proxyfarms
Sign inStart farming

Privacy Policy

Last updated 19 August 2026

This policy sets out what Proxy Farms collects when you run devices with us, why we hold it, and what we deliberately never touch. The short version: we run the control plane and the network nodes, you own the phones, and the traffic that passes through them stays yours.

Who we are and what this covers

Proxy Farms is operated by PrixHistory Technologies Private Limited, a company registered at [Registered address]. In this policy, we and us mean that entity, and you means the person or organisation holding a Proxy Farms account.

This policy covers the marketing site at proxyfarms.com, the farmer dashboard, the Proxy Farms Android application, and the API and network nodes behind them. It does not cover the sites and services your proxied traffic reaches. Those run under their own policies.

Two roles matter here. For your account, billing and device telemetry we are the controller: we decide why that data exists. For the traffic you route through your own devices you are the controller and we act as your processor, carrying what you instructed us to carry.

What we collect

Everything we hold falls into one of the categories below. The table is the summary; the notes underneath cover the parts that are specific to how this product works.

CategoryExamplesWhy we hold it
Account dataName, email address, password hash, company name, country, the use case you pick at onboarding, plan and billing status, invoices and payment referencesTo create and secure your account, apply your plan, bill you and contact you about the service
Device telemetryDevice name and model, Android and app version, pairing state, last seen time, battery level, connectivity state (WiFi or cellular), tunnel state and rotation eventsTo show you whether a device is healthy, to meter per device billing, and to diagnose faults
Trial device identifierA one way salted hash of the Android identifier of each phone that starts a free trial. We store the hash, never the identifier itself, and it is written once per phoneTo hold the free trial to one per handset, so it cannot be reclaimed by reinstalling the app or opening another account
Traffic metadataBytes in and out, live and cumulative connection counts, success and failure rates, timestamps, the network node a device is assigned to and the proxy ports in useTo draw your dashboard, apply plan limits, detect abuse and size our network
Message dataOnly where you enable the SMS features: the sender, timestamp and body of messages read from a paired device, and the delivery result of messages you sendTo deliver the SMS dashboard and the webhook forwarding you switched on
Support and salesMessages you send us, the address you send them from, and anything you choose to include in themTo answer you and keep a record of what was agreed
Site and server logsIP address, user agent, requested path and timestamp for requests to the marketing site, dashboard and APISecurity, fraud prevention and keeping the service available

Account data is what you type. You give it at registration and during onboarding, and you can edit most of it in the dashboard whenever you like.

Device telemetry comes from the phones you pair. The application on each device sends a regular heartbeat describing its own state, so the dashboard can tell you a device is offline, unplugged or low on battery before your jobs start failing. That heartbeat describes the device, not the person using it.

The trial identifier is a hash, and only a hash. When a phone starts a free trial, the application reads the Android identifier that the operating system gives it — a value that is already scoped to this app on this device, so it cannot be matched against any other app — and sends it once, at pairing. We keep only a salted one way hash of it, which is enough to recognise a phone that has already had a trial and not enough to reconstruct the identifier or to say anything else about the device. Phones that never start a trial are never hashed.

Traffic metadata is counted, not recorded. We total the bytes, connections and outcomes that pass through the tunnel so you can see throughput and success rates. Counting does not require knowing what the bytes contain, so we do not look and we do not keep them.

Message data only exists if you switch it on. The SMS dashboard and webhook forwarding are opt in, per device, on the plans that include them. While they are on we relay message content to you or to the webhook you nominate. While they are off the application does not read messages at all. Anyone whose messages reach that SIM is relying on you rather than on us, which is one place where your responsibilities as controller are very real.

What we explicitly do not collect

This deserves stating plainly, because people usually assume the opposite about a proxy provider.

  • We do not log the contents of proxied traffic. Payloads cross the tunnel and are neither inspected nor written to disk.
  • We do not build a per request URL history for proxied traffic. Where you configure allow or deny rules, matching happens on the device itself, and only the fact that a rule matched can reach a counter.
  • Your own devices are the egress point. Traffic leaves on your phone, over your SIM, on your carrier IP address, so the destination sees your connection rather than ours.
  • We do not sell personal data, and we do not share it with advertising networks or data brokers.
  • We do not ask for or store card numbers. Payment details go straight to our payment provider and never touch our servers.
  • We do not collect contacts, call logs, photos, files, microphone input or location from paired devices.

How we use it

  • Running the service: pairing devices, assigning a network node, keeping tunnels up, applying your access rules and routing your traffic.
  • Showing you your fleet: bandwidth charts, success rates, live connection counts, battery level and connectivity state.
  • Billing: counting active devices, applying your plan, taking payment and issuing invoices.
  • Support: answering your questions and reproducing the faults you report.
  • Safety: detecting abuse, fraud, and activity that breaches our acceptable use rules or a carrier agreement.
  • Legal obligations: keeping the records we are required to keep and responding to lawful requests.
  • Improvement: aggregate analysis of how the service performs, in a form that does not identify anyone.

