Overview
This policy explains what personal data Pigeon Proxies (“Pigeon Proxies”, “we”, “us”) collects when you use our website, dashboard and proxy network, why we collect it, who we share it with, and what control you have over it. It sits alongside our Terms of Service.
The short version: we collect the minimum needed to give you an account, take payment, issue credentials and meter bandwidth. We do not sell personal data, we do not run advertising trackers, and we do not read the contents of the traffic you route through the network.
What we collect
Account data
Sign-in is handled through Discord OAuth. When you authorise it, Discord shares your Discord user ID, username, avatar image URL and email address with us. We store the ID to identify your account, and the rest to display who you are in the dashboard and to contact you. We never receive your Discord password, and we cannot read your Discord messages or servers.
Payment data
Payments run through Stripe. Stripe collects your card details, billing name, billing address and any tax identifiers directly — that information goes to Stripe, not to us.
We never see or store your full card number, CVC or expiry. What we keep is the payment record: Stripe's order and payment identifiers, the amount, currency, status, and the last four digits and card brand when Stripe returns them.
Service data
- Your bandwidth balance, purchases, adjustments and order history.
- The proxy sub-account and credentials issued to you, and their status.
- Aggregated usage reported back by the network — bytes consumed over time, and per-destination or per-endpoint totals where the network provides them.
- Coupons applied, and administrative notes attached to your account by our team.
Technical data
Our hosting, database and analytics providers process standard request data: IP address, user agent, timestamps, pages requested, and error diagnostics. We use this to keep the site running, to investigate faults, and to apply rate limits and abuse controls.
Traffic metadata
When you route requests through the gateway, our network infrastructure processes connection metadata — source of the request, destination host, timestamps and byte counts — because that is how the connection is established and metered. We receive usage totals derived from it. We do not inspect, store or sell the contents of your traffic, and we do not build profiles of your browsing.
Communications
If you email us or open a ticket in our Discord community, we keep the conversation and anything you include in it so we can help you and keep a record of the outcome.
How we use it
- To create and authenticate your account, and to keep you signed in.
- To take payment, issue receipts and invoices, and meet our tax and accounting obligations.
- To provision your proxy credentials and credit purchased bandwidth to your account.
- To meter usage and show you accurate balances and history.
- To provide support, and to notify you about your orders, credentials or account status.
- To detect, investigate and prevent fraud, abuse, chargebacks and breaches of our acceptable use policy, and to protect the network.
- To understand aggregate product usage so we can improve the Service.
- To comply with law and respond to valid legal requests.
We do not use your data for automated decision-making that produces legal or similarly significant effects, other than automated fraud and abuse checks — where a decision blocks your account, you can ask us to review it by a human.
Legal bases (UK/EU)
If you are in the UK or the European Economic Area, we rely on the following bases under the UK GDPR and GDPR:
How long we keep it
Security
We encrypt data in transit, restrict database access with row-level security so an account can only read its own records, keep secrets and provider API keys server-side only, and limit administrative access to staff who need it, with an audit trail of admin actions.
No system is perfectly secure. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify you and the relevant supervisory authority as the law requires.
Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you, and receive a portable copy;
- correct data that is inaccurate or incomplete;
- delete your data, subject to records we must keep for legal or accounting reasons;
- restrict or object to certain processing, including processing based on legitimate interests;
- withdraw consent where we relied on it; and
- not be discriminated against for exercising any of these rights.
Email privacy@pigeonproxies.com from the address on your account and we will respond within 30 days. We may need to verify your identity first. If you are in the UK or EEA and are unhappy with our response, you can complain to your local data protection authority.
International transfers
We and our processors operate in several countries, including the United States. Where personal data moves out of the UK or EEA, we rely on the safeguards our processors provide — typically the UK Addendum and the European Commission's Standard Contractual Clauses — to keep the protection with the data.
Children
The Service is not for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us personal data, contact privacy@pigeonproxies.com and we will delete it.
Changes to this policy
When we update this policy we will change the “last updated” date at the top of the page. For material changes — a new category of data, a new purpose, or a new class of recipient — we will give notice in the dashboard, by email, or in our Discord community before the change takes effect.
Contact
Privacy questions, data requests and abuse reports: privacy@pigeonproxies.com. Anything else: support@pigeonproxies.com.