Privacy Policy
This policy explains what personal data we process when you visit seamlessproxies.com, create an account or use our proxy and server services, why we process it, on what legal basis, who receives it, and which rights you have. It is written to satisfy Articles 13 and 14 of the General Data Protection Regulation (GDPR) and the German Telecommunications Digital Services Data Protection Act (TDDDG).
1. Controller
The controller within the meaning of Art. 4 (7) GDPR is:
Sascha Wohlert, trading as seamless
Staffelstr. 3A, 94051 Hauzenberg, Germany
Email: hey@seamlessproxies.com
We are not required to appoint a data protection officer under Art. 37 GDPR or § 38 BDSG. Please address all data protection enquiries to the contact above.
2. Your rights
You have the following rights in relation to your data:
- Access (Art. 15 GDPR) — confirmation of whether we process your data and a copy of it.
- Rectification (Art. 16 GDPR) — correction of inaccurate or incomplete data.
- Erasure (Art. 17 GDPR) — deletion, unless statutory retention obligations apply.
- Restriction of processing (Art. 18 GDPR).
- Data portability (Art. 20 GDPR) — receipt of data you provided in a structured, machine-readable format.
- Withdrawal of consent (Art. 7 (3) GDPR) — at any time, with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before it.
- Complaint (Art. 77 GDPR) — see below.
To exercise any of these rights, contact us at hey@seamlessproxies.com. We will respond within one month.
Right to object (Art. 21 GDPR)
Where we process your personal data on the basis of our legitimate interests (Art. 6 (1) (f) GDPR), you have the right to object at any time, on grounds relating to your particular situation, to that processing. If you object, we will no longer process the data concerned unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
Where we process your personal data for direct marketing purposes, you have the right to object at any time without giving reasons. After such an objection we will no longer use your data for direct marketing. An objection is free of charge and can be sent informally to hey@seamlessproxies.com, or exercised via the unsubscribe link in every marketing email and in your email preferences.
3. Right to lodge a complaint
You may lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. The authority competent for us is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany
www.lda.bayern.de
4. What we process, why, and on what basis
4.1 Visiting the website (server log files)
Data: IP address, date and time of request, requested URL, referrer, HTTP status, transferred data volume, browser type and version, operating system.
Purpose: delivering the website, ensuring stability and security, defending against attacks and abuse.
Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest is the secure and reliable operation of the site.
Retention: log data is deleted or anonymised after 30 days at the latest, unless a specific incident requires longer storage as evidence.
4.2 Cookies and storage on your device
We store information on your device and read information from it. This requires your consent under § 25 (1) TDDDG, unless the storage or access is strictly necessary to provide a service you have expressly requested (§ 25 (2) TDDDG).
Strictly necessary (no consent required): session and authentication cookies (NextAuth), CSRF protection, your cookie choice itself, your light/dark theme preference, the Cloudflare Turnstile bot check on forms, and — where you arrive via a referral link — a short-lived referral cookie that stores only the referral code so we can attribute a later sign-up (§ 25 (2) TDDDG).
Consent-based: functional (live chat), analytics (Vercel Analytics / Speed Insights) and marketing categories as presented in our cookie banner. The marketing category is currently unused; no marketing cookies are set even if you enable it. Legal basis: § 25 (1) TDDDG in conjunction with Art. 6 (1) (a) GDPR.
You can change or withdraw your choice at any time via the cookie settings link in the footer, with effect for the future. You can also delete cookies in your browser at any time.
4.3 Reach and performance measurement
Data: anonymised or aggregated page views, referrer, device and browser category, approximate country, and page loading metrics (Core Web Vitals).
Provider: Vercel Analytics and Vercel Speed Insights. These services operate without cookies and do not build cross-site profiles.
Legal basis: your consent to the analytics category, Art. 6 (1) (a) GDPR in conjunction with § 25 (1) TDDDG.
4.4 Creating and operating an account
Data: email address, password (stored only as a bcrypt hash), verification status, account status, roles, notification preferences, referral code, acceptance of terms with timestamp and version, and — if you use social sign-in — your Google ID, name and profile picture, or your Discord ID and username.
