Last Updated: July 6, 2026
This Privacy Policy explains how Bypass.io (“Company,” “we,” “us,” or “our”) collects, uses, shares, protects and retains personal data when you visit https://bypass.io, sign in to https://dashboard.bypass.io, or use our proxy products and related services (together, the “Services”). It also describes the privacy rights available to you and how to exercise them.
Bypass.io is a premium proxy provider and white-label reseller. We offer Residential (rotating), Static Residential (ISP), Datacenter, and LTE/Mobile proxies through a self-serve dashboard with prepaid balance top-ups, per-GB residential pricing and fixed plans.
- Scope and About This Policy
- This Policy applies to visitors to our website, registered dashboard users, account owners and their authorized team members, prospective customers, and anyone who contacts us for support, sales or security matters.
- For the personal data we handle to operate your account and Services, Bypass.io acts as the data controller. When we process data solely on behalf of a business customer under our agreement, we act as a data processor for that customer.
- Key terms used below: Personal Data means information that identifies or can reasonably be linked to an individual; Processing means any operation performed on Personal Data (collection, storage, use, disclosure, deletion); Services means our website, dashboard and proxy products; and Subprocessor means a third party we engage to process Personal Data in support of the Services.
- This Policy is designed to be consistent with applicable data protection laws, including the EU and UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA).
- Our Services are intended for businesses and individuals who are at least 18 years old. See Section 12 (Children’s Privacy).
- Data We Collect
- Account data. Information you provide when you register and manage your account, such as:
- Name and, where provided, company or business name;
- Email address and login credentials (passwords are stored hashed);
- Two-factor authentication settings and, if you enable it, API keys or access tokens you generate;
- Communication and marketing preferences.
- Billing data. Information needed to process payments and prepaid balance top-ups, such as:
- Billing name, address and country;
- Invoice, order and top-up history and remaining balance;
- The payment method you choose at checkout (including cryptocurrency) and a confirmation or reference for each transaction. Full card or wallet details are handled directly by our payment processor — we do not store them on our own systems.
- Usage and telemetry. Information collected automatically when you use the website and dashboard, such as:
- IP address and approximate country (for example, derived at sign-up);
- Browser type and version, operating system and device characteristics;
- Referring URLs, pages viewed, features used, and access times;
- Diagnostic, performance and error logs used to keep the Services reliable and secure.
- Support communications.The contents of messages you send us and our replies — for example, support tickets, email, and any attachments or account details you share so we can help you.
- Proxy-service operational data. To deliver, meter and protect the proxy Services, we process operational records such as:
- Which proxy products, plans and locations are assigned to your account;
- Bandwidth and request volume for metering and billing;
- Connection metadata such as timestamps, protocol, and concurrency;
- Aggregated and abuse-signal data used to detect fraud, prevent misuse and enforce our Acceptable Use / Terms of Service.
We do not build profiles of the specific end destinations you browse for marketing purposes. Where technically necessary, limited connection data may be processed on a short-term basis to route traffic, meter usage, and investigate abuse or security incidents, and is minimized and retained only as described in Section 6.
- Cookies and similar technologies. See Section 8 for how we use cookies, local storage and comparable technologies.
- Account data. Information you provide when you register and manage your account, such as:
- How and Why We Use Your Data (Legal Bases)
- We use Personal Data only where we have a lawful basis to do so. The table below summarizes our main purposes and the legal basis we rely on under the GDPR/UK GDPR:
- Provide the Services— create and administer your account, provision proxies, apply prepaid balance, and deliver features you request. Basis: performance of a contract.
- Take payment— process top-ups, invoices and refunds, and keep required financial records. Basis: performance of a contract; legal obligation.
- Support you— respond to tickets, troubleshoot, and send service, security and transactional messages. Basis: performance of a contract; legitimate interests.
- Keep the Services secure and prevent abuse— detect fraud, stop misuse, protect our network and enforce our Terms. Basis: legitimate interests; legal obligation.
- Improve and analyze— understand usage, fix errors, and improve reliability and features. Basis: legitimate interests.
- Marketing— send product news and offers where permitted. You can opt out at any time. Basis: consent, or legitimate interests where allowed by law.
- Comply with law— meet tax, accounting, and other legal requirements and respond to lawful requests. Basis: legal obligation.
- Where we rely on consent (for example, certain marketing or non-essential cookies), you may withdraw it at any time without affecting processing carried out before withdrawal.
