Privacy Policy
This Policy describes how VPNVendor handles personal data about managers and related technical information when you use the billing portal, control panel, and configuration delivery services.
1. Introduction
This Privacy Policy explains how VPNVendor ("VPNVendor", "we", "us", or "our") collects, uses, stores, and protects personal data when you visit our website, create a billing account, use the manager control panel, interact with support, or use related services (collectively, the "Services").
The Services are provided by a Ditta Individuale (sole proprietorship) registered in Italy, registration number VAT IT01812780086, trading under the name "VPNVendor".
VPNVendor provides subscription-based managed VPN server infrastructure for business managers. We process data about account holders (managers) and limited technical identifiers related to end users that managers create in the panel.
By using the Services, you acknowledge this Privacy Policy. Where required by law, we will request separate consent for specific processing activities.
2. Data controller
The data controller responsible for personal data described in this policy is a Ditta Individuale registered in Italy, VAT IT01812780086, operating under the VPNVendor brand (billing portal and manager platform).
For privacy-related requests, contact us through the support ticket system in your client area after login, or via the public contact form on our website.
3. Personal data we collect
Depending on how you use the Services, we may collect:
Account and billing data: name, company name, email address, postal address, phone number, tax or VAT details, order history, invoices, payment status, and communication preferences.
Authentication data: login email, password hash, session tokens, single sign-on nonces between the billing portal and manager panel, and security logs related to account access.
Manager panel data: server assignments, client records you create, traffic limits, expiry dates, notes, and operational settings you configure.
End-user identifiers: unique client IDs issued by managers, configuration retrieval events on our converter service, and related technical metadata (timestamps, IP addresses of requests, user-agent strings) necessary to deliver configurations securely.
Support data: ticket content, attachments, and correspondence when you contact us.
Technical and security data: IP address, browser type, device information, referrer URL, pages viewed, error logs, abuse-prevention signals, and aggregated usage statistics.
Payment data: we do not store full payment card numbers. Payment processors handle card data according to their own privacy policies; we receive confirmation tokens, last four digits, and transaction references where applicable.
4. How we use personal data
We use personal data to:
- provide, operate, and maintain the Services;
- process orders, invoices, renewals, and subscription changes;
- authenticate you and enable secure access to the manager panel;
- deliver VPN configurations to end users who present valid client IDs;
- enforce plan limits, prevent abuse, and protect platform integrity;
- respond to support requests and service notifications;
- comply with legal, tax, and accounting obligations;
- improve reliability, security, and user experience through analytics and diagnostics.
We do not sell personal data. We do not use manager account data to monitor the content of VPN traffic passing through servers you operate for your end users.
5. Legal bases for processing (EEA/UK users)
Where the GDPR or similar laws apply, we rely on:
- Contract — processing necessary to provide the Services you requested.
- Legitimate interests — security, fraud prevention, service improvement, and direct communication about your account, balanced against your rights.
- Legal obligation — tax, accounting, and regulatory requirements.
- Consent — where required for optional marketing or non-essential cookies; you may withdraw consent at any time without affecting core service delivery.
6. Sharing and processors
We share personal data only when necessary:
- Infrastructure and hosting providers that operate servers and databases under our instructions.
- Payment processors to complete transactions you initiate.
- Email and notification providers to deliver account, billing, and service messages.
- Professional advisers or authorities when required by law or to protect rights and safety.
All processors are bound by contractual confidentiality and data-protection obligations appropriate to the nature of the Services. We do not authorize processors to use your data for their own marketing.
7. International transfers
Your data may be processed in countries other than your own, including where our infrastructure providers operate data centers. When we transfer personal data outside the EEA or UK, we implement appropriate safeguards such as standard contractual clauses or equivalent mechanisms required by applicable law.
8. Retention
We retain personal data only as long as necessary for the purposes described in this policy:
- Active account data — for the duration of your subscription and a reasonable period thereafter.
- Billing and tax records — as required by applicable law (typically up to seven years where tax rules apply).
- Support tickets — until resolved and for a limited archive period for quality and dispute handling.
- Security logs — typically up to twelve months unless needed for an investigation.
When data is no longer required, we delete or anonymize it using commercially reasonable methods.
9. Security
We implement administrative, technical, and organizational measures designed to protect personal data, including access controls, encryption in transit, segmented infrastructure, and monitoring for unauthorized activity.
No method of transmission or storage is completely secure. You are responsible for protecting your account credentials and for configuring appropriate access controls for end users you manage.
10. Your rights
Depending on your location, you may have the right to:
- access a copy of personal data we hold about you;
- request correction of inaccurate data;
- request deletion where no overriding legal basis requires retention;
- restrict or object to certain processing;
- receive data in a portable format where technically feasible;
- lodge a complaint with a supervisory authority.
To exercise these rights, contact us through support. We may need to verify your identity before responding. We will answer within timeframes required by applicable law.
11. Cookies and similar technologies
Our website and client area use cookies and similar technologies for essential functions (session management, language preference, security), analytics, and optional features.
You can control cookies through your browser settings. Disabling essential cookies may limit your ability to log in or complete checkout. Where required, we present consent choices for non-essential cookies.
12. End-user data and manager responsibility
Managers create end-user records and distribute client IDs. Managers determine what personal data—if any—they collect from their own customers outside the VPNVendor platform.
For data managers enter into the panel or transmit through support on behalf of end users, managers act as independent controllers toward their customers. VPNVendor processes such data as a processor on the manager's instructions to deliver the Services.
Managers must provide their own privacy notices to end users where required by law and must not upload unlawful content or unnecessary personal data into the Services.
13. Children
The Services are intended for business users aged 18 or older (or the age of majority in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will take appropriate steps to delete it.
14. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will post the revised policy on this page and update the effective date. Continued use of the Services after the effective date constitutes acknowledgment of the updated policy where permitted by law.
15. Contact
Privacy questions and data subject requests can be submitted through the support ticket system in your client area or via the public contact page on our website. Please include enough detail for us to identify your account and respond effectively.
Service operator: Ditta Individuale, VAT IT01812780086.
