Logo de FlashProxy

FlashProxy

Privacy Policy

FlashProxy B.V.

Last Updated: September 22, 2026

1. Introduction and Data Controller

FlashProxy B.V. ("FlashProxy", "we", "us", "our") is the data controller responsible for your personal data. FlashProxy B.V. is registered in the Netherlands under Chamber of Commerce (KvK) number 93923198.

This Privacy Policy explains how we collect, use, store, and protect your personal data when you use the FlashProxy website at flashproxy.com (and flashproxy.io) and our related services (collectively, the "Services"). It applies to all visitors, registered users, and customers of FlashProxy.

If you have any questions about this Privacy Policy or our data practices, you can contact us at contact@flashproxy.io.

2. Information We Collect

2.1 Account Information

When you create an account, we collect your email address, display name, and account credentials. Authentication is managed via Firebase Authentication.

2.2 Payment Information

Payment transactions are processed by our payment providers (Paddle and TheDex). We receive and store the following payment-related data:

  • Transaction IDs
  • Payment amounts
  • Payment method type
  • Partial card details (last four digits, card type, expiry)

We do not store full card numbers or CVVs.

2.3 Technical and Device Information

When you visit our website, we automatically collect the following technical information:

  • IP address, and information derived from it by our network provider: country, region, city, the network operator (autonomous system) and whether the address belongs to a hosting provider, VPN, proxy or consumer network
  • Connection characteristics: TLS protocol version and cipher, HTTP protocol version, browser client hints (browser brand and version, platform, architecture, device model)
  • Browser type and version, operating system, language and time-zone settings
  • Device characteristics used to recognise the same device across visits: screen size and pixel density, graphics adapter identification, canvas and audio rendering signatures, installed-font detection, processor core count and memory class, touch support, and storage capacity. These are combined into hashes; we do not store the raw rendering output.
  • Whether the values your browser reports agree with what our servers observe (for example a declared time zone that does not match the connection's country). We record such inconsistencies as a signal; we do not block anyone because of them.

2.4 Session and Security Data

We use a persistent session cookie and related technologies to maintain session continuity and protect against payment fraud. This includes:

  • A unique session identifier stored in a cookie and mirrored in browser storage
  • Associations between session identifiers, account identifiers, email addresses, IP addresses and device characteristics, collected in the background while you use the site (sent to us in encrypted form roughly once a minute and on page changes)
  • Payment identifiers received from our payment provider: card type, last four digits and expiry, a hashed cardholder name, and the customer and billing-address references assigned by the provider
  • Account lifecycle events (sign-up, sign-in, credential changes) and payment lifecycle events (checkout started, payment completed or declined, refund, chargeback)
  • For customers of our proxy services, the IP addresses from which your proxy credentials connect to our network, aggregated per day

Identifiers in the long-term security records (IP addresses, email addresses, card and cardholder details) are stored only as keyed one-way hashes, so they can be matched against each other but not read back. See Section 3.2, Section 5 and Section 7.3.

2.5 Usage and Analytics Data

We collect usage data including feature usage within the dashboard and service configuration data. On our public pages we also measure page views, scroll depth, button clicks, time on page, and the campaign or referral link that brought you to us. For visitors from the EU, EEA, UK and Switzerland this analytics measurement runs only with your consent (see Section 4.3 and our Cookie Policy).

2.6 Identity Verification (KYC) Data

When identity verification is required, we collect the following:

  • Full legal name
  • Current residential address
  • An image of a valid government-issued photo ID. Accepted documents include passports, national identity cards, and driver's licenses.
  • A biometric liveness selfie capture used to confirm you match your ID document

Identity verification is conducted through ComplyCube, our certified identity-verification provider, acting as a data sub-processor under a data processing agreement. You complete the check on a secure ComplyCube-hosted link; your ID and biometric data are captured, processed, and stored within ComplyCube's encrypted infrastructure. FlashProxy itself receives and retains only the verification result (pass/fail) and a reference identifier — not copies of your identity documents or biometric data. We do not collect KYC documents by email.

