Privacy Policy
Last updated: September 18, 2026 · Effective: September 18, 2026
Contents
1. Who we are
PD-Proxy ("PD-Proxy", "we", "us" or "our") is a VPN and proxy service provider that has been operating since 2009. We started as the first fully automated VPN provider in the Philippines and today serve customers around the world through our Personal VPN, Premium Proxies, Wi-Fi Protection, Streaming & Gaming servers and Business VPN services, together with the website at www.pdproxy.com and our applications for Windows, macOS, Linux, Android and iOS.
For the purposes of data protection law, PD-Proxy is the controller of the personal data described in this Privacy Policy. If you have any question about this policy or about how we handle your information, you can contact our privacy team at [email protected].
2. Scope of this policy
This Privacy Policy applies to personal data we process when you:
- visit or interact with our website, including the What is my IP tool, the contact form and the sign-up pages;
- create a free or Premium account, purchase a subscription, a Premium Proxy or a Business VPN plan;
- download, install and use any PD-Proxy application or connect to any PD-Proxy server;
- contact our support, sales, partner, abuse or legal teams by e-mail or through our ticket system;
- purchase our services through one of our authorised resellers.
This policy does not cover the websites, apps or services of third parties that you access while connected to our VPN or proxies. Those services' own privacy policies apply to whatever you share with them.
This Privacy Policy should be read together with our Terms of Use, our Cookie Policy, our Refund Policy and our Acceptable Use Policy.
3. Our no-logs commitment
Our no-logs commitment is the core of this policy. It applies to every PD-Proxy plan, free or paid, on every server location and every protocol we support (WireGuard, OpenVPN over UDP and TCP, IKEv2/IPsec and our Stealth TCP-443 obfuscation mode).
3.1 What we never log
We do not collect, record, store or share any of the following:
- your browsing history or the URLs, pages or domains you visit;
- the content of your traffic, including messages, files, downloads, streams or any data you send or receive;
- your DNS queries – our private DNS resolvers answer requests without writing them to disk;
- the IP addresses of the websites, services or peers you connect to (destination IP addresses);
- the originating IP address you connect from, beyond what is strictly necessary to route packets during a live session;
- which VPN IP address was assigned to you at any given time, in a way that could later be matched to your account;
- any other record that would allow us, or anyone who asks us, to link a specific online activity to a specific user.
3.2 Temporary session data held in memory
To keep a VPN connection running, our servers necessarily know certain things while you are connected: that a session is active, which server you are on, when the session started and how many bytes have passed through it. This information is held in memory only for the duration of the active session. It is never written to permanent storage and it disappears when the session ends or the server restarts.
We also compute aggregated counters from this session data, for two purposes only: enforcing the 1 GB daily data allowance on free plans and the simultaneous-device limit on Premium plans, and monitoring the overall load of each server so that we can add capacity where it is needed. Aggregated counters are deleted within 24 hours. Server-load statistics are anonymous totals that cannot be traced to any individual.
3.3 Why this matters
Because we do not create activity logs, we cannot be forced to hand them over. If a court, government authority or private party asks us which user visited a particular website or used a particular IP address at a particular time, the honest answer is that we do not have that information. We explain how we handle such requests in section 9.
