1. Who we are
This Privacy Policy explains how Floppydata ("Floppydata", "we", "us", or "our") collects, uses, shares, and protects personal data when you visit floppydata.com, use the dashboard at app.floppydata.com, use our proxy and data-access services, or communicate with us (together, the "Service").
Floppydata is operated by FLOPPYDATA – FZCO, Building A1, Dubai Digital Park, Dubai Silicon Oasis, Dubai, UAE. Certain commercial, contracting, licensing, or billing operations may also be carried out by Scalehat LLC, 4291 S. Tamiami Trail, 1063, Venice, FL 34293, United States.
Depending on how you interact with the Service and which entity is named on your order, invoice, or checkout page, FLOPPYDATA – FZCO and/or Scalehat LLC acts as the data controller of your personal data. Where both entities process the same data for the same purpose, they act as joint controllers and you may exercise your rights against either of them using the contact details in Section 12.
2. Who this policy applies to
This policy applies to everyone whose personal data we process in connection with the Service: visitors to our website, registered users, representatives of business customers, and people who contact us. It does not apply to the content you route through our proxy infrastructure, which we do not inspect except as described in Section 4(g), nor to the practices of third-party websites you access through the Service.
Our Service is not intended for anyone under 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, contact us and we will delete it.
3. What data we collect
3.1 Account data
When you register, we collect your email address, password (stored in hashed form), and the account settings you choose. If you register or pay as a business, we may also collect the company name, registration or tax number, billing address, and the name and role of the person acting for the company.
3.2 Transaction and Balance data
When you buy a product, top up your prepaid Account Balance, or use a feature that charges your Balance, we record:
- the amount, currency, date and time, and type of each transaction (top-up, purchase, refund, reversal, adjustment);
- the payment method used (for example "card", "PayPal", "cryptocurrency") and the transaction or invoice identifier assigned by the payment provider;
- the running Balance of your account, recorded in whole US cents, and the full history of movements that make it up;
- the products, quantities, and configurations purchased, and the settings you choose for automatic top-up or renewals;
- for refund, reversal, or chargeback events, the reason category and the outcome;
- for manual adjustments made by our support team, an internal reason recorded in our audit log.
We do not collect or store full payment card numbers, card security codes, or bank account details. These are entered directly with the payment provider. For cryptocurrency payments, we may receive the sending wallet address and transaction hash from the provider.
Your transaction history is visible to you in the dashboard. Because it is a financial record, we retain it after your account is closed, as described in Section 8.
3.3 Verification data
Where we ask you to verify your identity or business (for example, before a high-value top-up, a refund, or where account activity looks unusual), we may collect identity document details, a photo or video, proof of address, or company documents. Where we use a third-party verification provider, the documents are processed by that provider and we receive the result and limited verification data. We do not use verification data for any purpose other than verification, fraud prevention, and compliance.
3.4 Usage and technical data
When you use the Service we automatically collect: IP addresses, device and browser information, operating system, language, time zone, referring pages, pages visited and actions taken in the dashboard, login dates and times, API calls, and error and performance data. When you use our proxy infrastructure we record connection metadata needed to operate, meter, and secure the network — such as timestamps, bytes transferred, the proxy endpoint and port used, the target domain, and the exit country — but not the content of your traffic.
3.5 Communications
When you contact support, join our Telegram community, or reply to our emails, we collect the content of the messages, attachments you send, and related metadata. Please do not send payment card details or identity documents through support channels unless we ask you to.
3.6 Cookies and similar technologies
We use cookies and similar technologies on our website and dashboard as described in our Cookie Policy at floppydata.com/cookie-policy.
3.7 Data from other sources
We may receive data about you from payment providers (payment confirmations, fraud signals, dispute notices), fraud-prevention and sanctions-screening services, analytics providers, and affiliate or referral partners when you arrive through a referral link.