3. How We Use Your Information

3.1 Service Delivery

  • To provide, maintain, and improve our proxy services
  • To process payments and manage your account

3.2 Security and Fraud Prevention

We use your data to detect and prevent payment fraud, chargeback abuse, and unauthorized account usage. We link technical identifiers (IP addresses, session cookies, device characteristics, payment identifiers, and the IP addresses your proxy credentials connect from) into a security graph that shows when several accounts share the same device, payment instrument or network. When a payment is charged back, we look at which accounts are linked to it; at checkout we compute an internal risk indicator from account age, payment velocity, network type and these links. This processing is essential to protect our service and legitimate customers from financial fraud.

Human review. The risk indicator and the links from browsing data are information for our staff; they do not by themselves block, delay or refuse any purchase. The one automated safeguard is that after a chargeback has actually been received on a payment, card payments may be restricted on the accounts directly connected to that payment until a member of staff has reviewed the case. You can contest any such restriction through support, and a person will decide (Article 22 GDPR).

3.3 Communication

To send service-related notifications, support responses, and (with your consent) promotional materials.

3.4 Legal Compliance

To comply with applicable laws, respond to legal requests, and enforce our Terms of Service.

3.5 Identity Verification

We use KYC data solely to verify your identity for fraud prevention, to comply with account security requirements, and to respond to payment disputes. KYC data is not used for marketing, profiling, or any purpose unrelated to account verification and security.

5. Cookies and Similar Technologies

The complete list of cookies and browser-storage keys we set, with durations, is maintained in our Cookie Policy at flashproxy.com/cookies. In summary:

5.1 Strictly Necessary (no consent required)

  • __session (signed, not readable by scripts) and its readable mirror fp_sid: your session identifier, used for session continuity and fraud prevention. Persistent (10 years). Backup copies of the identifier are kept in local storage, IndexedDB and Cache Storage so an existing session can be restored if cookies are cleared; the copies cannot create a session by themselves.
  • fp_consent (your cookie-banner choice, 1 year) and fp_geo (your country code, 1 day, used only to decide whether the banner must be shown).
  • Language and theme preferences, and short-lived tokens for linking Telegram or Discord.

These are classified as strictly necessary under Article 5(3) of the ePrivacy Directive. They do not track you across other websites.

5.2 Analytics and Attribution (consent in the EU, EEA, UK and Switzerland)

Referral and campaign cookies (fp_ref, fp_refs, fp_utm, 30 days) and the page-usage measurement described in Section 2.5. Visitors from the regions above are asked in the cookie banner; choosing "Essential only" stops the measurement for that browser.

5.3 Third-Party Cookies

Google Ads and Google Analytics (conversion measurement and aggregate site statistics), the Crisp live-chat widget, and, during checkout or identity verification, Paddle and ComplyCube on their own pages. We do not build cross-site behavioural advertising profiles and do not sell data obtained through cookies. See the Cookie Policy for the providers' own policies.

6. Data Sharing and Third Parties

6.1 Payment Processors

Card payments are processed by Paddle (paddle.com), which acts as our Merchant of Record. Paddle is certified to PCI-DSS Level 1 (the highest card-data security standard) and is GDPR-compliant; full card numbers and CVVs are handled by Paddle and never reach our systems. TheDex processes cryptocurrency payments. These providers receive the payment details necessary to complete transactions and are subject to their own privacy policies.

6.2 Identity Verification Provider

When identity verification (KYC) is required, it is performed by ComplyCube (complycube.com), acting as our data sub-processor under a data processing agreement. ComplyCube is independently certified to ISO/IEC 27001 and UK DIATF, and processes your identity documents and biometric data to verify your identity. See Section 2.6 for what we collect and retain.

6.3 Infrastructure Providers

Firebase (Google Cloud) provides authentication and data storage services. Server hosting providers support our proxy infrastructure. These providers process data on our behalf under data processing agreements.

6.4 No Sale of Data

We do not sell, rent, or trade your personal data to any third party for their own purposes.

