Qiao VPN Privacy Policy
Draft prepared from research of reputable no-logs VPN policies (Mullvad, Proton VPN, Surfshark, and NordVPN/ExpressVPN patterns). Not legal advice. Have a licensed attorney in [JURISDICTION / GOVERNING LAW] review and fill every [PLACEHOLDER] before launch. Consumer-protection and data-protection laws (GDPR/UK GDPR/CCPA, etc.) can override contract terms, so local review is essential.
Effective date: [EFFECTIVE DATE]
This Privacy Policy explains what information Qiao VPN ("Qiao VPN", "we", "us", or "our"), operated by [COMPANY LEGAL NAME], collects when you visit our website, create an account, or use our applications and virtual private network service (the "Service"), how we use that information, and the choices you have. Our goal is to collect as little data as possible while still being able to operate a reliable, paid subscription service.
By using the Service, you agree to the practices described in this Policy. If you do not agree, please do not use the Service.
1. Our privacy commitment in short
- We operate a strict no-logs Service. We do not monitor, record, store, or share the content of your traffic, the websites or services you connect to, your DNS queries, or your browsing history.
- Our VPN servers run entirely from volatile memory (RAM-only). They are designed so that no user activity data is written to a persistent disk, and data does not survive a reboot or power-off.
- We collect only the limited account and operational information described below, and only for the purposes stated.
- We do not sell your personal data, and we do not rent, trade, or share it for advertising purposes.
2. What we do NOT log
When you use the VPN, we do not keep logs that would allow us to associate specific network activity with you or your account. In particular, we do not log:
- The websites, applications, services, or IP addresses you connect to through the VPN.
- Your browsing history, the content of your traffic, or the data transferred through the tunnel.
- Your DNS queries.
- Connection timestamps tied to your identity, session duration tied to your identity, or a history of the originating IP addresses you connect from.
Because our VPN servers are RAM-only, information needed to route a live connection exists only in memory for the duration of that active session and is not written to persistent storage. We cannot produce activity logs that we do not create or keep.
3. Information we do collect
We collect the minimum information necessary to create your account, process your payment, enforce your plan's device limit, prevent abuse, and provide support.
a. Account information. When you register, we collect an email address. We use email to identify your account, deliver a one-time passcode (OTP) for verification and sign-in, send transactional messages (such as receipts, expiry reminders, and important service notices), and provide support. To reduce fraud and abuse, we do not accept known disposable or temporary email addresses, and registration with such an address may be refused.
b. Order and billing records. Payments are handled by our third-party payment processor, iDataRiver (see Section 6). We receive and retain limited order records, such as a transaction or order identifier, the plan and term purchased, the amount, the currency, the approximate time of the transaction, and the payment method type (for example Alipay, WeChat Pay, UnionPay, card, Google Pay, Apple Pay, or crypto/USDT). We do not receive or store your full payment card number, card security code, or full banking credentials.
c. Device identifiers for the device cap. Each subscription tier permits a set number of devices (for example, 2 devices on Voyager and 4 devices on Meridian). To enforce this limit, our apps generate and transmit a device identifier for each device signed in to your account. We use these identifiers only to count and manage active devices against your plan and to let you remove devices. We do not use them to track your activity.
d. Aggregate operational data. To keep the Service secure, stable, and performant, we process aggregate, non-identifying operational information, such as total load on a server, aggregate bandwidth, app version, and general error or crash diagnostics. This information is used in aggregate for capacity planning, security, and troubleshooting, and is not used to build a profile of an individual user's activity.
e. Support communications. If you contact support, we collect the information you choose to provide (such as your email and the contents of your message) so that we can respond and resolve your issue.
f. Website data and cookies. See Section 9.
4. How we use your information
We use the information above only to:
- Create, authenticate, and secure your account, including sending OTP codes.
- Process your subscription, deliver receipts, and manage renewals, refunds, and expirations.
- Enforce your plan's device limit.
- Provide customer support.
- Detect, prevent, and address fraud, abuse, security incidents, and violations of our Terms of Service.
- Maintain, analyze in aggregate, and improve the reliability, security, and performance of the Service.
- Comply with applicable legal obligations that bind us.
We rely on the following legal bases where applicable: performance of our contract with you (providing the Service you purchased), our legitimate interests (security, fraud prevention, and operating our business), your consent (where required, for example certain cookies), and compliance with legal obligations.
