Last updated July 24, 2026
Download PDFOverview
This Privacy Policy explains how Vital Innovations LLC ("Vital," "we," "us," or "our") collects, uses, stores, and shares personal information when you use the Vital website, dashboard, application programming interfaces, proxy gateways, residential, mobile, and ISP proxy products, customer support channels, and related services (collectively, the "Services").
Vital Innovations LLC is the controller of personal information used for account administration, authentication, billing, website operation, analytics, security, fraud and abuse prevention, communications, and customer support. When a business customer uses the Services to process personal information for its own purposes, that customer is responsible for determining whether its use is lawful and for providing any notices or obtaining any permissions required by law.
This Policy applies to https://vital-data.io, the Vital dashboard, Vital APIs, Vital-operated proxy infrastructure, emails sent by Vital, and support provided by email, Crisp live chat, or Vital's Discord community.
Questions and privacy requests may be sent to legal@vital-data.io.
Summary of Key Points
- We collect account, authentication, billing, transaction, proxy configuration, usage, support, device, analytics, referral, and communication-preference information.
- We store connection metadata needed to operate and measure the proxy service, but we do not use standard analytics to store request or response bodies, cookies, authorization headers, file contents, or complete destination URLs.
- Vital does not perform TLS interception or decrypt HTTPS payloads. HTTPS content remains encrypted between the customer's client and the destination service.
- Complete payment-card numbers and card security codes are handled by Paddle or Stripe and are not stored by Vital. Vital may receive limited payment-method details such as card brand, last four digits, and expiration information.
- We do not sell personal information or share it for cross-context behavioral advertising.
- Optional marketing and product-update emails can be disabled independently. Essential account, security, billing, usage, and service messages cannot be disabled while an account remains active.
- Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal information.
1. Information We Collect
Account and profile information
We may collect your email address, display name, profile image URL, internal user ID, account type, company name, use case, role, account status, ban status and reason, ban expiration, onboarding progress, trial status, account creation date, and profile preferences.
If you provide business or billing information, we may collect a billing name, company name, billing address, country, postal code, tax or VAT number, and related Paddle or Stripe customer, address, business, tax, and payment identifiers.
Authentication and session information
You may sign in with email and password, Google, GitHub, or Discord. For email-and-password accounts, Vital stores a secure one-way password hash and does not store the account password in readable form. For social sign-in, we may receive and store the provider name, provider account ID, profile information, scopes, access tokens, refresh tokens, ID tokens, and token expiration information where supplied and necessary to maintain the connection.
We may store email-verification status, temporary verification and password-reset records, session tokens, session creation and expiration times, user agent, login IP address, initial signup IP address, initial user agent, impersonation metadata for authorized administrative support, and the date of the most recent persisted session.
We may use browser cookies or similar storage to remember the last sign-in method and an approximate country detected at the network edge. The detected-country cookie is retained for up to 30 days and is not ordinarily stored as an account database field.
Acquisition, referral, and attribution information
We may collect a referring URL, landing page, referral code, referring account, campaign and UTM parameters, acquisition source, and related attribution data. A referral cookie may be retained for up to 7 days.
If you participate in the referral program, we may store referral counts, revenue-share percentage, paid amounts, payout status, and related transaction records.
Payment and transaction information
Card payments are processed through Paddle or Stripe, depending on the checkout flow assigned to the transaction. Paddle may act as merchant of record for Paddle-processed transactions. For Stripe-processed transactions, Vital is the seller and Stripe acts as a payment processor. Vital may receive and store your name, email address, billing address, billing country, postal code, tax or VAT number, provider customer and transaction identifiers, invoices, product and order details, amount, currency, tax, payment status, refund status, dispute status, card brand, last four digits, and card expiration month and year. Vital does not store complete card numbers or card security codes.
For cryptocurrency payments, Cryptomus may process wallet, blockchain, transaction, payment-status, and related technical information. Vital may store the identifiers and status information needed to reconcile the payment with your account.