We do not use your data to train models, and we do not profile you for advertising. Decisions with real consequences, such as suspending an account, are reviewed by a person before they take effect.

Where a data protection law such as the UK GDPR or the EU GDPR applies to you, these are the bases we rely on. Your local law may organise them differently, and the final wording here depends on [Governing jurisdiction].

BasisWhat we rely on it for
ContractCreating your account, running paired devices, metering usage, and taking payment for the plan you chose
Legitimate interestsKeeping the service secure, preventing abuse and fraud, sizing our network, and improving the product, each balanced against your rights
Legal obligationTax and accounting records, and responses to valid legal process
ConsentOptional marketing email and any non essential analytics cookie. You can withdraw either at any time without losing access to the service

Sharing and sub-processors

We share personal data only with the categories of recipient below, and only as far as each one needs it.

  • Infrastructure and hosting providers that run our servers and network nodes.
  • Our payment provider, which handles card details and subscriptions directly.
  • Email providers used for account, billing and support messages.
  • Error monitoring and product analytics providers used to keep the service working.
  • Professional advisers, and authorities where the law requires disclosure.
  • A buyer or successor if the business is ever sold or reorganised, bound by commitments no weaker than these.

Every sub-processor works under a written agreement that limits it to our instructions. A current list is available from the contact address below, and Enterprise Plan customers can ask for advance notice of changes as part of a data processing agreement.

International transfers

Our people, our providers and our network nodes are not all in one country, so your data may be processed outside the country you are in. Where a transfer leaves a jurisdiction that restricts them, we rely on an approved mechanism such as standard contractual clauses, alongside technical measures including encryption in transit.

Where your proxy traffic goes is your decision rather than ours. You choose which devices to pair and which network node region they sit behind, and the traffic exits on your own carrier connection at the end of it.

How long we keep things

DataKept for
Account recordsWhile your account is open, then 12 months after you close it
Billing and tax records7 years, or the period the applicable tax law requires
Device telemetry and usage counters30 days at full resolution on self serve plans, then kept only in aggregate. Enterprise Plan retention is set in your agreement
Message dataOnly as long as delivery to you or your webhook requires, and no longer than 7 days
Support correspondence24 months from the last message in the thread
Server and security logs90 days, unless a log forms part of an active investigation

The contents of proxied traffic have no retention period because they are never stored in the first place. When you unpair a device its tunnel keys are revoked immediately and its telemetry ages out on the schedule above.

Your rights and how to use them

Depending on where you live, you may have some or all of the following rights over data we hold about you.

  • Access: a copy of the personal data we hold about you.
  • Correction: fixing anything inaccurate or incomplete.
  • Deletion: erasure where we no longer have a reason to keep it.
  • Restriction: pausing our use of it while a dispute is resolved.
  • Objection: telling us to stop processing that rests on legitimate interests.
  • Portability: a machine readable export of the data you gave us.
  • Withdrawing consent: for anything we do on that basis, with no effect on what came before.
  • Complaint: raising the matter with the data protection authority for your country.

To use any of them, email business@proxyfarms.com from the address on your account, or edit what you can directly in the dashboard. We reply within 30 days and never charge for a first request. We may ask you to confirm your identity before acting. Where the request concerns data you process through us on someone else's behalf, we will point the request back to you, since you are the controller of it.

Cookies and analytics

The marketing site is deliberately light. We use a small number of cookies and similar identifiers:

  • Strictly necessary cookies that keep you signed in to the dashboard and protect forms against cross site request forgery. Turning these off breaks the product.
  • Preference storage that remembers small interface choices you make.
  • Aggregate analytics that count page views so we know which pages earn their place. These load only if you accept them.

We run no advertising pixels and no cross site tracking. You can block or clear cookies in your browser at any time; the necessary ones are simply set again the next time you sign in.

Security

  • Traffic between our network nodes and your devices runs inside an encrypted tunnel. The site, dashboard and API are served over TLS.
  • Passwords are stored as salted hashes, never in a form anyone here can read.
  • Device pairing uses single use credentials, and unpairing revokes the keys straight away.
  • Access to production systems is limited to the people who need it and is logged.
  • Backups are encrypted, and restores are tested rather than assumed.
  • Dependencies are patched on a schedule and changes are reviewed before they reach production.

No system is perfectly secure. If we discover a breach likely to affect you, we will tell you and the relevant authority without undue delay, with what we know at the time and what we suggest you do about it.

Children

Proxy Farms is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 16, or the higher age set by your local law. If you believe a child has given us data, write to us and we will delete it.

Changes to this policy

We update this policy when the product or the law changes, and the date at the top always shows the current version. For material changes we will email account holders or show a notice in the dashboard at least 14 days before they take effect. Continuing to use the service after that date means the new version applies to you.

How to contact us

Questions, requests and complaints about privacy go to business@proxyfarms.com, or by post to PrixHistory Technologies Private Limited, [Registered address]. Ask at the same address for a data processing agreement, a sub-processor list or a completed security questionnaire.

If we fail to resolve something to your satisfaction, you can complain to the data protection authority for your country. For [Governing jurisdiction] that is [Supervisory authority].