4. Why we use your data and on what legal basis
We use personal data for the following purposes. Where the law requires a legal basis, we rely on the one indicated.
a) Providing the Service — creating and managing your account, delivering proxies and data-access products, crediting and debiting your Account Balance, running automatic top-ups and renewals, showing you your transaction history, and providing support. Basis: performance of our contract with you.
b) Payments, invoicing, and refunds — processing payments through our providers, issuing invoices and receipts, handling refunds, reversals, and chargebacks, and recovering amounts you owe. Basis: performance of our contract; compliance with accounting and tax law.
c) Fraud prevention, security, and abuse detection — screening payments and top-ups, detecting stolen payment instruments, chargeback abuse, duplicate accounts, and misuse of the Service, and verifying identity where needed. Basis: our legitimate interest in protecting the Service, our payment partners, and other users; compliance with anti-fraud and anti-money-laundering obligations.
d) Legal compliance — keeping financial and transaction records for the periods required by tax, accounting, and anti-fraud law, responding to lawful requests from authorities, and complying with sanctions rules. Basis: legal obligation.
e) Service communications — sending account, billing, security, and Balance notifications, including warnings when your Balance will not cover an upcoming automatic charge. Basis: performance of our contract. You cannot opt out of these while you hold an account.
f) Marketing — sending product news and offers by email, where you have agreed or where permitted by law. Basis: consent or legitimate interest. You can unsubscribe at any time.
g) Network integrity and acceptable use — analysing connection metadata to enforce our Acceptable Use Policy, respond to abuse reports, and protect the network. Basis: legitimate interest; legal obligation where we receive a lawful request.
h) Improving the Service — analytics on how the dashboard and products are used, diagnosing errors, and planning features. Basis: legitimate interest.
We do not use automated decision-making that produces legal or similarly significant effects on you without human involvement, except that our payment and fraud-prevention systems may automatically decline or hold a payment or top-up for review. You may contact us to request a human review of such a decision.
5. Who we share your data with
We do not sell personal data. We share it only as follows:
Payment and financial partners. Payment processors and gateways — currently Stripe, Paddle, PayPal, Cryptomus, and Unlimit — receive the data needed to process your payment, top-up, refund, or dispute. Some of these providers act as independent controllers or as merchant of record for your transaction and process your data under their own privacy policies. Banks, card networks, and chargeback-management services may receive transaction data in connection with a dispute.
Verification and fraud-prevention providers. Identity-verification services and fraud, risk-scoring, and sanctions-screening providers.
Infrastructure and operations providers. Hosting, cloud, database, content-delivery, email-delivery, monitoring, and security vendors that operate under our instructions.
Support and communication tools. Help-desk, chat, and email tools used to answer your requests.
Analytics and marketing providers. Web analytics, tag-management, and email-marketing platforms, subject to your cookie preferences.
Affiliate and referral partners. Where you arrive through a referral link, the partner receives confirmation that a referred account registered and made a qualifying purchase, without your personal details.
Group entities. FLOPPYDATA – FZCO and Scalehat LLC share personal data with each other as needed to operate, bill, and support the Service.
Legal and safety. We may disclose personal data to law-enforcement agencies, regulators, courts, payment partners, or injured third parties where required by law, to respond to a valid legal request, to enforce our Terms, to investigate fraud or abuse, or to protect the rights, property, or safety of Floppydata, our users, or others.
Business transfers. If Floppydata is involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction, subject to this policy.
Service providers acting on our behalf are bound by contract to process personal data only on our instructions and to protect it appropriately.
6. International transfers
Floppydata operates from the United Arab Emirates and the United States, and our service providers are located in various countries. Your personal data may therefore be transferred to and processed in countries other than your own, including countries whose data-protection laws differ from those where you live.
Where we transfer personal data out of the UAE, the European Economic Area, the United Kingdom, or another jurisdiction that restricts international transfers, we rely on an appropriate safeguard — such as a recognised adequacy decision, standard contractual clauses, or another mechanism permitted by law — and take supplementary measures where needed. You may request more information about the safeguards we use by contacting us.
7. How we protect your data
We use industry-standard technical and organisational measures to protect personal data, including encryption in transit, hashed password storage, access controls and role-based permissions, audit logging of administrative actions (including every manual Balance adjustment), network segmentation, monitoring, and regular review of our security practices. Payment card data is handled only by PCI-DSS-compliant payment providers and never touches our systems.
No online service can guarantee absolute security. If we become aware of a breach affecting your personal data, we will notify you and the relevant authorities where required by law.
You are responsible for keeping your account credentials confidential and for enabling any security features we offer.