For automatic top-ups, Vital stores the applicable Paddle or Stripe customer, setup, subscription, payment-intent, and payment-method references, together with plan and threshold settings, refill amount, optional monthly limit, activation status, and failure information. The assigned payment provider performs the charge and may perform fraud or risk screening.
Proxy profiles, credentials, and customer configuration
We may store proxy-profile and subuser identifiers, labels, plan, status, proxy username, proxy password, allowed IP addresses, bandwidth allocation and usage, concurrency and throughput limits, creation and update times, and whether a profile is the main profile.
Proxy passwords are separate from your account password. Because proxy passwords must be used to authenticate proxy connections, they may be stored in a recoverable form rather than as a one-way hash. You should treat proxy credentials as confidential and rotate them if you believe they have been exposed.
We may also store API keys, API request counts, last-used dates, generated proxy parameters encoded into usernames, and system-generated metadata used to operate the Services.
Usage thresholds, alerts, webhooks, and automatic top-up rules
For supported residential proxy features, we may store a user ID, subuser ID, plan, rule type, threshold in bytes, refill amount, monthly limit, trigger cycle, status, creation and update times, email-alert settings, Discord-alert settings, Discord webhook URL, and automatic-top-up operational records.
Discord webhook URLs may contain credentials that permit messages to be posted to the configured channel. You are responsible for providing a webhook that you are authorized to use and for revoking it if it is exposed.
Proxy session and network metadata
To provide proxy services, calculate usage, support customers, and maintain operational visibility, we may process and store connection metadata such as timestamp, proxy username or profile, protocol, destination hostname, TLS server-name indication when available, upstream or provider identifier, bytes uploaded, bytes downloaded, session duration, connection status, and aggregate error counts.
Network-layer information such as a source IP address, gateway IP address, source or destination port, and routing information may be processed temporarily as required to establish, route, secure, or troubleshoot a connection, even when it is not displayed in customer analytics.
Our standard analytics do not intentionally store complete destination URLs, URL paths, DNS query contents, HTTP request or response headers, cookies, authorization headers, request bodies, response bodies, search queries, or transferred file contents.
Vital does not perform TLS interception, generate substitute certificates, or decrypt HTTPS payloads. For unencrypted HTTP traffic, content may be readable by network intermediaries while in transit even though Vital does not intentionally retain that content in its standard analytics.
Support and communications
When you contact us by email, Crisp live chat, or Discord, we may collect your name, email address, Discord account information, message contents, attachments, order or account details, and technical information you choose to provide. Messages posted publicly in Discord may be visible to other community members.
Website, device, log, and analytics information
We may automatically collect IP address, approximate country or region, browser type, operating system, device and user-agent information, referring URL, landing page, pages and features used, timestamps, request and error logs, performance information, and other technical data needed to operate, secure, analyze, and improve the Services.
With your consent, we use Google Analytics 4 for acquisition and aggregate website measurement and PostHog for product analytics. After sign-in, Vital uses your normalized email address as the PostHog person identifier and may associate it with your internal user ID, account properties, product actions, checkout progress, purchases, and subscription events. We do not send your email address or internal user ID to Google Analytics 4.
We use Sentry for error and performance monitoring and Better Stack for operational logs and uptime monitoring. These services may process diagnostic, request, device, error, and performance information needed to operate and secure the Services. Analytics consent does not disable strictly necessary security, error, or operational logging.
Information received from third parties
We receive information from authentication providers such as Google, GitHub, and Discord; payment providers such as Paddle, Stripe, and Cryptomus; analytics, hosting, security, email, and support providers; referral sources; and upstream proxy or network providers. The information received depends on the service and may include profile data, account identifiers, tokens, transaction details, risk or payment status, technical logs, and abuse or support reports.
Sensitive information
We do not intentionally request or collect racial or ethnic origin, religious or philosophical beliefs, health information, sexual orientation, biometric identifiers, or similar special-category information as part of account registration. Account login credentials, proxy credentials, and certain financial or identity-related fields may be treated as sensitive personal information under some laws, and we use them only for the purposes described in this Policy.
