Panda Cloud

Privacy Policy

Last updated

Panda Cloud (the "Service") gives people reliable, private, and secure internet access. This policy explains what we collect, why, and how long we keep it. We aim for honesty over marketing language: where we keep data, we say so; where we don't, we say so too.

1. What we collect

Account data

  • Your email address (the only required identifier)
  • Your password, stored only as a salted hash — we cannot read it
  • Your subscription state: plan, expiry, traffic counter, top-ups
  • Payment records: amount, gateway, timestamp, transaction reference (no card numbers — those stay at the payment gateway)
  • Optional: Telegram user ID if you bind your account for support and notifications

Service data

  • Aggregate traffic counters (bytes used per billing period) for plan enforcement
  • Recent connection metadata: timestamps, source IP, server hit — kept for up to 30 days for abuse detection (DDoS, credential stuffing, mass-sharing)
  • Sign-in logs: IP, time, user-agent, success/failure — kept for 90 days
  • Support conversations: messages you send to us via in-app chat or email

2. What we do not collect

  • The websites you visit, the apps you use, or the content of your traffic
  • DNS query logs beyond ephemeral resolver state
  • Real names, government IDs, or address (we never ask)
  • Third-party tracking pixels, analytics SDKs, or advertising identifiers in this panel

3. How we use it

  • Operate the Service: route traffic, enforce plan limits, prevent abuse
  • Billing & refunds: process payments, issue refunds, prevent fraud
  • Account security: detect compromised credentials, send password-reset emails, run optional 2FA
  • Support: answer your questions via in-app chat and email
  • Legal compliance: respond to lawful requests in our operating jurisdictions

4. Who we share it with

We share data only with infrastructure providers needed to operate the Service:

  • Cloudflare — CDN, DNS, DDoS protection (request metadata, no payload)
  • Server hosting providers (AWS, Cloudflare, others) — the proxy nodes themselves
  • Payment gateways (third-party payment processors) — only the data they require to process payment
  • Email providers (Mailgun, Amazon SES) — transactional email only (sign-in, receipts, password resets)
  • Telegram — only if you choose to bind your account, and only the user ID

We do not sell or rent your data. Period.

5. How long we keep it

  • Account data: while your account is active, plus up to 90 days after deletion to handle disputes and accounting
  • Connection metadata: 30 days, then automatically purged
  • Sign-in logs: 90 days
  • Payment records: up to 7 years where required by tax / accounting law
  • Support conversations: while your account is active

6. Your rights

You can:

  • Sign in to view, export, or update your account data
  • Request deletion of your account — this purges your record after the retention windows above
  • Disable Telegram binding from your account page at any time

To exercise these rights, sign in and use the in-app live chat, or contact support@worldnod.com.

7. Security

We protect data with:

  • HTTPS with HSTS for all panel and node traffic
  • Salted password hashing (we never store plaintext passwords)
  • Optional two-factor authentication (TOTP, WebAuthn)
  • Rate limiting and bot protection on sign-in
  • Restricted, audit-logged staff access to operational systems

No system is perfectly secure. If we discover a breach affecting your data, we will notify affected users via email.

8. Cookies

The panel uses only the cookies it needs to function: a session cookie for login, a CSRF cookie for form security, and a small preference cookie for your chosen theme. We do not set third-party tracking cookies in the panel.

9. Children

The Service is not directed at people under 17. If you are under 17, please do not create an account.

10. International transfers

Our infrastructure is global. By using the Service you understand your data may be processed in countries other than your own.

11. Changes to this policy

We may update this policy as the Service evolves. The "Last updated" date above always reflects the current version. Material changes will be communicated via email to active accounts.

12. Contact

Questions about this policy? Reach us through the in-app live chat (signed-in users) or via email at support@worldnod.com.