Privacy Policy
Effective date: July 5, 2026
VPNzo ("Service") is operated by Taprise Ltd., a company registered in the United Kingdom. This Privacy Policy explains what personal data we collect, the legal basis on which we process it, how long we retain it, where it is transferred, and your rights as a data subject.
The list of partners you may find at Annex A
This Policy should be read together with our Terms of Use, which govern the legal relationship between you and Taprise Ltd., including the applicable governing law and jurisdiction.
By installing or using VPNzo, you acknowledge that you have read and understood this Policy.
1. Who We Are and How to Reach Us
Data Controller:
- Taprise Ltd.
- United Kingdom
- Email: support@vpnzo.app
- Website: vpnzo.app
UK Controller: Taprise Ltd. acts as data controller for UK residents under the UK GDPR and the Data Protection Act 2018.
2. What Data We Collect — Lawful Basis and Retention
We collect only the minimum data necessary to operate the Service. For each category we specify what is collected, why, the legal basis under GDPR Art. 6, and how long we keep it. A record of our legitimate interest assessments for processing under Art. 6(1)(f) is available on request.
2.1 Account and Authentication Data
What: Email address (if email registration); name or display identifier from Google or Apple Sign-In; authentication token (we never receive your password).
Why: Creating and maintaining your account; authenticating your identity on return.
Lawful basis: Performance of a contract — Art. 6(1)(b). This data is necessary to provide the Service.
Retention: Duration of active account + 30 days after account deletion request (for dispute resolution), then permanently deleted.
2.2 Subscription and Billing Data
What: Subscription status, plan, and billing period; purchase date and renewal date; payment method type (e.g. "card ending 4242") — we do not store full card numbers.
Why: Delivering the paid Service; managing the subscription lifecycle; resolving billing disputes.
Lawful basis: Performance of a contract — Art. 6(1)(b).
Processors:
- Adapty (USA) — subscription management and analytics; transferred under the EU Standard Contractual Clauses (SCCs) and, for UK personal data, the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs, as applicable
- Stripe (USA/EU) — payment processing for web purchases; transferred under the EU SCCs and UK IDTA/Addendum as applicable; Stripe's US entity is certified under the EU-US Data Privacy Framework
- CentroBill (EU) — payment processing for web purchases; EU-based, no international transfer
Retention: 7 years from transaction date, in accordance with UK and EU statutory accounting and tax record-keeping obligations.
2.3 Support and Communication Data
What: Email address; content of support messages and attachments; communication history with our support team.
Why: Responding to support requests; resolving technical issues; maintaining service quality.
Lawful basis: Legitimate interests — Art. 6(1)(f). We have a legitimate interest in providing customer support. This interest does not override your rights given the limited nature of the data and the reasonable expectation that support interactions are retained.
Processor:
- Freshdesk by Freshworks Inc. (USA) — transferred under the EU SCCs and, for UK personal data, the UK IDTA or UK Addendum, as applicable
Retention: 2 years from the date of the last interaction, then deleted.
2.4 Device and Technical Data
What: Device type and model; operating system and application version; language and regional settings; crash reports and diagnostic logs (anonymised where possible).
Why: Diagnosing technical issues; improving application stability; detecting abuse or fraud.
Lawful basis: Legitimate interests — Art. 6(1)(f). This data is technical in nature and does not identify you personally.
Processors:
- Adapty (USA) — analytics and crash reporting; transferred under the EU SCCs and UK IDTA/Addendum, as applicable
- Additional infrastructure providers (details available on request)
Retention: 90 days from collection, then deleted or fully anonymised.
2.5 VPN Session Metadata
What: Session start and end timestamps; server region selected; connection status and performance indicators (e.g. latency).
Why: Operating the VPN tunnel; diagnosing connection failures; capacity planning.
Lawful basis: Performance of a contract — Art. 6(1)(b). These signals are necessary to deliver the VPN connection you requested.
What we do NOT collect:
- Browsing history or DNS queries
- Traffic content, messages, or files transmitted through the VPN
- Destination IP addresses
- Any data that would allow us to identify which websites or services you visit
Retention: 30 days from session end, then deleted.
2.6 Payment Analytics Data
What: Subscription conversion events (trial started, subscription activated, cancelled); revenue metrics at cohort level; churn and retention signals.
Why: Understanding subscription performance; optimising pricing and trial mechanics; financial planning.
Lawful basis: Legitimate interests — Art. 6(1)(f). Analytics data is processed at an aggregated or pseudonymous level.
Processors:
- Adapty (USA) — transferred under the EU SCCs and UK IDTA/Addendum, as applicable
- Merchantro — jurisdiction to be confirmed; data processing agreement in place
Retention: Aggregated analytics: 3 years. Individual-level pseudonymous events: 12 months.
