Privacy Protection

Privacy Policy

Last Updated: February 19, 2026

GalePass deeply values privacy protection. This Privacy Policy explains how we collect, use, store, and protect your personal information. We are committed to complying with applicable privacy laws including PIPEDA (Personal Information Protection and Electronic Documents Act, Canada), GDPR (General Data Protection Regulation, European Union), and CCPA/CPRA (California Consumer Privacy Act / California Privacy Rights Act, USA).

Strict No-Log Policy

We do not log, store, or share with any third party your network activity, browsing history, traffic data, DNS queries, or connection logs.

1 Information We Collect

1.1 Account Information

  • Email address: For account creation, login verification, and important notifications
  • Password: Stored encrypted and hashed — we cannot see your plaintext password
  • Registration timestamp: For account management and statistics

1.2 Payment Information

  • Order details: Plan type, amount, and order timestamp
  • Payment processing: Handled by third-party platforms (Stripe, Alipay, WeChat Pay) — we do not store card numbers or payment credentials

1.3 Usage Data (Minimal Collection)

  • Traffic statistics: Total data usage only, used for billing and abuse prevention
  • Connection timestamps: Connect/disconnect times only — no content or destination records
  • Number of simultaneous devices: Used to enforce device limits

1.4 Device Information

  • Device type, OS version, app version: For technical support and device limit enforcement
  • Device fingerprint: For abuse prevention only

1.5 What We Do NOT Collect

  • Browsing history: The websites and pages you visit
  • Traffic content / payload: The data you transmit
  • DNS queries: The domain names you resolve
  • Connection logs / real IP during VPN use: Your true IP address and connection source
  • Specific server nodes used: Which VPN servers you connect to

2 How We Use Your Information

The limited information we collect is used solely for the following purposes:

  • Providing services: Account authentication, service access, and technical support
  • Billing management: Processing orders, calculating usage, and sending billing notifications
  • Abuse prevention: Detecting abnormal traffic patterns and preventing account sharing or service abuse
  • Service improvement: Anonymous statistical analysis to optimize server performance and user experience
  • Legal compliance: Responding to legal requirements in limited circumstances (see Section 6)

3 Data Storage and Protection

3.1 Storage

  • Account data is stored in secure data centers with multi-layer encryption and strict access controls
  • All data transmitted between your device and our servers uses TLS/SSL encryption

3.2 Security Measures

  • Data encryption: All sensitive data is encrypted at rest and in transit
  • Access controls: Strict employee access restrictions on user data
  • Regular audits: Periodic security audits and penetration testing
  • Automated backups: Regular backups to prevent data loss

3.3 Data Retention

  • Account information: Retained during account activity; deleted or anonymized within 30 days of account deletion
  • Order records: Retained 3–5 years per legal financial audit requirements
  • Traffic statistics: Reset monthly — no historical records kept
  • Session data: Access tokens expire in 2 hours; refresh tokens expire in 30 days

4 Third-Party Service Providers

To provide our services, we work with the following third-party providers:

Payment Processors

  • Stripe (international payments)
  • Alipay & WeChat Pay (China payments)
  • Each platform operates under its own privacy policy. We only receive payment confirmation — we never receive or store card details or payment credentials.

Cloud Storage

  • Cloudflare R2: Stores user avatar and profile images only

Authentication

  • Google OAuth 2.0: When you sign in with Google, only your email address, display name, and Google ID are collected

Email Service

  • An SMTP provider is used to send verification codes and notifications
  • Only your email address is transmitted — no other personal information is included

AI Assistant

  • Anthropic API powers our chat support feature. Messages you send may be processed by Anthropic's systems to generate responses.

Important: We do not sell, rent, or trade your personal information to any third party.

5 Cookies and Tracking Technologies

Our website uses the following categories of cookies:

  • Essential Cookies: Maintain login state and core functionality — these cannot be disabled
  • Functional Cookies: Remember your preferences such as language and theme settings
  • Analytics Cookies: Collect anonymous usage data to help us understand how the site is used

You can manage your cookie preferences via our Cookie Consent settings or through your browser settings. Disabling certain cookies may affect some site functionality.

6 Legal Disclosure

We may be required to disclose information in the following circumstances:

  • In response to a valid court order or subpoena
  • To comply with mandatory legal requirements
  • To protect the rights, property, or safety of GalePass, our users, or the public

Important: Due to our strict no-log policy, even if we receive a legal request, we cannot provide browsing history, traffic content, or connection logs — because we simply do not collect this information.

Where legally permitted, we will notify affected users of any legal requests we receive.

7 Your Rights

7.1 Rights Under GDPR (EU / EEA Residents)

  • Right of Access (Art. 15): Request a copy of the personal data we hold about you
  • Right to Rectification (Art. 16): Request correction of inaccurate or incomplete data
  • Right to Erasure / "Right to be Forgotten" (Art. 17): Request deletion of your personal data
  • Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format
  • Right to Object (Art. 21): Object to processing based on legitimate interests
  • Right to Restrict Processing (Art. 18): Request that we limit how we process your data

Legal bases for processing: Contract performance (account services), legitimate interests (abuse prevention and security), and legal obligation (financial records).

To exercise your GDPR rights, contact us at [email protected]. We respond within 30 days.

You also have the right to lodge a complaint with your local Data Protection Authority (DPA).

7.2 Rights Under CCPA / CPRA (California Residents)

  • Right to Know: What personal information we collect, use, disclose, share, or sell
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out: We do not sell or share personal information. See our Do Not Sell or Share My Personal Information page.
  • Right to Non-Discrimination: We will not discriminate against you for exercising these rights
  • Right to Correct: Request correction of inaccurate personal information

To exercise your CCPA rights, contact us at [email protected]. We respond within 45 days.

7.3 Rights Under PIPEDA (Canadian Residents)

  • Right to access your personal information held by us
  • Right to challenge the accuracy and completeness of your information
  • Right to withdraw consent, subject to legal and contractual restrictions
  • Right to complain to the Office of the Privacy Commissioner of Canada

8 Children's Privacy

Our services are intended for users aged 18 and older. We do not knowingly collect personal information from minors. If you believe a child has provided us with personal information, please contact us at [email protected] and we will promptly delete the relevant information.

9 International Data Transfers

GalePass is operated by GaleLink Inc., a Canadian company. Canada has been recognized by the European Commission as providing an adequate level of protection for personal data (adequacy decision), meaning transfers of personal data from the EU to Canada benefit from this protection without requiring additional safeguards.

If you are located in other countries, your data may be transferred to and stored in Canada or other countries where our service infrastructure operates. Regardless of where your data is stored, we apply the same protections described in this Privacy Policy.

10 Policy Updates

We may update this Privacy Policy periodically. When we do, we will post the new version on this page and update the "Last Updated" date. For significant changes, we will notify you via email or a site announcement. We recommend reviewing this policy periodically to stay informed about how we protect your information.

11 Contact Us

If you have any questions, concerns, or complaints about this Privacy Policy, or wish to exercise your privacy rights, please contact us through the following:

General support: [email protected]

Privacy officer: [email protected]

We respond to privacy requests within 15 business days (30 days for GDPR requests).

Our Commitment to Privacy

Protecting user privacy is a core value of GalePass. We maintain a strict no-log policy, advanced encryption, and comprehensive security measures to ensure your online activity remains private and secure. Your trust is our most valuable asset.