Privacy policy · version 1.0 · 21 September 2026
What we store, for how long, and what we never look at.
Short, because the list is short. An email address and a wallet open an account; the network carries your traffic without reading it.
The short version#
- An email address and a crypto payment open an account. No name, phone number or identity document is required.
- We meter traffic; we do not inspect it. TLS runs end to end between your client and the destination, and we do not store request or response bodies.
- Connection metadata (time, account, destination host, bytes, exit country) is kept for 30 days for abuse handling and billing accuracy, then deleted.
- The public website sets no cookies of its own and embeds no analytics, advertising or social-media scripts. The dashboard uses one strictly necessary session cookie.
- We do not sell or share personal data for marketing, and we send no marketing email without your explicit consent.
- You can obtain, correct, export or delete your data by asking. Closing the account deletes personal data within 30 days, except records that accounting law requires us to keep.
Who is responsible#
The controller of the personal data described here is HodlProxy, operator of the Service, identified in the Terms of service. This policy covers the website hodlproxy.com, the dashboard, the proxy gateways, the API and a support ticket.
What we collect, why, and for how long#
| Category | Data | Purpose | Kept for |
|---|---|---|---|
| Account | Email address, password hash, creation date, settings, sub-user labels | Providing and securing the account | Until closure, then 30 days |
| Wallet and orders | Transaction hashes, coins and amounts, USD conversions, orders, terms, refunds | Billing, refunds, bookkeeping | As long as accounting law requires, typically 5 to 10 years |
| Usage metering | Bytes and requests per day, per network and per sub-user | Billing, tiers, your own reports and API | 24 months, then aggregated without account reference |
| Connection metadata | Timestamp, account or sub-user, destination hostname, bytes, exit country | Abuse handling, fault diagnosis, billing disputes | 30 days |
| Authentication data | Whitelisted IP addresses, hashed API tokens, sign-in times and IP addresses | Authentication, detecting compromise | Until you remove them; sign-in history 90 days |
| Support tickets | Topic, subject, messages, references you quote, time stamps | Answering you, handling reports | For as long as the account exists, then erased with it |
| Website and edge logs | IP address, URL, time, browser identification, status code | Security, capacity planning | 14 days |
What we do not collect#
- The content of proxied traffic. HTTPS is tunnelled end to end; we never terminate, decrypt or re-sign TLS, and we store neither request nor response bodies, headers or URLs beyond the destination hostname kept in connection metadata.
- Identity documents, names, phone numbers or postal addresses. We ask for none of them, and we do not run identity verification unless a specific refund or fraud investigation requires proof of control over a wallet or an email address.
- Cookies, trackers, pixels, fingerprinting scripts or analytics on the public website. The dashboard sets one session cookie that is strictly necessary to keep you signed in.
- Data from your devices beyond what your browser or client sends with each request.
Legal bases#
We process account, wallet, order, usage and authentication data to perform our contract with you. We process connection metadata, website logs and abuse reports on the basis of our legitimate interest in keeping the Service secure, lawful and fair to every customer and to the people behind the exits. We keep billing records because accounting and tax law require it. Optional communications are sent only with your consent, which you can withdraw at any time.
Who receives data#
| Recipient | What they receive | Why |
|---|---|---|
| Content delivery and DNS provider | Request metadata for hodlproxy.com (IP address, URL, headers) | Serving and protecting the website |
| Cryptocurrency payment processor | Payment amount, coin, transaction hash, order reference | Detecting and confirming your top-ups |
| Infrastructure providers | Encrypted storage and compute for the Service | Hosting |
| Residential and mobile supply partners | Destination hostname and bytes needed to route each connection | Routing through consenting exits; they never receive your account identity |
| Competent authorities | The minimum required by a valid legal request, after review | Legal obligation |
We do not sell personal data and we do not share it for advertising or marketing. Where a provider processes data outside your country, we rely on contractual safeguards appropriate to the destination.
Security#
- Passwords are stored as salted hashes with a modern algorithm; API tokens are stored hashed and shown once.
- All connections to the website, dashboard and API use TLS. The hop from your client to a proxy gateway follows the protocol you choose; the Documentation explains the implications and offers the IP whitelist as an alternative to sending credentials.
- Access to production systems is limited to the people who operate the Service, with individual credentials and logging. Backups are encrypted.
- Security reports are welcome through a support ticket opened from a HodlProxy account and handled as described there.
Your rights#
You may ask for a copy of the personal data we hold about you, have it corrected, have it deleted, receive your usage data in a machine-readable form, object to or ask us to restrict processing based on legitimate interest, and withdraw a consent you gave. Send the request through a support ticket opened from your account from your account email, or use the export and deletion functions of the dashboard once available. We answer within 30 days. You may also lodge a complaint with the data protection authority of your country of residence.
Retention and deletion#
The retention periods in the table above apply automatically. When you close your account, personal data is deleted within 30 days, connection metadata rolls off within 30 days, and billing records are kept for the period required by accounting law and then deleted. Aggregated statistics that no longer identify anyone may be kept.
Children#
The Service is not directed at persons under 18 and we do not knowingly hold data about them. If you believe a minor has opened an account, tell us and we will close it and delete the data.
Changes and contact#
Changes to this policy are announced by email and on this page at least 14 days before they take effect, with a new version number and date at the top. Questions go through a support ticket; the operator's postal address is published in the Terms of service.