2. How We Use Personal Information
- To create, authenticate, secure, maintain, and administer user accounts and sessions.
- To provide residential, mobile, and ISP proxy services; generate and authenticate proxy credentials; route connections; calculate bandwidth usage; and enforce plan limits.
- To process purchases, cryptocurrency payments, refunds, renewals, invoices, taxes, payment failures, chargebacks, and automatic top-ups.
- To provide usage dashboards, alerts, low-balance notifications, Discord webhooks, billing notices, and service communications.
- To provide customer support, investigate technical problems, and respond to questions, complaints, or upstream-provider reports.
- To detect, prevent, investigate, and respond to fraud, abuse, security incidents, unauthorized access, violations of our Terms, and harmful or unlawful activity.
- To monitor performance, diagnose errors, maintain infrastructure, analyze product usage, and improve the Services.
- To administer referrals, attribution, trials, onboarding, and promotional programs.
- To send optional product updates and marketing communications when permitted by law and consistent with your preferences.
- To comply with tax, accounting, legal, regulatory, court, law-enforcement, and recordkeeping obligations and to establish, exercise, or defend legal claims.
- To complete a financing, merger, acquisition, reorganization, sale of assets, or similar business transaction.
3. Legal Bases for Processing in the EEA, United Kingdom, and Similar Jurisdictions
Where data-protection law requires a legal basis, we rely on one or more of the following bases:
- Performance of a contract. We process information needed to create and maintain your account, provide proxy services, measure usage, fulfill orders, process payments, provide support, and deliver requested features.
- Legitimate interests. We process information to secure the Services, prevent fraud and abuse, maintain infrastructure, understand product performance, provide operational support, enforce our Terms, administer referrals, and protect our legal rights. We consider the impact on your rights before relying on this basis.
- Consent. We rely on consent for optional marketing, product updates, and non-essential cookies or analytics where consent is required. You may withdraw consent at any time without affecting processing that occurred before withdrawal.
- Legal obligations. We process information when necessary to comply with tax, accounting, sanctions, regulatory, court, law-enforcement, or other legal requirements.
- Vital interests. In rare circumstances, we may process information to protect a person's life or physical safety.
4. Proxy Traffic, Customers, and Upstream Networks
A proxy service necessarily transmits network traffic to requested destinations. Depending on the product architecture, upstream residential, mobile, or ISP network providers may receive the target destination and technical connection data needed to route traffic. For direct ISP products, an upstream provider may also see the customer's source IP address or provider-issued proxy credentials.
Vital generally provides upstream networks only the information technically necessary to provision or route the service. We do not ordinarily provide upstream networks with a Vital account ID unless required to resolve a support, security, abuse, payment, or legal matter.
Upstream networks may maintain their own technical logs and may send Vital service, security, fraud, or abuse reports. Their processing is governed by their own agreements and privacy practices.
You are responsible for ensuring that your use of the Services, including any processing of third-party personal information through a proxy connection, complies with applicable law, website terms, intellectual-property rights, and our Terms and Conditions.
5. Cookies, Local Storage, and Analytics
We use cookies and similar storage technologies for authentication, session security, country detection, preferences, referral attribution, acquisition attribution, checkout-related functionality, analytics, and service operation.
- Essential technologies include authentication and session cookies, security controls, checkout functionality, and cookies needed to remember privacy choices.
- Functional technologies may remember preferences, the last-used login method, detected country, and referral attribution.
- Crisp live chat loads throughout the Services so customer support remains readily available. Crisp may use functional cookies with names beginning crisp-client/ to connect your browser to the conversation, restore the chat session, and process associated technical information such as your IP address. We configure those browser cookies for up to 180 days; deleting the cookies or asking us to delete a support conversation may end that continuity.
- Analytics technologies may be used by Google Analytics 4 and PostHog to understand visits, pages, events, performance, and feature use.
