Privacy Policy

Privacy Policy

1. Who we are

This website and the Aeria VPN service are operated by the publisher of aeria-vpn.com. Contact: contact@aeria-vpn.com.

2. Data we collect

  • Account data: email, first and last name, phone number, chosen language.
  • Payment data: handled by Stripe (card details never transit or are stored on our servers). We keep a record of plans, amounts, dates and statuses.
  • Technical data: server logs limited to operations (no browsing logs).
  • Contact messages: the data you send us via the contact form.
  • Conversion tracking: when you arrive from a Reddit or Facebook ad, we capture the click identifier (rdt_cid / fbclid) to attribute conversions to the correct ad. On purchase, we send a hashed version of your email and the transaction value to the Reddit Conversions API (CAPI) and the Meta Conversions API, so conversions are attributed even if the pixel is blocked.

3. Why we collect it

To provide the service (account, payment, VPN provisioning), to communicate with you (support, transactional emails), and to meet legal obligations (billing, tax).

4. No logs of your browsing

We do not log or store your browsing history, connection destinations or visited sites. Your VPN traffic is not retained.

5. VPN network policy (Zero-Log, RAM-only)

Our VPN network operates under a strict Zero-Log Policy: no connection logs, no source IP assigned to the server, no session timestamps, no DNS queries and no browsing history are ever recorded or kept.

All VPN servers run exclusively in RAM (RAM-only mode): no data is ever written to a hard drive, and everything is wiped on each reboot. There is therefore nothing to retain, expose or hand over — by design.

As the publisher of the service, we do not receive any browsing data from the VPN network, and our technical partner (SpiderSilk Limited, see below) has no way to link VPN activity to your identity.

6. Account data and legal retention (12 months)

Separate from VPN traffic, and to comply with the French LCEN law (art. 6-II), we keep access logs related to your account management for 12 months: registration/login/payment IP address, email address and transaction timestamps. These logs are automatically deleted after 365 days and are never used to trace your VPN browsing.

Your VPN credentials are strictly pseudonymous: they are generated and managed independently of your identity, and are completely disconnected from your real identity at the network infrastructure level.

7. GDPR compliance and sub-processor relationship (DPA)

Aeria VPN acts as the data controller for subscription management and authentication. SpiderSilk Limited acts as a technical sub-processor for routing network traffic in volatile memory (RAM-only).

We guarantee that no identifying personal data (name, email, address, banking details) is ever transmitted to the VPN infrastructure. Only anonymous tokens/API keys are exchanged.

8. Sharing

We share data only with our processors (Stripe for payments, Supabase for hosting, Brevo for transactional emails, our VPN provider) and only to provide the service. We never sell your data.

9. Your rights (GDPR)

You may access, rectify, delete or port your data, and object to its processing. Contact us at contact@aeria-vpn.com. You may also file a complaint with your local data protection authority.

10. Cookies

See our cookie policy for details on the cookies we use.