The controller of your personal data is HONGKONG LINGYUN NETWORK MDT INFOTECH LIMITED, Flat/Rm 401, 4/F, Wanchai Central Building, 89 Lockhart Road, Wan Chai, Hong Kong. This policy describes what we actually store, not what a generic template says we might. If you want any of it removed, write to service@pyproxy.com.
What we collect
- Your email address. It is your login and the only way we can reach you about an order. We do not ask for your name, address or phone number.
- A hash of your password. Stored with PBKDF2-SHA256 and a per-account salt. We cannot read your password and cannot tell it to you if you forget it.
- Your session. A random token, plus the IP address and browser user-agent that created it, so you can spot a session that is not yours.
- Your orders. Volume purchased, price, currency, any promo code used, payment status and timestamps, and the payment reference from our payment processor.
- Your traffic plans. The allowance issued and how much of it remains.
What we do not collect
We do not log the websites you visit through the proxies, the content of your requests, or the responses you receive. The network meters how many bytes you moved. It does not keep a record of where you moved them for us to browse, and we do not build profiles of customer activity.
We do not use advertising trackers, analytics pixels or third-party cookies. The only cookie we set is the session cookie that keeps you logged in.
Who else sees your data
- Our payment processor receives an order reference and an amount in order to create an invoice, and tells us whether it was paid. Your crypto wallet address is visible to them, not to us.
- Our upstream network provider receives a request to issue a traffic plan and an opaque label. It does not receive your email address.
- Nobody else. We do not sell, rent or share customer data, and we have no advertising partners to share it with.
Legal grounds and retention
We process your email and order history because we need them to perform the contract you entered into, and we keep order records for as long as accounting and anti-money-laundering obligations require. Session records are short-lived and expire on their own.
Your rights
You can ask us for a copy of everything we hold about you, ask us to correct it, or ask us to delete your account. Deletion removes your email, password hash and sessions; order records are retained in a reduced form where we are legally required to keep them. We answer such requests within 30 days.
Security
The site is served over TLS only. Passwords are hashed, never stored in readable form. Payment callbacks are cryptographically verified before we act on them, so a forged "paid" message cannot issue proxies.
Breaches
If customer data is exposed, we will say so by email to the affected accounts, promptly and without minimising it.
If anything here is unclear, email service@pyproxy.com before you buy. We would rather answer a question than process a dispute.
