A great idea and a great offer. One thing that always worries me though: my first welcome email included my account password (that is, the one I used when signing up as opposed to the one needed for VPN use) in plain text. Isn't that a big no-no for security?
This is currently in review - however generally this is seen as a "no-no" if the passwords are also stored in plaintext - which they are not. Hope this helps a little, and the fact that it's in review may give some confidence that it's actually being looked in to.