- We do not use your Personal Data to make solely automated decisions that produce legal or similarly significant effects about you without a lawful basis and appropriate safeguards. Automated checks we run for fraud and abuse prevention are subject to human review on request.
- We use Personal Data only where we have a lawful basis to do so. The table below summarizes our main purposes and the legal basis we rely on under the GDPR/UK GDPR:
- How We Share Your Data (Subprocessors and Others)
- We do not sell your Personal Data. We share it only as described here, and we require recipients to protect it and use it only for the purposes we specify.
- Service providers and subprocessors. We engage vendors that process Personal Data on our behalf under contract. By category, with representative examples of the role each performs:
- Upstream proxy networks— partners whose infrastructure supplies the residential, ISP, datacenter and mobile IP pools we resell;
- Payment processor— to charge top-ups and process payments, including cryptocurrency, and to help detect payment fraud;
- Transactional email provider— to send account, security and support messages, and permitted marketing;
- Cloud hosting and CDN— to host the website, dashboard and databases and deliver content reliably;
- Anti-abuse and CAPTCHA— to block bots, spam and fraudulent sign-ups and protect account security.
- Legal and safety. We may disclose data where we believe in good faith that it is necessary to comply with a law, regulation, subpoena, court order or other lawful request; to enforce our agreements; or to protect the rights, property or safety of Bypass.io, our users, or the public. Where permitted, we will seek to narrow such requests and, where appropriate, notify affected users.
- Business transfers. If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, Personal Data may be transferred as part of that transaction, subject to this Policy or a successor policy with equivalent protections.
- With your direction or consent. We share data with third parties when you ask us to or otherwise consent.
- A current list of the categories of subprocessors is maintained above; to request additional detail, contact [email protected].
- International Data Transfers
- We operate globally and use cloud infrastructure and subprocessors that may be located in countries other than yours. As a result, your Personal Data may be transferred to, stored in, or accessed from jurisdictions whose data protection laws differ from those where you live.
- When we transfer Personal Data out of the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards, principally the European Commission’s Standard Contractual Clauses (and the UK Addendum / International Data Transfer Agreement where applicable), together with supplementary technical and organizational measures.
- You may request a copy of the relevant transfer safeguards by emailing [email protected].
- Data Retention
- We keep Personal Data only for as long as necessary for the purposes described in this Policy, then delete or anonymize it. In choosing retention periods we consider the nature and sensitivity of the data, why we need it, and any legal, tax, accounting or security obligations.
- Illustrative retention periods (which may vary where the law requires or an active dispute, investigation or legal hold applies):
- Account data— for the life of your account and for a limited period after closure to handle reactivation, disputes and legal claims;
- Billing and transaction records— retained as required to meet tax and accounting obligations (typically several years);
- Proxy operational and connection metadata— kept for a short period for metering, troubleshooting, fraud and abuse prevention, then deleted or aggregated;
- Support communications— retained for a reasonable period to maintain a service history and resolve follow-up issues;
- Security and diagnostic logs— retained for a limited period for security monitoring and incident investigation.
- Where we anonymize data so it can no longer be linked to you, we may retain and use it indefinitely for statistical and product-improvement purposes.
- How We Protect Your Data
- We maintain technical and organizational measures appropriate to the risk, including:
- Encryption of data in transit using TLS;
- Hashing of account passwords and protection of secrets and API keys;
- Access controls and the principle of least privilege for staff and subprocessors;
- Network protections, monitoring, and logging;
- Regular backups and reviews of our security practices.
- No method of transmission or storage is completely secure. While we work to protect your data, we cannot guarantee absolute security, so please keep your credentials confidential and enable two-factor authentication.
- Data-breach posture. We maintain procedures to detect, investigate and respond to security incidents. If a breach affects your Personal Data, we will notify the relevant supervisory authority and affected individuals where and when required by applicable law (for example, without undue delay and, under the GDPR, generally within 72 hours of becoming aware of a notifiable breach), and we will describe the incident, its likely impact, and the steps we are taking. You can report a suspected vulnerability or incident to [email protected].
- We maintain technical and organizational measures appropriate to the risk, including:
- Cookies and Similar Technologies
- We and our providers use cookies, local storage, pixels and similar technologies to keep you signed in, remember preferences, secure the Services, measure performance and understand usage.
- We use these broad categories:
- Strictly necessary— required for sign-in, security, and core dashboard functionality; these cannot be switched off;
- Preferences— remember settings such as language and display choices;
- Analytics/performance— help us understand how the Services are used so we can improve them.
- You can control cookies through your browser settings and, where offered, through an on-site cookie control. Blocking some cookies may affect how the Services work.
