Privacy Policy

Last updated: 09/2026

This policy explains what data VPNCZ handles when providing cross-border network acceleration, why it is handled, how long it is kept, and how users can request deletion.

Key points

Signing up does not require an email address; the websites visited and DNS queries are not logged; data deletion requests can be submitted through the ticket section of the user panel.

What data is collected, and why

Signing up requires only a username and password. The service does not ask for an email address, so no email address is held in the account system. Passwords are stored as irreversible hashes and cannot be turned back into the original password; the username is used for signing in and identifying the account.

Order records include the plan name, amount, payment channel, order and activation times, and the traffic used within the plan. This information is used to activate and renew plans, generate invoices, process refunds and settle billing disputes.

The site records page views, traffic sources, device and browser types and similar metrics, to see which content is useful and which pages need work. Statistics are reviewed in aggregate and are not used for advertising.

The table below lists the data the service actually handles, and what it explicitly does not collect.

Data typeCollected?Purpose
Username and passwordYesCreating an account, signing in and identifying the account
Order and payment recordsYesActivating plans, reconciliation and refunds
Traffic usageYesTracking remaining plan traffic
Websites visited and connection logsNoN/A
Contacts, photo library and locationNoN/A

No-logs stance

VPNCZ does not record which websites users visit. The acceleration routes only forward traffic that is already encrypted; destination domains and page addresses are not stored, DNS queries are not stored, and connection times are not linked to source addresses in a way that could reconstruct browsing activity.

Connection log retention: to measure plan usage and troubleshoot route problems, a small amount of connection metadata passes between the client and the servers, for example the byte count for a session and the route type used. This data contains no destination information, is used only for billing and fault diagnosis, is not stored long term, and is never used for profiling or advertising.

Note that this policy covers the service's own logging practices; user devices, browsers and the platforms visited may still record access information under their own rules.

Cookies and local storage

The site uses no third-party advertising cookies and does no cross-site tracking. A few kinds of local data are written to the browser, each for a specific purpose:

  • Language preference: remembers the interface language you last selected, so your next visit opens directly in that language.
  • Sign-in state: after signing in to the user panel, the credential is kept in the browser's local storage so you do not have to sign in again; signing out or clearing browser data removes it.
  • Visit statistics: a random identifier used to tell unique visitors apart, used only to count page views and never to identify anyone.

All of this local data can be cleared or blocked in your browser settings. After clearing it, you will need to choose a language and sign in again; nothing else is affected.

Payment processing is handled by third parties

Plan and data pack payments are completed through third-party payment channels: Alipay / WeChat / USDT.

The site never touches or stores card numbers or payment account passwords. Identity checks and charges during payment are handled by the relevant channel under its own rules, and that information is covered by the channel's privacy policy.

On the order side, only what is needed for reconciliation is kept: plan name, amount, payment channel and payment time. Refunds are handled under the 30-day no-questions-asked policy; see the refund policy for the exact process.

Data retention periods and how to request deletion

Data retention follows one principle: keep only what the relevant purpose needs, for as short a time as possible. Sign-up details and order records are kept while the account is active, for sign-in, renewal and reconciliation; after an account is closed, all other data is deleted, apart from records needed for refunds and reconciliation still in progress.

How to request deletion: submit a request through the ticket section of the user panel, stating which data you want deleted. Once account ownership is verified, the request can be processed; if the account has unfinished orders or refunds, settlement is completed first and the data is then deleted as requested.

Sign-in credentials stored in the browser are cleared by the user and are separate from the deletion of account data.

Policy updates and questions

When this policy changes, the “Last updated” date at the top of this page is revised. Important changes to what is collected or how it is used are announced in the user panel, rather than only changing the date.

Continuing to use the service after a policy update means you accept the updated content; if you do not agree, you can stop using the service and request deletion as described in the previous section.

Questions about this policy can be submitted through the ticket section of the user panel, or see the contact page for other ways to get in touch.

Start Free Trial