Legal
Identity Verification & KYC Policy
Effective date: 1 January 2025 · Last updated: 28 June 2025
1. Overview
Hoststack is a web hosting and infrastructure provider — not a bank, financial institution, telecom operator or payment company. No law requires us to run a Know-Your-Customer (KYC) program, and we do not operate a blanket, mandatory identity-verification process that every customer must complete before ordering.
That said, like most hosting and cloud providers, we reserve the right to ask a customer to verify their identity in specific, limited situations — chiefly to prevent payment fraud, investigate abuse, and resolve billing disputes. This page explains, in plain language, when that can happen, what we may ask for, and how the process works.
1–3 Days
Typical Review Time
Business days
Manual
Review Only
No automated decisions
Limited
Retention
Kept no longer than necessary
This is not a mandatory KYC system
Hoststack does not currently operate a mandatory Know-Your-Customer program. This policy explains when we may ask for identity verification and how that process works — it is a fraud-prevention safeguard used in specific cases, not a requirement applied to every order or account.
2. When Verification May Be Requested
We do not ask every customer to verify their identity. A verification request is typically triggered by one of the following:
- Suspicious or high-risk payment activity — for example, a payment flagged by our processor's fraud checks, or mismatched billing details.
- A chargeback or payment dispute — to confirm that the account holder authorised a disputed charge.
- An abuse or Acceptable Use Policy investigation — where we need to confirm who is responsible for an account or server linked to a reported incident.
- High-value or high-risk order categories — such as dedicated servers or bulk VPS orders, where fraud exposure is greater.
- Account recovery — when normal recovery methods (registered email, phone, security questions) cannot confirm you own the account.
- A government or legal request — where we are required to verify or disclose account information under applicable Indian law.
Outside of these situations, we will not ask you to submit identity documents.
3. What Documents May Be Requested
Depending on the situation, our support or compliance team may ask for one or more of the following. These are examples of acceptable document types — Hoststack does not integrate with UIDAI, DigiLocker or any government identity-verification API, and does not perform automated Aadhaar/PAN checks.
- Government-issued photo ID — such as Aadhaar, PAN card, passport or driving licence (any one, your choice).
- Proof of address — a recent utility bill, bank statement or similar document showing your name and address.
- A live selfie or short video call — in some cases, a support agent may ask you to join a brief video call or submit a short live selfie video holding your ID, which a member of our team reviews manually. This is a manual identity check performed by a person, not an automated or AI-driven video-KYC product.
- Proof of payment-method ownership — for chargeback or payment-dispute cases, a screenshot of your card or bank statement with all sensitive digits (other than the last 4) masked.
We only ask for what is reasonably necessary for the specific situation — identity documents are never collected as a matter of routine.
4. How Verification Works
- Request: A support or compliance agent contacts you by email or through a support ticket, explaining exactly why verification is needed and what to submit.
- Submission: You submit the requested documents through your support ticket or the client area — a secure, access-controlled channel. We never ask for documents over public social media or unofficial channels.
- Manual review: A member of our team reviews the submission by hand, typically within 1–3 business days. There is no automated or algorithmic approval — a person reviews every submission.
- Outcome: You're notified of one of three results — approved (order/account proceeds normally), more information needed (we'll say exactly what's missing), or the order/account remains on hold pending further review.
5. Data Handling for Verification Documents
Any documents you submit for verification are:
- Used solely for the verification purpose they were requested for — never for marketing, profiling, or any unrelated use.
- Stored securely, with access restricted to our support/compliance team on a need-to-know basis.
- Retained only as long as necessary for the purpose collected, as described in our Privacy Policy — not kept indefinitely.
- Not shared with third parties except where required by law, or as necessary to resolve a payment dispute with our payment processor or your bank.
Full details of how we handle personal data generally, including your rights, are in our Privacy Policy.
6. If Verification Isn't Completed
If requested identity verification is not completed, or the documents provided don't resolve the concern that prompted the request, one or more of the following may follow, depending on the situation:
- The specific order or service may be held or delayed pending verification.
- The account or service may be suspended until the matter is resolved.
- Where applicable, any refund due is handled per our Refund Policy.
This is a risk-management process, not a penalty. We'll always explain why verification is needed and what your options are.
7. Your Rights
- You have the right to ask why identity verification has been requested for your account or order.
- You have the right to know what happens to any documents you submit, including how long they are retained.
- You retain all data-subject rights described in our Privacy Policy and, where applicable, our GDPR page — including access, correction and erasure requests.
8. Contact
Questions about identity verification, a request you've received, or this policy generally can be sent to [email protected] or via our Contact page.
Related Legal Documents