RoamingProxy

Privacy Policy

Effective 10 August 2026

This policy describes exactly what the RoamingProxy platform collects, why, how long we keep it, and what you can ask us to do with it. It reflects what the system actually stores today, not what we might build later.

1. Who we are

Trade Vault LLC, trading as RoamingProxy, operates the API platform available in this dashboard. For data-protection purposes Trade Vault LLC is the controller of the account and logging data described below. Contact: privacy@roamingproxy.com.

2. What we collect

Account data. Your email address, your full name, a bcrypt hash of your password (never the password itself), and your account creation and activation timestamps.

Authentication logs. For every sign-in attempt, successful or not, we record the email address entered, the originating IP address, the browser user-agent string, the outcome, and the timestamp.

API request logs. For every API call we record the first characters of the API key used (a prefix, never the full key), the originating IP address, the user-agent string, the endpoint called, the response status, and the timestamp. We do not store proxied response bodies.

Usage records. Per-request counts and the computed cost, used to meter and invoice your account.

We do not collect card numbers or bank details. Where you pay by card, the card is collected by our payment provider acting as merchant of record; it is that provider, not us, that receives and holds the card data, and no card number, security code or expiry date is accepted, transmitted or stored by us at any point. Where we invoice you directly we hold no payment instrument at all. We do not buy personal data from third parties, and we do not use your content to train models.

3. Why we collect it, and our legal basis

  • To provide the Service — account data and usage records. Basis: performance of our contract with you.
  • Abuse prevention and platform security — authentication logs and API request logs let us detect credential stuffing, key sharing, quota evasion, and traffic aimed at systems our users are not authorised to reach. Basis: our legitimate interest in running a proxy network that is not used to attack others, and our legal obligation to respond to abuse reports.
  • Billing and payment-dispute evidence — usage records and request logs are the evidence that a service was actually delivered. If you or your bank disputes a charge, we will produce these logs to the payment network. Basis: performance of our contract, and our legitimate interest in defending against chargebacks.
  • Legal and tax compliance — invoice records. Basis: legal obligation.

4. How long we keep it

  • Account data — for as long as your account is open, then deleted within 30 days of account closure.
  • Authentication logs and API request logs — 13 months. This spans the chargeback window used by the major card networks, which is the reason for the length. They survive account closure.
  • Usage records — 7 years, because they underpin invoices and tax records.

Backups are retained for up to 35 days, so deleted records may persist in an encrypted backup for that period before ageing out.

5. Who we share it with

We do not sell personal data and we do not share it for advertising. We disclose it only to:

  • Infrastructure providers — Amazon Web Services hosts our servers and database in the United States.
  • Email delivery — Amazon SES sends account and verification email.
  • Payment networks and banks — only when a payment dispute is opened, and only the logs needed as evidence.
  • Law enforcement — where we are legally compelled. We will notify you unless prohibited from doing so.

6. Where your data is processed

Our infrastructure runs in the United States. If you are in the European Economic Area or the United Kingdom, using the Service involves transferring your data to the US. We rely on the European Commission's Standard Contractual Clauses with our processors for those transfers.

7. Your rights

Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, restrict or object to processing, port it elsewhere, and withdraw consent. You can update your name and email and delete your account directly from the profile page.

For anything else, email privacy@roamingproxy.com. We will respond within 30 days. We may need to verify your identity first.

Note the limit on erasure: we cannot delete authentication and request logs on request while they are within the retention windows above, because we need them for abuse prevention and to defend payment disputes. We will delete them when the window expires.

EEA and UK users may complain to their local supervisory authority.

8. Security

Passwords are stored as bcrypt hashes. Provider API keys are stored encrypted at rest. Traffic to the API and the dashboard is encrypted in transit with TLS. Access to production data is restricted to staff who need it.

No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant regulator as required by law.

9. Cookies and analytics

The dashboard stores your access token and theme preference in browser local storage. These are strictly necessary to keep you signed in and are not used for tracking. We do not use advertising cookies or cross-site trackers.

10. Children

The Service is not directed at anyone under 18 and we do not knowingly collect their data. If you believe a child has given us personal data, email us and we will delete it.

11. Changes to this policy

We will email account holders at least 30 days before a material change takes effect and update the effective date above.

© 2026 Trade Vault LLC. RoamingProxy is a service of Trade Vault LLC. Contact: support@roamingproxy.com or +1 (888) 527-9275.