Privacy Policy

Thalatta VPN

Basic Provisions

This Privacy Policy describes how Thalatta VPN ("we", "our", or "us") collects, uses, and protects information about users ("you" or "your") of our VPN service. By using Thalatta VPN, you agree to the terms of this Privacy Policy. If you do not agree with any part of this policy, please do not use our service.

Data We Collect

We collect minimal information necessary to provide and improve our service:

  • Account Information: Email address, username, and encrypted password
  • Payment Information: Transaction data (processed through third-party payment providers)
  • Support Data: Communication history when you contact our support team
  • Technical Data: Device type, app version, and connection timestamps for troubleshooting. We do NOT log your browsing activity, DNS queries, or IP addresses after connection.

How We Use Your Data

We use your information only for:

  • Providing and maintaining VPN service and your account
  • Ensuring service quality and performance
  • Processing payments and managing subscriptions
  • Responding to support requests and troubleshooting
  • Analyzing service usage to improve performance and features
  • Sending important service updates (we never sell your data to third parties)

Data Sharing

We do not share your personal data with third parties except:

  • Payment processors: Only for transaction processing
  • Law enforcement: Only when legally required by valid court orders
  • Service providers: Who help us operate under strict confidentiality agreements. We will notify you if legally permitted before sharing any data with authorities.

Servers and Jurisdictions

Our VPN servers are located in privacy-friendly jurisdictions that respect user privacy. We carefully select server locations to minimize data retention requirements and maximize your privacy protection. Connection logs are kept for a maximum of 24 hours for technical troubleshooting and are automatically deleted.

Data Retention

We retain your data only as long as necessary:

  • Account data: Until account deletion. Payment records: As required by law (typically 3-7 years). Connection timestamps: Maximum 24 hours.
  • You can request account deletion at any time through our support team.

Your Rights

You have the right to:

  • Access your personal data
  • Request correction of inaccurate data and limit data processing
  • Request deletion of your account and data, or export your data in a portable format
  • Object to data processing and withdraw consent at any time

Contact our support team to exercise these rights.

Security

We implement industry-standard security measures to protect your data:

  • Military-grade encryption (AES-256) for all VPN connections
  • Secure password hashing (bcrypt) and regular security audits
  • Secure server infrastructure with access controls and monitoring
  • Protection against DDoS attacks. However, no method of transmission over the internet is 100% secure.

International Data Processing

Our service operates globally. Your data may be processed in countries outside your residence. We ensure that all international data transfers comply with applicable privacy laws and regulations. We use appropriate safeguards to protect your data regardless of location.

Minors

Our service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from minors. If we discover that a minor has provided personal information, we will delete it immediately.

Policy Updates

We may update this Privacy Policy from time to time. We will notify you of significant changes by email, website notice, or in-app notification. Your continued use of the service after changes constitutes acceptance of the updated policy. We encourage you to review this policy periodically.