

---

OffshoreServ is an offshore hosting provider: VPS, dedicated servers, Windows RDP and GPU servers in seven jurisdictions (Iceland, Switzerland, Moldova, Romania, the Netherlands, Bulgaria and Malaysia), paid only in cryptocurrency (Bitcoin, Ethereum, Monero, Tether (USDT) and Solana), with no identity checks (no KYC).

Prices and plans: https://offshoreserv.com/pricing · Answers: https://offshoreserv.com/faq · Every page: https://offshoreserv.com/llms.txt
