Privacy Policy

Rainproxy serves customers worldwide. This policy is written to comply with the EU GDPR (Regulation 2016/679), the Dutch UAVG, the UK GDPR & Data Protection Act 2018, the California Consumer Privacy Act / CPRA, Brazil's LGPD, Canada's PIPEDA, the Australian Privacy Act 1988, and equivalent privacy laws in other jurisdictions.

Last updated: 1 September 2026

1. Controller

  • Rainproxy
  • Registered office: Utrecht, the Netherlands
  • KvK (Dutch Chamber of Commerce) number: 81234953
  • Contact: privacy@rainproxy.io

The data controller (or "business" under CCPA / "responsible party" under LGPD) is:

EU/EEA representative (art. 27 GDPR), UK representative (art. 27 UK GDPR) and our Data Protection Officer can all be reached at dpo@rainproxy.io. For California / US privacy requests use privacy@rainproxy.io with the subject line "US Privacy Request".

2. What data we process

  • Account data: name, email, hashed password, company.
  • Billing data: billing address, tax ID (VAT, GST, ABN, EIN), invoice history. Card details are handled by our PSP and never reach our servers.
  • Usage data: dashboard logins, API key identifiers, bandwidth counters, request metadata (timestamps, target hostname, status codes).
  • Technical data: IP address, browser/user-agent, device type, referrer, language.
  • Support data: messages you send to chat or email support.
  • Cookies & similar: see our Cookie Policy.

We do not log the content of traffic that flows through our proxy network, we do not sell personal information, and we do not "share" personal information for cross-context behavioural advertising as defined under CPRA.

3. Legal bases & purposes

  • Performance of a contract (GDPR art. 6(1)(b)): operate your account, deliver proxy traffic, bill you, provide support.
  • Legal obligation (GDPR art. 6(1)(c)): retain invoices (7 years NL fiscal law / 6 years UK / IRS retention in the US / equivalent elsewhere) and respond to lawful authority requests.
  • Legitimate interest (GDPR art. 6(1)(f)): fraud prevention, network security, abuse detection, product analytics on aggregated data.
  • Consent (GDPR art. 6(1)(a) / CCPA opt-in for sensitive uses / LGPD art. 7(I)): non-essential cookies, marketing emails. You can withdraw consent at any time.

4. Residential peer network

Our residential IP supply is sourced exclusively through paid, opt-in partner applications worldwide. End-users (peers) explicitly consent via an in-app screen, are compensated, and can revoke consent at any time. We never bundle the SDK with free apps without disclosure. Peer IP usage is governed by our Terms of Service.

5. Retention periods

  • Account data: while the account is active, then deleted within 90 days of closure.
  • Invoices and tax records: up to 7 years (the longest of applicable NL / UK / US / other local fiscal retention obligations).
  • Proxy request metadata: up to 30 days for abuse and billing reconciliation, then aggregated.
  • Support tickets: 24 months after closure.
  • Server / security logs: 90 days.

6. Recipients & processors

  • Cloud hosting (EU, US and APAC regions, chosen to minimise latency)
  • Payment service providers (Stripe, Paddle)
  • Email and customer-support tooling
  • Product analytics (cookie-less or aggregated)
  • Anti-fraud, sanctions screening and KYB providers when required by law

We share data only with vetted sub-processors under written data-processing agreements (GDPR art. 28, UK GDPR, LGPD art. 39, CCPA "service provider" terms). Current categories:

A current list is available on request at dpo@rainproxy.io.

7. International transfers

  • EU Standard Contractual Clauses (Commission Decision 2021/914) and a transfer impact assessment;
  • The UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs;
  • The EU-US Data Privacy Framework and the UK Extension, where the recipient is certified;
  • LGPD art. 33 mechanisms for transfers from Brazil;
  • PIPEDA-compliant contractual safeguards for transfers from Canada;
  • The Australian Privacy Principle 8 contractual measures for transfers from Australia.

Rainproxy operates globally. Personal data may be transferred to and processed in the EEA, the United Kingdom, the United States, Canada, Brazil, Australia, and other regions where our infrastructure or sub-processors are located. Cross-border transfers rely, as applicable, on:

8. Your rights

  • Access, a copy of your personal data (GDPR art. 15, CCPA "right to know", LGPD art. 18(II)).
  • Rectification / correction (GDPR art. 16, CCPA, LGPD art. 18(III)).
  • Erasure / deletion ("right to be forgotten" / CCPA "right to delete").
  • Restriction of processing.
  • Portability in a machine-readable format.
  • Objection to processing based on legitimate interest or for direct marketing.
  • Opt-out of sale / sharing (CCPA/CPRA), we don't do either, but you can confirm in writing.
  • Limit use of sensitive personal information (CPRA).
  • Withdraw consent at any time, without affecting prior lawful processing.
  • Non-discrimination for exercising your privacy rights (CCPA §1798.125).
  • Not be subject to fully automated decision-making with legal effects (GDPR art. 22).

Depending on where you live, you have some or all of the following rights:

To exercise any right, email privacy@rainproxy.io. We respond within the statutory deadline that applies to you (1 month under GDPR, 45 days under CCPA, 15 days under LGPD, 30 days under PIPEDA) and never charge a fee for reasonable requests. You may authorise an agent to submit a request on your behalf where local law allows.

9. Complaints & supervisory authorities

  • 🇳🇱 Netherlands. Autoriteit Persoonsgegevens (AP), Postbus 93374, 2509 AJ Den Haag. Autoriteitpersoonsgegevens.nl
  • 🇪🇺 Other EU/EEA. Your national DPA (full list at edpb.europa.eu).
  • 🇬🇧 United Kingdom. Information Commissioner's Office (ICO). Ico.org.uk
  • 🇺🇸 California. California Privacy Protection Agency (CPPA). Cppa.ca.gov
  • 🇧🇷 Brazil. Autoridade Nacional de Proteção de Dados (ANPD). Gov.br/anpd
  • 🇨🇦 Canada. Office of the Privacy Commissioner (OPC). Priv.gc.ca
  • 🇦🇺 Australia. Office of the Australian Information Commissioner (OAIC). Oaic.gov.au

You have the right to lodge a complaint with the privacy regulator in your country. Examples:

10. Security

We apply appropriate technical and organisational measures (GDPR art. 32 and equivalent global standards including ISO/IEC 27001, SOC 2 control families): TLS-everywhere, encryption at rest, least-privilege access controls, MFA on admin consoles, immutable audit logs, periodic penetration testing, and a documented incident response plan. Data breaches are notified to affected regulators and users within the deadlines required by law (72 hours under GDPR / UK GDPR; without unreasonable delay under CCPA, LGPD, PIPEDA, Australian NDB scheme).

11. Children

Rainproxy services are intended for businesses and developers. We do not knowingly collect personal data from individuals under 16 (under 13 in the US, per COPPA; under 18 for sensitive data in some jurisdictions).

12. Changes to this policy

Material changes will be announced by email and on this page at least 30 days before they take effect. The "Last updated" date reflects the most recent revision.