Privacy Policy
Key summary
IPROAM processes the information needed to operate accounts, deliver and meter proxy services, secure the network, reconcile billing, and provide support. We do not sell personal data or proxy traffic payloads.
1. Who controls your data
This Privacy Policy applies to personal data processed by the IPROAM operator through this website, customer area, APIs, and proxy services. The IPROAM operator acts as the controller for this processing. You may request the operator's current legal identity and contact details through the address below.
2. Data we process
Depending on how you use IPROAM, we may process:
- Account data: email address, bcrypt password hash, account status, language and profile preferences, verification records, and security settings;
- Security and access data: IP address, user agent, request time, login and account activity, session identifiers, rate-limit events, and Turnstile verification results;
- Commercial records: orders, recharges, account balances, coupons, plan entitlements, adjustment history, payment method or confirmation status, and related audit records;
- Proxy configuration and credentials: proxy usernames and protected credentials, authentication method, allowed IP or CIDR entries, country, rotation, protocol, endpoint, and tunnel settings;
- Service usage: allocated and consumed traffic, tunnel quantity and status, aggregate upload and download totals, connection or reporting times, and operational error or abuse indicators;
- Support data: messages, email correspondence, reports, and information you provide when asking for support, exercising a right, or reporting abuse.
We do not intentionally inspect, profile, or sell the content payload you transmit through a proxy. Network systems necessarily carry that traffic and may process limited connection metadata to route requests, meter usage, prevent abuse, and maintain security. You should use end-to-end encryption such as HTTPS where appropriate.
3. Purposes and legal bases
We process data to perform our contract with you, comply with legal obligations, pursue legitimate security and operational interests, and obtain consent where applicable. Uses include:
- creating and verifying accounts, authenticating sessions, and delivering proxy access;
- provisioning plans, applying coupons, measuring usage, processing orders, and reconciling balances and payments;
- detecting fraud, abuse, attacks, credential compromise, and violations of our Terms;
- maintaining reliability, debugging incidents, analyzing aggregate service performance, and improving the product;
- sending verification codes, security alerts, transaction messages, and important service or policy notices;
- responding to support, privacy, legal, and regulatory requests.
4. Cookies, local storage, and analytics
We use an HttpOnly session cookie to maintain authentication, a non-sensitive proxyc_logged_in hint cookie to select the initial navigation state, and localStorage key proxyc.language to remember your language. Security providers such as Cloudflare may set additional cookies or similar identifiers needed for Turnstile, bot protection, delivery, and security.
Production pages may use Cloudflare Web Analytics to understand aggregate page performance and usage. Where applicable law requires consent for optional storage or analytics, we will request it or provide the required control. Blocking required cookies may prevent login or security checks from working.
5. Service providers
We use providers that process data on our behalf or provide independent services:
- Cloudflare: CDN and reverse proxy delivery, DDoS and bot protection, Turnstile verification, and Web Analytics;
- Brevo: account verification and other transactional email delivery;
- hosting and network providers: application hosting, storage, connectivity, logging, monitoring, and proxy infrastructure;
- payment providers: payment processing or confirmation when an external payment method is enabled.
Providers receive only information reasonably required for their role and are subject to their own terms, privacy commitments, or contractual safeguards.
6. Sharing, sale, and global processing
We do not sell or rent personal data, account records, or proxy usage history to advertisers or data brokers. We may disclose information to service providers, professional advisers, authorities where legally required, or a successor in a legitimate business reorganization, subject to appropriate safeguards.
IPROAM uses global infrastructure, so information may be processed outside your country or region. We apply reasonable contractual, organizational, and technical safeguards and follow mandatory cross-border transfer requirements that apply to the processing.
7. Data retention
We retain each category only as long as reasonably necessary for account operation, service delivery, security, dispute handling, and legal, tax, accounting, or audit obligations. Retention varies by record and jurisdiction. When information is no longer needed, we delete or anonymize it through normal production and backup lifecycles, unless preservation is required for a legal claim or investigation.
8. Security
We use safeguards appropriate to the service, including TLS/HTTPS for supported web traffic, bcrypt password hashing, access restrictions, protected secret configuration, session controls, monitoring, and security updates. No internet service can guarantee absolute security. You are responsible for keeping credentials confidential and for choosing secure destination protocols.
9. Your rights and choices
Depending on applicable law, you may have rights to access, obtain a copy of, correct, delete, or restrict processing of your personal data; object to certain processing; withdraw consent for future optional processing; and complain to a competent regulator. These rights may be limited by identity verification, security needs, legal retention duties, and the rights of others.
To make a request, email [email protected] from your account email where possible. We may ask for information needed to verify the request. Account deletion may end active services and does not require deletion of records we must lawfully retain.
10. Minors
IPROAM is intended for organizations and individuals aged 18 or older. We do not knowingly offer the service to or collect personal data from children. Contact us if you believe a child has provided personal data so we can investigate and take appropriate action.
11. Updates to this Policy
We may update this Policy when the service, providers, or legal requirements change. The current version and effective date will remain available here. For material changes, we will provide reasonable notice through the website, account interface, or email where practicable.
12. Contact
For privacy questions, requests, or complaints, contact the IPROAM operator at [email protected].