Information Collected and Why It Is Used
CacaVPN only processes information needed for account management, order fulfillment, service maintenance, and security checks. No email address is required to register; a username and password are sufficient. The system stores the username, password verification data, account status, and necessary login session information to identify the account, maintain the signed-in state, and prevent unauthorized access.
When a subscription or data package is purchased, the system stores the order items, amount, payment status, creation time, and transaction reference returned by the payment channel. These records are used to confirm payment, deliver the plan, process refunds, resolve disputes, and maintain financial records. Data usage and plan status are also processed to apply monthly subscription resets, deduct package usage, and handle mid-cycle upgrades.
The website may collect page paths, referring pages, browser type, device category, language settings, and button interactions as usage analytics. This helps verify that pages work properly, improve content structure, and analyze feature usage. Analytics are used in aggregate and not to build individual browsing profiles.
No-Logs Position and Connection Information
CacaVPN does not record which websites users visit, or retain network request content, transmitted content, or history that could reconstruct specific browsing activity. The service does not create or retain connection logs for tracking personal online activity, nor does it associate specific visits to international websites with an account.
To establish connections, assign routes, and calculate plan usage, the system may temporarily process necessary technical information during a connection. This information is used only for the active connection and resource accounting, and is not retained as personal browsing history after the connection ends. Client error details are stored on the user's device by default; they enter a support ticket record only when the user actively submits diagnostic materials.
Cookies and Local Storage
The website and user panel use cookies or browser local storage to save login sessions, language choices, interface preferences, and necessary security states. This data maintains sign-in access, restores page settings, and completes actions initiated by the user. It is not used to sell personal data.
If the browser blocks necessary cookies or clears local storage, the login state, language preference, and some panel features may need to be configured again. Users can clear this data through browser settings, but should confirm that important actions are complete first.
Payment Processing and Third-Party Services
CacaVPN supports Alipay, WeChat, and USDT. Payment processing is handled by the relevant payment channel or network. Account details, authorization information, and transaction verification data required for payment are handled by the relevant service under its own rules. CacaVPN does not directly store complete payment-account credentials; it receives only the result information needed to confirm order status and provide after-sales support.
Payment services, infrastructure providers, or analytics processors may need access to data necessary for their duties. CacaVPN limits the scope of information provided and requires that it be used only for delivery, settlement, security maintenance, or analytics. The data practices of third-party services are also governed by their own privacy policies.
Data Retention, Deletion, and Policy Updates
Account data is retained while the account remains in use. Order and transaction records are kept for as long as needed to handle delivery, refunds, disputes, and applicable compliance requirements. Analytics are retained only as needed for aggregated analysis and website maintenance. Support ticket materials are used while an issue is being handled and then managed according to support-record maintenance needs.
Users can sign in to the user panel and submit a ticket to request access to, correction of, or deletion of data associated with the account. After a deletion request is completed, account features may no longer be available. Records that must be retained by law, relate to an unresolved order dispute, or are necessary to prevent abuse may be deleted only after the relevant purpose ends. Cookies and local storage can be cleared directly by the user in the browser.
This policy may be updated when service features, data-processing procedures, or applicable rules change. The revised text will be published on this page, and the last-updated date at the top will be adjusted. If there is a significant change to the scope of processing, an explanation will be provided through the website or user panel. Reviewing the relevant terms again before continuing to use the updated service is recommended.
If you have questions about privacy practices, submit a ticket through the user panel and describe the account data or specific activity involved.