Privacy policy
1. Introduction
This Privacy Policy explains how EndorVPN ("EndorVPN," "we," "us," or "our") collects, uses, shares, and protects personal data when you use our website (endorvpn.com), applications, and VPN services (collectively, the "Services").
EndorVPN is operated by ReadPartner DACH GmbH, a company registered in Austria under registration number FN538896w. The Company is the data controller for the purposes of the EU General Data Protection Regulation (GDPR).
We process personal data in accordance with the GDPR and other applicable Austrian and EU data protection laws. This Policy does not apply to third-party websites, products, or services, even if linked from our Services.
By using EndorVPN, you acknowledge that you have read and understood this Privacy Policy.
2. Our No-Logs Commitment
EndorVPN operates a strict no-logs policy. When you are connected to our VPN, we do not collect, store, or share:
- Your browsing history, DNS queries, or visited domains
- The content of your internet traffic
- Your originating IP address once connected to our VPN servers
- Connection timestamps, session duration, or bandwidth usage tied to your identity
- Any information that could be used to reconstruct your online activity
This means that even if we receive a legal request concerning a specific user's VPN activity, we are technically unable to comply, because the relevant data does not exist on our systems. Our infrastructure is designed so that this remains true regardless of server jurisdiction.
We collect only the minimum account, billing, and diagnostic information described below, which is necessary to operate and improve the Services and is entirely separate from your VPN usage.
3. Information We Collect
3.1 Account Information
- Email address (for account creation, login, and communication)
- Hashed/encrypted password
- Language and regional preference
3.2 Payment Information
We use third-party payment processors: Stripe (card payments), NOWPayments (cryptocurrency payments), and Telegram Stars (in-app payments via Telegram), and may add other compliant payment providers over time. Depending on the method you choose, we receive:
- Payment confirmation, amount, currency, and date
- A transaction/subscription identifier
- Limited billing details necessary for tax compliance (e.g., country)
We do not receive or store full card numbers, card CVV codes, or crypto wallet private keys. These are handled exclusively by our payment processors, who act as independent data controllers for the payment data they process. We encourage you to review their respective privacy policies:
- Stripe: stripe.com/privacy
- NOWPayments: nowpayments.io/privacy-policy
- Telegram: telegram.org/privacy
3.3 Application & Diagnostic Data
- App version and operating system (for compatibility and support)
- A device or installation identifier, used solely to link a subscription license to a device and to enable recovery of active sessions; this identifier is not linked to VPN traffic or browsing activity
- Crash reports and error diagnostics, if you opt in to sending them
3.4 Support Communications
- Content of emails, live chat, or tickets you send us for support purposes
- Any attachments or device information you voluntarily provide to help us resolve an issue
3.5 Website Data
When you visit endorvpn.com (as distinct from using the VPN application), we may collect limited, privacy-preserving analytics, such as:
- Browser type, operating system, and approximate (city/country-level) location
- Pages visited and referring URLs
- Aggregated, anonymized usage statistics
Where possible, we use privacy-respecting, cookie-free or self-hosted analytics tools that do not build individual profiles. We do not use this data to track you across other websites or our VPN service.
4. Purposes of Processing
We use the information above to:
- Create, maintain, and secure your account
- Process payments, prevent fraud, and comply with tax obligations
- Provide customer support and respond to inquiries
- Maintain, troubleshoot, and improve the Services
- Detect, prevent, and respond to abuse of our infrastructure (see Section 8)
- Send essential service communications (e.g., renewal notices, security alerts)
- Send optional marketing communications, only with your consent, which you may withdraw at any time
5. Legal Basis for Processing (GDPR)
We rely on the following legal bases:
- Contract: to provide the Services you subscribed to (account and payment data)
- Legitimate interest: to secure our infrastructure, prevent abuse, and improve the Services
- Consent: for optional marketing communications and non-essential cookies
- Legal obligation: for tax, accounting, and lawful request compliance
6. Information Sharing
We do not sell your personal data. We share limited information only with:
- Payment processors (Stripe, NOWPayments, Telegram): solely to process the payment method you selected
- Infrastructure and hosting providers: to operate our servers and website, bound by data processing agreements
- Professional advisors (e.g., accountants, auditors): where necessary for legal or financial compliance
- Anonymized web-analytics providers: data not tied to your VPN usage and only outside of our applications (e.g., website)
- Authorities: only where legally compelled, see Section 8
Because we do not log VPN activity, there is no browsing or traffic data to share with any of the above, even where account or billing data might be disclosed.
