Purpose
This Privacy Policy explains how ASHVPN LTD may collect, use, store, share, and protect personal data when operating ASHVPN.
This policy should be read together with the Data & Logging Statement, Terms of Service, Acceptable Use Policy, Fair Use Policy, Refund & Cancellation Policy, Cookie Policy, and Abuse Reports and Contact page.
Who we are
ASHVPN is operated by ASHVPN LTD.
Company name: ASHVPN LTD
Company number: 17184685
Registered in: England and Wales
Registered office:
71-75 Shelton Street
Covent Garden
London
WC2H 9JQ
United Kingdom
Contact email: admin@ashvpn.com
VAT number: Not currently provided / not confirmed VAT registered.
Personal data ASHVPN may process
ASHVPN may process the following categories of personal data where needed:
- account email address;
- customer name, where provided;
- plan, access period, payment, and device-limit information;
- access start, access end, cancellation, expiry, suspension, or revocation status;
- payment processor metadata such as Stripe customer ID, checkout session ID, access or payment reference, price ID, receipt, invoice, or dispute reference;
- device slot and VPN configuration metadata such as slot number, location code, peer public key, assigned VPN IP address, configuration status, delivery status, replacement status, or revocation status;
- support messages and troubleshooting details supplied by the customer;
- abuse reports, legal notices, provider notices, payment disputes, security incident records, and investigation notes;
- email delivery and fulfilment records;
- limited technical and operational records needed to run, secure, support, and protect the service.
Why ASHVPN processes personal data
ASHVPN may process personal data for these purposes:
- creating and managing customer accounts;
- processing orders and access periods;
- providing VPN access;
- managing device slots and configuration delivery;
- sending service emails, setup information, reminders, support replies, and important notices;
- handling cancellations, refunds, billing questions, payment disputes, and chargebacks;
- providing customer support and troubleshooting;
- detecting, preventing, and responding to abuse, fraud, spam, malware, credential attacks, scraping abuse, platform abuse, piracy, unlawful activity, or security threats;
- protecting ASHVPN infrastructure, customers, providers, payment processors, and third parties;
- complying with legal, accounting, regulatory, provider, payment processor, or law-enforcement obligations where applicable;
- keeping internal records needed to operate the service safely and lawfully.
Lawful basis
Depending on the situation, ASHVPN may rely on one or more lawful bases for processing personal data, including:
- contract: where processing is needed to provide the service requested by the customer;
- legitimate interests: where processing is needed to operate, secure, support, improve, or protect ASHVPN, customers, providers, payment processors, and third parties;
- legal obligation: where processing is needed to meet legal, accounting, regulatory, tax, court, law-enforcement, or other legal obligations;
- consent: where ASHVPN specifically asks for consent for a particular optional use, such as certain non-essential cookies or marketing communications.
Payment processing
Payments are handled through Stripe or another approved payment processor.
ASHVPN may receive or store payment-related metadata needed for fulfilment, support, dispute handling, accounting, fraud prevention, and customer operations.
ASHVPN does not receive or store full payment card numbers, card security codes, or payment card passwords.
Payment processors may process personal data under their own terms and privacy notices.
VPN service and configuration data
To provide VPN access, ASHVPN may process device-slot and VPN configuration metadata.
This may include location code, peer public key, assigned VPN tunnel address, configuration status, delivery status, replacement status, revocation status, and related support information. This technical configuration data is used to provision, manage, replace, or revoke WireGuard access; it is not a record of the websites or content a customer visits.
ASHVPN does not require customers to send WireGuard private keys. Customers must not send private keys, passwords, one-time codes, or unrelated sensitive information to ASHVPN.
Operational, support, abuse, and security records
ASHVPN may keep records connected to support requests, abuse reports, legal notices, provider notices, payment disputes, security incidents, fulfilment events, and service-protection decisions.
These records may be needed to investigate issues, respond to customers, preserve evidence, protect the service, respond to payment processors, or meet legal or provider obligations.
Cookies and website tracking
ASHVPN may use cookies or similar technologies where needed for website operation, security, analytics, checkout, support, or customer experience.
ASHVPN does not use non-essential cookies or tracking unless the Cookie Policy and consent approach support that use.
More information should be provided in the Cookie Policy.
Sharing personal data
ASHVPN may share relevant personal data where needed with:
- payment processors;
- hosting and infrastructure providers;
- email delivery providers;
- domain, DNS, website, security, or monitoring providers;
- professional advisers such as accountants, legal advisers, or compliance advisers;
- regulators, courts, law-enforcement bodies, or public authorities where legally required or appropriate;
- third parties where needed to investigate abuse, fraud, payment disputes, legal claims, or security incidents.
ASHVPN does not sell customer personal data.
International processing
Some providers used by ASHVPN may process data outside the United Kingdom.
Where this happens, ASHVPN uses appropriate safeguards required by applicable data-protection law to protect your data.
Retention
ASHVPN keeps personal data only for as long as reasonably needed for the purpose for which it is processed.
Retention periods may depend on service operation, customer support, accounting, tax, fraud prevention, abuse handling, security, legal claims, payment disputes, provider obligations, and legal compliance.
Retention is managed in line with the Data & Logging Statement, Cookie Policy, Terms of Service, accounting requirements, provider requirements, and applicable legal obligations.
Customer rights
Depending on applicable law and circumstances, customers may have rights relating to their personal data, including rights to:
- access personal data;
- correct inaccurate personal data;
- request deletion;
- restrict processing;
- object to processing;
- request portability;
- withdraw consent where processing is based on consent;
- complain to a data-protection authority.
These rights may be subject to legal limits, identity checks, fraud prevention, security, accounting, legal claims, abuse handling, or other lawful grounds.
Requests should be sent to admin@ashvpn.com.
Security
ASHVPN aims to use reasonable technical and organisational measures to protect personal data.
No internet service can guarantee absolute security.
Customers should keep account emails, devices, passwords, and VPN configuration files secure and should contact ASHVPN promptly if they believe their access has been misused.
Children
ASHVPN is not intended for children.
Customers must not use ASHVPN to exploit, harm, contact, target, or process data about children unlawfully.
Changes to this policy
ASHVPN may update this Privacy Policy as the service, providers, legal requirements, or operational processes change.
Material changes should be reflected on the ASHVPN website or communicated where appropriate.
Contact
Privacy questions, rights requests, support questions, refund/cancellation requests, abuse reports, or legal notices should be sent to admin@ashvpn.com.