Privacy policy
This policy explains what personal data busyip collects, why, who else sees it, how long we keep it, and what you can ask us to do with it. It applies to customers of busyip and to visitors to busyip.com.
The short version. We collect your email address, what you bought, how many bytes you moved, and a record of the destinations you connected to. We keep the destination records for 90 days so that we can answer an abuse complaint. We never inspect the contents of your traffic. We do not sell personal data to anyone, ever.
1. Who is responsible for your data #
1.1 EFIRITY PTE. LTD. is the data controller for the personal data described here. The registered particulars are at the foot of this page.
1.2 For any privacy question or request, email support@busyip.com. A person reads that address.
2. Which laws apply #
2.1 We are a Singapore company, so the Personal Data Protection Act 2012 (PDPA) applies to what we do.
2.2 If you are in the European Economic Area or the United Kingdom, the General Data Protection Regulation applies to our processing of your personal data as well. Being established outside the EU does not remove that, and we do not argue otherwise.
2.3 Where the two regimes differ, we apply whichever gives you more.
3. What we collect #
3.1 What you give us #
- Your email address. Required. It is your login, it is where the confirmation and password-reset messages go, and it is how we reach you about your balance.
- A password, stored only as a salted hash by our authentication system. We cannot read it and cannot tell it to you.
- The use case you select at signup, from a fixed list, and whether you are buying for a business. This is the basis on which we supply the service.
- Optionally, a company name and country.
- Anything you write to support.
3.2 What your use of the service produces #
- Usage totals. Bytes up and down, per day, per credential. This is what your balance and your usage page are made of, and it is the evidence in a billing dispute.
- Connection records. For each connection: the destination host you asked for, the source IP address the request came from, which credential was used, the time, and whether it succeeded. The source IP address here is stored as given, not hashed, because a hash cannot answer an abuse complaint. Kept 90 days, then deleted.
- Not the content. We do not record, inspect, store or analyse the contents of your traffic. The gateway moves bytes and does not read them. This is a promise we make to the people supplying the connections as much as to you.
3.3 What we collect about your visit #
- Funnel telemetry. Which pages you viewed and in what order, a first-party identifier held in a cookie, your browser's user-agent string, your country, and a keyed hash of your IP address. The raw address is not stored. The only question we ask of that column is "is this the same origin as before?", and a hash answers it without keeping a location log for people who have not bought anything.
- Free-allowance anti-abuse data. When an account claims the free allowance we record a keyed hash of the email address, the email domain, and keyed hashes of the signup IP address and of its network block. Again, hashes, not addresses. This is how we stop one person taking a hundred free allowances and exhausting the network for paying customers.
- Server logs, held briefly for operations and security.
3.4 Payments #
Stripe processes payments. We never receive your full card number. Stripe gives us an identifier for you, the amount, the currency, the result, and enough detail to issue an invoice and answer a dispute. Stripe processes your payment data as a controller in its own right, under its own privacy policy.
4. Why we use it, and on what legal basis #
| What we do | Basis under the GDPR |
|---|---|
| Create and run your account, supply the service, take payment, issue invoices | Performance of a contract |
| Send confirmation, password reset, balance and suspension emails | Performance of a contract |
| Meter usage and maintain the byte balance | Performance of a contract |
| Keep connection records to investigate abuse and protect the people supplying connections | Legitimate interests, and the legitimate interests of those people |
| Prevent abuse of the free allowance | Legitimate interests |
| Understand how people move through the public pages | Legitimate interests — page-view analytics on public pages only; never on a signed-in page, and never with a customer identifier |
| Keep accounting records | Legal obligation |
| Respond to a lawful request from an authority | Legal obligation |
4.1 Under the PDPA we rely on your consent, given when you create an account, and on the legitimate-interests and business-improvement exceptions where the Act provides them.
4.2 We do not sell personal data, and we do not share it for advertising. There is no advertising on the signed-in parts of this service and no third-party tracker on any page that shows your balance or your usage.
5. How long we keep it #
5.1 One retention period per category, and a job that actually deletes. The periods are:
| Data | Kept for | Why that number |
|---|---|---|
| Connection records (destination host, source IP) | 90 days | Long enough for a complaint to arrive; short enough that a legal demand or a breach yields little |
| Funnel telemetry (page views, hashed IP) | 90 days | Same job, same number |
| Usage records, daily and detailed | Life of the account, plus 30 days | It is the evidence in a billing dispute and the basis of your invoices |
| Purchases, invoices, byte and money ledgers | 7 years | Accounting record we are required to keep. Pseudonymised when an account closes (section 7) |
| Free-allowance anti-abuse fingerprints (hashed) | 12 months | Long enough to catch repeat claiming across a plausible cycle |
| Account audit log (what we did to your account, and why) | Life of the account | It is what we produce if you or a regulator asks what we did |
| Your login record and email address | Erased 30 days after closure | See section 7 |
5.2 We may keep something longer where the law requires it, or where it is needed for a live dispute, a live abuse investigation, or a legal claim. If that happens to your data, it is confined to what the matter needs.
