1. General provisions
1.1. This Policy describes what data about users of the ipv.rent service the Operator collects, the purposes for which it processes that data, who it shares it with and how it protects it. The Operator acts as the controller of that data: it determines the purposes and the means of its processing.
1.2. The Policy applies to the ipv.rent website, the Personal Account and the Services provided. It does not apply to third-party websites you connect to through the proxies.
1.3. By using the service you confirm that you have read this Policy. If you do not agree with its terms, do not use the service.
1.4. This Policy forms an integral part of the Public Offer.
1.5. Terms capitalised in this Policy have the meanings given to them in the Public Offer.
2. Data we collect
2.1. Account data
- email address;
- password (stored only as an irreversible hash; it is available in plain text to no one, including the Operator's staff);
- date of registration, interface language, notification settings.
2.2. Service and payment data
- order composition: proxy type, geography, traffic volume, term;
- Balance transaction history, amounts and dates;
- blockchain transaction identifiers and the wallet addresses from which payment was received (to the extent transmitted by the payment provider).
We do not process payment cards or bank details: payment is accepted only in cryptocurrency through a third-party payment provider.
2.3. Technical data
- the IP address from which you log in to the Personal Account, and the IP addresses authorised to connect to the proxies;
- device type, browser, operating system, language;
- the date, time and duration of proxy connections, and the volume of data transferred;
- service records of errors and failures.
2.4. Support request data
- the content of the correspondence, attached files, logs and screenshots you provided for diagnosis;
- your messenger identifier, where the request was made through a messenger.
2.5. Affiliate program data
- the referral link identifier, the fact of a click-through and registration by a referred user, the amounts accrued and paid out, and the payout details for remuneration.
2.6. Web analytics and cookie data - see section 10 of this Policy.
3. What we do not collect
3.1. We do not analyse, decrypt or retain the content of your traffic: pages, requests, files or messages transmitted.
3.2. We do not require identity documents for ordinary use of the service. Such data may be requested only in the course of investigating fraudulent activity or pursuant to a lawful request from a competent authority.
3.3. We do not collect special categories of personal data (health, beliefs, biometrics) and we do not carry out automated decision-making producing legal effects for the user, with the exception of automated anti-fraud checks at payment and registration.
4. Purposes of processing and legal bases
| What we process | Why | Legal basis |
|---|---|---|
| Email, password | Account creation, sign-in, access recovery | Performance of the agreement |
| Order and payment data | Delivery of Services, billing, renewal, accounting | Performance of the agreement, legal obligation |
| Technical connection logs | Diagnostics, traffic charging, investigation of complaints and abuse | Performance of the agreement, legitimate interest |
| Sign-in IP, anti-fraud signals | Protection of accounts, detection of multi-accounting and fraud | Legitimate interest |
| Support correspondence | Resolution of requests, confirmation of what was agreed | Performance of the agreement, legitimate interest |
| Affiliate program data | Accrual and payment of remuneration, abuse control | Performance of the agreement |
| Email for service messages | Notices of service expiry, incidents, changes to documents | Performance of the agreement, legitimate interest |
| Email for marketing mailings | News, offers, promo codes | Consent (withdrawable at any time) |
| Analytics cookies | Assessment of website usability and traffic sources | Consent |
5. Who we share data with
5.1. We do not sell personal data and we do not disclose it to third parties for their own marketing.
5.2. Data may be shared with the following categories of recipient, strictly to the extent necessary to provide the Services:
- infrastructure partners - the owners of the networks and IP address pools through which the Services are provided (technical connection parameters are shared, not account data);
- the payment provider - to accept and confirm payment;
- the hosting provider and the attack protection provider - by virtue of the technical hosting of the service;
- the transactional email service - to deliver order-related messages and access recovery messages;
- the web analytics service - in anonymised form, where you have given consent;
- competent authorities - upon receipt of a lawful request, to the extent provided for by applicable law.
5.3. Recipients that process data on our instructions are bound by agreements requiring them to maintain a comparable level of protection and not to use the data for their own purposes.
6. International transfers
6.1. The infrastructure of the service and of its partners is located in a number of countries, and your data may therefore be processed outside the country in which you reside.
6.2. Where such a transfer takes place, we use providers that ensure an adequate level of data protection and we include appropriate data protection provisions in our agreements with them.
