Privacy Policy
This policy explains what personal data we collect on surferproxy.com, why we collect it, how long we keep it, and what you can ask us to do with it. We keep it deliberately short: we collect only what is needed to sell, licence and support the software, and nothing else.
Last updated: 5 August 2026
1 Who we are
SurferProxy is a Windows desktop application. We own and operate surferproxy.com, which is the product site and licensed customer portal for it.
Data controller: SurferProxy, Singapore.
Contact for any privacy question or request:
[email protected].
2 Scope
This policy covers the website and customer portal at surferproxy.com. The SurferProxy application itself runs locally on your own computer; data it keeps on your machine (settings, saved accounts, logs) stays on your machine and is under your control. The only data the application sends to us is what is needed to validate your licence, described in section 3.
3 What we collect, and why
Payment details. Payments are handled by our payment gateway, SurferCID. We do not collect, transmit or store card numbers or any other payment credentials — no card data reaches our servers at any point. We receive only the order reference and the confirmation needed to issue your licence.
4 Legal basis
- Performance of a contract — account, licence key, HWID binding, download delivery, payment and order records. Without these we cannot provide the product you bought.
- Legitimate interests — access logs, hashed IP addresses, the device signal hash, referral codes, rate-limiting and ban enforcement, used to keep the service secure, to run our referral programme, and to prevent fraud, abuse and licence piracy.
- Legal obligation — retention of invoice and transaction records for the period required by tax and accounting law.
5 What we do not do
- We do not sell, rent or trade your personal data.
- We do not run advertising networks or behavioural-tracking scripts, and no advertising or analytics code from anyone else is loaded anywhere on this site.
- We do not store payment card data.
- We do not use your hardware identifier for anything other than licence binding.
- We do not share your data with anyone except the processors listed in section 6.
The one exception, stated plainly. So that our referral programme cannot be abused, the sign-up and portal pages read ordinary device characteristics in your browser and send us a one-way hash of them, as described in section 3. It answers one question — whether two accounts were created on the same device — and nothing else. It is not used for advertising, it is not shared with anyone, and the characteristics behind it never leave your browser.
6 Who else processes your data
We share the minimum necessary with service providers who act on our instructions:
- Payment gateway — SurferCID, to take payment for licences and to handle refunds.
- Hosting and infrastructure — the providers who operate the servers and network this site and its database run on, which store the data described above on our behalf.
We may also disclose data where we are legally required to do so, or where it is necessary to establish, exercise or defend legal claims.
7 How long we keep it
- Account data (username, email, password hash, licence key, HWID, and which account introduced yours) — for as long as your account exists. If you ask us to delete your account, we remove it within 30 days.
- Access logs, hashed IP addresses and device signal hashes — 12 months, then deleted.
- Payment and invoice records — for the period required by Singapore tax and accounting law, which we cannot shorten on request.
- Support correspondence — 24 months after the case is closed.
Records kept for fraud, chargeback or ban enforcement may be retained for as long as that purpose applies.
8 Security
- All traffic between your browser or the application and our servers is encrypted with TLS.
- Passwords are stored only as salted one-way hashes.
- IP addresses used for abuse and ban enforcement are stored hashed rather than in the clear.
- Access to production data is restricted to the people who need it to operate the service.
- Downloads are served through short-lived signed links issued to an authenticated, licensed user — they expire and cannot be shared publicly.
9 Deleting your data
You can ask us to delete your account and the data attached to it, except records we must keep by law. Write to [email protected] from the email address on your account and we will respond within 30 days.
Deleting your account also ends your licence. The licence key and its device binding cease to be valid, and this cannot be undone.
10 International transfers
Our servers and service providers may be located outside the country you live in. Where data is transferred across borders, we rely on the safeguards required by applicable law, including contractual terms with the providers who process it on our behalf.
11 Children
The service is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will remove it.
13 Changes to this policy
If we change this policy we will update the date at the top of the page, and for material changes we will notify account holders by email before the change takes effect.