6.5 Legal Requirements

We may disclose information if required by law, regulation, legal process, or governmental request.

7. Data Retention

7.1 Account Data

Retained for the duration of your account plus 2 years after account closure.

7.2 Transaction Data

Retained for 7 years as required by Dutch tax and commercial law.

7.3 Security Data

  • Raw browsing and device event records (Section 2.3 and 2.4), including readable IP addresses, are deleted 180 days after collection.
  • The long-term security graph — the links between sessions, accounts and hashed identifiers, account and payment lifecycle events, daily proxy-connection summaries, and the internal risk indicators — is retained for 5 years from collection. Records that are part of a confirmed fraud or chargeback case may be kept for as long as necessary to establish, exercise or defend legal claims. Identifiers in these records are one-way hashes (Section 2.4).
  • Raw payment-provider notifications attached to payment events are cleared after 2 years; the transaction record itself follows Section 7.2.
  • Security flags associated with active fraud cases are retained until the case is resolved plus 2 years. Security event logs are retained for 2 years.

7.4 Communication Data

Support correspondence is retained for 2 years after resolution.

7.5 Identity Verification Data

Your identity documents and biometric data are held by ComplyCube, our identity-verification sub-processor, in line with their retention controls and our data processing agreement. FlashProxy retains only the verification result (pass/fail) and a reference identifier for the duration of your active account plus 12 months after closure or termination, after which it is permanently deleted.

You may request earlier deletion of your identity data by contacting us, subject to any legal obligations requiring us to retain certain records.

8. Your Rights

Under GDPR Chapter III, you have the following rights regarding your personal data:

  • Right of Access (Art. 15) — You have the right to obtain confirmation of whether we process your personal data and to access that data.
  • Right to Rectification (Art. 16) — You have the right to have inaccurate personal data corrected.
  • Right to Erasure (Art. 17) — You have the right to request deletion of your personal data.
  • Right to Restriction of Processing (Art. 18) — You have the right to request restriction of processing in certain circumstances.
  • Right to Data Portability (Art. 20) — You have the right to receive your data in a structured, commonly used, machine-readable format.
  • Right to Object (Art. 21) — You have the right to object to processing based on legitimate interests, including fraud prevention processing.

To exercise any of these rights, contact us at contact@flashproxy.io. We will respond within 30 days.

Note: Certain data may be exempt from erasure requests where retention is required by law or necessary for the establishment, exercise, or defence of legal claims (including fraud prevention).

9. International Data Transfers

Your data may be processed by service providers located outside the European Economic Area. Where this occurs, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission.

10. Data Security

We implement appropriate technical and organizational measures to protect your data, including encrypted data transmission (TLS), access controls, and secure infrastructure.

No method of electronic storage is 100% secure, and we cannot guarantee absolute security.

11. Children

Our Services are not directed to individuals under 18 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy periodically. We will notify registered users of material changes via email. Continued use of our Services after changes constitutes acceptance.

13. Contact and Supervisory Authority

For questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

FlashProxy B.V.

Softbalplein 8

2492 VR 's-Gravenhage, Netherlands

KvK: 93923198 | VAT: NL866574566B01

You have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

14. Browser Extension

The FlashProxy Browser Extension does not collect, store, or transmit any personal data to external servers. Specifically:

  • Proxy Credentials:Your proxy usernames, passwords, and server configurations are stored locally in your browser using Chrome's secure storage API. This data never leaves your device and is not transmitted to FlashProxy or any third party.
  • IP Address Display: The extension fetches your current IP address from ipinfo.io solely to display your connection status within the extension interface. This information is used for display purposes only and is not stored or transmitted elsewhere.
  • WebRTC Protection: The extension modifies browser WebRTC settings to prevent IP leaks. This is done locally and no data is collected.
  • Website Content: The extension routes web traffic through your configured proxy servers. We do not intercept, read, store, or analyze any website content or browsing activity.

All data stored by the extension remains locally on your device within Chrome's secure storage. Uninstalling the extension will remove all locally stored data.

© 2026 FlashProxy B.V. All rights reserved.