Privacy Policy
What we collect, what we deliberately do not log, how long we keep it, and the rights you have over it.
Last updated: 13 August 2026
1. Who we are and what this covers
This Privacy Policy explains how ProxyFalcon, a brand operated by LeadifyCPA, handles personal data when you visit this website, apply for an account, or use our proxy services. It applies to you as our client. It does not describe how the websites you access through the network handle data — that is between you and them.
For questions or to exercise a right described in Section 8, write to media@leadifycpa.com.
2. Data we collect
2.1 Account and verification data
- Name, email address, and business name where applicable.
- Contact handle you choose to use with us, such as a Telegram username.
- Your stated use case, target countries and expected volume, as provided during verification.
- Any identity or business documentation you send us for higher-volume or reseller verification.
2.2 Billing data
- Invoice records, amounts, currency, payment method type and payment status.
- Where relevant, the transaction reference supplied by the payment provider or bank.
We do not receive or store full card numbers. Card payments, where offered, are handled by the payment provider.
2.3 Service usage data
- Bandwidth volume consumed per sub-account, and per time period.
- Connection metadata: timestamps, gateway and port used, source IP addresses you connect from, session identifiers, concurrency, and success or error response codes.
- Destination hostname and category information where our upstream network requires it for abuse prevention and policy enforcement.
2.4 Website data
- Standard server request logs for this website, including IP address, user agent and requested page.
- Anything you type into the contact form — note that the contact form opens your own email client, so that message reaches us as an ordinary email.
This website does not use advertising or cross-site tracking cookies.
3. What we do not log
To be specific, because it matters to technical buyers:
- We do not inspect, record or store the content of the pages or responses you request through the network.
- We do not perform TLS interception on your traffic.
- We do not record full URLs with query strings for routine traffic.
- We do not record credentials, form data, cookies or session tokens belonging to the sites you visit.
- We do not sell, rent or trade your personal data, and we do not use your data to build advertising profiles.
What we keep is what is needed to bill accurately and to answer an abuse report. Nothing is retained "just in case".
4. Why we use it
- To provide the service — issuing credentials, routing traffic, metering bandwidth. (Basis: performance of a contract.)
- To verify clients — confirming who you are and that your workload is permitted. (Basis: legitimate interests and legal obligation.)
- To bill and keep records — invoicing, accounting, tax records. (Basis: contract and legal obligation.)
- To prevent abuse — detecting AUP violations, responding to abuse reports, protecting the network and our upstream supply. (Basis: legitimate interests.)
- To support you — answering messages, sending service notices. (Basis: contract and legitimate interests.)
- To comply with law — responding to lawful requests and sanctions obligations. (Basis: legal obligation.)
We send service and billing notices to active clients. We do not add you to a marketing list without your consent, and any marketing email we do send will have a working unsubscribe.
5. Retention
- Account and verification records: for the life of the account and then up to 24 months after closure, so that we can handle disputes and repeat applications.
- Billing and invoice records: as long as required by applicable accounting and tax law, typically 6 years.
- Connection metadata and usage counters: retained for a rolling operational window, then reduced to aggregate totals used for billing history. Our target window is 90 days.
- Abuse investigation records: retained for up to 24 months where needed to prevent recurrence or to respond to a legal claim.
- Website server logs: retained per our hosting provider's standard log rotation.
6. Third parties we share data with
We share the minimum necessary, and only with:
- Upstream proxy network providers — who receive the connection metadata required to deliver and police the service, and who may receive your account identity in connection with a substantiated abuse report.
- Payment providers and banks — who process your payment and hold their own records of it.
- Hosting and email providers — who process this website's traffic and our correspondence.
- Professional advisers — accountants and lawyers, where necessary and under confidentiality.
- Authorities — where we are legally required to disclose, or where disclosure is necessary to report unlawful content or activity.
We do not have advertising or data-broker recipients. Because we and our providers operate in several countries, your data may be processed outside your own; where that involves a transfer from the UK or EEA we rely on appropriate safeguards such as standard contractual clauses.
7. Security
We protect data with access controls limited to people who need it, credentials that are issued per sub-account and rotated on request or on suspected exposure, encrypted transport for our website and dashboards, and separation of client sub-accounts so that one client's activity and usage records are not visible to another.
No system is perfectly secure. If a breach affects your personal data and presents a risk to you, we will notify you and any required regulator without undue delay, and tell you what happened and what to do about it.
8. Your rights (GDPR / UK GDPR / CCPA)
Depending on where you are, you may have the right to:
- Access the personal data we hold about you, and receive a copy.
- Correct inaccurate or incomplete data.
- Delete data, where we are not required to keep it for legal, accounting or abuse-prevention reasons.
- Restrict or object to processing based on legitimate interests.
- Portability — receive your data in a machine-readable format.
- Withdraw consent where processing was based on consent.
- Opt out of "sale" or "sharing" under the CCPA/CPRA — we do not sell or share personal information as those terms are defined, so there is nothing to opt out of, and we do not discriminate against anyone who exercises a privacy right.
- Complain to your data protection authority if you are unhappy with our response.
To exercise a right, email media@leadifycpa.com with "Privacy Request" in the subject. We respond within 30 days and may ask you to confirm your identity first, so that we do not disclose your data to someone else.
9. Children
The service is sold to businesses and to adults over 18. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
10. Changes and contact
We update this policy when our processing changes. The current version and its "Last updated" date are always on this page, and we notify active clients of material changes by email.
Data controller: ProxyFalcon, a brand operated by LeadifyCPA.
Contact: media@leadifycpa.com
Questions about this policy?
Write to media@leadifycpa.com and a person will answer. If you are reporting abuse, mark the subject line ABUSE REPORT.