Shunlian VPN — Privacy Policy
Draft — not yet in force.
This document was prepared by the development team. The effective date, the operating entity's legal name, and the contact address must be supplied and confirmed by the operator (see "Items requiring confirmation" at the end). Until the operator confirms it in writing, this page must not be used as a published privacy policy.
1. Scope
This policy explains what Shunlian VPN ("the App") collects while you use it, why, how it is used, how long it is kept, and what control you have over it.
The App is a virtual private network (VPN) tool. We understand what people expect from software in this category, so this policy is explicit about both what we collect and what we deliberately do not collect. Please read section 3 in particular.
2. What we collect
2.1 Account information
| Data | Purpose | Required |
|---|---|---|
| Email address | Account identity, sign-in, password recovery, subscription notices | Yes |
| Password | Sign-in. Stored only as a one-way cryptographic hash; we cannot recover your plaintext password | Yes |
| Display name | Shown inside the App | Optional |
2.2 Device information
To enforce the number of simultaneous devices allowed by your plan, and to let you remove one lost device without disturbing the others, we must be able to tell one device from another:
| Data | Notes |
|---|---|
| Device identifier | On Android, the system-provided ANDROID_ID. On other platforms, a random identifier generated on first run and kept in the platform's secure storage. It identifies the device; it is not used to track you across apps and is not linked to any advertising identifier. |
| Device name | Shown in your device list; you can rename it in the App |
| Device type | e.g. Android, iOS — for display |
| Last connection time | Used to order your device list so you can tell which device was used most recently |
About the device identifier, stated plainly:
- We do not collect IMEI, MAC address, phone number, contacts, SMS, photos, precise location, or the list of apps installed on your device.
- The identifier is used only for device management and the per-plan device limit in this App. It is not sold and not shared with advertisers.
- You can remove a device at any time from Device Management in the App. Once removed, we no longer associate it with your account.
2.3 Subscription and transaction information
| Data | Purpose |
|---|---|
| Plan purchased, start date, expiry date, status | Determining your entitlement |
| Order number, amount, status, payment time | Transaction record, reconciliation, refunds |
| Transaction reference returned by the payment channel | Matching your payment with the processor |
We never receive or store your card number, payment password, or payment-account credentials. Payment is completed on a checkout page operated by the payment platform; we receive only whether the order succeeded.
2.4 Connection information
| Data | Notes |
|---|---|
| Connection authorisation records | Each device is issued its own connection credential, so the server can record that a given credential was used to establish a connection at a given time. This is the minimum needed for device management and fault diagnosis; it contains only a timestamp and a credential identifier. |
3. What we do not collect
The following is not visible to us and is not recorded:
- Your browsing history — which sites you visit or which apps you use;
- Your communications — messages, email, or file contents;
- DNS query logs;
- Your real IP address — the App does not send your device IP to our servers, and our servers do not record it.
One exception, stated honestly: when creating a payment order, the App submits your network IP to the payment platform as part of that platform's risk-control requirements. This is a condition of their API, the value is processed by them, and we do not store it. Outside of that, your IP appears nowhere in our records.
4. How we use the information
- To create and verify your account and let you sign in;
- To determine whether your subscription is active, and therefore whether to provide the service;
- To enforce your plan's simultaneous-device limit and let you remove devices;
- To allocate a connection credential to your device and establish the connection;
- To process payments, reconcile them, handle refunds, and expire subscriptions;
- To diagnose faults and prevent abuse (for example, one account used by an abnormal number of devices).
We do not use this information for advertising or user profiling, and we do not sell or rent it to anyone.
5. Retention
| Data | Retention |
|---|---|
| Account information (email, display name) | Until you delete your account |
| Device information | Until you remove the device in the App, or delete your account |
| Subscription and transaction records | Retained after account deletion for the financial and tax period required by law |
| Connection authorisation records | Short-term, for reconciliation and fault diagnosis |
6. Sharing
We share information with third parties only as far as necessary:
| Third party | What is shared | Why |
|---|---|---|
| Cloud infrastructure provider (Supabase) | All data listed above | Storage, authentication, backend services |
| Payment platform and its channels (WeChat Pay, Alipay) | Order number, amount, description, your ordering IP | Collecting payment |
| Content delivery network (Cloudflare) | Standard access logs when you visit our pages | Hosting and protection |
Beyond the above, we do not disclose your information except:
- with your explicit consent; or
- where required by law, or by a binding order of a judicial or administrative authority. Where legally permitted, we will tell you that we received such a request.
7. Security
- Traffic between you and our servers is encrypted with TLS;
- Each device holds its own connection credential, so removing one device does not affect your others;
- The database enforces row-level access control: your account data is reachable by you, and by operations staff only where necessary;
- The operations console is restricted to authorised personnel and is protected by access control separate from user accounts.
No method of transmission or storage over the internet is perfectly secure. We take reasonable measures to protect your information, and we will tell you if a breach affects you.
8. Your rights
At any time you may:
- Access and correct — view and change your display name and email in the App;
- View and remove devices — see every registered device and remove them individually;
- Delete your account — request it using the contact details below; we will act once we have verified your identity;
- Export — ask us for a copy of your account information;
- Complain — contact us using the details below.
9. Minors
The App is not intended for anyone under 18. We do not knowingly collect information from minors. If you are a guardian and believe a minor has provided us with information, please contact us and we will delete it.
10. Changes to this policy
If this policy changes materially, we will notify you prominently in the App and update the date at the top of this page. Continuing to use the App means you accept the revised policy.
11. Contact
To be completed — the operating entity's legal name, registered address, contact email, and the contact details of the person responsible for data protection. These must be supplied by the operator and must match the developer information registered on Google Play / the App Store.
12. Items requiring confirmation (delivery note — delete before publishing)
This section is a handover note for the operator and must be deleted before publication. The following cannot be determined by the development team alone:
- The operating entity's legal name and registered address — must match the developer account on the app stores, or the review will query the mismatch.
- A contact email — must be a real, monitored address maintained by the operator. Users will use it to exercise deletion and export rights.
- The effective date.
- The "financial period required by law" in the retention table — the actual number of years depends on the operator's jurisdiction and needs legal advice.
- The specific number of days for "short-term" in the retention table — the development team suggests 90 days; the operator must confirm.
- The actual server-side connection-log retention policy. Section 2.4 is worded on the basis that only a credential identifier and a timestamp are recorded. If the operations team enables more detailed logging on the OpenVPN server (for example, recording source IP addresses), either this section must be revised or that logging must be turned off. This must be verified with the operations team before publication.