Privacy Statement MenaVPN
Privacy Policy of MenaVPN
Last updated: 15 October 2025
MenaVPN (“we”, “us”, “our”) is committed to protecting your privacy and maintaining your trust.
This policy explains what data we collect, how we use it, and your rights.
It applies to visitors of menavpn1.com and users of our VPN services (“Service”).
1. Summary of Our Privacy Commitments
- No activity or connection logs. We do not record browsing history, DNS queries, IP addresses, timestamps, or session durations.
- Minimal data only. We collect only what is required to operate and support our website and VPN service.
- Data segregation. Website analytics and support data are kept separate from VPN systems.
- Transparent third parties. All external providers operate under strict Data Processing Agreements (DPAs).
- User control. You can correct, or delete your data at any time by emailing [email protected].
2. Data We Collect
2.1 VPN Service Data
We do not log or monitor your online activity.
We do not collect:
- Browsing history or content of traffic
- DNS requests or destination IPs
- Connection timestamps, session durations, or source IPs
We may collect minimal operational data, such as aggregated server load, anonymous diagnostic logs (if you consent), and payment confirmation data.
This data is anonymous and stored separately from any account information.
2.2 Website Visitor Data
When you visit menavpn1.com, we use several third-party tools to operate, secure, and improve our website and marketing performance.
These tools collect limited data for analytics, performance optimization, and affiliate attribution — never linked to VPN usage or activity.
- Google Analytics 4: Collects anonymized usage metrics and aggregated visitor data; IP anonymized (retained 14 months).
- Microsoft Clarity: Tracks user interactions (clicks, scrolls) in aggregated form to improve UX (retained 6 months).
- Google reCAPTCHA: Detects spam and bot activity in real time for forms and login protection.
- Cloudflare: Provides CDN caching and DDoS protection; temporary request logs held ≤24h unless flagged for abuse.
- Meta Pixel (Facebook Pixel): Helps measure marketing campaign performance and conversions.
- Data is pseudonymized and never combined with VPN service usage.
- You can opt out via your browser or Facebook Ads preferences.
- Affiliate tracking (Click ID): When you arrive via an affiliate link, we share a unique click ID with the affiliate partner to verify legitimate referrals and commissions.
- This identifier does not reveal personal browsing or VPN activity.
- Stored only as long as necessary for affiliate validation and fraud prevention.
- YouTube (Privacy Enhanced Mode): Loads videos only when you click “Play”; YouTube may set cookies at that time.
- Google Tag Manager: Loads and manages analytics tags; does not collect user data itself.
All processors act under signed Data Processing Agreements (DPAs) and are restricted from using data for their own profiling or advertising outside MenaVPN’s instructions.
2.3 Account & Payment Data
If you subscribe to MenaVPN or contact us for support, we collect and process limited account information to manage your subscription and provide customer assistance.
We collect:
- Your email address (for login, receipts, and support)
- Subscription details such as plan type, renewal dates, and payment status
- Purchase metadata and receipts from our payment processors to verify transactions and provide refunds or support
We do not store full payment card details or sensitive billing data on our servers.
All payment processing is securely handled by our trusted partners:
- RevenueCat: Manages app subscriptions, in-app purchases, and entitlement validation. Receives a pseudonymous user identifier, purchase receipts, and basic device data to confirm your subscription.
- App Store / Google Play (In-App Purchase): If you subscribe through our mobile apps, Apple or Google process your payment and billing information directly, under their own privacy policies.
- Stripe: Handles web-based payments and billing securely on our behalf. Stripe processes payment method details and transaction IDs.
- Stripe’s privacy policy: stripe.com/privacy
We store limited receipt records (e.g., transaction ID, amount, and timestamp) in our secure database to confirm payment status, provide support, and handle refunds.
These records do not contain card numbers or sensitive billing information.
All stored receipts are protected by encryption and restricted access.
None of our payment or subscription partners have access to any VPN traffic or browsing data.
3. Legal Bases for Processing
We process data under these bases:
- Performance of a contract (to deliver VPN service)
- Your consent (for analytics cookies or marketing)
- Legitimate interest (security, performance)
- Legal obligation (billing, tax, fraud prevention)
4. Data Retention
We keep data only as long as needed for operational, legal, and security purposes.
- VPN diagnostics: We do not log browsing activity, traffic content, or DNS data.
However, we sometimes monitor anonymous connection statistics (for example, number of active sessions per server or overall service load) to measure quality and stability.
This information is aggregated, non-identifiable, and used only for network optimization.