- The vital_analytics_consent cookie stores your choice for up to 180 days. After consent, vital_acquisition may retain first-touch attribution for up to 30 days, while Google Analytics and PostHog may create analytics identifiers in cookies or local storage. Withdrawing consent through Privacy settings stops optional collection and removes those browser-side analytics identifiers where accessible.
- Sentry may collect error, diagnostic, device, request, and performance information when an application error or performance event occurs.
Where applicable law requires consent, we request consent before activating non-essential cookies or analytics. We treat Crisp live chat as functional support technology and load it independently of your analytics choice. You may change your analytics choices through the cookie controls made available on the Services or through your browser settings. Blocking essential or functional cookies may prevent parts of the Services from working.
Vital does not currently use advertising pixels or customer lists for cross-context behavioral advertising.
6. Email, Discord, and Other Communications
Essential communications
We send essential messages concerning email verification, password resets, account security, purchases, receipts, payment failures, automatic top-ups, renewals, data usage, low balances, service incidents, and material account or policy changes. These communications are necessary to operate and secure an active account and cannot be disabled through marketing preferences.
Optional product updates and marketing
Product updates and marketing are separate optional categories. Product updates may include new products, locations, features, improvements, betas, and changelogs. Marketing may include promotions, discounts, referrals, surveys, company news, onboarding campaigns, and abandoned-checkout reminders where permitted by law.
Marketing and product-update preferences are disabled by default at signup and can be changed independently in the dashboard or through an unsubscribe link. We retain the current preference state and may retain a minimal suppression record to ensure that an opt-out is honored.
Vital does not currently use email open tracking or link-click tracking in verification, password-reset, billing, usage-alert, product-update, or marketing emails.
7. How We Share Personal Information
We do not sell personal information or share it for cross-context behavioral advertising. We may disclose personal information to service providers, infrastructure partners, payment providers, professional advisers, authorities, and transaction counterparties for the purposes described below.
Major service providers and recipients
- Cloudflare: DNS, content delivery, network security, traffic protection, and approximate country detection.
- Vercel: website and dashboard hosting and delivery.
- Railway: application and API hosting.
- Hetzner: proxy infrastructure, databases, analytics storage, and related hosting.
- Sentry: error monitoring, diagnostics, and performance monitoring.
- PostHog: consented product analytics, funnels, and feature-usage measurement.
- Better Stack: operational log search, uptime monitoring, incident alerting, and request diagnostics.
- Resend: transactional, product-update, and marketing email delivery.
- Paddle: card payments, billing, merchant-of-record services, taxes, refunds, subscriptions, invoices, and fraud prevention.
- Stripe: card and supported payment-method processing, saved payment methods, billing, subscriptions, invoices, tax calculation where enabled, refunds, disputes, and fraud prevention.
- Cryptomus: cryptocurrency payment processing and transaction reconciliation.
- Google: Google sign-in and Google Analytics 4.
- GitHub: GitHub sign-in.
- Discord: Discord sign-in, customer support, community communication, and customer-configured webhook alerts.
- Crisp: live-chat support and customer communications.
- Upstream residential, mobile, and ISP network providers: provisioning, routing, capacity, service operation, and investigation of network or abuse issues.
A current subprocessor list is available at https://vital-data.io/legal/subprocessors. Providers may change as the Services evolve. We require providers to process information only for authorized purposes and subject to applicable contractual and legal obligations.
Legal, safety, and compliance disclosures
We may disclose information when we reasonably believe disclosure is required by law, subpoena, warrant, court order, regulatory request, law-enforcement request, tax obligation, abuse complaint, emergency, or to protect the rights, property, security, or safety of Vital, our users, upstream networks, destinations, or others.
Business transfers
We may disclose or transfer information in connection with a merger, financing, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction. Where required, we will provide notice before personal information becomes subject to a materially different privacy policy.
8. International Processing and Transfers
Vital Innovations LLC is established in the United States. Our primary systems and infrastructure are located in the United States, and our providers and upstream networks may process information in the United States and other countries.