Purpose: creating and managing your account, authenticating you, providing the dashboard.
Legal basis: Art. 6 (1) (b) GDPR (performance of the contract and pre-contractual steps).
Retention: for the duration of the account. After deletion, data is removed except where statutory retention obligations apply (see section 6).
4.5 Sign-in with Google or Discord
If you choose social sign-in, the respective provider tells us your user ID, email address and public profile information. The provider learns that you have signed in to our service. Using social sign-in is optional; you can always register with an email address and password instead.
If you link your Discord account, we can add you to our Discord community server with your consent (OAuth scope guilds.join) and use your Discord account to deliver certain products and notifications.
Legal basis: Art. 6 (1) (b) GDPR for account creation and delivery, Art. 6 (1) (a) GDPR for the optional community join. Google and Discord act as independent controllers for their own processing; see their respective privacy policies.
4.6 Orders, payments and invoices
Data: ordered products, prices, discount codes, billing address, country and VAT status, tax ID where provided, payment method, payment status, subscription and renewal data, invoice documents, account balance and transaction history.
Payment service providers: Stripe processes card and wallet payments and subscriptions; NOWPayments processes cryptocurrency payments. Your full payment credentials are entered directly with the payment provider and are never stored on our systems.
Legal basis: Art. 6 (1) (b) GDPR for performing the contract; Art. 6 (1) (c) GDPR for invoicing and accounting obligations under the German Commercial Code (HGB), the Fiscal Code (AO) and the VAT Act (UStG).
4.7 Fraud prevention and automated checks
Payments are screened for fraud indicators by Stripe, including Stripe Radar. This involves an automated evaluation of, among other things, IP address, device and browser characteristics, billing and location data and payment history, and can result in a payment being declined or an order being rejected.
Insofar as this constitutes a decision based solely on automated processing within the meaning of Art. 22 (1) GDPR, it is permitted under Art. 22 (2) (a) GDPR because it is necessary for entering into or performing the contract. You have the right to obtain human intervention, to express your point of view and to contest the decision — contact us at hey@seamlessproxies.com.
Legal basis: Art. 6 (1) (b) and (f) GDPR. Our legitimate interest is preventing payment fraud, chargeback abuse and misuse of our infrastructure.
4.8 Security activity log in your account
Data: logins, failed login attempts, password changes and comparable security-relevant actions, each with timestamp, IP address, browser and operating system and an approximate location derived from the IP address.
Purpose: allowing you to detect unauthorised access to your account, and protecting our systems against account takeover and abuse.
Recipient: the approximate location is resolved via the external service ip-api.com, which receives the IP address for that purpose.
Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest, and yours, is the security of the account.
4.9 Support, live chat and contact form
Data: the content of your message, your email address and nickname, and, if you are logged in, a pseudonymous token that links the conversation to your account so that your chat history is preserved. The contact form additionally processes your name and, optionally, your company.
Providers: Crisp IM SAS (live chat, France), Cloudflare Turnstile (spam and bot protection), Resend (email delivery).
Legal basis: Art. 6 (1) (b) GDPR where your request concerns a contract or its initiation, otherwise Art. 6 (1) (f) GDPR based on our legitimate interest in answering enquiries.
Retention: support conversations are deleted no later than two years after the last message, unless they are needed as evidence for a longer period.
4.10 Service and marketing emails
Service emails (email verification, password resets, order confirmations, invoices, expiry and renewal reminders, security alerts, low-balance notices) are part of the contractual relationship and are sent on the basis of Art. 6 (1) (b) GDPR.
Marketing emails about our own similar products and offers are sent to existing customers under § 7 (3) of the German Act Against Unfair Competition (UWG), with the corresponding processing based on Art. 6 (1) (f) GDPR. You can object at any time, free of charge, using the unsubscribe link in every email or in your account settings. Where we rely on a separate consent instead, the legal basis is Art. 6 (1) (a) GDPR.
