Privacy Policy

Last updated: March 2026

1. Introduction

NexTunnel ("we," "our," "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and safeguard your information when you use our VPN service ("Service"). We process data in accordance with the General Data Protection Regulation (GDPR) and applicable privacy laws.

2. Data Controller

The data controller responsible for your personal data is NexTunnel, operating under the jurisdiction of Romania / European Union. For data protection inquiries, contact our Data Protection Officer (DPO) at dpo@nextunnel.com.

3. Information We Collect

3.1 Account Information

When you register, we collect:

3.2 Payment Information

All payment processing is handled by Stripe, our PCI DSS-compliant payment processor. We store:

We do NOT have access to or store your full credit card number, CVV, or card expiration date.

3.3 Usage Data

3.4 Security & Authentication Data

4. What We Do NOT Collect

We do not and cannot collect:

The VLESS+Reality protocol is designed so that we cannot inspect the content of your encrypted tunnel traffic.

5. Legal Bases for Processing (GDPR)

We process your personal data based on the following legal grounds:

6. How We Use Your Information

7. Data Sharing

We do not sell, trade, or rent your personal information to third parties. We share data only with:

We do not use any analytics, advertising, or tracking services that collect user data.

8. Data Retention

Data TypeRetention Period
Account dataWhile account is active + 30 days after deletion
Connection metadata72 hours (auto-purged)
Traffic countersReset monthly; historical totals while account active
Payment records7 years (tax/legal requirement)
Support ticketsWhile account is active + 1 year
Login/security logs90 days

9. Your Rights (GDPR)

If you are located in the European Economic Area (EEA), you have the following rights:

To exercise any of these rights, contact our DPO at dpo@nextunnel.com or use the support ticket system. We will respond within 30 days.

10. International Data Transfers

Your data may be processed on servers located within the European Union. If data is transferred outside the EEA, we ensure appropriate safeguards are in place (Standard Contractual Clauses or adequacy decisions).

11. Security Measures

We implement appropriate technical and organizational measures to protect your data:

12. Cookies

We use only essential cookies for authentication and session management. No tracking, advertising, or analytics cookies are used. For details, see our Cookie Policy.

13. Children's Privacy

The Service is not intended for use by individuals under 18 years of age. We do not knowingly collect personal data from children. If we learn that we have collected data from a child, we will delete it promptly.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.

15. Contact — Data Protection Officer

For privacy inquiries, data access requests, or complaints:

We aim to respond to all requests within 30 days as required by GDPR.