1. Introduction
StackVPN ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our VPN service at stackvpn.app.
By using StackVPN, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Account Information
When you create an account or subscribe to StackVPN, we collect:
- Email address - Required for account creation, authentication, and service communications
- Payment information - Processed securely through our payment provider (Lemon Squeezy). We do not store full credit card numbers.
- Subscription details - Plan type, subscription status, billing cycle
2.2 Technical and Operational Data
To provide and maintain our service, we collect minimal technical information:
- Device information - WireGuard public keys (cryptographic identifiers, not linked to your identity)
- VPN server assignments - Which server you're connected to (for load balancing and troubleshooting)
- Connection metadata - Last handshake time, total bytes transferred (aggregate tunnel metrics)
- Provisioning events - When your VPN access is created, updated, or revoked
2.3 What We Do NOT Collect
StackVPN does NOT collect, log, or store:
- Browsing history, websites visited, or URLs accessed
- DNS queries (what domains you look up)
- Traffic content (packet payloads, file contents, messages)
- Connection timestamps that could identify your activity
- Source IP addresses in connection with your browsing
See our Logging Policy for complete details.
3. How We Use Your Information
We use collected information for the following purposes:
- Service delivery - Provision VPN access, manage your account, route your traffic
- Billing and payments - Process subscriptions, handle refunds, manage billing issues
- Customer support - Respond to inquiries, troubleshoot technical issues
- Service improvement - Analyze aggregate usage patterns, maintain server infrastructure
- Security and abuse prevention - Detect and prevent spam, fraud, or network abuse
- Legal compliance - Comply with applicable laws and respond to valid legal requests
4. Data Sharing and Disclosure
4.1 Third-Party Service Providers
We share limited information with trusted service providers who help us operate our business:
- Payment processor (Lemon Squeezy) - Handles subscription billing and payments
- Email service - Sends account notifications and VPN configuration emails
- Infrastructure providers - Cloud hosting for VPN servers and web services
These providers are contractually obligated to protect your data and use it only for specified purposes.
4.2 Legal Requirements
We may disclose information if required by law, such as:
- In response to valid legal process (subpoenas, court orders)
- To protect our rights, property, or safety, or that of our users
- To comply with applicable laws and regulations
However, because we minimize data collection, we have very limited information to provide even if legally compelled.
4.3 No Selling of Data
We do NOT sell, rent, or trade your personal information to third parties for marketing or advertising purposes.
5. Data Retention
We retain data only as long as necessary for service operation:
- Account information - Retained while your account is active and for up to 90 days after cancellation
- Billing records - Retained for up to 90 days for accounting and dispute resolution
- Operational logs - Retained for 7-90 days depending on type (see Logging Policy)
- Support communications - Retained for up to 1 year
After retention periods expire, data is permanently deleted from our systems.
6. Data Security
We implement appropriate technical and organizational measures to protect your information:
- Encryption in transit (TLS/SSL) and at rest where applicable
- Restricted access to personal data (only authorized personnel)
- Regular security assessments and updates
- Secure server infrastructure with hardened configurations
However, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.
7. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access - Request a copy of the personal data we hold about you
- Correction - Request correction of inaccurate or incomplete data
- Deletion - Request deletion of your personal data (subject to legal retention requirements)
- Portability - Request transfer of your data to another service
- Objection - Object to certain processing of your data
- Withdrawal of consent - Withdraw consent where processing is based on consent
To exercise these rights, contact us at privacy@stackvpn.app.
8. International Data Transfers
StackVPN operates servers in multiple countries. Your data may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place for such transfers.
9. Children's Privacy
StackVPN is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
10. Cookies and Tracking
Our website uses minimal cookies and tracking technologies:
- Essential cookies - Required for website functionality (session management)
- Analytics - Basic usage statistics to improve our website (can be disabled)
We do not use third-party advertising cookies or tracking pixels. See our Cookie Policy for details.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. We encourage you to review this policy periodically.
For material changes, we will notify you via email or through our service.
12. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us: