What we collect

  • Account data — email address, optional Telegram handle, workspace and team structure.
  • Billing data — invoice records, payment amounts and transaction references. We never see wallet keys, and we do not receive or store card details because we do not accept cards.
  • Operational metadata — device state, region, plan, the identity parameters we generated, IP assignment and API usage.
  • Ban Shield telemetry — attestation results, integrity verdicts, signal-level risk indicators and account-state changes reported by you.
  • Support correspondence — messages you send us.

What we do not collect

We do not log screen content, keystrokes, message bodies, media files, contact lists or browsing history from your devices. We do not inspect or decrypt application traffic. Device traffic is routed, not read.

Why we process it

To provide and bill the service, to generate coherent device identities, to operate Ban Shield, to prevent abuse of our platform, and to comply with legal obligations. Our lawful bases under GDPR are contract performance, legitimate interests and legal obligation.

Who we share it with

  • Our payment provider (OxaPay), for invoice creation and settlement.
  • Our infrastructure and carrier partners, limited to what is needed to route your device.
  • Law enforcement, where we receive a legally valid order from a competent authority with jurisdiction over us. We publish an annual transparency report.

We do not sell data, and we do not share it with advertising networks or data brokers.

Retention

Account and operational data are retained while your account is active and for 60 days after termination, then permanently deleted. Billing records are retained for 7 years as required by Hong Kong law. Ban Shield telemetry is aggregated and anonymised after 90 days.

Your rights

Access, rectification, erasure, portability, restriction and objection, exercisable by writing to [email protected]. We respond within 30 days. If you are in the EEA or UK you may also complain to your supervisory authority.

Security

Encryption at rest and in transit, role-based access control internally, quarterly third-party penetration testing, and a published security contact at [email protected]. We disclose material breaches to affected customers within 72 hours.

Cookies

This website uses one cookie, to remember your language and theme preference. There is no analytics, no advertising pixel and no third-party tracker on this site. The console uses a session cookie for authentication.

Questions about this document? Write to [email protected].