Quick answer
What personal data does PontProxy keep?
PontProxy keeps only the data it needs to run your account. That data is: account number, order history, payment records and per-day traffic totals; connection metadata (timestamp, target domain, bytes) kept 7 days for abuse handling, then deleted. Adding an email address is optional. We never ask for your name, an ID document, a selfie, a postal address, a phone number or card details. No KYC — no ID, no selfie, no documents. Pay in crypto.
Privacy at a glance
| Data controller | ProxyGoat LLC |
|---|---|
| Privacy contact | [email protected] |
| Identity checks (KYC) | None — no ID, no selfie, no documents |
| Login | account-number login — email optional |
| Payment | Crypto only: Bitcoin (BTC), Tether (USDT), USD Coin (USDC), Ethereum (ETH), Solana (SOL), Litecoin (LTC) |
| Card or bank details | Never collected |
| Connection metadata | Timestamp, target domain and bytes — used for abuse handling only, then deleted |
| Cookies set by our website or client area code | None |
| Browser storage | Public website: none · Client area: sign-in token, language choice and, if you came through a partner link, the referral code |
| Third-party trackers | None — no analytics, advertising or social-media scripts |
| Regulators | UK: Information Commission (formerly the ICO) · EU/EEA: your national data protection authority |
Who is responsible for your data?
The data controller is ProxyGoat LLC, which operates PontProxy at https://pontproxy.com. The controller decides why and how your personal data is used.
This policy covers the website, the client area and the proxy service itself. It applies the EU General Data Protection Regulation (Regulation (EU) 2016/679) and the UK GDPR, together with the UK Data Protection Act 2018.
For any privacy question, write to [email protected].
Why do we collect so little?
We follow the data minimisation principle. Article 5(1)(c) of the GDPR says personal data must be "adequate, relevant and limited to what is necessary" for the purpose of the processing. The UK GDPR contains the same principle in the same words.
A proxy service needs an account, a payment and a traffic balance. It does not need your identity. That is why you can buy any plan on the pricing page with an account number only. The no-KYC proxies page explains how this works in practice.
What personal data do we collect?
We collect the data below, and nothing else:
- Account number — created for you at sign-up. It is your login.
- Email address (optional) — only if you add one, for receipts and account notices.
- Order history — the plans you bought, with dates and amounts.
- Payment records — the amount, coin, network and blockchain reference matched automatically to your top-up.
- Per-day traffic totals — how much traffic your account used each day, to show your balance.
- Connection metadata — the timestamp, target domain and bytes of each connection, kept for a short time for abuse handling.
- Messages you send us — the content of support or abuse emails, and the address they come from.
- Referral code — only if you reached the client area through a partner link. It is sent with your sign-up so we can credit that partner.
When you visit the website, our hosting provider also receives your IP address and the page you request. Every web server needs this to deliver a page.
What do we never collect?
We never ask for, and never store:
- your name;
- an ID document, such as a passport, driving licence or identity card;
- a selfie or any other biometric data;
- a postal address;
- a phone number;
- card or bank details.
We also do not store the content of the pages or files you load through the proxies. No KYC — no ID, no selfie, no documents. Pay in crypto.
On what legal basis do we use your data?
Each use of your data has one of three legal bases under Article 6(1) of the GDPR and the UK GDPR:
- Contract — Article 6(1)(b). We need your account number, orders, payment records and traffic totals to deliver the service you buy. The same applies to your email address if you choose to add one. The law allows processing that "is necessary for the performance of a contract" with you.
- Legitimate interests — Article 6(1)(f). We keep connection metadata for a short time to detect and stop abuse, to protect our network partners and to enforce the Acceptable Use Policy. We also keep a referral code, if any, to credit the partner who sent you. Some targets are blocked for every customer: online banking, government portals, payment processors and outgoing email (SMTP ports 25, 465 and 587).
- Legal obligation — Article 6(1)(c). We keep order and payment records when accounting or tax law requires it. We also answer legal orders that bind us.
We do not use your data for advertising, and we do not sell it.
How long do we keep each type of data?
Our retention statement: account number, order history, payment records and per-day traffic totals; connection metadata (timestamp, target domain, bytes) kept 7 days for abuse handling, then deleted. The table applies it to each type of data. When you close your account, we delete the data linked to it, except records that the law requires us to keep.
| Data | Why we keep it | How long |
|---|---|---|
| Account number | Sign-in, and the link between you and your orders | As long as the account exists |
| Email address (optional) | Receipts and account notices | Until you remove it or close the account |
| Order history | Delivering the service, refunds and accounting | As long as the account exists, or as required by law |
| Payment records | Matching each crypto payment to its order | As long as the account exists, or as required by law |
| Per-day traffic totals | Showing your usage and balance, answering billing questions | As long as the account exists |
| Connection metadata (timestamp, target domain, bytes) | Abuse handling | The short period stated in our retention statement above, then deleted |
| Referral code (only if you came through a partner link) | Crediting the partner who sent you | As long as the account exists |
| Support and abuse emails | Answering you and keeping a record of decisions | As long as needed to handle the request, or as required by law |
Who else handles your data?
We use a small number of service providers. Each one receives only the data it needs for its task:
- Hosting and content delivery — serves this website and the client area. It receives your IP address and the pages you request.
- Crypto payment processing — creates the payment request and confirms the transaction. It receives the order amount, the coin and the transaction details. It does not receive your name, because we do not have it.
- Network partners — established residential and mobile networks carry your proxy traffic. They process the technical data needed to route it, and they may keep their own technical logs under their own policies. Read how we source our IPs.
