Last updated Last updated: 8 August 2026
Privacy Policy
1. Introduction and scope
This policy explains how the Company collects, uses, stores, shares and protects your personal information when providing the ZapIP residential proxy service — this website, the console at https://user.zapip.net, the API and the technical support around them (together, the Service) — and what rights you hold over that information and how to exercise them.
The Company is incorporated in the People's Republic of China, and this policy is written under the Personal Information Protection Law (PIPL), the Cybersecurity Law, the Data Security Law, the Regulations on Telecommunications and the Measures for the Administration of Internet Information Services of the PRC. This site holds a PRC ICP filing.
By registering an account, placing an order or otherwise using the Service, you confirm that you have read and understood this policy and accept the processing it describes. If any part of it is unacceptable to you, please stop using the Service.
This policy does not extend to any third-party site or platform you reach through the proxy channel. Whatever those parties do with information is governed by their own policies, and the Company is not responsible for it.
2. Personal information we collect
Account information: the email address, username and password you supply at registration (the password is stored as a salted one-way hash and cannot be recovered by us), plus any phone number, contact name or company name you choose to add. This set is necessary to create an account and deliver the Service.
Transaction and billing information: order records, the plan and volume tier purchased, and the transaction reference and status returned by the payment channel. Payments are handled by licensed third-party processors — the Company never receives or stores your full card number, CVV or payment password.
Service logs: sign-in times and source addresses, console actions, proxy session metadata (start time, duration, exit region, request volume and bandwidth used) and API calls. These support billing reconciliation, account security and abuse investigation. The Company does not record or store the content of the traffic you pass through the proxy channel.
The Service does not seek out the categories PIPL defines as sensitive personal information — biometrics, religious belief, specific identity, medical or health data, financial accounts or location trails. Identity documents are collected only where real-name verification is required by law, and then only after we tell you separately what will be processed, why and how, and obtain your separate consent.
3. Purposes and legal basis
The Company processes personal information to open and maintain your account; to deliver proxy resources and meter and bill them; to provide support and diagnose faults; to keep accounts and the network secure by detecting anomalous sign-ins, account theft and fraud; to meet obligations imposed by law and respond lawfully to competent authorities; and, where you have agreed, to send notices about maintenance, service changes and product updates.
The legal bases sit in Article 13 of PIPL. Account, transaction and service-log processing is necessary to conclude and perform the contract to which you are a party. Log retention and identity verification are necessary to discharge statutory obligations. Marketing messages rest on your separate consent, which you may withdraw at any time without affecting the lawfulness of processing carried out before withdrawal.
The Company does not use your personal information for automated decisions with a significant effect on your rights, and does not profile you or supply your usage data to third parties for targeted advertising. Any future purpose not described here will be notified to you and consented to afresh before it begins.
4. Storage and security
Location: personal information is stored on servers inside the People's Republic of China. Where a node you have chosen sits outside the PRC and a cross-border transfer is genuinely required, the Company follows the routes set out in Articles 38 to 40 of PIPL — telling you in advance who the overseas recipient is, how to contact them, why and how they will process the data and what categories are involved, and obtaining your separate consent.
Retention: account information is kept for as long as the account exists. After you close it, the Company deletes or anonymises the data within a reasonable period unless law requires otherwise. Article 21 of the Cybersecurity Law requires network operation and security logs to be retained for no less than six months, and transaction and tax records are held for the periods set by accounting and tax rules.
Safeguards: traffic is encrypted in transit with TLS; passwords are stored as salted hashes; internal access follows least-privilege and separation-of-duties rules with an audit trail on sensitive operations; staff who handle personal information receive regular security and compliance training; and data is classified with access granted through a documented approval process.
Incident response: the Company maintains an incident plan for personal information breaches. If data is leaked, altered or lost — or is at risk of it — remediation begins immediately, and affected individuals are notified and the competent supervisory authority informed as required by Article 57 of PIPL.
5. Sharing, transfer and public disclosure
The Company does not sell your personal information and does not supply it to any third party for commercial gain.
Entrusted processing: to run the Service the Company engages a small number of processors with access to a limited set of data — payment institutions that execute payment instructions, cloud and CDN providers that host the platform, helpdesk and ticketing providers that hold correspondence, and identity-verification providers where the law requires them. Each is bound by a data processing agreement fixing purpose, term, method and security obligations, is supervised by the Company, and may not use the data for anything beyond the agreed purpose.
