LoginToolsPricing
BirdProxies
BirdProxies
Anmelden

Privacy Policy

Effective Date: 9 August 2026

Jump to a section

  1. 1. Controller
  2. 2. What we collect
  3. 3. Why we may process it
  4. 4. How long we keep it
  5. 5. The traffic you route through us
  6. 6. Who receives data
  7. 7. Transfers outside the EU
  8. 8. Cookies and analytics
  9. 9. Your rights
  10. 10. Security
  11. 11. Minors
  12. 12. Changes to this policy

1. Controller

The controller for the processing described here is:

Luis Scharf, trading as BirdProxies
Waldstraße 81, 65451 Kelsterbach, Germany
[email protected]

We are not required to appoint a Data Protection Officer under Art. 37 GDPR or § 38 BDSG, and none is appointed. Data protection enquiries go to the address above and are handled by the controller personally.

2. What we collect

  • • Account data: email address, password hash, and where you sign in with Google or Discord, the identifier and profile name from that provider
  • • Order and billing data: products purchased, amounts, invoices, and the billing details you enter
  • • Payment data: handled by our payment providers. We see the status, the amount and the last four digits of a card, never the full card number
  • • Service configuration and usage: which plans you hold, generated proxy credentials, data consumed, sub-users you create
  • • Security data: login timestamps and the IP address used, so we can show you your own login history and detect account takeover
  • • Server logs: IP address, timestamp, requested page, referrer, browser and operating system
  • • Support communication: what you write to us by email, live chat or in a Discord ticket
  • • Referral data: who referred you and the commissions arising from it

3. Why we may process it

PurposeLegal basis
Running your account, delivering the service, billingArt. 6 (1) (b) GDPR, performance of the contract
Invoices, bookkeeping, tax recordsArt. 6 (1) (c) GDPR, legal obligation
Security, fraud and abuse prevention, keeping the site upArt. 6 (1) (f) GDPR, legitimate interests
Analytics and non-essential cookiesArt. 6 (1) (a) GDPR and § 25 (1) TDDDG, your consent
Marketing emailArt. 6 (1) (a) GDPR, your consent, withdrawable at any time

Where we rely on legitimate interests, our interest is in operating a service that is not abused and stays available. You can object at any time under Art. 21 GDPR.

4. How long we keep it

  • • Account data: for as long as the account exists, then deleted
  • • Invoices and accounting records: 10 years, as required by § 147 AO and § 257 HGB
  • • Server logs: at most 30 days
  • • Login and security history: at most 12 months
  • • Support conversations: at most 2 years
  • • Traffic data of the proxy service: see section 5

If you delete your account we remove your personal data except where a retention obligation applies. In that case the data is blocked from further use rather than kept in circulation.

5. The traffic you route through us

We do not inspect the content of the traffic you route through our proxies beyond what is technically necessary to deliver it.

We do not build browsing profiles, we do not sell traffic data, and we do not hand traffic data to advertisers. Connection metadata that arises technically is processed only to route the connection, to meter the volume you have used, and to detect abuse, and is erased as soon as it is no longer needed for those purposes, in line with § 9 TDDDG.

We may be obliged to disclose data where a competent authority makes a lawful and binding request. We check every such request rather than answering it automatically.

6. Who receives data

We use the following processors and service providers. Each is bound by a data processing agreement under Art. 28 GDPR:

  • • Stripe (payments, Ireland and USA)
  • • NOWPayments (cryptocurrency payments)
  • • MongoDB Atlas (database hosting, EU region)
  • • Cloudflare (CDN, bot protection, Turnstile captcha)
  • • Resend (transactional and marketing email)
  • • Zoho (business mailboxes)
  • • Crisp (live chat)
  • • Discord (community, support tickets, optional sign-in)
  • • Google (optional sign-in)
  • • Telegram (optional notifications, only if you connect it)
  • • Sentry (error monitoring)
  • • Plausible and PostHog (website analytics, only with your consent)
  • • Our upstream network partners, who operate parts of the proxy infrastructure. They receive the technical identifiers needed to provision and run your plan, not your name or payment details

We do not sell personal data and we do not pass it on for third-party advertising.

7. Transfers outside the EU

Some of the providers above are based in the United States. Transfers are made either on the basis of the EU-U.S. Data Privacy Framework where the provider is certified, or on Standard Contractual Clauses under Art. 46 (2) (c) GDPR together with supplementary measures. You can request a copy of the safeguards from us at any time.

8. Cookies and analytics

Strictly necessary cookies keep you signed in and protect forms against abuse. They run on § 25 (2) TDDDG and need no consent.

Everything else, in particular analytics, runs only after you have agreed in the cookie banner. You can change or withdraw that decision at any time through the banner, with effect for the future. Details are in our Cookie Policy.

9. Your rights

Under the GDPR you have the right to:

  • • access your data (Art. 15)
  • • have inaccurate data corrected (Art. 16)
  • • have data erased (Art. 17)
  • • restrict processing (Art. 18)
  • • receive your data in a portable format (Art. 20)
  • • object to processing based on legitimate interests (Art. 21)
  • • withdraw consent at any time, without affecting what was lawful before (Art. 7 (3))

Write to [email protected]. We answer within one month.

You also have the right to complain to a supervisory authority. The one responsible for us is:

Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
Gustav-Stresemann-Ring 1, 65189 Wiesbaden, Germany

10. Security

Traffic to and from this site is encrypted with TLS. Passwords are stored only as bcrypt hashes. Access to production systems is limited to the controller. These measures are reviewed as the service changes; no measure makes a system perfectly secure, and we do not claim otherwise.

11. Minors

Our services are directed at adults. We do not knowingly collect data from persons under 18. If you believe a minor has given us data, tell us and we will delete it.

12. Changes to this policy

We update this policy when the service or the law changes. The current version is always the one on this page, with the date shown below. Material changes affecting registered users are announced by email.

If anything here is unclear, ask us. A privacy policy nobody can follow is not worth much.

Last Updated: August 2026

BirdProxies
BirdProxies

Fast, secure, reliable proxies. ISP, Residential, and Mobile, ready when you are.

Products

  • ISP Proxies
  • Residential Proxies
  • Sneaker Proxies
  • Ticket Proxies
  • Crypto Proxies
  • Social Media Proxies
  • Betting Proxies

Company

  • Pricing
  • Partners
  • Imprint
  • Terms

Resources

  • Blog
  • Docs
  • Glossary
  • Integration Guides
  • Compare Providers
  • FAQ
  • Changelog
  • Brand Assets

Connect

  • Dashboard
  • Sign Up
  • Contact

© 2026 BirdProxies. All rights reserved.

PrivacyCookiesRefunds