5. Email OTP verification and disposable-email rejection
We use email one-time passcodes to verify ownership of an email address and to help secure account access. To limit fraud, abuse, and trial abuse, we screen registration emails and may reject addresses associated with known disposable or temporary email providers. If a valid, non-disposable email cannot be verified, we may decline to create or maintain the account.
6. Payment processing (third-party processor)
Payments are processed by our third-party payment aggregator, iDataRiver, and by the underlying payment providers it supports (which may include Alipay, WeChat Pay, UnionPay, cards, Google Pay, Apple Pay, and crypto/USDT). When you pay, your payment details are provided to and handled by the payment processor and the relevant provider under their own terms and privacy policies. Qiao VPN never receives or stores your full card number, card security code, or full banking credentials. We receive only the limited order records described in Section 3(b), which we use to activate and manage your subscription, to provide receipts and support, and to process refunds. We encourage you to review the privacy policy of the payment processor and your chosen payment provider.
7. Data retention and deletion
We keep personal information only for as long as it is needed for the purposes described in this Policy, and then delete or anonymize it.
- Account information is retained while your account is active. If you delete your account, or if your account remains inactive with no active subscription for [RETENTION PERIOD, e.g. 12 months], we delete or anonymize the associated account information, subject to the exceptions below.
- Order and billing records may be retained for a longer period where we are required to keep financial and tax records under applicable law. Where retention is legally required, we keep only the records necessary to meet that obligation.
- Support communications are retained for as long as needed to resolve your matter and for a reasonable period afterward, then deleted.
- Aggregate operational data is not linked to your identity and may be retained in aggregate form.
Because the Service is no-logs and our servers are RAM-only, there are no browsing, traffic, DNS, or identity-linked connection logs to retain or delete.
8. Your rights
Depending on where you live, you may have rights over your personal information, which can include the right to access the information we hold about you, to request correction, to request deletion, to object to or restrict certain processing, and to data portability. You may also have the right to lodge a complaint with your local data-protection authority.
To exercise these rights, contact us at [SUPPORT EMAIL] or [DPO/CONTACT] using the email associated with your account so that we can verify your request. We will respond within the time required by applicable law. Please note that fulfilling certain requests (for example, deleting your account) may limit or end our ability to provide the Service or support to you, and that we may retain limited records where we are legally required to do so.
9. Cookies and website analytics
Our website uses cookies and similar technologies. Strictly necessary cookies are required to operate the site, keep you signed in, and secure your session. Where required by law, we ask for your consent before using any non-essential cookies (such as basic, privacy-respecting analytics), and you can decline non-essential cookies. You can also control cookies through your browser settings. We do not use cookies to sell your data or to build advertising profiles.
10. No sale of data
We do not sell your personal information, and we do not share it with third parties for their own advertising or marketing. We share limited information only with service providers who help us operate the Service (such as our payment processor and email delivery provider), and only to the extent needed for them to perform their function under appropriate confidentiality and data-protection obligations.
11. Disclosure required by law
We will not disclose personal information except where we are legally compelled to do so by a valid, binding, and lawful order from an authority with jurisdiction over us. Even then, we can only provide the limited information we actually hold. Because we do not keep activity logs and our servers are RAM-only, we cannot provide browsing history, traffic contents, DNS queries, or identity-linked connection logs, as this information does not exist in our systems.
12. Security
We use technical and organizational measures designed to protect the information we hold, including strong, modern encryption in transit and access controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security, but we work to protect your information consistent with the minimal-data approach described here.
13. International users and data transfers
We operate the Service globally. Your information may be processed in countries other than your own, including the country of our operation and the countries where our service providers are located. Where required, we use appropriate safeguards for such transfers.
14. Children
The Service is not directed to children, and it is not intended for anyone under the age of 18 (or the age of majority in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
15. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will update the effective date above and, where appropriate, notify you. Your continued use of the Service after an update means you accept the revised Policy.
16. Jurisdiction and contact
This Policy is governed by the laws of [JURISDICTION / GOVERNING LAW]. The data controller is [COMPANY LEGAL NAME], [REGISTERED ADDRESS].
For any privacy question or request, contact:
- Support: [SUPPORT EMAIL]
- Data protection contact: [DPO/CONTACT]