Privacy Policy
Last updated: August 2026
This policy applies to the cross-border network acceleration service provided by NZVPN (hereinafter "the Service"). The Service follows a data minimization principle. This page explains what information is collected, why it is collected, and how users can manage it.
1. What Information the Service Collects
Registration information. Registration only requires a username and password; no email address is needed. The username is used for login and account identification, and the password is stored encrypted. The Service does not require users to provide their real name or ID documents.
Order records. When a user purchases a plan or data package, the Service stores the order number, selected plan, amount, payment status, and activation time. These records are used to verify orders, process refunds, and issue invoices.
Access statistics. To improve the service and troubleshoot issues, the Service records anonymized access data such as device type, operating system version, browser type, access time, and time spent on pages. Identifiable information is removed from statistics before they enter the analytics pipeline, and they do not include users' browsing content or specific websites visited.
Client connection information. When a user connects to a server via the client, the server briefly records connection time and transferred traffic for monthly usage statistics and troubleshooting. This information is cleared after the session ends and does not include the content of websites visited by the user.
2. Logging and Privacy Stance
The Service does not record which websites users visit. Network content transmitted through the Service is not written to server logs in any form.
Connection log retention policy. Session information generated when the client connects to a server (connection time, traffic) is used only for monthly usage statistics and troubleshooting, and is automatically deleted after the session ends. The Service does not retain logs that can be linked to specific users' browsing behavior.
Anonymization first. Access statistics and diagnostic data are anonymized before entering the analytics pipeline and cannot be traced back to individuals.
3. Cookies and Local Storage
Cookies. The Service uses a small number of necessary cookies to maintain login state and language preferences. Session cookies expire when the browser closes, and persistent cookies are used only to remember language selection. The Service does not use third-party advertising cookies.
Local storage. The client stores subscription configuration and connection preferences locally on the user's device. This data stays on the user's device and is never uploaded to the server.
Managing cookies. Users can clear cookies in their browser settings or clear the local cache in the client. After clearing, they will need to log in again or re-import the subscription configuration.
4. Payments and Third-Party Processing
Payment methods. The Service supports Alipay, WeChat Pay, and USDT payments. The payment process is completed by the respective payment channels, and the Service never accesses or stores users' payment account passwords.
Payment records. The Service only stores information necessary for orders (order number, amount, payment status) for reconciliation and refunds. The payment channels' own privacy policies apply to the data they process.
5. Data Retention and Deletion
Retention period. Order records are retained from order completion until financial and tax compliance requirements are met. Access statistics are periodically deleted after their analytical purpose is fulfilled. Registration information is retained for as long as the account exists.
Deletion. Users can request account deletion through account settings. Upon receiving a request, the Service will delete or anonymize data related to the user. Order records subject to financial compliance requirements will be deleted after the statutory retention period expires.
Account cancellation. After an account is cancelled, the user's login credentials and personal configuration are permanently deleted and cannot be recovered. Existing order records are handled according to the previous clause.
6. Policy Updates
Update notifications. This policy may be updated due to service adjustments or regulatory changes. Significant changes will be announced on the website or through in-site notifications.
Effective date. The updated policy takes effect from the "Last updated" date shown on this page. Continued use of the Service constitutes acceptance of the revised policy.
Contact us. If you have questions about this policy, you can contact the Service through the in-site ticket channel.