- Website analytics (Google Analytics, Clarity, Pixel): Data is retained indefinitely in our analytics accounts to measure performance and improve our services.
These analytics datasets are pseudonymized and not linked to VPN user activity.
- Support chats Messages and support history are retained to improve customer service and maintain continuity in ongoing support.
You can request deletion of your support history at any time by contacting [email protected].
- Billing and receipt records: We keep transaction receipts and purchase confirmations for accounting, refund, and fraud-prevention purposes as long as your account remains active and for a reasonable period afterward.
- Backups: We maintain regular encrypted backups of our systems for data integrity and disaster recovery.
These backups are stored securely and rotated periodically but may contain older data until overwritten.
We do not retain or log VPN session data, browsing activity, or traffic destinations.
5. Data Sharing & Transfers
We do not sell, rent, or trade any personal data.
MenaVPN is built on a strict no-logs architecture.
We do not collect or store activity logs, connection timestamps, source IP addresses, or traffic data.
As a result, we have no identifiable user data to share, even if requested by legal authorities.
We only use a few authorized processors (such as RevenueCat, Stripe, Cloudflare, Google Analytics) to operate our services.
These partners handle limited technical or billing data strictly under signed Data Processing Agreements (DPAs) and are not permitted to use it for their own purposes.
We do not disclose or provide user data to any government, law enforcement, or third party because we simply do not possess activity logs or identifiable VPN session information.
Cross-border transfers (for example, between our EU and non-EU infrastructure or to third-party processors) are protected using GDPR Standard Contractual Clauses (SCCs) or equivalent safeguards.
6. Your Rights
Because MenaVPN operates on a strict no-logs policy, we do not hold identifiable VPN usage data.
This means we generally have no personal activity data to access, export, or delete.
However, you still have the following rights regarding any personal information we may process (for example, your email, subscription details, or support messages):
- Access and correction: You can ask us to confirm what personal data we hold (if any) and request corrections.
- Deletion (“right to be forgotten”): You can request deletion of account or support data that we control, such as your email or chat history.
- Restriction or objection: You may ask us to limit certain processing activities, like marketing communications.
- Data portability: Where applicable, you may request a copy of your account-related data in a portable format.
To exercise any of these rights, contact [email protected].
We respond within 30 days of verified requests.
If we cannot identify you in our systems because no personal data is stored, we will explain this clearly in our response.
7. Cookies & Consent
We use cookies and similar technologies to help our website function, analyze performance, and measure marketing campaigns.
When you first visit our site, a consent banner allows you to accept or reject non-essential cookies.
You can also change your preferences at any time through your browser settings or our cookie banner.
Cookie types we use:
-
Necessary:
These cookies are essential for the website to operate securely and correctly.
Examples: Cloudflare (for CDN and DDoS protection) and Google reCAPTCHA (to prevent spam or bot abuse).
-
Analytics:
Used to understand how visitors interact with our site.
Examples: Google Analytics 4 (with IP anonymization) and Microsoft Clarity (for aggregated UX insights).
-
Marketing:
Used to measure ad performance and affiliate referrals.
Examples:
- Meta Pixel (Facebook Pixel): Tracks conversions and helps us measure marketing effectiveness.
- Affiliate tracking cookies: Store a temporary click ID when you visit from an affiliate link, allowing us to verify referrals and commissions.
These IDs are pseudonymous and never linked to VPN usage or personal browsing activity.
You can opt out of analytics and marketing cookies by rejecting them in the cookie banner or adjusting your browser’s cookie settings.
8. Security Measures
We take security seriously and apply multiple layers of protection to safeguard our systems and user information.
- End-to-end encrypted VPN tunnels for all VPN traffic
- TLS 1.3 encryption for all website communications
- Strict access controls and least-privilege permissions for staff
- Regular security scans and internal reviews to detect vulnerabilities
- Data minimization and anonymization wherever possible
We continuously monitor our infrastructure and may engage independent security assessments in the future as part of our ongoing security program.
9. Children’s Privacy
Our services are not directed to children under 16.
We do not knowingly collect personal data from minors.
If you believe a minor has provided data, please contact us to remove it.
10. Policy Updates
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons.
The latest version is always available at https://menavpn1.com/privacy-policy.
If we make a significant change in how we collect or use personal data, we will post a clear notice on our website or within our app before the changes take effect.
Minor edits or clarifications may be made without additional notice.
11. Contact
MenaVPN Privacy Office
Email: [email protected]
Address: (Insert your company’s registered address)
For EU users, our EU representative can be reached at the same address.