Privacy
Last updated 2026-08-23
The short version: we collect an email address, the IP you signed up from, and what you send us in tickets. We do not ask for your name, your address, your phone number or any identity document, and we cannot hand over what we never collected.
1What we collect
- Email address. The account identifier, and how we reach you about renewals, suspensions and credentials.
- Signup IP address. Kept because it is the only thread we have when an abuse report arrives. Without any identity data, it is that or nothing.
- Payment records. On-chain transaction hashes, amounts, and the deposit address assigned to you.
- Service records. Which servers you have, their IPs, and the root credentials we generated for you — encrypted at rest.
- Support tickets and the access logs of our own website.
2What we deliberately do not collect
No legal name, no postal address, no phone number, no government ID, no card details. This is a design decision, not an oversight: data we do not hold cannot leak, cannot be subpoenaed from us, and cannot be sold by a future owner of this business.
3Your deposits are on a public blockchain
TRC-20 and ERC-20 transactions are permanently public. Anyone who learns your deposit address can see every payment you have ever made to it, and trace it back to whatever exchange or wallet it came from. We assign one permanent address per account, which means all of your deposits are linked to each other on-chain.
This is a property of the payment method, not something we can change. If it matters to you, use a wallet you do not use for anything else.
4Who else sees your data
- Our datacentre and network providers. They carry the traffic to and from your server, as they do for any hosted service. They do not receive your account details.
- Resend — delivers our transactional email, so it processes your address and the content of those messages.
- TronGrid and our Ethereum RPC provider — we query them for the deposit addresses we watch, so they can see which addresses we are interested in.
- Cloudflare — sits in front of this website and sees request metadata.
We do not sell your data, and we do not run advertising or analytics trackers.
5Credentials
Server passwords are encrypted with AES-256-GCM and only decrypted when you click to reveal them. Every reveal is logged. We never send a password by email. When a service is terminated the stored credentials are deleted, not archived.
If you supply an SSH public key when ordering, we never generate a password for that server at all — which is the better option, and the one we recommend.
6How long we keep things
- Account and billing records: for as long as the account exists, then as required for accounting purposes.
- Server credentials: deleted when the service is terminated.
- Signup IP and abuse records: retained while the account exists, because they are what let us tell a repeat offender from a first mistake.
7Your rights
Email us and we will export everything we hold about you, correct anything wrong, or delete your account. Deletion removes your personal data; it cannot remove the on-chain record of your payments, because nobody can.
We will not ask you to prove your identity with a document in order to exercise these rights — we have no document on file to compare it against. Control of the account email is what we go by.
8Legal requests
We respond to lawful requests from authorities with jurisdiction over us. What we can produce is limited to what section 1 lists. We will tell you when we receive a request about your account unless we are legally barred from doing so.
Questions about any of this? support@coresserver.com. Reporting abuse? abuse@coresserver.com.