LAST UPDATED 13 SEPTEMBER 2026
Privacy Notice
This notice explains how CocoaVPN processes personal data when you visit the website, create an account, pay for a subscription, or use the VPN service.
Controller
CocoaVPN
Address required before launch
Privacy contact required before launch
CocoaVPN is the data controller for account and VPN-service data. Stripe or its Managed Payments provider acts as merchant of record and handles payment data under its own privacy terms.
Data we process
- Account: email address, salted password hash, verification status, and hashed session tokens.
- Subscription: Stripe customer, subscription and invoice references; plan; payment status; and paid period. CocoaVPN does not receive full card details.
- VPN service: client and subscription identifiers, upload and download totals, allowance, expiry, device model, operating system, user agent, hashed device identifier, first and last seen times, and technical connection logs needed to operate and secure the service.
- Support and rights requests: your messages, request type, and response history.
Why we process it
| Purpose | Legal basis |
|---|---|
| Create and secure your account; provide, limit, renew, and pause VPN access. | Performance of our contract. |
| Process subscriptions, invoices, fraud checks, and tax records. | Contract and legal obligations. |
| Prevent abuse, protect accounts, troubleshoot failures, and keep the service reliable. | Our legitimate interests in operating a secure service. |
| Send verification, password-reset, payment, and service messages. | Contract and legitimate interests. We do not use these for marketing. |
Recipients and international transfers
Data is shared only as needed with Stripe/Managed Payments, the VPS hosting provider, the transactional email provider, and professional advisers or authorities where legally required. Some providers may process data outside Switzerland or the EEA. Before launch, list the actual providers, destination countries, and applicable safeguards such as adequacy decisions or standard contractual clauses.
Retention
- Account and VPN configuration: while the account is active, then deleted or anonymised within 30 days after a valid deletion request unless retention is required.
- Session tokens: up to 7 days. Verification tokens: 24 hours. Password-reset tokens: 1 hour.
- Device registrations and operational logs: normally 30 days after removal or collection, unless needed to investigate abuse or security incidents.
- Invoices and records required by tax or accounting law: up to 10 years after the relevant financial year.
- Rights requests: up to 3 years after closure to demonstrate compliance.
Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, objection, or portability. You may complain to the Swiss Federal Data Protection and Information Commissioner or your local EU/EEA supervisory authority. We normally respond within one month. Identity verification may be required.
Cookies
CocoaVPN uses one strictly necessary, HTTP-only session cookie named cocoa_session. It lasts up to 7 days and is used only to keep you signed in. There are no advertising, analytics, or cross-site tracking cookies, so no optional-cookie banner is shown.
Automated actions
The service automatically pauses VPN access when the paid period or data allowance ends, and restores it after successful payment. This is necessary to perform the subscription contract. Contact support to ask for a human review.
Security and VPN limits
Passwords are stored as salted hashes and service secrets stay on the server. A VPN protects traffic between your device and the VPN server. It does not make you anonymous, prevent all tracking, or protect activity after it leaves the VPN server.