Privacy Policy
Last updated: June 10, 2026
This Privacy Policy describes what ProxyTower ("we", "us") collects, why, and how it is handled when you use our websites and proxy services (the "Service"). It is part of the Terms of Service.
What we collect
- Account data: your email address and a hash of your password. If you set a custom proxy password, it is stored encrypted so it can be shown back to you.
- Billing data: card payments are processed by Stripe — we never receive or store your card number, only payment status, amounts, and Stripe's references. Cryptocurrency payments are recorded as blockchain transactions (addresses, amounts, transaction IDs), which are inherently public on their networks.
- Usage data: operational metadata such as bandwidth consumed, connection counts, plan status, IP rotation and relocation events, and timestamps. We do not inspect or store the content of traffic you send through your proxy endpoint.
- Cookies: a session cookie to keep you signed in. We do not use advertising or cross-site tracking cookies.
How we use it
- To provide, bill for, and support the Service.
- To prevent fraud and abuse, and to investigate credible abuse reports (using operational metadata, not traffic content).
- To send transactional email (sign-in, billing, service notices). We do not send marketing email without your consent.
Who we share it with
- Processors: Stripe (card payments), Resend (transactional email), and our hosting and database providers, each only to the extent needed to run the Service.
- Legal: we respond to valid legal process and may disclose information where required by law or to protect the Service and others from harm.
- We do not sell your personal information.
Retention
Account and billing records are retained while your account is active and as required for tax, accounting, and fraud-prevention purposes. Operational metadata is retained on a rolling basis and aggregated or deleted over time. You may request deletion of your account by contacting support; we will delete data not subject to a legal retention requirement.
Security
Credentials are stored hashed or encrypted, secrets are managed outside source control, payment card data never touches our servers, and access to production systems is restricted. No system is perfectly secure; we will notify affected users of a breach as required by law.
Children
The Service is not directed to anyone under 18, and we do not knowingly collect information from children.
Changes
We may update this policy; the date above reflects the current version. Material changes will be reflected on this page before they take effect.
Contact
Privacy questions and deletion requests: support@proxytower.io