Provider: Resend. Delivery data such as dispatch status is processed to operate the mailings.
4.11 Referral programme, giveaways and discount codes
Data: your referral code, referred accounts, qualifying purchases and credited rewards, plus entries and, where applicable, winner details for giveaways.
Purpose: operating and settling the referral programme, running giveaways and preventing abuse such as self-referral and multi-accounting.
Legal basis: Art. 6 (1) (b) GDPR for the performance of the participation relationship and Art. 6 (1) (f) GDPR for abuse prevention.
4.12 Providing the proxy and server services
Delivering the service requires us to process the credentials and configuration of your proxy accounts and servers, the assigned endpoints and locations, saved proxy generator configurations, volume data such as bandwidth consumed and remaining, bandwidth transfers between accounts where you initiate them, and — if you create them — residential sub-user credentials and share codes that grant limited access to bandwidth.
Confidentiality of communications: we observe the secrecy of telecommunications under § 3 TDDDG. We do not inspect the content of the traffic routed through our services beyond what is technically necessary to deliver it.
Traffic data: under § 9 TDDDG, traffic data is processed only to the extent required to establish and maintain the connection and to bill the service, and is erased without undue delay once it is no longer needed for those purposes. Volume figures needed for billing are retained for the statutory periods.
Anonymous use: in accordance with § 19 (2) TDDDG we inform you that the service can be paid for in cryptocurrency, which allows a largely pseudonymous payment route. An account with a valid email address remains necessary for the delivery and management of the service.
Legal basis: Art. 6 (1) (b) GDPR, and Art. 6 (1) (c) GDPR where we are legally obliged to provide information to competent authorities (for example under §§ 174 et seq. of the German Telecommunications Act).
4.13 Free tools (My IP, Proxy Tester)
My IP returns your public IP address and approximate connection metadata (user agent, country, region, city, language) derived from the current request. The response is generated on the fly and is not stored by us beyond ordinary server log retention (section 4.1).
Proxy Tester forwards the proxy list you submit (up to the published limit) to our self-operated test endpoint in Germany so connectivity can be checked. If your list contains credentials, those credentials are transmitted to that endpoint for the duration of the test. Do not submit credentials you are not authorised to use.
Legal basis: Art. 6 (1) (b) GDPR where the tool is used in connection with our services, otherwise Art. 6 (1) (f) GDPR based on our legitimate interest in providing the requested diagnostic function.
4.14 Short links
For branded short links we operate, we store the destination URL, creation metadata and an aggregated click counter with the time of the last click. We do not store the IP address, user agent or other identifiers of individual clickers for that purpose.
Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest is operating and measuring the short-link service.
4.15 Referral attribution cookie
If you visit the site with a valid referral parameter, we set an httpOnly cookie that stores only the referral code for up to 30 days so that a later registration can be attributed to the referrer. No advertising profile is built from this cookie.
Legal basis: § 25 (2) TDDDG (strictly necessary for a service you requested by following the referral link) in conjunction with Art. 6 (1) (b) / (f) GDPR.
5. Recipients
We only pass on personal data where this is necessary for the purposes described above. Service providers acting on our instructions are bound by a data processing agreement under Art. 28 GDPR.