On-chain crypto payments are also recorded on a public blockchain. The blockchain shows the transaction, not your account number.
We do not sell personal data, and we do not share it with advertisers or data brokers.
Is your data transferred outside the UK or the EU?
It can be. Some of our providers may process data outside the UK or the European Economic Area (EEA). When that happens, we use a transfer tool that the law recognises:
- an adequacy decision of the European Commission (EU GDPR Article 45), or UK adequacy regulations (UK GDPR Article 45A); or
- appropriate safeguards, such as standard contractual clauses (EU GDPR Article 46(2)(c); UK GDPR Article 46).
Your proxy traffic also leaves the network in the country you choose. That routing is the service you buy. To learn which transfer tool covers a given provider, write to [email protected].
What are your rights, and how do you use them?
You have these rights under the EU GDPR and the UK GDPR:
- Access (Article 15) — get a copy of the data we hold about you.
- Rectification (Article 16) — correct data that is wrong, such as your email address.
- Erasure (Article 17) — ask us to delete your data. We then keep only the records that the law requires.
- Restriction (Article 18) — ask us to pause the use of your data while a question is checked.
- Objection (Article 21) — object to processing based on legitimate interests, such as abuse handling.
- Portability (Article 20) — receive the account data you gave us in a structured, commonly used and machine-readable format.
To use a right, email [email protected] and include your account number. Never send your password. We check that the request comes from the account holder, and we never ask for an ID document to do so.
We answer within one month of receipt, free of charge. For complex or numerous requests, the law allows two more months. If we need them, we tell you why within the first month.
How do you complain to a regulator?
You can complain to us first, by email to [email protected]. Under section 164A of the UK Data Protection Act 2018, we acknowledge a data protection complaint within 30 days. We then respond without undue delay and tell you the outcome.
You also have the right to complain to a supervisory authority:
- United Kingdom — the Information Commission. It replaced the Information Commissioner, known as the ICO, on 30 September 2026. Use the complaint page on ico.org.uk.
- European Union and EEA — the data protection authority where you live, where you work, or where the alleged infringement took place (GDPR Article 77). The European Data Protection Board lists every national authority.
What happens when the police or a court ask for data?
We disclose data only to answer a valid legal order that binds us under the laws of the State of Delaware, United States. We check each order before we act on it.
We can only hand over the limited data listed on this page. That is the account number, the email address if one was added, order history and payment records. It also includes per-day traffic totals and any connection metadata not yet deleted. We hold no names, ID documents, postal addresses, phone numbers or card details, so we cannot disclose them.
We do not give customer data to people who report abuse. Authorities should follow the process on our contact page.
Does this website use cookies or trackers?
No. Our website and client area code set no cookies. They load no third-party analytics, advertising or social-media scripts. Three technical points apply:
- Referral and campaign links on the public website. Some links contain a
reforutm_parameter. A short script then copies those parameters into the buy links on that page. The public website stores nothing in your browser. - Referral code in the client area. If the client area opens with a
refparameter, it saves that code in your browser's local storage. The code is sent with your sign-up so we can credit the partner who sent you. - Sign-in and language. The client area keeps a sign-in token in local storage, so you stay signed in. Signing out removes it. It also remembers your language choice.
UK law allows storage that is strictly necessary for a service you asked for. It also allows storage that adapts a website to your preferences, such as language (PECR regulation 6 and Schedule A1). EU law exempts storage that is strictly necessary for a service you asked for (ePrivacy Directive, Article 5(3)). You can remove all these items at any time by clearing this site's data in your browser settings.
How will we tell you about changes to this policy?
The date at the top of this page shows the last update. We list material changes, with their date, in the changelog.
How do you contact us about privacy?
Email [email protected] with your account number, and never your password. To report abuse of our network, write to [email protected]. All contact details are on the contact and abuse reports page.
Legal sources (13)
- Regulation (EU) 2016/679 (General Data Protection Regulation) — Articles 5, 6, 12, 15–18, 20, 21, 45, 46 and 77 — EUR-Lex, Publications Office of the European Union
- UK GDPR, Article 5 — Principles relating to processing of personal data — legislation.gov.uk (2026-10-05)
- UK GDPR, Chapter V — Transfers of personal data to third countries — legislation.gov.uk (2026-10-05)
- Data Protection Act 2018, section 164A — Complaints by data subjects to controllers — legislation.gov.uk (2026-10-05)
- Data Protection Act 2018, section 165 — Complaints by data subjects to the Commission — legislation.gov.uk (2026-10-05)
- Data (Use and Access) Act 2025, section 118 — Abolition of the office of Information Commissioner — legislation.gov.uk (2026-10-05)
- Data (Use and Access) Act 2025, section 119 — Transfer of functions to the Information Commission — legislation.gov.uk (2026-10-05)
- The Data (Use and Access) Act 2025 (Commencement No. 9 and Transitional and Saving Provisions) Regulations 2026 (S.I. 2026/1015), regulation 2 — in force 30 September 2026 — legislation.gov.uk (2026-10-05)
- Privacy and Electronic Communications Regulations 2003, regulation 6 — Storing information in the terminal equipment of a subscriber or user — legislation.gov.uk (2026-10-05)
- Privacy and Electronic Communications Regulations 2003, Schedule A1 — exceptions (strictly necessary, website appearance) — legislation.gov.uk (2026-10-05)
- Directive 2002/58/EC (ePrivacy Directive), Article 5(3) — EUR-Lex, Publications Office of the European Union
- Make a complaint — ico.org.uk (2026-10-05)
- Our members — national data protection authorities — European Data Protection Board (2026-10-05)