Policy, in plain language
No KYC hosting, explained properly
What we ask for, what we store, what we hand over, and where the limits are. In plain language, with no marketing in it.
01What we ask for
An email address. That is the whole account creation flow. No phone number, no identity document, no selfie, no proof of address, no company registration and no card. Support is not able to ask you for any of those either, because there is no field to store them in.
02Why we can do this
Identity verification is a requirement of the card networks and the banks behind them, not of hosting law. We settle in crypto through OxaPay, so no acquirer sits between you and us imposing its own onboarding rules. That is the entire mechanism. There is nothing clever about it.
03What we store
Your email address, your invoices, the servers on your account and the tickets you open. Web access logs rotate after seventy-two hours. Hypervisor logs keep only what is needed to diagnose a fault and rotate after fourteen days. We do not inspect the content of your traffic and we do not run deep packet inspection on customer uplinks.
04Where the limits are
No KYC is not the same as no law. Each server lives in a physical building in a real country, and we comply with valid legal process issued by that country. What we can produce is what we hold: an email address, a payment reference and a server allocation. We publish a transparency report every six months with the number of requests received, the number complied with and the number refused.
05What we will not host
Child sexual abuse material, targeting of critical infrastructure, network-flood origination, phishing infrastructure and mass unsolicited email. These are grounds for immediate termination without refund, and are the only categories where we act on our own initiative rather than on legal process.
FAQ
Common questions
No. CrestVPS never asks for identity documents, a phone number, an address or a card. Never. There is no field in our systems to store one and no support workflow that requests one. Account creation is an email address and a password. If anyone contacts you claiming to be CrestVPS support and asks for a document, it is not us.
Web access logs with IP addresses, rotated after seventy-two hours. Hypervisor event logs, rotated after fourteen days. Your email address, invoices, server allocations and tickets, kept while the account exists. We do not perform deep packet inspection on customer uplinks and we do not log DNS queries on the resolver we provide.
We check whether the request is valid legal process from the jurisdiction where the hardware physically sits. If it is, we comply with exactly what it compels and nothing more, which in practice is an email address, a payment reference and a server allocation. If it is not, we refuse. Both outcomes are counted in the transparency report we publish every six months.
VPNs and proxies for your own use or your own users are fine and are one of the most common workloads on the platform. Tor middle relays and bridges are allowed everywhere. Tor exit nodes are allowed only in Amsterdam, Reykjavik and Bucharest, and require you to open a ticket first so we can flag the address with our upstreams.
Add your PGP public key in settings and every message we send, including invoices and root credentials, is encrypted to it. If you lose that key you will need to remove it from the account before you can read our mail again.
Then we cannot recover the account, because the email address is the only identifier we hold for you. This is the direct cost of not collecting anything else. Enable two-factor authentication, store the recovery codes offline, and consider using an address you control the domain for.