Last updated: 09/2026
This policy applies to all marketing pages and the user dashboard on vpnay.com. It explains what information VPNAY collects when providing cross-border network acceleration services, why it is collected, how long it is kept, and how users can manage it.
Information Collected and How It Is Used
VPNAY collects only the information required to provide the service, in four categories:
- Account details: username and password. No email address is required to register, and passwords are stored as irreversible hashes — VPNAY never keeps plaintext passwords.
- Order and subscription records: the plan or data package purchased, the amount, the payment channel, the order time, and data usage.
- Visit statistics: aggregate data such as page views, referrers, and device types; it does not include the specific destinations visited.
- Ticket records: the content of tickets users submit and the records of how they were handled.
Account and order information is used to create accounts, activate routes, reset data allowances, reconcile payments, and process refunds. Visit statistics help determine whether pages load correctly and whether content is useful; they are reviewed in aggregate and are never used to build personal profiles or serve ads. Ticket records are used only to answer questions and troubleshoot issues; if contact details are voluntarily left in a ticket, they are used only to reply to that ticket.
No-logs stance and connection log retention policy
VPNAY follows an anonymous no-logs approach: it does not record which websites users visit, does not record the contents of DNS queries, and does not keep connection logs linking an account to a destination address at a particular time. Temporary technical data generated while routes are running exists only in memory and is cleared when the session ends — nothing is retained long term.
Traffic statistics record totals only, which are used to calculate plan allowances; they never include specific destinations. When troubleshooting route connectivity, VPNAY looks at the operational status of the route itself, not at any individual account's access records.
Cookies and Browser Local Storage
This site does not use third-party advertising cookies and does not connect to ad tracking networks. Browser local storage is used for three things: keeping the login session token so you stay signed in, remembering your interface language preference, and restoring the last page you had open.
Visit statistics are handled by a self-hosted component, and the data stays on this site's servers. It is never sold or shared with third parties.
You can clear cookies and local storage at any time in your browser settings. You will need to sign in again afterwards, but your account, subscription, and traffic records are unaffected.
Payments and Third-Party Processing
Payments are completed through Alipay, WeChat, or USDT and are handled by the respective provider. VPNAY does not see or store payment credentials such as bank card numbers; it only receives the payment result and the order number.
Order records are used for reconciliation and refund processing. Subscriptions come with a 30-day no-questions-asked refund, and the order record serves as the proof when applying.
If a payment provider collects information under its own rules, that provider's privacy policy applies, and VPNAY cannot amend it on your behalf.
Data Retention, Deletion, and Account Closure
Account information is kept while the account is active, and collection stops after closure. To close the account or delete data, sign in to the user dashboard and submit a request through a ticket; once it is processed, the account cannot be restored.
Deletion covers:
- username and password hash;
- subscription configuration and route assignment records;
- session data stored locally in the browser.
Order records needed to handle refunds and disputes are kept until the relevant matter is resolved. Data is never sold or exchanged with any third party.
How This Policy Is Updated
When the policy changes, the Last updated date at the top of this page is revised along with the body text; no separate archive of past versions is kept. For significant changes to the scope of data collected or to retention practices, a notice is posted in the user dashboard.
Continuing to use the service after an update means accepting the revised content; if you do not accept it, you can stop using the service and request account closure.
For service scope, refund conditions, and liability terms, see the Terms of Use.