4. Data we collect
The table below lists every category of personal data we process, why we process it, the legal basis we rely on under the EU and UK General Data Protection Regulation (GDPR), and how long we keep it.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| E-mail address | Creating your account, sending login details, receipts, security notices and support replies | Performance of a contract | For the life of your account, then deleted within 30 days of account closure |
| Username | Identifying your account when you log in to the apps and the member area | Performance of a contract | For the life of your account, then deleted within 30 days of account closure |
| Password (hashed) | Authenticating you; we store only a salted one-way hash, never the password itself | Performance of a contract | For the life of your account |
| Subscription records (plan, start and expiry date, renewal status, device count) | Providing the plan you bought, enforcing plan limits, handling renewals and refunds | Performance of a contract | For the life of your account plus up to 12 months |
| Payment records (transaction ID, amount, currency, date, payment method type, country) | Accounting, tax compliance, fraud prevention, refunds and chargebacks | Legal obligation; legitimate interests | As required by tax and accounting law, typically up to 7 years |
| Daily data counter (free plans) | Enforcing the 1 GB per day free allowance | Performance of a contract | Reset and deleted within 24 hours |
| Temporary session data (connection timestamp, server, bytes transferred) | Keeping the active connection running and enforcing device limits | Performance of a contract | In memory only for the active session; aggregated counters deleted within 24 hours |
| Support correspondence (your messages, our replies, any attachments you send) | Answering your questions and troubleshooting problems | Performance of a contract; legitimate interests | Up to 24 months after the ticket is closed |
| Contact form data (name, e-mail, subject, message) | Responding to pre-sales and general enquiries | Legitimate interests | Up to 12 months after the last message |
| Business VPN administrator and team member details (name, work e-mail, role) | Managing team accounts, dedicated IPs and invoicing | Performance of a contract | For the life of the business contract, then deleted within 90 days |
| Premium Proxy configuration (proxy type, location, authorised IP addresses you whitelist) | Delivering and authenticating your dedicated proxies | Performance of a contract | For the life of the proxy subscription, then deleted within 30 days |
| Crash reports (optional; app version, operating system, error trace) | Fixing bugs in our applications | Consent | Up to 90 days |
| Marketing preferences | Sending newsletters and offers only if you asked for them | Consent | Until you unsubscribe |
4.1 Information you give us
You can sign up for a free account with nothing more than an e-mail address and a username. We do not ask for your real name, postal address or telephone number for individual plans. You may use an e-mail address that does not reveal your identity, as long as you can receive mail at it.
4.2 Information generated when you use the apps
Our apps authenticate against our account servers with your username and password to learn your plan and limits. They store your login credentials and your settings (preferred protocol, kill-switch state, trusted Wi-Fi networks for auto-connect and similar options) locally on your device. Your trusted Wi-Fi list never leaves your device.
4.3 Crash reports and what we do not collect
Crash reports are optional and contain only technical information (app version, operating system, error trace), never browsing activity. We do not collect precise location, contacts, photos, microphone or camera data, or advertising identifiers, and our apps contain no third-party advertising or analytics SDKs.
5. Website data and cookies
Our website is deliberately simple. It uses only first-party, essential browser storage and does not load advertising or analytics trackers. In summary:
pd_cookie(localStorage) remembers that you have seen and acknowledged our cookie notice;pd_ipinfo(sessionStorage) temporarily caches the result of the IP lookup shown on the What is my IP page, so it does not have to be repeated on every page view;pd_form(sessionStorage) passes the details you just submitted on a form to our thank-you page so that we can confirm what you sent.
The What is my IP feature asks a third-party IP geolocation service (ipapi.co) directly from your browser for your public IP address and its approximate location, so that we can display it to you. We do not receive or store the result. Full details, including how to delete stored items, are in our Cookie Policy.
Like every web server, the servers hosting our website receive standard technical information (such as your IP address and browser type) when your browser requests a page. Web server access logs are kept for no longer than 14 days and are then deleted. These website logs are completely separate from our VPN infrastructure and contain nothing about your VPN usage.
6. How we use your data
We use the limited personal data we hold only to: provide and authenticate your account and apply plan limits; process payments, renewals and refunds and meet tax obligations; answer support requests (within 24 hours, 365 days a year); send essential service messages about your subscription, renewals and security; prevent fraud, account sharing and network abuse in ways consistent with our no-logs design; plan capacity using anonymous aggregate statistics and fix bugs using optional crash reports; send marketing e-mails only with your consent (see section 15); and comply with valid legal obligations within the limits of the data we actually hold. We never use your data for profiling or behavioural advertising.
7. Legal bases for processing
Under the GDPR and UK GDPR we rely on performance of a contract to provide the service, legal obligation for tax and accounting records, legitimate interests for fraud and abuse prevention, answering enquiries and defending legal claims (only where not overridden by your rights), and consent for optional crash reports and marketing, which you can withdraw at any time. The basis for each category is shown in the table in section 4.