7. VPN Server Locations
EndorVPN operates servers in multiple countries to provide performance and choice of location. Server host countries may have varying levels of legal protection for user data and varying likelihood of government interference with network traffic. Where we are aware that a server location carries materially higher risk, we will indicate this in the application. Choosing a server location is at your discretion, and we recommend considering the legal environment of a given location if this is a concern for you.
8. Law Enforcement & Government Requests
We may receive requests from government or law enforcement authorities. Our approach:
- We only act on requests submitted through valid legal channels recognized under Austrian and EU law (e.g., a court order or mutual legal assistance request).
- We assess every request for legal validity and scope, and will challenge requests we believe are unlawful, overbroad, or issued without proper jurisdiction.
- Because we do not retain VPN connection or traffic logs, we are generally unable to provide information linking a user identity to specific online activity, regardless of the request.
- Where legally permitted, we will notify the affected user of a request concerning their data.
9. Data Retention
- Account data: retained while your account is active, and deleted or anonymized within 90 days of account closure, unless a longer period is required by law.
- Billing/tax records: retained for 7 years or as otherwise required by law.
- Support communications: retained for up to 12 months after resolution, except where content is needed longer to defend against a dispute.
- Diagnostic/crash data: retained for up to 6 months.
- Marketing consent records: retained until you withdraw consent or 3 years of inactivity, whichever comes first.
We do not retain VPN connection logs at all, so no retention period applies to that category — it is never created.
10. International Data Transfers
Some of our service providers (e.g., payment processors, hosting infrastructure) may process data outside the European Economic Area (EEA). Where this occurs, we rely on appropriate safeguards, including Standard Contractual Clauses approved by the European Commission, or transfers to jurisdictions recognized as providing adequate protection.
11. Your Rights (GDPR)
As a data subject, you have the right to:
- Access a copy of your personal data
- Rectify inaccurate or incomplete data
- Erase your data ("right to be forgotten"), subject to legal retention obligations
- Restrict or object to certain processing
- Data portability for data you provided to us
- Withdraw consent at any time, without affecting prior lawful processing
- Lodge a complaint with the Austrian Data Protection Authority (Österreichische Datenschutzbehörde, dsb.gv.at) or your local supervisory authority
To exercise these rights, contact us at privacy@endorvpn.com. We will respond within 30 days, and may need to verify your identity first.
12. Security
We apply technical and organizational measures appropriate to the risk, including encryption of data in transit and at rest, access controls, and regular security review of our infrastructure. No system is perfectly secure, and we cannot guarantee absolute security. In the event of a data breach affecting your personal data, we will notify you and the relevant supervisory authority as required under the GDPR.
13. Children's Privacy
EndorVPN is not directed at, and is not intended for use by, individuals under 18 years of age. We do not knowingly collect personal data from minors. If we become aware that we have inadvertently collected data from a minor, we will delete it promptly.
14. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be notified via email or a prominent notice on our website prior to taking effect. Your continued use of the Services after such changes constitutes acceptance of the revised Policy.
15. Contact Us
Data Controller: ReadPartner DACH GmbH
Address: Börsegasse 9/14a, 1010 Vienna
Email: privacy@endorvpn.com
If you are not satisfied with our response, you may lodge a complaint with the Austrian Data Protection Authority: https://www.dsb.gv.at