8. How long we keep your data
We keep personal data only as long as necessary for the purposes described in this policy, and then delete or anonymise it. Our standard periods are:
| Data | Retention |
|---|---|
| Account data (email, settings, company details) | For as long as your account exists, and for at least 6 months after the account is deleted or terminated, unless a longer period applies below |
| Transaction and Balance records (top-ups, purchases, refunds, reversals, adjustments, invoices, Balance history) | For as long as required by applicable tax, accounting, and anti-fraud law, counted from the end of the financial year in which the transaction took place — even after your account is deleted. On deletion your account data is anonymised, but the financial records remain linked to a pseudonymous account identifier so that they stay complete and auditable |
| Verification data (results and limited verification details) | For as long as your account exists and for at least 6 months after termination; longer where needed to prevent re-verification with the same identity or to comply with law |
| Proxy connection metadata and usage logs | At least 6 months from collection; longer where needed to investigate abuse, resolve a dispute, or respond to a lawful request |
| Support communications | For as long as needed to resolve your request and any related dispute |
| Marketing data | Until you unsubscribe or object, then only a suppression record |
We may keep data for longer where necessary to establish, exercise, or defend legal claims; to resolve an open dispute, chargeback, or negative Balance; to comply with a legal hold; or where the law requires.
Deleting your account does not delete your transaction history, and any Balance remaining on a deleted account is forfeited as described in our Terms of Service. Please spend or, where eligible, request a refund of your Balance before deleting your account.
9. Your rights
Depending on your location and applicable law, you may have the right to:
- access the personal data we hold about you and receive a copy;
- correct inaccurate or incomplete data;
- delete your data, subject to the retention obligations in Section 8;
- restrict or object to certain processing, including processing based on legitimate interest;
- withdraw consent where processing is based on consent, without affecting processing already carried out;
- receive your data in a portable format where technically feasible;
- not be subject to a decision based solely on automated processing that has legal or similarly significant effects, and to request human review of such a decision;
- lodge a complaint with a data-protection authority, including the UAE Data Office or the supervisory authority in your country of residence.
Your transaction history is available to you at any time in the dashboard; you do not need to submit a request to see it.
To exercise any right, contact us using the details in Section 12. We may need to verify your identity before acting on a request, and we will respond within the time required by law (generally within 30 days, extendable where permitted).
9.1 Notice to residents of the EEA and the United Kingdom
Where the General Data Protection Regulation or the UK GDPR applies to our processing, the legal bases set out in Section 4 apply, and the rights in this Section 9 are those provided under Articles 15 to 22 of the GDPR. International transfers are made in accordance with Chapter V of the GDPR as described in Section 6.
9.2 Notice to California residents
Where the California Consumer Privacy Act applies, you have the right to know the categories of personal information we collect, the purposes, the categories of third parties we share it with, and the specific pieces of information we hold; the right to delete; the right to correct; and the right to non-discrimination for exercising your rights. We do not sell personal information and do not share it for cross-context behavioural advertising. In the preceding 12 months we have collected the categories described in Section 3 for the purposes described in Section 4. Requests may be submitted using the contact details in Section 12; we respond within 45 days, extendable once by a further 45 days where permitted.
10. Browser Extension
The Floppydata Proxy Extension and Switcher ("the Extension") is a separate product from our website, and this section describes how it handles data.
Single purpose: the Extension lets you configure and switch your browser's proxy settings and verify that the active proxy is working.
Data the Extension collects. When you open the Extension, it sends a request to https://time.gologin.com (operated by Gologin) to determine your current public IP address, approximate location, and connection latency. This is used only to display your current connection status inside the Extension so you can confirm whether your proxy is active. The lookup runs on demand and the result is not retained.
Data stored locally on your device. Proxy addresses, ports, authentication credentials, and preferences you enter are stored locally in your browser (chrome.storage) so they persist between sessions. This data never leaves your device.
Data sharing. Your IP address is sent only to time.gologin.com for the lookup described above. We do not sell this data or share it with any other third parties.
What the Extension does not collect. The Extension has no user account and does not collect your browsing history, the content of pages you visit, your email, or any account information.
11. Changes to this policy
We may update this Privacy Policy from time to time. The updated version will be posted on this page with a new "Last Updated" date and becomes effective when published. Where a change materially affects how we use personal data you have already provided, we will notify you by email or in the dashboard before it takes effect.
12. Contact us
For questions about this Privacy Policy, to exercise your rights, or to raise a concern about how we handle your personal data, contact us at:
FLOPPYDATA – FZCO
Building A1, Dubai Digital Park
Dubai Silicon Oasis,
Dubai, UAE
Scalehat LLC
4291 S. Tamiami Trail, 1063
Venice, FL 34293, United States