Panda Cloud (the "Service") gives people reliable, private, and secure internet access. This policy explains what we collect, why, and how long we keep it. We aim for honesty over marketing language: where we keep data, we say so; where we don't, we say so too.
1. What we collect
Account data
- Your email address (the only required identifier)
- Your password, stored only as a salted hash — we cannot read it
- Your subscription state: plan, expiry, traffic counter, top-ups
- Payment records: amount, gateway, timestamp, transaction reference (no card numbers — those stay at the payment gateway)
- Optional: Telegram user ID if you bind your account for support and notifications
Service data
- Aggregate traffic counters (bytes used per billing period) for plan enforcement
- Recent connection metadata: timestamps, source IP, server hit — kept for up to 30 days for abuse detection (DDoS, credential stuffing, mass-sharing)
- Sign-in logs: IP, time, user-agent, success/failure — kept for 90 days
- Support conversations: messages you send to us via in-app chat or email
2. What we do not collect
- The websites you visit, the apps you use, or the content of your traffic
- DNS query logs beyond ephemeral resolver state
- Real names, government IDs, or address (we never ask)
- Third-party tracking pixels, analytics SDKs, or advertising identifiers in this panel
3. How we use it
- Operate the Service: route traffic, enforce plan limits, prevent abuse
- Billing & refunds: process payments, issue refunds, prevent fraud
- Account security: detect compromised credentials, send password-reset emails, run optional 2FA
- Support: answer your questions via in-app chat and email
- Legal compliance: respond to lawful requests in our operating jurisdictions
4. Who we share it with
We share data only with infrastructure providers needed to operate the Service:
- Cloudflare — CDN, DNS, DDoS protection (request metadata, no payload)
- Server hosting providers (AWS, Cloudflare, others) — the proxy nodes themselves
- Payment gateways (third-party payment processors) — only the data they require to process payment
- Email providers (Mailgun, Amazon SES) — transactional email only (sign-in, receipts, password resets)
- Telegram — only if you choose to bind your account, and only the user ID
We do not sell or rent your data. Period.
5. How long we keep it
- Account data: while your account is active, plus up to 90 days after deletion to handle disputes and accounting
- Connection metadata: 30 days, then automatically purged
- Sign-in logs: 90 days
- Payment records: up to 7 years where required by tax / accounting law
- Support conversations: while your account is active
6. Your rights
You can:
- Sign in to view, export, or update your account data
- Request deletion of your account — this purges your record after the retention windows above
- Disable Telegram binding from your account page at any time
To exercise these rights, sign in and use the in-app live chat, or contact support@worldnod.com.
7. Security
We protect data with:
- HTTPS with HSTS for all panel and node traffic
- Salted password hashing (we never store plaintext passwords)
- Optional two-factor authentication (TOTP, WebAuthn)
- Rate limiting and bot protection on sign-in
- Restricted, audit-logged staff access to operational systems
No system is perfectly secure. If we discover a breach affecting your data, we will notify affected users via email.
8. Cookies
The panel uses only the cookies it needs to function: a session cookie for login, a CSRF cookie for form security, and a small preference cookie for your chosen theme. We do not set third-party tracking cookies in the panel.
9. Children
The Service is not directed at people under 17. If you are under 17, please do not create an account.
10. International transfers
Our infrastructure is global. By using the Service you understand your data may be processed in countries other than your own.
11. Changes to this policy
We may update this policy as the Service evolves. The "Last updated" date above always reflects the current version. Material changes will be communicated via email to active accounts.
12. Contact
Questions about this policy? Reach us through the in-app live chat (signed-in users) or via email at support@worldnod.com.