Skip to content

Draft — must be reviewed by a lawyer before launch

This is a template. Highlighted items in [BRACKETS] are placeholders to replace, and the whole text must be reviewed by a qualified lawyer for your jurisdiction before it is published.

Legal

Privacy Policy

Effective date: [EFFECTIVE DATE]

This policy explains what personal data [COMPANY LEGAL NAME] (“we”) processes when you use ProxyBrand, why, and your rights. The data controller is [COMPANY LEGAL NAME], [REGISTERED ADDRESS].

1. Data we collect

We collect only what we need to run the Service:

  • Account data: email address, username, a hash of your password (never the password itself), and optional profile data from Google or GitHub if you sign in with them.
  • Billing data: handled by Stripe. We receive your plan, payment status and invoice details, but never your full card number.
  • Usage data: bytes transferred and number of connections per hour, used to enforce your plan and show your usage.
  • Security data: IP addresses and user agents of logins, failed authentication attempts and connections to the gateway, used to prevent abuse and attacks.
  • Support data: messages you send us.

2. What the proxy gateway logs

We do not record the content of your traffic (pages, request bodies or responses). While a connection is open, the gateway holds operational metadata such as your client IP and the destination host and port, so it can enforce limits and block abuse. [CONFIRM: which connection metadata is stored, and for how long — e.g. N days.]

Usage totals are kept for as long as your account exists, and deleted with it.

3. Why we use it

  • To provide the Service and your dashboard (contract).
  • To bill you and keep accounting records (contract and legal obligation).
  • To keep the Service secure and prevent fraud and abuse (legitimate interest).
  • To send essential emails such as verification, password resets and usage notices (contract).

4. Who we share it with

We use processors that act on our instructions: Stripe (payments), [EMAIL PROVIDER] (email delivery), [HOSTING PROVIDER] (servers), and Cloudflare Turnstile (bot protection on sign-up and login). We do not sell personal data. We may disclose data when required by law.

5. Cookies

We use only essential cookies: a session cookie to keep you signed in and a preference for the light or dark theme. Cloudflare Turnstile may set cookies to tell humans from bots. We do not use advertising cookies.

6. Retention

Account data is kept while your account exists. When you delete your account we delete your profile and usage data; payment records are kept for [N] years as required by accounting law. Backups are overwritten within [N] days.

7. Your rights

Depending on where you live, you may have the right to access, correct, delete or export your data, and to object to or restrict processing. You can delete your account yourself in the dashboard. For other requests, email support@proxies.com. You may also complain to your data protection authority.

8. International transfers

Our servers are located in [COUNTRY]. Where data is transferred outside your country, we rely on appropriate safeguards such as Standard Contractual Clauses.

9. Changes

We will post updates here and notify you of significant changes by email.