IVPN
IVPN is a virtual private network service offered by the Gibraltar-based company Privatus Limited.
Score
Notes
No information mentioning such
Even if there is a reasonable delay before the data is fully deleted (as is common), the data still counts as "permanently deleted" and satisfies the parameters for this question.
Score
Citation
When a VPN account is terminated on our network due to the subscription ending, non-payment or for any other reason, all data associated with that VPN account including the account itself is deleted from all systems.
We do not delete our customer's client area account which includes the email address and password which they use to sign up for their account.
However if you wish you can simply request deletion of your client area account by submitting a ticket to our billing department.
This may come in the form of outright data sharing or by using local third-party analytics software (such as Google Analytics, which collects a plethora of user information).
Note that whether the policy allows sharing aggregated user data does not affect this question.
If the personal data is encrypted when it passes through the third-party, it does not count as third-party access (as the data is inaccessible to that party).
If personal data has been made public by, for example, posting it to a blog, it does not count as private personal information (and is therefore not considered by this question).
Score
Citation
Some payment information may be related to your account, for example, if PayPal is used a PayPal transaction ID with be associated with your account, as well as a subscription ID should you set up a PayPal subscription.
[...]
For credit card payments, we use Braintree as our payment processor, and store a Braintree transaction ID against your account. If you elect to enable auto-renew for card payments, a subscription ID will also be stored.
[...]
IVPN have selected Piwik as their web analytics platform.
[...]
Piwik is open source software that is hosted on our own server infrastructure to ensure your privacy[...].
Notes
Piwik is, presumably, hosted under https://stats.ivpn.net (according to NoScript logging)
Score
Citation
The company is incorporated in Gibraltar. If a court order is received from a recognised legal authority with jurisdiction over IVPN then the company will comply with that order. However, the company cannot be compelled to hand over information which it does not have. When a customer signs up we request the minimum information possible, a valid email address. If it ever becomes required by law for us to keep a persistent log of our customers connections or any personal data relating to their network activity, we will immediately notify our customers and do everything in our power to move jurisdictions or close the service to protect those who entrust their privacy to us.
Score
Citation
IVPN is subject to EU law and is in compliance with the EU Data Protection Directive (Directive 95/46/EC), which prohibits companies transferring data to overseas jurisdictions with weaker privacy laws. IVPN will not locate servers in countries where it's forced to break this compliance. Due to the nature of our logging practices VPN servers do not contain any personally identifiable information and thus, if seized, could not be used to identify users.
No 3rd parties have access to any of your data. We always use 1st or 3rd party tools we can host on our own servers in a protected and secure environment.
Notes
An audit by Cure53 happened 2020-01-23 (https://www.ivpn.net/blog/independent-security-audit-concluded/)
Score
Notes
No date or changelog
Note that all companies operating in the EU are subject to Art. 33 of the GDPR, which requires companies to notify their data protection authority of a data breach within 72 hours of discovering it.
Score
Notes
There is no mention of alerting a user due to breach
Score
Citation
IVPN reserves the right to change this privacy policy at any time. In such cases, we will take every reasonable step to ensure that these changes are brought to your attention by posting all changes prominently on the IVPN web site for a reasonable period of time, before the new policy becomes effective as well as emailing our existing customers.
This includes the use of data brokers and independent verification authorities (such as background check providers).
Score
Notes
No data is fetched from third parties.
Score
Citation
To create an IVPN account you need only provide an email address. That address is used to facilitate password resets and to send important security updates relating to our service. Should you wish to opt out of email communication please contact out support team to be removed from our mailing list. You're free to use any email address, disposable or permanent. Your email address will be associated with an IVPN ID, an internal ID used to manage your account.
We don't require any other personally identifiable information should you use more anonymous payment methods such as cash or cryptocurrency.
Each account also carries a subscription expiry date so we can manage both trial period expiry and re-subscription.
[...]
Some payment information may be related to your account, for example, if PayPal is used a PayPal transaction ID with be associated with your account, as well as a subscription ID should you set up a PayPal subscription.
For credit card payments, we use Braintree as our payment processor, and store a Braintree transaction ID against your account. If you elect to enable auto-renew for card payments, a subscription ID will also be stored.
In order to process your payment Braintree and PayPal will request additional information. Braintree requires collection of your card details to process your payment, and PayPal will require name, email and address information to create a new PayPal account as well as agreement to their terms of service. These additional datapoints are not stored by IVPN, though Braintree and PayPal are required to retain them for many years. In addition, no 3rd party payment provider has access to your IVPN ID.
In short, where we can offer anonymous payment methods we will, and we collect as little information as possible to process them. However centralised or 3rd party payment systems and their data processing and storage are out of our control.
Please select cash or cryptocurrency payments should this be of concern.
Some services allow users to opt-out or opt-in to of non-critical collection or use of personal data, such as collecting data for personalized advertisements.
Score
Citation
Should you wish to opt out of email communication please contact out support team to be removed from our mailing list.
On our mobile apps, you can opt-out of crash log reporting by disabling it in user preferences.
Score
Citation
o create an IVPN account you need only provide an email address. That address is used to facilitate password resets and to send important security updates relating to our service. Should you wish to opt out of email communication please contact out support team to be removed from our mailing list. You're free to use any email address, disposable or permanent. Your email address will be associated with an IVPN ID, an internal ID used to manage your account.
We don't require any other personally identifiable information should you use more anonymous payment methods such as cash or cryptocurrency.
Each account also carries a subscription expiry date so we can manage both trial period expiry and re-subscription.
Some payment information may be related to your account, for example, if PayPal is used a PayPal transaction ID with be associated with your account, as well as a subscription ID should you set up a PayPal subscription.
For credit card payments, we use Braintree as our payment processor, and store a Braintree transaction ID against your account. If you elect to enable auto-renew for card payments, a subscription ID will also be stored.
In order to process your payment Braintree and PayPal will request additional information. Braintree requires collection of your card details to process your payment, and PayPal will require name, email and address information to create a new PayPal account as well as agreement to their terms of service. These additional datapoints are not stored by IVPN, though Braintree and PayPal are required to retain them for many years. In addition, no 3rd party payment provider has access to your IVPN ID.
In short, where we can offer anonymous payment methods we will, and we collect as little information as possible to process them. However centralised or 3rd party payment systems and their data processing and storage are out of our control.
Last Updated
June 24, 2020
Sources
Contributors