Privacy Policy
1. Principle
We run infrastructure, not an advertising business. We collect the minimum needed to deliver what you ordered, bill you for it, keep the network healthy, and answer abuse reports. We do not sell or rent any information about you, and we do not run third-party analytics or advertising trackers on this site.
2. What we collect
- Email address, given at checkout. Used for the order link, delivery of connection details, renewal reminders, suspension and deletion notices, and replies to your support requests.
- Order details: product, region, size, term, price, order ID, the payment invoice ID, provisioning result, and the connection details we generated for you (addresses, ports, and for a VPS the generated SSH key until you delete the service).
- Optional inputs you choose to give: an SSH public key, a game server login token, a CDN origin domain.
- IP address of the browser placing an order or using the chat, kept briefly for rate limiting and abuse prevention (see section 6).
- Acceptance record: the Terms version you accepted and when.
3. What we never collect
- No account, no password, no name, no address, no phone number, no identity documents. There is no KYC.
- No cookies for tracking. The site sets no cookies at all; the order page and checkout work from the URL you are given.
- No third-party analytics, pixels, fonts-as-tracking, or advertising scripts. Fonts are loaded from Google Fonts, which sees the request like any web host does; we receive nothing from it.
- No transcripts of support chat conversations (section 5).
- No access to, or copies of, the data inside your servers (section 7).
4. Payments
Payments are processed by our own self-hosted BTCPay Server at pay.cryptoip.io. It records the invoice, the cryptocurrency address it issued, the amount received and the transaction ID, which is public information on the respective blockchain. We do not receive card numbers, bank details, or wallet identities beyond what the blockchain itself shows. If you pay through the optional swap option on the invoice page, that swap is performed by SideShift and is subject to SideShift's own policy; we receive only the settled payment.
5. Support chat
The chat widget on our site is answered by an AI model. Your messages are sent to Anthropic's API to generate the reply and are handled under Anthropic's commercial data terms. Our own service is stateless: the conversation lives in your browser for the duration of the chat, and we store no transcripts. We keep only daily counters (number of chats, answered, rate-limited, errors) without any message content. Please do not paste private keys or passwords into the chat; email support instead if account-specific help is needed.
6. Logs & security
Our web servers keep standard access logs (IP address, time, requested path, status code) for security and troubleshooting; request bodies are not logged. These logs are rotated automatically and are typically gone within two weeks. Order placement and chat use are rate-limited per IP address using short-lived in-memory counters. Failed SSH attempts against our own infrastructure are logged and blocked automatically. Encrypted backups of our control plane (orders, invoices, configuration) are kept for up to 30 days for disaster recovery; they never include the contents of customer servers.
7. Your server content
What you store or run on your service is yours. We do not inspect it, index it, or copy it, and we keep no backups of it, as stated in the Terms. We look at a service only when required to investigate a credible abuse report, a security incident affecting the network, or when you ask us to. When a service is deleted, its storage is released and overwritten in the normal course of operation.
8. Third parties
- Anthropic (support chat model), SideShift (optional coin swap on invoices), Google Fonts (typefaces), and the upstream data centers hosting our servers, which see network traffic like any carrier.
- Transaction data is public on the blockchain you pay with by the nature of those networks.
- We do not use payment processors, analytics providers, or advertising networks beyond the above.
9. Retention
- Order records and the associated email address: for the life of the service and up to 12 months after it ends, for billing history and abuse handling, then deleted or reduced to non-identifying totals.
- Generated credentials (for example a VPS SSH key): removed when the service is deleted.
- Web access logs: about two weeks. Rate-limit counters: minutes to hours, in memory only.
- Payment invoices in BTCPay Server: kept as required for accounting.
10. Disclosure
We disclose information only when compelled by valid legal process in a jurisdiction that binds us, or when necessary to protect the Service, our users, or the public from ongoing harm. We hold very little, and we say so when asked. We do not voluntarily share customer information with anyone.
11. Your choices
You may use a dedicated or alias email address at checkout. You may ask us to delete the order record and email address once a service has ended by writing to the address below from the email used at checkout, quoting the order ID. Because we hold no account or identity data, requests are verified through that order email and ID.
12. Changes
If this policy changes materially, we update the version and date at the top and note the change on our status page. Continued use after a change means you accept the updated policy.
13. Contact
Privacy questions: support@cryptoip.io. Abuse reports: abuse@cryptoip.io.