- Do Not Track.Because there is no consistent industry standard for honoring browser “Do Not Track” signals, we do not currently respond to them. Where required by law, we treat recognized opt-out preference signals (such as Global Privacy Control) as a valid request to opt out of “sales” or “sharing” as those terms are defined under applicable law.
- Your Rights in the EU/EEA and UK (GDPR)
- If you are in the EU/EEA or the UK, you have the following rights, subject to the conditions and exceptions in the law:
- Access— obtain confirmation of whether we process your data and a copy of it;
- Rectification— correct inaccurate or incomplete data;
- Erasure— ask us to delete your data (the “right to be forgotten”);
- Restriction— ask us to limit processing in certain circumstances;
- Portability— receive data you provided in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible;
- Objection— object to processing based on legitimate interests, and object to direct marketing at any time;
- Withdraw consent— where we rely on consent, withdraw it at any time;
- Lodge a complaint— complain to your local supervisory authority (see Section 13).
- How to exercise them. Email [email protected] with your request and the account email you use. Many actions (such as updating profile details or marketing preferences) can also be done directly in the dashboard. We will respond within one month, and may extend by two further months for complex requests, in which case we will tell you.
- We may need to verify your identity before acting, and we will not charge for exercising your rights unless a request is manifestly unfounded, excessive or repetitive.
- If you are in the EU/EEA or the UK, you have the following rights, subject to the conditions and exceptions in the law:
- Your Rights in California (CCPA/CPRA)
- If you are a California resident, you have the following rights, subject to the conditions and exceptions in the law:
- Know / Access— request the categories and specific pieces of Personal Information we collected, the sources, the purposes, and the categories of third parties with whom we disclosed it;
- Delete— request deletion of Personal Information we collected from you, subject to legal exceptions;
- Correct— request correction of inaccurate Personal Information;
- Opt out of sale/sharing— we do not sell your Personal Information and do not share it for cross-context behavioral advertising; if that ever changes, we will provide a “Do Not Sell or Share My Personal Information” mechanism;
- Limit use of sensitive information— we do not use sensitive Personal Information for purposes that would trigger this right;
- Non-discrimination— we will not discriminate against you for exercising your rights.
- How to exercise them. Email [email protected]. We will confirm receipt within 10 business days and respond within 45 days, extendable by another 45 days where reasonably necessary, and we will let you know if we need more time. You may use an authorized agent, and we may require verification of your identity and the agent’s authority.
- We do not knowingly sell or share the Personal Information of consumers under 16 years of age.
- If you are a California resident, you have the following rights, subject to the conditions and exceptions in the law:
- Marketing Choices
- You can opt out of marketing emails at any time by using the unsubscribe link in the message or by updating your preferences in the dashboard. We will still send non-promotional service messages, such as security alerts, billing notices and important account updates.
- To ask a question about marketing preferences, contact [email protected].
- Children’s Privacy
- The Services are intended for users who are at least 18 years old and are not directed to children. We do not knowingly collect Personal Data from anyone under 18.
- If you believe a minor has provided us with Personal Data, contact [email protected] and we will take reasonable steps to delete it.
- Complaints and Supervisory Authorities
- If you have a concern about how we handle your Personal Data, please contact us first at [email protected] so we can try to resolve it.
- You also have the right to lodge a complaint with a data protection authority: in the EU/EEA, your local supervisory authority; in the UK, the Information Commissioner’s Office (ICO); and in California, the California Privacy Protection Agency or the California Attorney General.
- Third-Party Links
- Our Services may link to third-party websites, plugins and applications we do not control. This Policy does not apply to those third parties, and we are not responsible for their practices. Please review the privacy policy of any site you visit.
- Changes to This Policy
- We may update this Policy to reflect changes in our practices or for legal, operational or regulatory reasons. When we do, we will revise the “Last Updated” date at the top of the page.
- If changes are material, we will provide a more prominent notice — for example, by email or an in-dashboard message — before they take effect where required. Your continued use of the Services after an update means you accept the revised Policy.
- How to Contact Us
For any privacy question or to exercise your rights, contact us at:
Bypass.io
1209 Orange Street
Wilmington, Delaware, 19801
United States- Privacy: [email protected]
- Support: [email protected]
- Security: [email protected]
- Abuse: [email protected]
- General / legal: [email protected]
By using the Services provided by Bypass.io, you acknowledge that you have read and understood this Privacy Policy.
Bypass.io Privacy Policy
Last Updated: July 6, 2026