8. Payment processors
We do not see or store your full card number. Payments are handled by our payment partners:
- PayPal: when you pay with a PayPal balance or with a credit or debit card, the transaction is processed by PayPal. PayPal collects your card or account details under its own privacy policy. We receive only the information needed to confirm and account for your payment: a transaction ID, the amount, the currency, the date, the status of the payment and, where provided, the payer's e-mail address and country.
- Authorised resellers: in some countries you can pay with local methods such as bank transfer, e-wallets, prepaid cards or over-the-counter payment through an authorised reseller. The reseller handles your payment information under its own privacy terms; we receive only your username or e-mail address and the plan purchased.
Payment records are the only data we hold that could connect an account to a real-world identity, and they say nothing about how you use the VPN.
9. Sharing and disclosure
9.1 We do not sell your data
We have never sold, rented or traded personal data and we never will. We do not share personal data with advertisers or data brokers. In the terms of the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), we do not "sell" or "share" personal information for cross-context behavioural advertising.
9.2 Service providers
We share personal data only with carefully selected service providers who help us run the business, and only to the extent they need it: payment processors, data-centre and hosting providers that operate our servers and website, e-mail delivery providers that send account messages, and our help-desk ticketing system. They act only on our instructions under confidentiality and data-protection obligations. Data-centre providers that host our VPN servers do not receive any customer account data.
9.3 Resellers and Business VPN administrators
If you bought through a reseller, we may share with that reseller the information needed to activate, renew or refund the account it sold. Business VPN administrators can see their team members' names or work e-mails, seat status and assigned dedicated IPs. Administrators cannot see members' browsing activity, because we do not record it.
9.4 Legal requests
We may disclose personal data if we are required to do so by a valid and legally binding order from a competent authority, or where disclosure is necessary to protect the rights, property or safety of PD-Proxy, our customers or others. We challenge requests that are overly broad or lack a proper legal basis.
We can only hand over what we have. Because of our no-logs design, we cannot identify who used a particular VPN IP address at a particular time, what websites a user visited or what content they transmitted. At most, if an order identifies a specific account, we could disclose the account data listed in section 4, such as the e-mail address, subscription dates and payment records. Where legally permitted, we will notify the affected user before disclosing their data.
9.5 Business transfers
If PD-Proxy is involved in a merger or sale of assets, account data may be transferred, and we will require any successor to honour this policy, including the no-logs commitment.
10. International transfers
PD-Proxy serves customers worldwide and operates more than 40 server locations in over 25 countries. Our account systems and service providers may be located outside your country.
When we transfer personal data out of the European Economic Area, the United Kingdom or Switzerland to a country that has not been recognised as providing an adequate level of protection, we use appropriate safeguards, such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum. You can request a copy of these safeguards at [email protected].
Connecting to a VPN server abroad does not transfer your account data there; servers hold no customer database.
11. Security measures
We protect the data we hold with technical and organisational measures appropriate to the risk, including:
- modern VPN encryption (WireGuard, OpenVPN with AES-256-GCM, IKEv2/IPsec) and HTTPS for our website and account systems;
- passwords stored only as salted one-way hashes using a slow, modern algorithm;
- hardened VPN servers with no persistent activity logging and no local customer database;
- least-privilege staff access protected by multi-factor authentication and reviewed regularly;
- private DNS resolvers to prevent DNS leaks, a kill switch in our apps, network segmentation, encrypted backups and a documented incident-response process.
No system is perfectly secure. If a personal data breach is likely to put your rights at risk, we will notify the competent supervisory authority and affected users as required by law, without undue delay.
12. Data retention
We keep personal data only as long as needed for the purposes in this policy; the period for each category is in the table in section 4. Session data exists only in memory, aggregated counters are deleted within 24 hours, account data is deleted within 30 days of account closure, payment records are kept as long as tax law requires (typically up to 7 years), and website server logs are kept for no longer than 14 days. Deleted data may persist in encrypted backups for up to 30 days until they are overwritten.