7. Retention periods
| Data | Retention period |
|---|---|
| Account and its settings | For as long as the account is active |
| Order and payment data | 3 years after the last transaction (accounting and dispute resolution) |
| Technical connection logs | 6 months |
| Support correspondence | 12 months after the request is closed |
| Affiliate program data | 3 years after the last payout |
| Data of a deleted account | Deleted or anonymised within 30 days, except for information we are required by law to retain |
8. Security
8.1. Data transmitted between your device and the website is protected by TLS encryption.
8.2. Passwords are stored as an irreversible salted hash.
8.3. Access to data within the service is granted on a least-privilege basis, only to those who need it to perform their duties.
8.4. No system is absolutely secure. Should a breach occur that creates a high risk to your rights, we will notify the affected users and, where the law so requires, the supervisory authority.
9. Your rights
9.1. You have the right to:
- obtain confirmation that your data is being processed and a copy of that data;
- request the rectification of inaccurate data;
- request the erasure of your data (the "right to be forgotten"), where there is no other lawful basis for retaining it;
- restrict processing, or object to processing based on legitimate interest;
- receive your data in a machine-readable format and transmit it to another controller;
- withdraw consent to marketing mailings and analytics cookies at any time - withdrawal does not affect the lawfulness of processing carried out before it was received;
- lodge a complaint with the data protection supervisory authority in your place of residence.
9.2. To exercise these rights, send a request from the email address registered on your account to the Operator's address stated at the foot of this page. We respond within 30 calendar days. Where we have reasonable doubts as to the identity of the applicant, we may request further verification.
9.3. Deletion of an account does not override the obligation to retain payment data for the periods established by law.
10. Cookies and analytics
10.1. Cookies are small text files that a website stores in the browser on your device. On subsequent visits the browser returns them to the website, which then "recognises" the session or the saved settings. Alongside cookies we use similar technologies: browser local storage (localStorage) and session storage. Everything said here about cookies applies equally to them.
10.2. Strictly necessary
Without these the website and the Personal Account do not work, so they are always set and do not require consent:
- the session identifier - keeps you signed in to the Personal Account;
- request forgery protection (CSRF token);
- service records for load balancing and protection against automated attacks;
- the saved language choice and the remembered choice regarding cookies.
10.3. Affiliate (referral)
If you arrived via an affiliate link, we store its identifier so that the affiliate's remuneration is credited correctly. This marker contains no personal data and is not used for advertising.
10.4. Analytics
These help us understand which pages are used, where visitors get lost and which traffic sources work. The data is processed in aggregated form. Analytics cookies are set only with your consent.
10.5. We do not use advertising or tracking cookies of third-party advertising networks. We do not sell data about your behaviour on the website and we do not pass it to advertising brokers.
10.6. Retention periods:
| Category | Period |
|---|---|
| Personal Account session | Until the browser is closed or you sign out |
| CSRF token, service cookies | Session |
| Language choice, saved cookie decision | Up to 12 months |
| Affiliate marker | Up to 90 days from the click-through |
| Analytics | Up to 24 months |
10.7. Some cookies may be set by our providers: the web analytics service, the attack protection provider, and the payment provider on the payment page. Such providers process data in accordance with their own policies; we limit the information passed to them.
10.8. Strictly necessary cookies are set without consent, because they are strictly necessary in order to provide the service you have requested: without them the website and the Personal Account do not work. Where such cookies involve personal data, that data is processed for the performance of the agreement. Analytics cookies are set only after your consent. Consent may be withdrawn at any time: clear the website's cookies in your browser and decline analytics cookies on your next visit. Withdrawal does not affect the lawfulness of processing carried out before it was received. Declining analytics cookies does not restrict your access to the website or the Services.
10.9. You can block or delete cookies in your browser settings:
10.10. Blocking cookies entirely will make it impossible to sign in to the Personal Account and to place an order: the session will not persist. Private browsing mode deletes cookies when the window is closed, so you will have to sign in again on every visit.
11. Minors
11.1. The service is not intended for persons under 18 years of age. We do not knowingly collect children's data. If you become aware that a minor has provided us with their data, please tell us and we will delete it.
12. Changes to this Policy
12.1. We may update this Policy. The current version is always available on this page, and the date of the version is stated at the head of the document.
12.2. We will notify you of material changes by email or by a prominent notice on the website.