This Privacy Policy explains what data Nodetonet collects, why, and what we do with it.
1. Data we collect
- Account data — email, hashed password, username, role.
- Billing data — Stripe customer id, masked card last-4 and expiry (Stripe holds the full PAN; we never see it), balance, transaction history.
- Operational data — proxies you create, tokens you generate, IP / domain restrictions you configure, traffic byte counters per tunnel.
- Connection metadata — source IP + timestamp + target host of connections through your tunnels, retained for 30 days for abuse / debugging purposes.
- Server logs — request paths, HTTP status, response time, requesting IP. Retained 14 days.
We do NOT log the contents of tunneled traffic.
2. Why we collect it
- To operate the service — match users to their tunnels, run health checks, deliver email.
- To bill correctly — match payments to accounts, prevent fraudulent chargebacks.
- To respond to abuse reports.
- To improve the product (aggregate stats only — never user-identifying).
3. Sharing
We don't sell your data. We share it with these processors only as needed:
- Stripe — payments. Subject to their privacy policy.
- Cloudflare — DNS + edge caching. Subject to their privacy policy.
- Email provider — for transactional email only.
- Law enforcement — only on receipt of a valid, properly-served legal request.
4. Where it lives
Primary data store is in the EU. Stripe stores cardholder data in the US under SCC. Cloudflare uses its global edge network.
5. Your rights
- Access — request a copy of your data.
- Correction — edit your account profile directly, or email us.
- Deletion — delete your account and we erase identifying data within 30 days. Some records (billing, abuse) may be retained as long as legally required.
- Portability — export your data in JSON via the API.
- Opt-out — turn off non-essential email in account settings.
Send requests to privacy@nodetonet.com.
6. Cookies
We use a single session cookie (connect.sid) to keep you logged in. No tracking cookies, no third-party analytics in the panel. The public marketing site may use a privacy-friendly analytics service in the future — we will update this page if that changes.
7. Security
Passwords are bcrypt-hashed. Cards are tokenised — we never see the full number. API keys are stored in plaintext but readable only by the owner. Internal admin access is audit-logged.
8. Children
Nodetonet is not intended for children under 13. We don't knowingly collect data from them. If you believe a child has created an account, email us and we'll delete it.
9. Contact
Privacy questions: privacy@nodetonet.com.