| Recipient | Purpose | Location | Safeguard |
|---|---|---|---|
| Vercel Inc. | Website and application hosting, CDN, server log files | USA / EU | DPA, EU-U.S. Data Privacy Framework, SCCs |
| Vercel Analytics & Speed Insights | Aggregated, cookieless reach and performance measurement | USA / EU | DPA, EU-U.S. Data Privacy Framework, SCCs |
| Our database hosting provider | Operation of the application database (MongoDB) | European Union | DPA under Art. 28 GDPR |
| Stripe Payments Europe, Ltd. | Card and wallet payments, subscriptions, invoicing, tax and fraud checks | Ireland / USA | DPA, EU-U.S. Data Privacy Framework, SCCs |
| NOWPayments | Cryptocurrency payments and account top-ups | Outside the EU | DPA, SCCs |
| Crisp IM SAS | Live chat and support conversations | France | DPA under Art. 28 GDPR |
| Resend (Plus Five Five, Inc.) | Transactional and service emails | USA | DPA, EU-U.S. Data Privacy Framework, SCCs |
| Cloudflare, Inc. | Turnstile bot protection on sign-up and contact forms | USA / EU | DPA, EU-U.S. Data Privacy Framework, SCCs |
| Google Ireland Limited | Optional sign-in with Google (OAuth) | Ireland / USA | EU-U.S. Data Privacy Framework, SCCs |
| Discord Netherlands BV / Discord Inc. | Optional sign-in with Discord, community access, delivery notifications | Netherlands / USA | EU-U.S. Data Privacy Framework, SCCs |
| ip-api.com | Approximate location lookup for security activity entries | Outside the EU | SCCs |
| Network and hosting operators (as needed to deliver the ordered service) | Operation of endpoints, IP allocation and technical delivery of proxy/server access | EU and, where required for the chosen location, third countries | Art. 28 GDPR / SCCs where a processor relationship applies |
| proxy-test.seamlessproxies.com (self-operated) | Optional proxy connectivity tests you initiate | Germany (Falkenstein) | Self-operated infrastructure; TLS in transit |
| Tax advisor, auditors, authorities | Statutory accounting, tax and disclosure obligations | Germany | Legal obligation, professional secrecy |
6. Transfers to third countries
Some of the providers listed above are established in the United States or process data there. Transfers to the USA take place either on the basis of the European Commission's adequacy decision of 10 July 2023 for the EU-U.S. Data Privacy Framework, where the recipient is certified under that framework, or on the basis of Standard Contractual Clauses under Art. 46 (2) (c) GDPR together with supplementary measures.
Despite these safeguards, US authorities may under certain conditions access data held by US providers, and the legal remedies available to you may not correspond in every respect to those under EU law. A legal challenge to the adequacy decision is currently pending before the Court of Justice of the European Union. You may request a copy of the safeguards in place from us at any time.
7. Retention periods
We keep personal data only for as long as necessary for the purpose concerned, and thereafter only where a statutory retention obligation or the establishment, exercise or defence of legal claims requires it.
- Account data: for the term of the account; deleted or anonymised after closure, subject to the periods below.
- Invoices, orders and accounting records: 10 years under § 147 AO and § 257 HGB, calculated from the end of the calendar year in which the document was created.
- Commercial and business letters: 6 years under § 257 (1) no. 2 and (4) HGB.
- Server log files: maximum 30 days.
- Security activity entries: maximum 12 months.
- Support conversations: maximum 2 years after the last message.
- Marketing objections and suppression lists: kept for as long as necessary to honour your objection.
- Traffic data of the proxy service: erased without undue delay in accordance with § 9 TDDDG once no longer required for connection or billing purposes.
8. Is providing data mandatory?
You are not legally obliged to provide us with personal data. However, we need certain data to conclude and perform a contract with you — in particular an email address, and for paid orders billing and payment data required by tax law. Without this data we cannot create an account for you or provide the service.
9. Data security
We take appropriate technical and organisational measures under Art. 32 GDPR to protect your data, including:
- TLS encryption for all traffic to and from this site
- Passwords stored exclusively as salted bcrypt hashes
- Role-based access control and least-privilege access
- Bot and abuse protection on public forms
- Logging of security-relevant events
- Contractual commitments from our processors under Art. 28 GDPR
No method of transmission or storage is entirely secure. We keep our measures under review and adapt them to the state of the art.
10. Minors
Our services are directed at businesses and at consumers who have reached the age of majority. We do not knowingly process data of children. In Germany, consent by a child in relation to information society services is only valid from the age of 16 (Art. 8 (1) GDPR). If you believe that a minor has provided us with personal data, please contact us and we will delete it without undue delay.
11. Changes to this policy
We update this policy when our processing or the legal framework changes. The version published here always applies. For material changes affecting you we will inform you separately, for example by email.
Last updated: August 2026 (version 2026-08)