3. International Data Transfers
Some of our processors are located outside the UK and EEA. For transfers of personal data originating in the EEA, we rely on the EU Standard Contractual Clauses (SCCs). For transfers of personal data originating in the UK, EU SCCs alone do not satisfy UK GDPR requirements post-Brexit, so we additionally rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs, as applicable.
- Adapty — United States — EU SCCs; UK IDTA / UK Addendum for UK data
- Freshdesk (Freshworks) — United States — EU SCCs; UK IDTA / UK Addendum for UK data
- Stripe — United States / EU — EU SCCs + EU-US Data Privacy Framework; UK IDTA / UK Addendum for UK data
- CentroBill — European Union — No transfer — EU-based
- Merchantro — To be confirmed — Not yet confirmed — see Section 2.6
Copies of applicable SCCs, the UK IDTA, and the UK Addendum are available on request: support@vpnzo.app.
4. Data Sharing and Disclosure
We do not sell, rent, or trade your personal data to third parties for marketing purposes.
We share data only in the following circumstances:
4.1 With processors listed in Section 2
Solely for the purposes described, under binding data processing agreements compliant with Art. 28 GDPR.
4.2 For legal compliance
When required by applicable law, court order, or a lawful request from a competent authority. We will notify you of such requests where legally permitted.
4.3 To protect our rights
When necessary to prevent fraud, enforce our Terms of Use, or protect the safety of users or the public.
4.4 Business transfers
In the event of a merger, acquisition, or asset sale, personal data may be transferred to the acquiring entity. We will provide at least 30 days' advance notice before your data becomes subject to a materially different privacy policy.
5. Your Rights
EEA and UK residents (GDPR / UK GDPR)
- Access (Art. 15) — Receive a copy of the personal data we hold about you
- Rectification (Art. 16) — Request correction of inaccurate or incomplete data
- Erasure (Art. 17) — Request deletion of your personal data
- Restriction (Art. 18) — Request that we limit processing of your data
- Portability (Art. 20) — Receive your data in a structured, machine-readable format
- Objection (Art. 21) — Object to processing based on legitimate interests
- Withdraw consent (Art. 7(3)) — Where processing relies on consent, withdraw it at any time without affecting prior lawful processing
Note: certain rights, such as erasure, may be limited where we are required to retain data to comply with a legal obligation — for example, the statutory accounting and tax retention period described in Section 2.2.
Automated decision-making: we do not carry out solely automated decision-making, including profiling, that produces legal or similarly significant effects concerning you.
To exercise any right, contact us at support@vpnzo.app. We will respond within 30 days. For complex requests, we may extend this by a further 60 days with written notice.
You also have the right to lodge a complaint with your national supervisory authority, and the right to an effective judicial remedy under Article 79 GDPR:
- UK: Information Commissioner's Office — ico.org.uk — 0303 123 1113
- EU: Your national Data Protection Authority — edpb.europa.eu/about-edpb/about-edpb/members_en
California residents (CCPA/CPRA)
You have the right to know what personal information we collect, to request deletion, to opt out of the sale or sharing of your personal information (we do not sell or share personal information, including for cross-context behavioural advertising), and to non-discrimination for exercising these rights. Similar rights may be available to you under other applicable US state privacy laws. Submit requests to support@vpnzo.app.
6. Data Security
We apply appropriate technical and organisational measures to protect your personal data, including:
- Encryption in transit (TLS 1.2+) and at rest
- Access controls and least-privilege principles
- Regular security reviews
No internet-based system is completely secure. In the event of a personal data breach posing a high risk to your rights and freedoms, we will notify you without undue delay as required by applicable law. Where required, we will also notify the competent supervisory authority within 72 hours of becoming aware of a qualifying breach, in accordance with Article 33 GDPR.
7. Children and Minors
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe a person under 18 has submitted data through the Service, contact us at support@vpnzo.app and we will delete it promptly.
8. Cookies and Tracking
The VPNzo mobile application does not use cookies. Our website (vpnzo.app) may use essential cookies required for site functionality only. We do not use advertising or behavioural tracking cookies. If this changes, we will update this Policy and obtain consent where required by applicable law.
9. Changes to This Policy
We may update this Policy from time to time. Material changes will be communicated at least 14 days before taking effect via in-app notification, website notice, or email where we hold your address. The "Effective date" at the top reflects the most recent revision.
Continued use of the Service after an updated Policy takes effect constitutes acceptance, to the extent permitted by applicable law.
10. Contact
- Taprise Ltd.
- United Kingdom
- Email: support@vpnzo.app
- Website: vpnzo.app
UK supervisory authority:
- Information Commissioner's Office — ico.org.uk | 0303 123 1113
EU supervisory authorities:
We respond to all privacy inquiries within 30 days.


