Privacy Policy
Key summary
IPROAM processes the information needed to operate accounts, deliver and meter proxy services, secure the network, reconcile billing, and provide support. We do not sell personal data or proxy traffic payloads.
1. Who controls your data
This Privacy Policy applies to personal data processed by the IPROAM operator through this website, customer area, APIs, and proxy services. The IPROAM operator acts as the controller for this processing. You may request the operator's current legal identity and contact details through the address below.
2. Data we process
Depending on how you use IPROAM, we may process:
- Account data: email address, bcrypt password hash, account status, language and profile preferences, verification records, and security settings;
- Security and access data: IP address, user agent, request time, login and account activity, session identifiers, rate-limit events, and Turnstile verification results;
- Advertising attribution data: when you arrive through an enabled Baidu advertising campaign, the
bd_vidclick identifier, the landing-page URL containing it, attribution and registration timestamps, and conversion-delivery status; - Commercial records: orders, recharges, account balances, coupons, plan entitlements, adjustment history, payment method and status, currency-conversion snapshots, payment-provider transaction identifiers, and related audit records;
- Proxy configuration and credentials: proxy usernames and protected credentials, authentication method, allowed IP or CIDR entries, country, rotation, protocol, endpoint, and proxy port settings;
- Service usage: allocated and consumed traffic, port quantity and bandwidth subscription status, aggregate upload and download totals, connection or reporting times, and operational error or abuse indicators;
- Support data: messages, email correspondence, reports, and information you provide when asking for support, exercising a right, or reporting abuse.
We do not intentionally inspect, profile, or sell the content payload you transmit through a proxy. Network systems necessarily carry that traffic and may process limited connection metadata to route requests, meter usage, prevent abuse, and maintain security. You should use end-to-end encryption such as HTTPS where appropriate.
Identity verification data
When you submit an identity verification application, we process your legal name and PRC identity number, the verification result and timestamps returned by Alipay face verification, and the status, decision, rejection reason, and audit records of the application. Enterprise applications additionally include the enterprise name, unified social credit code, the applicant's role, an optional use-case description, an uploaded business license, and, where an authorized agent applies, an authorization letter. One identity number may be bound to only one account, a verified personal account may be upgraded to enterprise verification, and submitted information cannot be modified while review is pending or after approval.
3. Purposes and legal bases
We process data to perform our contract with you, comply with legal obligations, pursue legitimate security and operational interests, and obtain consent where applicable. Uses include:
- creating and verifying accounts, authenticating sessions, and delivering proxy access;
- provisioning plans, applying coupons, measuring usage, processing orders, and reconciling balances and payments;
- detecting fraud, abuse, attacks, credential compromise, and violations of our Terms;
- maintaining reliability, debugging incidents, analyzing aggregate service performance, and improving the product;
- sending verification codes, security alerts, transaction messages, and important service or policy notices;
- attributing registrations to enabled advertising campaigns, measuring campaign effectiveness, and reporting a successful registration as a conversion;
- verifying identity for compliance, controlling access to new purchases, renewals, and recharges, keeping audit records, preventing fraud and duplicate accounts, and granting configured verification rewards;
- responding to support, privacy, legal, and regulatory requests.
4. Cookies, local storage, and analytics
We use an HttpOnly session cookie to maintain authentication, a non-sensitive proxyc_logged_in hint cookie to select the initial navigation state, and localStorage key proxyc.language to remember your language. If you arrive through an enabled Baidu advertising campaign, we set an HttpOnly proxyc_baidu_click cookie for the configured attribution period (30 days by default and no longer than 90 days) so that a later successful registration can be attributed to that click. Security providers such as Cloudflare may set additional cookies or similar identifiers needed for Turnstile, bot protection, delivery, and security.
Production pages may use Cloudflare Web Analytics to understand aggregate page performance and usage. Where applicable law requires consent for optional storage or analytics, we will request it or provide the required control. Blocking required cookies may prevent login or security checks from working.
