We get asked this weekly, usually in the form "I would buy today if you took a card." It costs us real revenue. Here is why the answer will not change.
The chain
Cards → chargebacks → fraud liability → identity verification. Four steps, each following from the last, none of them optional.
A host that accepts cards inherits chargeback liability. A fraudster buys a server with a stolen card, uses it for a week, the cardholder disputes, and the host loses the money, the service already delivered, and a dispute fee on top. Card networks also police chargeback ratios: exceed roughly 1% and you enter a monitoring programme, with fines and eventually loss of processing.
Hosting is a magnet for card fraud, because the product is instant, remote and immediately monetisable. So a card-accepting host must run fraud controls. And the cheapest effective control is demanding identity.
What happens next is the part that matters
Once identity is collected for payment reasons, it does not stay in the payment system. It lands in the billing database. It gets reused for account recovery. It gets exported to a CRM. It gets included in the data migration when the company is acquired. It gets accessed by support staff who have no operational reason to see it. Eventually it appears in a breach.
Very little of that is malicious. It is simply what happens to data that exists. Which is why the only durable control is not collecting it.
"Just make it optional"
The most common counter-proposal: take cards from people who want convenience, take crypto from people who want privacy.
It does not work, for a structural reason. The moment card revenue exists, chargeback exposure exists, and fraud controls follow. Those controls do not stay confined to card orders — a fraud team scoring card transactions will score crypto orders too, because the patterns are correlated and the tooling is the same. Within a year there is a risk engine, and it flags unusual orders, and the cheapest way to clear a flag is to ask for ID.
We have watched several providers make exactly this journey. They did not announce a policy change. The verification step simply appeared, first for "high-risk" orders, then for most of them.
The honest cost
We are not going to pretend this is free for you.
- You lose chargeback protection. Crypto payments are irreversible. If we take your money and fail to deliver, you have no card network to appeal to. What you have instead is our 7-day money-back guarantee, which is a promise rather than a mechanism.
- Renewals cannot be automatic. Push payments cannot be pulled, so every renewal needs an action from you. We send notices at 7, 3 and 1 days, and hold data for 7 days past expiry, but the friction is real.
- Some people simply do not hold crypto. For them, "buy some Monero first" is a genuine barrier, and we lose those customers.
Why we take the trade anyway
Because the alternative is a privacy claim that depends on our continued good behaviour rather than on how the business is built. "We promise not to ask for ID" is worth very little from a company with the commercial incentive to ask. "We cannot ask for ID because we have no mechanism that would ever require it" is worth considerably more.
Structural guarantees beat policy guarantees. That is the whole argument, and it is why crypto-only and no-KYC are the same decision rather than two features that happen to appear together.