# ROOT VPN — Privacy Policy **Version 1.0** **Effective: 6 September 2026** --- ## 1. Introduction and scope 1.1 This Privacy Policy explains how **ROOT VPN LTD** ("**we**", "**us**", "**our**") collects, uses, shares and protects personal data when you use our products and websites. It is written to meet our obligations under the **UK General Data Protection Regulation (UK GDPR)**, the **Data Protection Act 2018 (DPA 2018)** and the **Privacy and Electronic Communications Regulations 2003 (PECR)**. 1.2 This Policy applies to the following products and services (together, the "**Services**"): - **ROOT VPN** — our consumer virtual private network application. ROOT VPN offers a **free tier** that is funded by **opt-in idle-bandwidth sharing**, and a **paid subscription tier** that disables bandwidth sharing. - **Meridian Peer SDK** — a software development kit that enables **opt-in bandwidth sharing** within participating partner applications. - **Root Proxies Network** — a business-to-business (B2B) residential and ISP proxy network, made available only to **verified (KYC'd) business customers**. - Our websites, dashboards, support channels and related systems. 1.3 Because the ways in which we process personal data differ significantly between these Services, this Policy identifies, for each processing activity, the personal data involved, the purpose, and the lawful basis relied upon. 1.4 Separate contractual terms (for example, our Terms of Service, Acceptable Use Policy, B2B Customer Agreement and Bandwidth Sharing Consent) govern the use of the Services. Where those documents address privacy matters, they should be read alongside this Policy. --- ## 2. Who we are (data controller) and how to contact us 2.1 The data controller responsible for your personal data is **ROOT VPN LTD**, registered in England and Wales. See the Company details section at the end of this Policy for our registered office and company number. 2.2 We have appointed a **Data Protection Officer (DPO)**. You can contact the DPO with any question about this Policy or about how we handle your personal data: - **Email (DPO):** dpo@rootproxies.com - **Email (general privacy enquiries):** privacy@rootproxies.com - **Email (ROOT VPN support):** support@rootvpn.com 2.3 If your query relates to the Meridian Peer SDK inside a partner application, the partner (the app publisher) may be a separate or joint controller for some data. Where that is the case, we will tell you and provide the partner's contact details. --- ## 3. Summary of what we collect (at a glance) 3.1 The table below is a high-level summary only. The detailed processing descriptions in section 4 are authoritative. | Activity | Main data categories | Primary purpose | |---|---|---| | Account creation & login | Email, hashed password or OAuth identifier, display name, verification/auth tokens | Provide and secure your account | | Device & VPN session | Device name, platform, WireGuard public key, assigned tunnel IP, IP address, session timestamps, user-agent | Establish and operate the VPN tunnel | | Bandwidth sharing (opt-in) | Consent record, exit IP, coarse geo/ASN, bytes metered, connection health | Route shared traffic, calculate rewards, enforce fair use | | Billing | Subscription status, Stripe/app-store customer & subscription IDs | Manage subscriptions (we do **not** store card data) | | Support | Contact details and message content | Respond to and resolve your query | | Abuse & security | Minimised security/abuse logs | Protect the network and comply with law | --- ## 4. Personal data we collect, why, and our lawful basis For each activity below we state (a) **what** we collect, (b) **why**, and (c) the **lawful basis** under Article 6 UK GDPR (and, where relevant, PECR). ### 4.1 Account data (a) **What:** your email address; either a securely **hashed password** (we never store passwords in plaintext) **or** an OAuth identifier from your chosen provider (for example, the Google or Apple **`sub`** subject identifier); your **display name**; and **email-verification and authentication tokens** (including short-lived session and refresh tokens). (b) **Why:** to create and secure your account, verify your email address, authenticate you at sign-in, maintain your logged-in session, and communicate essential service messages. (c) **Lawful basis:** **Article 6(1)(b) — performance of a contract** (creating and operating your account so we can provide the Services you request). Where we send security-related notifications, we may also rely on **Article 6(1)(f) — legitimate interests** (protecting account security). ### 4.2 Device and VPN session data (a) **What:** **device name** and **platform** (e.g. iOS, Android, Windows, macOS, Linux); the **WireGuard public key** generated by your device and the **tunnel IP address** we assign to it; the **IP address** your device connects from; **session timestamps** (connect/disconnect events); and **user-agent**/client version information. (b) **Why:** to establish the encrypted WireGuard tunnel, assign and route your traffic, associate a device with your account, maintain and troubleshoot connectivity, manage concurrent-device limits, and protect the network from abuse. (c) **Lawful basis:** **Article 6(1)(b) — contract** (operating the VPN you have asked us to provide). Certain minimal, short-retention records used to prevent fraud, abuse or attacks rely on **Article 6(1)(f) — legitimate interests** (see section 5 for the "no-log" scope and section 4.7 for abuse logs). > **Note on the tunnel IP and your source IP:** Operating a VPN necessarily involves handling IP addresses momentarily to route packets. What we do **not** do is retain a persistent log linking your source IP to the sites or services you visit through the tunnel — see section 5. ### 4.3 Bandwidth-sharing (peer) data — opt-in only This section applies **only** if you have separately and explicitly opted in to share idle bandwidth (on the ROOT VPN free tier, or through a partner app using the Meridian Peer SDK). Sharing is **off by default** and paid ROOT VPN subscriptions **disable** sharing. (a) **What we collect from a sharing peer:** - the **fact and record of your consent**, stored in a **consent ledger** (consent version, opt-in timestamp, any withdrawal timestamp, and the mechanism used); - the **exit IP address** presented to the destination and **coarse geolocation** (e.g. country/region) and **ASN** (network operator), used for routing and quality; - **bytes metered** (volume of shared traffic), used to calculate rewards and enforce fair-use limits; - **connection health** signals (e.g. latency, uptime, error rates). (b) **What we do NOT collect from a sharing peer.** We do **not** collect, inspect, store or sell: - the **content** of traffic that passes through your connection; - the **files, messages, documents or media** on your device; - your **own personal browsing history or personal internet traffic**; - any application data belonging to you as the peer beyond the routing/metering signals listed in (a). (c) **Why:** to route business-customer requests through the shared network, measure usage fairly, calculate any rewards or credits, monitor and maintain network quality, and prevent misuse. (d) **Lawful basis:** **Article 6(1)(a) — consent**, given separately for bandwidth sharing. Where the sharing feature stores or accesses information on your device (for example, reading connection/network information for routing), we also rely on your **consent under PECR regulation 6**. This consent is **separate, specific, unbundled from other terms, freely given and revocable at any time** — see section 6. ### 4.4 B2B customer (Root Proxies Network) data (a) **What:** business contact details, account administrator identities, and **Know-Your-Customer (KYC)/identity-verification information** required to onboard a business customer (which may include documents identifying individuals such as directors or beneficial owners), plus authentication credentials and API keys. (b) **Why:** to verify the legitimacy of business customers, prevent illegal or abusive use of the proxy network, operate the customer's account, and meet our own legal and regulatory obligations. (c) **Lawful basis:** **Article 6(1)(b) — contract** (providing the B2B service), **Article 6(1)(c) — legal obligation** and/or **Article 6(1)(f) — legitimate interests** (fraud prevention, anti-abuse and network integrity) for KYC and screening. ### 4.5 Billing and subscription data (a) **What:** your **subscription status**, plan/tier, and the **customer and subscription identifiers** issued by our payment providers (**Stripe** and the **Apple App Store / Google Play** billing systems). **We do not store your full payment-card number, CVC or bank details.** Card data is captured and processed directly by the payment provider. (b) **Why:** to take payment, manage renewals and cancellations, apply the correct tier (including disabling bandwidth sharing on paid tiers), and provide receipts and support. (c) **Lawful basis:** **Article 6(1)(b) — contract**. Records kept for tax and accounting purposes rely on **Article 6(1)(c) — legal obligation**. ### 4.6 Support communications (a) **What:** the contact details you use and the content of your messages to support@rootvpn.com, privacy@rootproxies.com or other channels, together with related account context. (b) **Why:** to respond to and resolve your enquiry and keep a record of the interaction. (c) **Lawful basis:** **Article 6(1)(b) — contract** where support relates to a Service you use, otherwise **Article 6(1)(f) — legitimate interests** (responding to enquiries). ### 4.7 Abuse-prevention and security logs (minimised) (a) **What:** deliberately **minimised** security records — for example, rate-limiting counters, authentication-failure events, indicators of fraud or attack, and records necessary to investigate abuse reports or respond to lawful requests. (b) **Why:** to protect users, peers, business customers and the network from fraud, abuse, attack and unlawful use, and to comply with legal obligations. (c) **Lawful basis:** **Article 6(1)(f) — legitimate interests** (network and information security), balanced against your rights (see 4.8), and **Article 6(1)(c) — legal obligation** where we must retain or disclose data by law. ### 4.8 Legitimate-interests balancing (summary) Where we rely on legitimate interests, we carry out a **Legitimate Interests Assessment (LIA)** weighing our interest in security and abuse-prevention against your rights and expectations. We limit these activities to what is necessary, minimise the data involved and keep it only as long as needed. You may object to processing based on legitimate interests — see section 12. --- ## 5. The "no-log" position — precise scope 5.1 We aim to operate ROOT VPN with strong privacy and to minimise the data we retain. To avoid over-claiming, we set out precisely what is and is not logged. 