The privacy and data-protection laws of those countries may differ from the laws where you live. Where applicable law requires a transfer mechanism, we seek to use legally recognized safeguards, which may include adequacy decisions, contractual safeguards, standard contractual clauses, or another lawful transfer mechanism made available by the relevant provider.
You may contact legal@vital-data.io to request available information about safeguards used for a particular transfer.
9. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including service delivery, security, dispute resolution, legal compliance, and enforcement. Our standard retention schedule is:
- Active account, profile, proxy configuration, credentials, API, and preference data: while the account is active and for up to 30 days after an approved deletion or closure request, unless a longer period is required for another purpose below.
- Active session and OAuth-token data: until expiration, logout, account disconnection, revocation, or account deletion, plus up to 30 days in operational systems.
- Verification and password-reset records: until they expire or are used, and ordinarily no longer than 7 days.
- Incomplete or abandoned signup records: up to 30 days, unless needed for fraud prevention or support.
- Raw proxy session metadata: up to 30 days.
- Aggregated hourly, daily, or account-level usage and billing metrics: while the account is active and for up to 24 months afterward.
- Security, fraud, and abuse records: up to 180 days, or longer when associated with an active investigation, dispute, legal hold, or repeated abuse.
- Application, infrastructure, Better Stack, and Sentry error logs: up to 30 days, unless needed to investigate an active incident.
- Consented Google Analytics 4 and PostHog analytics records: up to 24 months, subject to the configured provider retention period and earlier deletion where applicable.
- Payment, invoice, tax, refund, chargeback, and accounting records: up to 7 years after the relevant transaction or longer when required by law.
- Support conversations and attachments: up to 24 months after the last interaction, unless needed for an unresolved dispute, security matter, or legal obligation.
- Referral, commission, and acquisition records: while the account or referral relationship is active and for up to 24 months afterward, except transaction and accounting records retained longer under the payment-record rule.
- Marketing and product-update preference records: while the preference is active and for up to 3 years after withdrawal or the last relevant interaction.
- Unsubscribe and suppression records: for as long as reasonably necessary to honor the opt-out, ordinarily using only the minimum identifier required.
- Backups: ordinarily overwritten or deleted within 30 days. Data deleted from active systems may remain in protected backups until the relevant backup expires.
We may retain information longer if required by law, court order, tax or accounting rule, payment dispute, chargeback, fraud or abuse investigation, legal claim, or legal hold. We may anonymize information so that it can no longer reasonably identify you and retain the anonymized information for analytics or service improvement.
10. Security
We use administrative, technical, and organizational measures intended to protect personal information. These measures may include access controls, authentication, encryption in transit, network protections, restricted administrative access, monitoring, backups, and procedures for responding to security incidents.
No system, network, transmission, or storage method is completely secure. You are responsible for using a strong account password, protecting account, API, proxy, OAuth, and webhook credentials, limiting allowed IP addresses where appropriate, and notifying us promptly if you believe credentials or an account have been compromised.
11. Fraud, Abuse, Account Restrictions, and Automated Processing
We use account, payment, device, transaction, proxy-usage, and security information to detect fraud, abuse, unusual activity, payment risk, and violations of our Terms. Paddle, Stripe, Cryptomus, upstream networks, and other service providers may also use automated risk or security systems.
Payment providers may automatically reject or review a payment. Product access may also be restricted when a balance is exhausted, a renewal fails, an automatic top-up is paused, or an upstream network blocks traffic.
Vital account bans are currently imposed or reversed by authorized administrators rather than by a documented solely automated banning system. You may contact support@vital-data.io to request review of an account restriction. We may request information needed to investigate the issue and may refuse restoration where necessary to protect users, networks, third parties, or legal compliance.
12. Your Privacy Rights
Depending on your location and the law that applies, you may have the right to:
- Request confirmation of whether we process your personal information and obtain access to it.
- Request correction of inaccurate or incomplete information.
- Request deletion of personal information, subject to legal and operational exceptions.
- Request restriction of processing or object to certain processing.
- Withdraw consent for processing based on consent.