6. Who else sees it #
6.1 We use a small number of service providers. Each processes data on our instructions and for no purpose of their own, except Stripe, which is also a controller for payment data.
| Provider | What they do | What they see |
|---|---|---|
| Stripe | Payments | Your card details, your email, the amount |
| Mailgun | Transactional email | Your email address and the message we send you |
| DigitalOcean | Hosting for our servers and database | Everything held on our servers, as infrastructure |
| Google Analytics 4 | Marketing-page analytics only | Page views on public pages. Never a customer identifier, and never a page that shows a balance or usage |
6.2 We also disclose data where we must: to a law-enforcement or regulatory authority acting under valid process, to a professional adviser under a duty of confidence, and to a complainant, an internet service provider or an authority where it is necessary to investigate abuse of our network under the Acceptable Use Policy.
6.3 If the business is ever sold or merged, your data may transfer to the buyer, subject to this policy. We would tell you.
7. Closing your account, and what deletion means #
7.1 You can close your account yourself, from your settings page, at any time.
7.2 Immediately on closing: your proxy credential is revoked, no new connections stop, your sessions end, and the account becomes read-only. Your usage history and invoices remain exportable to you for 30 days.
7.3 At 30 days: we erase your email address, your login record, our funnel telemetry about you, and the free-allowance fingerprints.
7.4 We keep the financial records — purchases, invoices, and the byte and money ledgers — for seven years, without your email address, linked only to an opaque account identifier.
7.5 We state 7.4 plainly because it is the part people are surprised by. We are required to keep an auditable accounting record, and that obligation outlives a deletion request under both the PDPA and the GDPR. What we erase is the link to you. What survives is a row of numbers that no longer identifies anybody. That satisfies the request without making the books unauditable, and it is the ordinary resolution of this conflict rather than a clever one.
7.6 Connection records made before closure run out their 90 days and are then deleted like everyone else's.
8. Your rights #
8.1 Under the PDPA you may ask us for access to the personal data we hold about you and for information about how we have used it, ask us to correct it, and withdraw consent. We will respond within 30 days, and tell you if we need longer.
8.2 If the GDPR applies to you, you also have the rights to erasure, to restriction of processing, to data portability, to object to processing based on legitimate interests, and not to be subject to a solely automated decision with legal effect. We make no automated decisions with legal effect about you. Account suspension is a decision a person takes.
8.3 To exercise any of these, email support@busyip.com from the address on your account. Most of it you can do yourself: your usage is exportable as CSV from your dashboard, and closing your account starts the erasure in section 7.
8.4 If you think we have got this wrong, tell us first. You may also complain to the Personal Data Protection Commission of Singapore, or, if the GDPR applies to you, to the supervisory authority in your country.
9. Where your data is #
9.1 We are established in Singapore and our servers are hosted with DigitalOcean. Personal data is therefore transferred to and stored outside your own country.
9.2 Where we transfer personal data covered by the GDPR outside the EEA, we do so only with the safeguards the GDPR requires, and we contract with our providers on terms that oblige them to protect it to the same standard.
10. Cookies #
- A session cookie, set when you sign in. Strictly necessary; without it you cannot stay signed in. It is signed, sent only over HTTPS in production, and not readable by scripts.
- A first-party visitor identifier, used to understand how people move through the site before they sign up. It does not follow you to other websites.
- Google Analytics cookies, set on public pages so we can count page views and see which pages help people decide. They are never set on a signed-in page, and Google Analytics never receives a customer identifier, a balance or a usage figure. IP addresses are anonymised before they reach Google.
10.1 Opting out. Block googletagmanager.com in your browser or
with any content blocker, or use Google's own opt-out add-on; the site works identically
without it. There is nothing to undo on our side beyond what Google already holds.
10.3 You can also block or delete cookies in your browser directly. Blocking the session cookie will stop you signing in; blocking the others changes nothing you can see.
11. Security #
11.1 Traffic to busyip.com is encrypted in transit. Passwords are stored hashed. The keys that reach our database are held only on our servers and are never sent to a browser.
11.2 Your dashboard password and your proxy secret are separate credentials with separate blast radii. Compromising one does not compromise the other, and resetting one does not reset the other.
11.3 No system is perfectly secure. If we suffer a breach affecting your personal data we will notify you and the relevant authorities as the PDPA and the GDPR require.
12. Children #
12.1 busyip is not directed at children, and we do not knowingly collect personal data from a child. If you believe a child has created an account, email support@busyip.com and we will delete it.
12.2 A minimum age for an account has not yet been fixed. See section 13 of the Terms of Service.
13. Changes to this policy #
13.1 We may update this policy. The version identifier is at the top of this page. Where a change materially affects you we will email the address on your account before it takes effect.
14. Contact #
14.1 Privacy questions and requests: support@busyip.com.
14.2 Reports of abuse of our network: abuse@busyip.com.
Formal identification
busyip is operated by EFIRITY PTE. LTD., a private limited company incorporated in Singapore. The registered particulars of the contracting entity, which also appear on every invoice, are:
- Registered name
- EFIRITY PTE. LTD.
- Registration number
- 202402844G
- Registered address
- 68 Circular Road #02-01, Singapore 049422
- General and support
- support@busyip.com
- Abuse reports
- abuse@busyip.com
- Governing law
- Singapore
Legal process and law-enforcement requests should be directed to the registered address above.