Privacy Policy
Last updated: April 21, 2026
This Privacy Policy describes how ProxyGlide collects, uses, stores and protects personal data when you use our 4G mobile proxy service. It applies to every visitor, prospect and paying customer. Our guiding principle is minimalism: we collect the data strictly needed to run the Service and meet our legal obligations, we do not log the content of traffic that passes through our proxies, and we apply GDPR-aligned retention windows even where not strictly required.
This document is a draft and must be reviewed by a qualified attorney or DPO before go-live.
1. Who we are
The data controller for personal data processed through the Service is POLYMORPH, a French SASU (share capital €1,000), registered office at 1 rue de Stockholm, 75008 Paris, France, SIREN 100 668 920, operating the Service under the commercial brand ProxyGlide (“we”, “us”). We operate EU-based infrastructure and are reachable for any privacy matter at privacy@proxyglide.io. Full company identification on the Legal notice page.
2. Data we collect
- Account data: email, name (optional), hashed password, 2FA secret.
- Billing data: orders, payment references (provider transaction IDs, no card numbers stored on our side).
- Usage data: per-proxy aggregated byte counters, rotation timestamps, audit logs (login IP, user agent).
- Support data: correspondence you send us via support, sales, abuse or security channels.
3. What we do NOT log
We do not log the URLs, destination hosts, request bodies, response bodies, or payloads of traffic routed through proxies. Only aggregate byte counters and per-proxy request counts are retained for billing, fair-use review and abuse prevention. Individual request-level data is discarded.
4. Legal bases (GDPR)
- Performance of the contract (account, billing, proxy delivery).
- Legitimate interest (security, audit logs, fraud prevention, service integrity).
- Consent where required (marketing emails — opt-in and revocable at any time).
- Legal obligation (accounting records, responding to lawful requests).
5. Sub-processors
- Vercel (hosting)
- Neon (primary database)
- Upstash (Redis / rate-limiting)
- Card2Crypto.org (card & fiat on-ramp, settled as USDC Polygon)
- CoinGecko (public crypto exchange rates)
- Resend (transactional email)
- Sentry (error tracking, scrubbed of PII)
6. Retention
- Account data: until account deletion, then 30 days of backup retention.
- Audit logs: 12 months.
- Billing records: 10 years (French accounting obligation).
- Aggregate usage counters: 24 months.
7. Your rights
You may access, correct, port, or delete your personal data, and object to processing. You may also lodge a complaint with your supervisory authority (CNIL in France). Contact privacy@proxyglide.io to exercise any of these rights; we respond within one month.
8. International transfers
Some sub-processors are located outside the EU/EEA. Transfers rely on Standard Contractual Clauses (SCCs) and, where required, supplementary measures.
9. Cookies
We use strictly necessary cookies for session management and security. We do not deploy third-party analytics or advertising cookies without explicit consent.
10. Changes
We will notify material changes by email and dashboard notice at least 14 days before they take effect. The “last updated” date at the top of this page always reflects the current version.