- Object to direct marketing at any time.
- Request a portable copy of information you provided where the right applies.
- Request information about recipients, sources, purposes, retention, or international-transfer safeguards.
- Lodge a complaint with a competent privacy or data-protection authority.
You can edit certain profile information, email settings, and communication preferences in the dashboard. Account deletion and formal privacy requests must be submitted by email to legal@vital-data.io.
A request should be sent from the email address associated with the account. We may request additional information where reasonably necessary to verify identity, protect the account, or confirm an authorized agent's authority. We will respond within the period required by applicable law.
Some information may be retained or excluded from a request where permitted by law, including information needed for payment records, taxes, fraud prevention, security, legal claims, third-party rights, backups, or compliance obligations.
Individuals in the EEA may complain to the data-protection authority in the country where they live or work or where the alleged infringement occurred. Individuals in the United Kingdom may complain to the Information Commissioner's Office. We encourage you to contact us first so that we can try to resolve the concern.
13. United States State Privacy Disclosures
Residents of certain US states may have privacy rights when the relevant state law applies to Vital and to the particular processing. The following disclosures describe categories of personal information Vital may have collected during the preceding 12 months.
- Identifiers: name, email address, IP address, online and account identifiers, OAuth identifiers, API keys, session identifiers, proxy usernames, referral codes, and similar identifiers.
- Customer-record and financial information: billing name and address, company, tax or VAT number, transaction and invoice details, payment status, card brand, last four digits, and expiration information.
- Commercial information: products purchased, order history, balances, top-ups, subscriptions, renewals, refunds, chargebacks, trials, referral commissions, and usage allocations.
- Internet or other electronic network activity: website and dashboard interactions, device and browser data, login and session records, proxy session metadata, destination hostnames, protocols, byte counts, duration, status, and error information.
- Approximate geolocation: country or region inferred from an IP address and billing country supplied during checkout.
- Professional or business information: company name, business account type, tax identifier, business use case, and related billing details when supplied.
- Sensitive personal information under certain state laws: account login credentials, OAuth tokens, API keys, proxy credentials, and payment-account authentication references. We use this information only to provide, secure, and administer the Services and do not use it to infer characteristics about you.
We do not collect biometric information or protected-classification information as part of ordinary account registration. We do not sell personal information and do not share personal information for cross-context behavioral advertising.
Depending on applicable law, you may request access, correction, deletion, or portability; obtain information about categories, sources, purposes, and recipients; opt out of sale, targeted advertising, or certain profiling; use an authorized agent; appeal a denied request; and receive equal service when exercising your rights.
Because Vital does not currently sell personal information or share it for cross-context behavioral advertising, an opt-out preference signal such as Global Privacy Control does not change our current processing. If our practices change, we will update this Policy and recognize signals where required by law.
To submit a request or appeal a denied request, email legal@vital-data.io from the account email address. We may request reasonable verification and proof of authority for an agent.
14. Children
The Services are not directed to individuals under 18 years of age, and we do not knowingly collect personal information from children. If you believe a person under 18 has provided personal information to us, contact legal@vital-data.io. We will investigate and take reasonable steps to delete or restrict the information where appropriate.
15. Do-Not-Track Signals
Some browsers offer a Do-Not-Track signal, but there is no uniform standard governing how websites must interpret it. Vital does not currently respond to general Do-Not-Track signals. This does not affect our commitment that we do not sell personal information or share it for cross-context behavioral advertising, or our obligation to honor legally recognized opt-out signals if those practices change.
16. Changes to This Policy
We may update this Privacy Policy to reflect changes to the Services, providers, technology, legal requirements, or our data practices. The updated version will show a revised "Last updated" date. If a change is material, we may provide additional notice through the Services, by email, or by another appropriate method.
17. Contact Us
Vital Innovations LLC is responsible for this Privacy Policy and for the personal information described in it.
Email: legal@vital-data.io
Postal address:
Vital Innovations LLC
5830 E 2nd St, Ste 7000 #11015
Casper, WY 82609
United States