5. Service providers
We use providers that process data on our behalf or provide independent services:
- Cloudflare: CDN and reverse proxy delivery, DDoS and bot protection, Turnstile verification, and Web Analytics;
- Brevo: account verification and other transactional email delivery;
- Baidu advertising: when campaign conversion reporting is enabled, the landing-page URL containing Baidu's click identifier, the registration event type, and the registration timestamp; we do not send the account email address or password;
- hosting and network providers: application hosting, storage, connectivity, logging, monitoring, and proxy infrastructure;
- Alipay and other enabled payment providers: payment initiation, processing, confirmation, reconciliation, and refunds;
- Alipay identity verification: identity and face verification, receiving only the name and identity number necessary to perform that check.
Providers receive only information reasonably required for their role and are subject to their own terms, privacy commitments, or contractual safeguards. Business licenses, authorization letters, and other enterprise documents are not sent to Alipay; they are reviewed by authorized IPROAM administrators.
6. Sharing, sale, and global processing
We do not sell or rent personal data, account records, or proxy usage history to advertisers or data brokers. We may disclose information to service providers, professional advisers, authorities where legally required, or a successor in a legitimate business reorganization, subject to appropriate safeguards. Except where necessary to perform verification, required by law, or authorized by you, we do not publicly disclose, sell, or disclose identity verification information to unrelated third parties.
IPROAM uses global infrastructure, so information may be processed outside your country or region. We apply reasonable contractual, organizational, and technical safeguards and follow mandatory cross-border transfer requirements that apply to the processing.
7. Data retention
We retain each category only as long as reasonably necessary for account operation, service delivery, security, dispute handling, and legal, tax, accounting, or audit obligations. Retention varies by record and jurisdiction. When information is no longer needed, we delete or anonymize it through normal production and backup lifecycles, unless preservation is required for a legal claim or investigation.
Raw identity verification material, including identity numbers and uploaded documents, is retained only for the configured period and for as long as legally or operationally necessary, after which it is deleted or anonymized through normal cleanup processes. Pseudonymous binding identifiers, reward records, decision outcomes, and audit markers may be retained for as long as needed to prevent duplicate accounts or duplicate rewards, enforce verification state, resolve disputes, and comply with law. We do not promise indefinite retention of raw verification material.
8. Security
We use safeguards appropriate to the service, including TLS/HTTPS for supported web traffic, bcrypt password hashing, access restrictions, protected secret configuration, session controls, monitoring, and security updates. No internet service can guarantee absolute security. You are responsible for keeping credentials confidential and for choosing secure destination protocols.
Identity verification fields and uploaded files are encrypted at rest. Administrative access to full identity verification information is limited to authorized staff and is logged together with the reason for access for audit purposes.
9. Your rights and choices
Depending on applicable law, you may have rights to access, obtain a copy of, correct, delete, or restrict processing of your personal data; object to certain processing; withdraw consent for future optional processing; and complain to a competent regulator. These rights may be limited by identity verification, security needs, legal retention duties, and the rights of others. Immutable review records, fraud-prevention identity bindings, security and audit requirements, and mandatory retention duties may further limit requests to correct or delete identity verification information.
To make a request, email support@iproam.com from your account email where possible. We may ask for information needed to verify the request. Account deletion may end active services and does not require deletion of records we must lawfully retain.
10. Minors
IPROAM is intended for organizations and individuals aged 18 or older. We do not knowingly offer the service to or collect personal data from children. Contact us if you believe a child has provided personal data so we can investigate and take appropriate action.
11. Updates to this Policy
We may update this Policy when the service, providers, or legal requirements change. The current version and effective date will remain available here. For material changes, we will provide reasonable notice through the website, account interface, or email where practicable.
12. Contact
For privacy questions, requests, or complaints, contact the IPROAM operator at support@iproam.com.