5.2 **What we do NOT log for the VPN service:** - the **websites, domains, IP addresses or services you visit** through the tunnel; - the **content** of your traffic (which is in any case encrypted in transit); - **DNS query logs** tied to your identity for the purpose of building a browsing profile; - a persistent, retained mapping of your **source IP to your online activity**. 5.3 **What we may process or retain (and for how long):** - **operational session data** described in section 4.2 (e.g. connect/disconnect timestamps, assigned tunnel IP, device association), retained for the periods in section 10; - **minimised abuse and security data** described in section 4.7, retained only as long as necessary for the purpose; - data we are **legally required** to retain or disclose (see section 13). 5.4 **Use of the phrase "no-log".** We only use marketing language such as "no-log" where it is accurate and consistent with sections 5.2–5.3, and we qualify such claims appropriately pending an independent audit of our logging practices. --- ## 6. Bandwidth-sharing consent — special provisions 6.1 Consent to share idle bandwidth (ROOT VPN free tier and Meridian Peer SDK) is treated as a **distinct, high-transparency consent**. It is: - **Separate** — presented apart from account creation and from acceptance of general terms; - **Specific** — limited to bandwidth sharing and the data in section 4.3; - **Unbundled** — not a condition of creating an account or using unrelated features; - **Freely given** — you can use the paid tier (no sharing) or decline sharing; - **Informed** — accompanied by a plain-language explanation of what sharing does and does not involve; - **Revocable** — you can withdraw at any time in the app settings or by contacting privacy@rootproxies.com, without affecting the lawfulness of processing before withdrawal. 6.2 We keep a **consent ledger** recording the consent version, timestamps and mechanism, so we can demonstrate valid consent as required by Article 7 UK GDPR. 6.3 On the **paid subscription tier**, bandwidth sharing is **disabled**. If you downgrade to the free tier, sharing is only enabled again if you actively opt in. --- ## 7. Cookies and similar technologies 7.1 Our websites and apps use cookies and similar local-storage technologies. Essential/strictly-necessary storage (such as session and authentication tokens) is used to operate the Services; analytics or other non-essential technologies are used **only with your consent** under PECR. 7.2 Full details, a cookie table and how to manage your choices are in our separate **[Cookie Policy](./COOKIE_POLICY.md)**. --- ## 8. Automated decision-making and profiling 8.1 We do **not** make decisions that produce legal or similarly significant effects about you based solely on automated processing within the meaning of Article 22 UK GDPR. 8.2 We use automated signals for **routing and network quality** (for example, selecting exit routes using coarse geo/ASN and connection-health data). These are operational decisions **about traffic and network paths**, not evaluative decisions **about you as an individual**, and they do not determine your rights, pricing or access based on a profile of you. 8.3 Automated systems used for **fraud and abuse prevention** may flag activity for human review; material decisions affecting a customer are subject to human involvement. --- ## 9. Sharing your data — recipients and sub-processors 9.1 We do not sell your personal data. We share it only as needed to run the Services, and with appropriate contracts in place. Categories of recipient include: - **Payment providers** — **Stripe** and the **Apple App Store / Google Play** billing systems (subscription processing); - **Hosting and infrastructure providers** — the providers that run our servers and network; - **Email/communications providers** — our transactional email provider, for verification and service messages; - **OAuth identity providers** — **Google** and **Apple**, where you choose to sign in with them (they authenticate you and return an identifier); - **Analytics providers** — used on the website only with consent; where we use no third-party analytics, none are engaged; - **Professional advisers, auditors and authorities** — where necessary for legal, accounting or security reasons (see section 13). 9.2 Where recipients act on our behalf, they are engaged as **processors** under Article 28 UK GDPR contracts and may only process data on our instructions. A current list of sub-processors is maintained separately — see our **[Sub-processors list](./SUBPROCESSORS.md)**. 9.3 **Business customers of the Root Proxies Network** are independent controllers for their own use of the proxy network and are contractually required to use it lawfully. We are not responsible for their independent processing but we require lawful use and carry out KYC to reduce abuse. --- ## 10. Retention 10.1 We keep personal data only for as long as necessary for the purposes described in this Policy, then delete or anonymise it. Indicative categories are set out below; concrete retention periods are maintained in our internal retention schedule and finalised by the DPO. | Data category | Notes | |---|---| | Account data | Kept for the life of the account, then deleted or anonymised within a defined period after closure | | VPN session/device data | Minimised; see section 5 | | Bandwidth-sharing consent ledger | Kept to evidence consent (Art. 7) for the duration