Transfer: the Company does not transfer personal information to another controller, except where a merger, division, dissolution or bankruptcy makes it unavoidable. In that case you will be told the recipient's name and contact details, the recipient remains bound by this policy, and any change to the original purpose or method of processing requires your consent afresh.
Disclosure and lawful requests: the Company does not publicly disclose your personal information. It may provide what is necessary in response to law, litigation or a request made through proper procedure by a judicial or administrative authority — but each request is checked for legal basis, the requester's standing and its scope, only the minimum genuinely required is produced, and you are notified where the law permits it.
6. Cookies and analytics
Essential cookies keep you signed in, remember your language, protect against cross-site request forgery and flag anomalous sessions. The site and the console cannot function without them — disable these and sign-in stops working.
Analytics cookies count page views, referral sources and feature use in aggregate, which is how we work out which documentation is missing and where a flow is failing people. The output is summary-level and is not used to identify an individual.
You can inspect, delete or refuse cookies in your browser settings, and most browsers also offer a do-not-track signal. The Company does not use cross-site advertising trackers and does not pass your browsing history to any ad network.
7. Your rights
Chapter IV of PIPL gives you the following rights over the personal information the Company holds: to access and obtain a copy; to correct and supplement it; to have it deleted where the purpose has been achieved, where you withdraw consent, or where processing has been unlawful; to have it ported to a controller you nominate where the conditions set by the national cyberspace authority are met; to withdraw a consent previously given; to ask the Company to explain its processing rules; and to close your account.
How to exercise them: most are self-service in the console — edit your profile, change the bound email, export usage records or request closure. For anything else, write to the contact email published on our site and the Company will respond within fifteen working days of verifying who you are. Identity checks may be required first, to keep an account from being opened up to someone else.
If a request is refused you will be given the reason, together with notice that you may complain to the competent personal-information-protection authority or bring proceedings in a People's Court. Exercising these rights is free; for repetitive or manifestly excessive requests the Company may charge a reasonable cost or explain why it will not act.
Additional rights for EU residents: if you are habitually resident in the European Union, then to the extent the General Data Protection Regulation applies to the relevant processing, you may additionally object to processing, request its restriction, and lodge a complaint with your national supervisory authority. These sit on top of the rights above and take nothing away from those you hold under PRC law.
8. Protection of minors
The Service is offered to businesses and to individuals aged 18 or over. If you are under 18, please do not register an account or send the Company any personal information.
The Company does not knowingly collect personal information from children under 14. Article 31 of PIPL classifies such information as sensitive and requires the consent of a parent or guardian before it may be processed. If the Company learns it has collected data on a child without that consent, processing stops immediately and the data is deleted.
A parent or guardian who believes a child in their care has registered an account or submitted information without consent can write to the contact email published on our site, and the Company will help verify and remove it.
9. Changes to this policy
This policy may change as law, business or technology changes. Any revised version is published on this page with its update date and takes effect from the day it appears.
Where a change is material — a new purpose, a new method, new categories of information, or a change in how data is shared or sent abroad — the Company gives separate advance notice by site announcement, console banner or a message to the email bound to your account, and seeks fresh consent wherever the law requires it.
For editorial changes that do not alter your rights or obligations in substance, continuing to use the Service after publication is taken as acceptance of the updated policy.
10. Governing law and contact
The formation, effect, interpretation, performance and enforcement of this policy are governed by the laws of the People's Republic of China (for this purpose excluding the laws of Hong Kong SAR, Macao SAR and Taiwan).
The Company has appointed a person responsible for personal information protection, who handles enquiries, requests and complaints about personal data. For any question about this policy or your own information, write to the contact email published on our site.
Disputes arising out of this policy should first be settled through good-faith negotiation. Failing that, either party may bring proceedings before a competent People's Court in Hangzhou, where the Company is domiciled.
- Legal entity
- Hangzhou ZapIP Network Technology Co., Ltd.
- support@zapip.net
- Address
- Bldg 1, Changdi Torch Mansion, 259 Wensan Rd, Xihu District, Hangzhou, Zhejiang, China
- ICP filing
- 浙ICP备2026062289号-2
- Governing law
- Laws of the People's Republic of China