Legal & Privacy

Privacy Policy

Last updated: August 2026

This policy explains how BbsVPN handles data when providing cross-border access, international routes, and subscription services. Processing follows the principles of clear purpose, necessity, and restricted access. By using the service, users confirm that they have read this policy. If they disagree with these practices, they should stop using the relevant features and submit a deletion request as described below.

Data Collected and Processing Purposes

Account data: BbsVPN accounts can be created with a username and password without an email address, so an email address is not required for registration. Usernames and account credentials support authentication, account security, plan association, and restored access. Details, attachments, or an email address voluntarily submitted in a support ticket are used only to handle that request.

Order and service records: To activate plans, calculate usage, look up orders, process refunds, and resolve disputes, the service may retain order identifiers, selected plans, payment amounts, payment status, activation status, and necessary account links. Payment methods include Alipay, WeChat Pay, and USDT.

Website analytics: To understand whether pages load correctly, entry points work, and features are easy to use, the website may process technical information such as page addresses, referring pages, browser and device types, network addresses, approximate regions, and button interactions. This information supports aggregate analysis, troubleshooting, and security protection; it is not used to create a profile of the international websites users visit.

No-Logs Position and Connection Records

BbsVPN does not record which websites users access through international routes, or retain web content, search content, DNS queries, or browsing history that could reconstruct browsing activity. The service also does not create long-term connection logs linking an account to visits to specific websites.

Route scheduling and troubleshooting may generate necessary temporary technical states during operation, such as service error types, route status, or aggregate resource usage. This information is used only to maintain the service, investigate anomalies, and prevent abuse. It does not contain a list of websites visited by users and is overwritten or deleted once its purpose is fulfilled. Access and connection activity do not enter persistent records for long-term analysis, so there is no routine retention period for browsing logs.

Cookies, Local Storage, and Analytics

The website and user panel may use cookies or browser local storage to save login status, interface language, necessary session identifiers, and security settings, allowing the correct state to persist when users change pages or return later. Local storage may also retain authentication information required by the account panel. After signing out, clearing browser data, or deleting site storage, these states may expire and a new login may be required.

Analytics are used to assess page visit trends and conversion entry points. Analytics data is handled separately from browsing activity on subscription routes and is not used to identify the specific international websites a user visits. If a browser restricts cookies, some preferences or login functions may not persist, but public pages such as this privacy policy remain readable.

Payment Processing and Data Sharing

Payments are handled by the channel selected by the user. Payment credentials and information required by the payment channel are subject to that channel's privacy rules. BbsVPN generally receives only the result information needed to complete an order, such as payment status, amount, and order identifier. When users select USDT, the transaction is also subject to the rules of the network and service provider used.

BbsVPN allows relevant processors to access data only as necessary to deliver the service, settle payments, operate infrastructure, protect security, or meet applicable legal obligations. Processors may handle information only for the agreed purposes. Except with user authorization, to fulfill a user-initiated request, or to meet a legal obligation, account data is not used for unrelated purposes.

Data Retention and Deletion

Account data is generally retained until the account is deleted or the service relationship ends. Order records are retained for the period required for settlement, financial reconciliation, refund processing, dispute resolution, or applicable legal requirements. Support ticket content is retained until the request and necessary follow-up checks are complete. Analytics are retained as needed for analysis and security and may be converted into aggregate information that cannot be directly linked to an account.

Users may log in to the panel and use Submit a support ticket to request access to, correction of, or deletion of account-related data. To prevent action by another person, account verification may be required before processing a deletion request. After deletion, account features and related subscriptions may no longer be available. Order, settlement, or dispute records that must be retained by law will continue to be kept only as necessary, then be deleted or stripped of their account link.

Policy Updates and User Choices

This policy may change as service features, data practices, or applicable rules change. Updated versions will be published on this page, and the last-updated month at the top will be changed accordingly. If a change materially affects user rights or data purposes, the website or user panel will clearly highlight the relevant information.

Users can manage cookies and local storage through browser settings, stop using specific features, sign out, or submit a data deletion request. For questions about this policy, account data processing, or the deletion process, please submit specific questions through a user-panel support ticket and avoid attaching sensitive information unrelated to the request.

Start Free