of sharing plus a defined period after withdrawal | | Bandwidth-sharing metering/health data | Kept for rewards/fair-use purposes, then deleted or aggregated | | Billing/subscription records | Kept for the period required by tax/accounting law | | KYC/B2B verification records | Kept per anti-abuse/AML requirements | | Support communications | Kept for a limited period to resolve and review enquiries | | Abuse/security logs | Kept only as long as necessary, and minimised | 10.2 Where we are legally required to keep data for longer (for example, financial records or in response to a lawful order), we will retain it for that period only. --- ## 11. International transfers 11.1 By its nature, our network involves connections across borders — peers, business customers and exit points may be located in different countries. As a result, personal data may be transferred to or accessed from countries outside the UK. 11.2 Where we transfer personal data outside the UK, we protect it using an appropriate safeguard, such as: - transfers to countries with UK **adequacy** regulations; or - the UK **International Data Transfer Agreement (IDTA)** or the **UK Addendum to the EU Standard Contractual Clauses (SCCs)**; together with - a **Transfer Risk Assessment (TRA)** and any additional technical or organisational measures needed. 11.3 You can ask us for information about the safeguards we use by contacting dpo@rootproxies.com. --- ## 12. Your rights 12.1 Under UK GDPR you have the right to: - **access** a copy of your personal data; - **rectify** inaccurate or incomplete data; - **erase** your data ("right to be forgotten") in certain circumstances; - **restrict** processing in certain circumstances; - **data portability** — receive certain data in a portable format; - **object** to processing based on legitimate interests, and to direct marketing at any time; - **withdraw consent** at any time where we rely on consent (including bandwidth-sharing consent), without affecting prior lawful processing; and - **not be subject** to solely automated decisions producing legal or similarly significant effects (see section 8). 12.2 **How to exercise your rights.** Contact privacy@rootproxies.com or dpo@rootproxies.com. We may need to verify your identity. We will respond **within one month** of a valid request, extendable by up to two further months for complex requests, in which case we will tell you. 12.3 Exercising your rights is normally free. We may charge a reasonable fee or refuse a request that is manifestly unfounded or excessive, and will explain our reasons. 12.4 **Complaints.** You can complain to the **Information Commissioner's Office (ICO)** — ico.org.uk, helpline 0303 123 1113 — though we would welcome the chance to resolve your concern first. --- ## 13. Legal requests and disclosure 13.1 We may retain or disclose personal data where we are legally required to do so (for example, in response to a valid court order or lawful request from a competent authority) or where necessary to establish, exercise or defend legal claims, or to protect the rights, safety and security of our users, peers, customers, the public or ROOT VPN LTD. 13.2 We assess the validity of any request, disclose only what is legally required, and — where lawful and appropriate — record such requests. See our [Law Enforcement Guidelines](./LAW_ENFORCEMENT_GUIDELINES.md) for further detail. --- ## 14. Children 14.1 The Services are intended for users aged **18 or over**. They are not directed at children, and we do not knowingly collect personal data from anyone under 18. If we learn that we hold such data, we will delete it. If you believe a child has provided us with personal data, contact privacy@rootproxies.com. --- ## 15. How we protect your data (security) 15.1 We apply appropriate technical and organisational measures to protect personal data, including, at a high level: - **encryption in transit** (including the WireGuard-encrypted VPN tunnel and TLS for our web/API traffic); - **encryption at rest** for stored data where appropriate; - **password hashing** using a strong, modern algorithm (**Argon2id**), with no plaintext password storage; - **least-privilege access controls**, authentication and, where appropriate, multi-factor authentication for staff and systems; - **network segmentation, monitoring and logging** of security events (minimised as described above); - **data minimisation** and secure development and change-management practices. 15.2 No system is perfectly secure, but we work to protect your data and to detect and respond to incidents, including notifying you and the ICO where we are legally required to do so. --- ## 16. Changes to this Policy 16.1 We may update this Policy from time to time. We will change the "Effective" date above and, where changes are material, provide more prominent notice (for example, by email or in-app). Your continued use of the Services after an update takes effect indicates you are aware of the changes; where a change requires fresh consent, we will ask for it. --- ## 17. Contact - **General privacy enquiries:** privacy@rootproxies.com - **Data Protection Officer:** dpo@rootproxies.com - **ROOT VPN support:** support@rootvpn.com - **Supervisory authority:** Information Commissioner's Office (ICO), ico.org.uk --- ## Company details **ROOT VPN LTD** Registered in England and Wales Company number: [to be added] Registered office: [to be added] --- *ROOT VPN — Privacy Policy, Version 1.0.*