Pigeon Proxies
TermsPrivacy
Back to site

Legal

Privacy Policy

What we collect, why we collect it, and who touches it. We don't sell personal data, we don't run ad trackers, and we don't read the contents of your traffic.

Last updated July 27, 2026

On this page

  1. Overview
  2. What we collect
  3. How we use it
  4. Legal bases (UK/EU)
  5. Cookies
  6. Who we share it with
  7. How long we keep it
  8. Security
  9. Your rights
  10. International transfers
  11. Children
  12. Changes to this policy
  13. Contact

Overview

This policy explains what personal data Pigeon Proxies (“Pigeon Proxies”, “we”, “us”) collects when you use our website, dashboard and proxy network, why we collect it, who we share it with, and what control you have over it. It sits alongside our Terms of Service.

The short version: we collect the minimum needed to give you an account, take payment, issue credentials and meter bandwidth. We do not sell personal data, we do not run advertising trackers, and we do not read the contents of the traffic you route through the network.

What we collect

Account data

Sign-in is handled through Discord OAuth. When you authorise it, Discord shares your Discord user ID, username, avatar image URL and email address with us. We store the ID to identify your account, and the rest to display who you are in the dashboard and to contact you. We never receive your Discord password, and we cannot read your Discord messages or servers.

Payment data

Payments run through Stripe. Stripe collects your card details, billing name, billing address and any tax identifiers directly — that information goes to Stripe, not to us.

We never see or store your full card number, CVC or expiry. What we keep is the payment record: Stripe's order and payment identifiers, the amount, currency, status, and the last four digits and card brand when Stripe returns them.

Service data

  • Your bandwidth balance, purchases, adjustments and order history.
  • The proxy sub-account and credentials issued to you, and their status.
  • Aggregated usage reported back by the network — bytes consumed over time, and per-destination or per-endpoint totals where the network provides them.
  • Coupons applied, and administrative notes attached to your account by our team.

Technical data

Our hosting, database and analytics providers process standard request data: IP address, user agent, timestamps, pages requested, and error diagnostics. We use this to keep the site running, to investigate faults, and to apply rate limits and abuse controls.

Traffic metadata

When you route requests through the gateway, our network infrastructure processes connection metadata — source of the request, destination host, timestamps and byte counts — because that is how the connection is established and metered. We receive usage totals derived from it. We do not inspect, store or sell the contents of your traffic, and we do not build profiles of your browsing.

Communications

If you email us or open a ticket in our Discord community, we keep the conversation and anything you include in it so we can help you and keep a record of the outcome.

How we use it

  • To create and authenticate your account, and to keep you signed in.
  • To take payment, issue receipts and invoices, and meet our tax and accounting obligations.
  • To provision your proxy credentials and credit purchased bandwidth to your account.
  • To meter usage and show you accurate balances and history.
  • To provide support, and to notify you about your orders, credentials or account status.
  • To detect, investigate and prevent fraud, abuse, chargebacks and breaches of our acceptable use policy, and to protect the network.
  • To understand aggregate product usage so we can improve the Service.
  • To comply with law and respond to valid legal requests.

We do not use your data for automated decision-making that produces legal or similarly significant effects, other than automated fraud and abuse checks — where a decision blocks your account, you can ask us to review it by a human.

Legal bases (UK/EU)

If you are in the UK or the European Economic Area, we rely on the following bases under the UK GDPR and GDPR:

ContractCreating your account, provisioning credentials, metering bandwidth, taking payment, support.
Legal obligationTax, accounting and financial record-keeping; responding to lawful requests.
Legitimate interestsSecuring the network, preventing fraud and abuse, product analytics, and defending legal claims — balanced against your rights.
ConsentAny optional marketing messages. You can withdraw consent at any time.

Cookies

We use a small number of first-party cookies, and no third-party advertising cookies:

  • Authentication. Session cookies set by our auth provider so you stay signed in and your session can be refreshed. These are strictly necessary — the dashboard cannot work without them.
  • Preferences. Local storage for interface settings such as theme.
  • Analytics. Privacy-preserving, aggregate page analytics on our hosting platform. It does not build cross-site advertising profiles.

You can block or delete cookies in your browser, but blocking the authentication cookies will sign you out and prevent the dashboard from loading.

Who we share it with

We do not sell your personal data and we do not share it for cross-context behavioural advertising. We share it only with the processors that make the Service work, and only as far as each one needs:

Identity providerDiscord — sign-in, and the community server where support is provided.
PaymentsStripe — card processing, receipts, refunds, fraud checks and tax calculation.
Database and authSupabase — hosts your account record, orders and bandwidth ledger.
Hosting and analyticsVercel — serves the site and provides aggregate traffic analytics.
Network infrastructureThe providers that carry our proxy network — receive the sub-account and usage data needed to issue credentials and meter bandwidth.

We may also disclose data where we are legally required or permitted to:

  • in response to a valid subpoena, court order or law-enforcement request, after reviewing it for validity and scope;
  • to establish, exercise or defend legal claims, or to investigate abuse of the network; and
  • to a buyer or successor in a merger, acquisition or sale of assets — with the same protections continuing to apply.

How long we keep it

Account recordFor as long as your account is open, and up to 12 months after closure.
Orders and invoicesUp to 7 years after the transaction, to meet tax and accounting requirements.
Bandwidth ledger and usageFor the life of the account, then aggregated or deleted within 12 months of closure.
Proxy credentialsRevoked on account closure and deleted shortly afterwards.
Support conversationsUp to 24 months after the conversation ends.
Abuse and security recordsRetained as long as needed to prevent repeat abuse and defend claims.

Security

We encrypt data in transit, restrict database access with row-level security so an account can only read its own records, keep secrets and provider API keys server-side only, and limit administrative access to staff who need it, with an audit trail of admin actions.

No system is perfectly secure. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify you and the relevant supervisory authority as the law requires.

Your rights

Depending on where you live, you may have the right to:

  • access the personal data we hold about you, and receive a portable copy;
  • correct data that is inaccurate or incomplete;
  • delete your data, subject to records we must keep for legal or accounting reasons;
  • restrict or object to certain processing, including processing based on legitimate interests;
  • withdraw consent where we relied on it; and
  • not be discriminated against for exercising any of these rights.

Email privacy@pigeonproxies.com from the address on your account and we will respond within 30 days. We may need to verify your identity first. If you are in the UK or EEA and are unhappy with our response, you can complain to your local data protection authority.

International transfers

We and our processors operate in several countries, including the United States. Where personal data moves out of the UK or EEA, we rely on the safeguards our processors provide — typically the UK Addendum and the European Commission's Standard Contractual Clauses — to keep the protection with the data.

Children

The Service is not for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us personal data, contact privacy@pigeonproxies.com and we will delete it.

Changes to this policy

When we update this policy we will change the “last updated” date at the top of the page. For material changes — a new category of data, a new purpose, or a new class of recipient — we will give notice in the dashboard, by email, or in our Discord community before the change takes effect.

Contact

Privacy questions, data requests and abuse reports: privacy@pigeonproxies.com. Anything else: support@pigeonproxies.com.

Also readTerms of Service
Pigeon Proxies© 2026 Pigeon Proxies. Built for performance.
TermsPrivacy