This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use vaultproxies.net and the VaultProxies services (the "Service"). It is written to meet U.S. requirements including the California Consumer Privacy Act as amended by the CPRA, and the comparable Virginia, Colorado, Connecticut and Utah laws, and to give EU/UK visitors their GDPR / UK GDPR rights.
1. Who we are
The Service is operated by N.R. Digital LLC ("VaultProxies", "we", "us"), a limited liability company formed in New Mexico, USA, registered address 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, USA. We are the "business" / data controller responsible for your personal information. Contact: [email protected].
2. Information we collect
We collect only what we need to run the Service and bill you correctly. In the last 12 months we collect these categories of personal information:
- Identifiers & account data. Email, hashed password, optional username, account ID, role, account creation date.
- Commercial / billing information. Plans purchased, top-up amounts, invoice IDs, and payment-provider references (Stripe customer/charge IDs, crypto transaction hashes). We do not store full card numbers - our payment processors do.
- Internet / service-usage metadata. Per-request timestamps, the destination hostname at the request edge, response code, plan ID and account ID, the minimum needed to bill accurately and answer abuse complaints. We do not log request bodies, response bodies, headers, or anything that would let us reconstruct the content you fetched.
- Linked accounts. If you link Discord or Telegram, the platform user ID and username, used only to bind the integration to your account.
- Device / log data. IP address, user agent, pages requested and status codes in server logs, retained briefly for security and abuse handling.
- Device & security signals. We may use standard device and connection signals, including browser/device characteristics and a derived device identifier, to keep accounts secure, prevent fraud, abuse and duplicate accounts, enforce limits, and develop and improve our products and services. We use these for those purposes and do not use them for advertising.
- Approximate location. Coarse, IP-derived country only (for fraud prevention and analytics), never precise GPS location.
We do not knowingly collect sensitive personal information (e.g. government IDs, precise geolocation, biometric or health data) and do not ask for it.
3. Where it comes from
Directly from you (registration, top-ups, support, account linking), automatically from your use of the Service (usage metadata, logs), and from our payment and infrastructure providers (e.g. a payment confirmation from Stripe or a crypto gateway).
4. How and why we use it
- Operate, secure, maintain, and develop and improve our products and services (including the proxy gateway and dashboard).
- Process payments, issue invoices and meet tax/accounting obligations.
- Detect, investigate and prevent abuse, fraud and multi-accounting and enforce our acceptable-use policy using device and security signals, and respond to law-enforcement requests we are legally required to act on.
- Send operational email (receipts, security alerts, maintenance notices).
- With your consent, measure site traffic and show our Trustpilot reviews, see our Cookie Policy.
5. Legal bases (EU/UK visitors)
Where the GDPR / UK GDPR applies we rely on: performance of a contract (providing the Service you signed up for), legal obligation (tax records, lawful requests), legitimate interests (security, fraud and abuse prevention, product improvement, and basic service analytics), and consent (optional cookies and marketing), which you may withdraw at any time.
6. How we disclose information
We disclose personal information only to:
- Service providers / processors who act on our instructions under contract (see the list in Section 10).
- Authorities when required by valid legal process or to protect rights, safety and the integrity of the Service.
- A successor in a merger, acquisition or asset sale, subject to this Policy.
We do not sell your personal information, and we do not "share" it for cross-context behavioural advertising as those terms are defined under California and other U.S. state laws. We have not done so in the preceding 12 months.
7. Cookies & tracking
Strictly-necessary cookies keep you signed in and secure; optional analytics and the Trustpilot widget run only with your consent. We honour the Global Privacy Control signal. Full detail and controls are in our Cookie Policy.
8. Retention
Account data is kept until you delete your account. Billing records are kept for the period required by U.S. tax law (generally up to 7 years). Per-request usage metadata is kept for 90 days; aggregate daily counters are kept for billing history for the life of the account. Server logs rotate within 30 days. We delete or de-identify data when it is no longer needed for these purposes.
9. Your privacy rights
U.S. residents (California, Virginia, Colorado, Connecticut, Utah and similar). Subject to verification, you may: know/access the personal information we hold and how we use and disclose it; request deletion; request correction; opt out of any sale or "sharing" of personal information (we do neither) and of targeted advertising (we do none); and limit the use of sensitive information (we collect none). You will not be discriminated against for exercising these rights. You may use an authorized agent, and California residents may appeal a denied request.
EU/UK residents. You may access, rectify, erase, restrict or object to processing, request portability, and withdraw consent. You also have the right to lodge a complaint with your local supervisory authority.
To exercise any right, email [email protected] from the address on your account, or use account-deletion in dashboard settings. We respond within 45 days (U.S.) or 30 days (EU/UK) and may extend once where the law allows. Statutorily-required billing records cannot be deleted before their retention period ends.
10. Service providers we use
- Stripe, card payment processing (they hold card data, not us).
- OxaPay / crypto gateways, cryptocurrency payment processing.
- Cloudflare, edge security, DDoS protection and bot mitigation (Turnstile).
- Hosting providers, database and gateway servers.
- Transactional email provider, receipts and security email.
- Trustpilot, review widget (loads only with cookie consent).
Each operates under a data-processing agreement limiting use of the data to providing services to us. We keep this list current.
11. International data transfers
We are based in the United States and process data there. If you access the Service from the EU/UK, your information is transferred to the U.S. under appropriate safeguards (e.g. Standard Contractual Clauses with our processors).
12. Security
All traffic is encrypted in transit with modern TLS. Passwords are stored with a slow, salted hash (Argon2id); API keys are stored hashed and can only be rotated, not recovered. Backups are encrypted at rest and internal access is limited to a small set of operators using multi-factor authentication. No system is perfectly secure, but we work to protect your data and will notify you and any required authority of a breach affecting your personal information without undue delay.
13. Children
The Service is for adults and is not directed to anyone under 18. We do not knowingly collect personal information from children under 13 (COPPA). If you believe a minor has created an account, contact [email protected] and we will close it and delete the data.
14. Changes
We post material changes here with a fresh "Last updated" date and, for significant changes, email active accounts at least 14 days before they take effect.
15. Contact
Privacy requests: [email protected]
Abuse reports: [email protected]
Mailing address: 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, USA
Terms: /terms · Cookies: /cookies