PRIVACY POLICY
Privacy Policy
Last updated: August 2026
This policy explains what information 40VPN processes when providing subscription services, international route connections, and user panel features, why it is processed, and how users can manage it. Using the service means you have read this policy; if you disagree with these practices, stop using the relevant features.
Collection Scope and Processing Purposes
Registration requires no email address and can be completed with a username and password, so the service does not make an email address a required registration field. The system processes usernames, account status, and necessary authentication information for login, account security, and subscription delivery. Text, screenshots, or other materials that users voluntarily provide in tickets are used only to handle the relevant request.
When an order is completed, the system stores the order identifier, selected plan, amount, payment method, payment status, and refund status to confirm entitlements, handle billing disputes, and apply the refund rules. The website also collects analytics such as page visits, referring pages, browser type, device category, and basic network information to identify page issues, assess content availability, and prevent abnormal requests. Analytics are not used to build profiles of the content users access.
No-Logs Position and Connection Data
40VPN does not record which websites users access through international routes, retain browsing content, transmitted content, or detailed network request history, or create personal browsing profiles from connection activity. Account status, plan traffic usage, and route resource scheduling information required to operate the service are handled separately from specific access content.
Routine connection diagnostic information is not retained as a long-term record by default. When a connection issue occurs, users may voluntarily submit client messages, the time of occurrence, and the selected route for troubleshooting; these materials are handled only with the relevant ticket and enter the cleanup process after troubleshooting is complete. Minimal records needed for service security incidents are used only to identify abnormal requests and maintain account and route stability, not to analyze browsing content.
Cookies and Local Storage
The website may use Cookies or browser local storage to save login sessions, language preferences, interface state, and necessary security markers. This data maintains the user panel login state, restores page selections, and reduces repeated actions. After necessary storage is disabled, login, plan management, or client download links may not retain their state correctly.
Markers needed for analytics distinguish repeat visits and help assess how pages operate. Data that can be used in aggregate is prioritized for aggregation, and original identifiers are not used for cross-site advertising tracking. Users can clear Cookies and local storage through browser settings; after clearing them, they will need to log in again and reselect relevant preferences.
Payment Processing and Third-Party Services
The service supports Alipay / WeChat / USDT. Payment confirmation is handled by the relevant payment service, and payment credentials and payment account details are governed by that service's rules. 40VPN receives only the payment result, transaction identifier, and status information required to complete an order, and does not require users to submit complete payment credentials on marketing pages.
Third-party payment services may process transaction information under their own privacy policies. Users should review the relevant service's rules before choosing a payment method. 40VPN does not expand the purposes for using transaction information because it connects to payment processing; order data is used only to deliver subscriptions, reconcile accounts, handle risks, and apply the provision allowing a full, no-reason refund within 60 days after the first payment.
Data Retention, Deletion, and Policy Updates
Account information is retained while the account remains active to maintain login access and subscription entitlements. Order records are retained as needed to complete transactions, process refunds, reconcile accounts, and meet applicable requirements; identifiable information in analytics is reduced after aggregation. Ticket materials enter the cleanup process after issue handling and any necessary review are complete.
Users can log in to the user panel and submit a ticket to request access to, correction of, or deletion of data associated with their account. After verifying a deletion request, information no longer necessary for service delivery, billing, security, or compliance will be processed for deletion. Aggregated results that can no longer be linked to a specific account are not recoverable account information.
This policy may be updated when service features, payment processes, or data handling practices change. The updated version will be published on this page, and the last-updated date at the top will be revised. If a change significantly affects the scope of data processing, the website will provide notice through a method suitable for the current service process; users should review the updated content before continuing to use the relevant features.