13. Your rights
Depending on where you live, you have rights over your personal data. We extend the core rights below to all our customers, regardless of location.
13.1 Rights under the GDPR and UK GDPR
If you are in the European Economic Area or the United Kingdom, you have the right to:
- Access your data and receive a copy of it;
- Rectification of inaccurate or incomplete data;
- Erasure, subject to legal retention duties such as keeping invoices;
- Restriction of processing while a query is resolved;
- Portability of the data you gave us in a machine-readable format;
- Objection to processing based on legitimate interests, and to direct marketing at any time;
- Withdraw consent at any time where processing is based on consent;
- Complain to your local data-protection supervisory authority (we would appreciate the chance to help first).
13.2 Rights under the CCPA/CPRA (California residents)
If you are a California resident, you have the right to:
- Know the categories and specific pieces of personal information we have collected about you, the sources, the purposes and the categories of third parties with whom we share it;
- Delete personal information we have collected from you, subject to legal exceptions;
- Correct inaccurate personal information;
- Opt out of the sale or sharing of personal information – we do not sell or share personal information, so there is nothing to opt out of;
- Limit the use of sensitive personal information – login credentials are used only to authenticate you;
- Non-discrimination – we will not deny you service, charge you a different price or provide a different level of quality because you exercised your privacy rights.
In the preceding 12 months we have collected the following categories of personal information as defined by the CCPA: identifiers (e-mail address, username), commercial information (subscription and payment records) and account login credentials. We have disclosed these only to the service providers described in section 9 for business purposes.
13.3 How to exercise your rights
You can exercise any of these rights by e-mailing [email protected] from the e-mail address registered on your account, or by opening a support ticket.
To protect your account, we must verify that the request comes from you. Usually a request from your registered e-mail address is enough; occasionally we may ask you to confirm details only the account holder would know. California residents may use an authorised agent; we will ask the agent for proof of authorisation and may still need to verify your identity directly.
13.4 Response times
| Law | Acknowledgement | Full response | Possible extension |
|---|---|---|---|
| GDPR / UK GDPR | Within 3 business days | Within one month of receipt | Up to two further months for complex or numerous requests, with notice |
| CCPA / CPRA | Within 10 business days | Within 45 calendar days of receipt | Up to a further 45 days, with notice |
| All other customers | Within 3 business days | Within 30 days | We will explain any delay |
We respond to requests free of charge. We may refuse, or charge a reasonable fee for, requests that are manifestly unfounded or excessive, and will explain our reasons if we do.
14. Children
PD-Proxy services are intended for adults. You must be at least 18 years old, or the age of majority where you live, to create an account, as set out in our Terms of Use. We do not knowingly collect personal data from children under 16 (or under 13 in the United States). If you believe a child has provided us with personal data, please contact [email protected] and we will delete the account and associated data promptly.
15. Marketing e-mails
We send marketing e-mails, such as news about new server locations, product features or seasonal offers, only if you have opted in, or where the law allows us to contact existing customers about similar services and you have not objected. Every marketing e-mail contains a one-click unsubscribe link, and you can also unsubscribe by writing to [email protected]. Essential service messages such as receipts continue. We use no tracking pixels.
16. Automated decision-making
PD-Proxy was founded as a fully automated VPN provider, which means account creation, activation and renewals happen automatically. However, we do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you. If a payment is declined or an account suspended, a member of our team will review the decision on request.
17. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page shows when it was last revised. If we make material changes, particularly any change affecting our no-logs commitment or the categories of data we collect, we will notify account holders by e-mail and through a notice on our website at least 30 days before the change takes effect.
18. Contact us
If you have any question, request or complaint about this Privacy Policy or our handling of your personal data, please contact us:
- Privacy and data-protection requests: [email protected]
- General support: [email protected]
- Legal notices: [email protected]
- Contact form: pdproxy.com/contact
We aim to acknowledge every privacy enquiry within 3 business days.