1. Data we collect
- Account: name, email, password (stored only as a secure hash).
- Security: session and 2FA records, IP address, browser/device info.
- Usage: request metadata from your tunnels (time, method, path, status, latency, source IP) and device telemetry.
- Payment: handled by Paddle (Merchant of Record); we never see or store card details.
We do not persist the content (request/response bodies) passing through your tunnels — only the metadata above as logs.
2. Why we process data
- To provide the service, verify your account and manage your tunnels.
- To ensure security and prevent abuse and fraud.
- To send transactional emails (verification, password reset, login codes).
- To meet legal obligations.
3. Sharing
We never sell your data. We share only with providers necessary to run the service: Paddle for payments, our data center for hosting. Emails are sent from our own mail server (Postfix).
4. Security
All traffic is TLS-encrypted; passwords are hashed. Optional 2FA, IP allowlists and scoped API keys are available. Sensitive actions are rate-limited.
5. Retention & deletion
Account data is kept while your account is active; logs for your plan's retention (e.g. 1–30 days). On account closure, your data is deleted or anonymized within a reasonable time.
6. Your rights
You can access, correct or request deletion of your data via Profile, or email kvkk@zorven.app.