CrestVPS

Last updated 2026-06-01

Privacy policy

This policy describes every category of personal data we hold, why we hold it and how long. It is short because the list is short.

What we collect

Your email address, which you provide. Your invoices and payment references, which are generated when you buy. The servers on your account and their addresses. The tickets you open and our replies. Web server access logs containing IP addresses, timestamps and requested paths. That is the complete list.

What we do not collect

We do not ask for or store identity documents, phone numbers, physical addresses, dates of birth, card details or bank account numbers. We do not run analytics scripts, we do not embed third-party trackers, we set no advertising cookies and we do not build behavioural profiles. The only cookie we set is a session cookie after you sign in.

How long we keep it

Access logs rotate after seventy-two hours. Hypervisor event logs rotate after fourteen days. Account data, invoices and tickets are kept while the account exists and for the period tax law in the Netherlands requires for invoices, which is seven years. Everything else is deleted within twenty-four hours of account deletion.

Who we share it with

Our payment processor receives an invoice amount and reference, never your identity, because we do not have one. Our transactional email provider receives your address to deliver mail. Nobody else receives anything, and we sell nothing to anybody under any circumstances.

Legal disclosure

We disclose data only in response to valid legal process from the jurisdiction where the relevant hardware sits, and only what that process compels. We publish the number of requests received, complied with and refused every six months in our transparency report. Where we are legally permitted to notify you of a request, we do.

Your rights

You may request a copy of everything we hold, correct it, or have it erased, from the dashboard or by ticket. Erasure requests are executed within twenty-four hours except for invoices we are required to retain. There is no verification step because there is nothing to verify against: control of the email address is the identity.

Security

Data at rest on our management systems is encrypted. Access to production requires hardware tokens and is logged. Customer volumes are encrypted at rest at the storage layer by default, and you can add your own LUKS layer that we hold no key for.

CrestVPS B.V. · AS204871 · [email protected]