1. Who this policy covers
This policy explains how VERSUS VPN LTD (company number 14455374), trading as VersusVPN, collects and uses personal information when you visit the website, request a trial, purchase or use the VPN service, contact support, submit a business online safety assessment, request a Domain Shield exposure check, request an AI Governance or Cyber Essentials readiness review, or use the referral rewards programme. VERSUS VPN LTD is the data controller for this information. Our registered office is 10 Maidwell Way, Bradford, BD6 2QR.
2. Information we collect
Website, orders and support
We may collect your name, role, business or trading name, email address, telephone number, reseller panel identifier, order and payment references, plan, support messages, account status, device or app details you choose to provide, and records of consent. A business online safety assessment may also contain information you provide about your organisation's technology, working arrangements, information types, current safeguards, concerns and priorities. A Domain Shield request may include the business domain you are authorised to submit, email provider, optional DKIM selector, concern, notes, monitoring interest and the resulting publicly available DNS, email-authentication and registration observations. If paid monitoring is agreed, we also keep the approved public-record baseline, alert contacts, declared sending services, monitored hostnames, renewal dates and monitoring history needed to provide the service. An AI Governance request may describe tools, use cases, important decisions, policy status, data concerns and UK or EU operations. A Cyber Essentials readiness request may describe organisation size, devices, IT support, certification drivers, deadlines, current progress and perceived gaps. Do not include passwords, recovery codes, private keys, live employee or customer datasets, confidential prompts, full payment-card details or unnecessary personal information in an assessment or check request. Card details are collected directly by Stripe and are not stored by VersusVPN.
Referral rewards
When you take part in the referral programme or use a referral link or code, WHMCS processes the code, relevant client identifiers, order, invoice and service status, referral dates, reward history and limited matching signals such as telephone number, billing address and order IP used to identify duplicate identities or abuse. We use this to attribute referrals, show aggregate progress, issue or reverse rewards, resolve disputes and protect the programme. A referrer sees only dates and pending, qualified or reversed statuses; we do not disclose the referred customer's identity, contact details, payment information or order details. Review signals, referral entries, rewards and related financial audit records may be retained for up to six years after the last relevant transaction so we can resolve disputes, prevent duplicate rewards and meet accounting or legal obligations.
Domain Shield public checks
When you authorise a Domain Shield check, the submitted domain and public record names are sent to Cloudflare's public DNS resolver and the IANA-designated registry RDAP service for that domain. Those services can receive the queried domain and request timing. We retain the extracted public findings with your request, but do not retain raw RDAP contact records. For paid monitoring, agreed public signals and expiry sources are checked on a schedule, compared with the approved baseline and used to prepare alerts and monthly summaries. Automated systems may assist with checks and drafting, but VersusVPN reviews potentially meaningful changes before notifying you. The service does not log in, scan ports, access private systems or change DNS automatically.
Support assistant
Questions submitted to the support assistant, its replies, a conversation identifier and any optional reply email are stored so we can answer the request, escalate it to a person and improve our approved support guidance. When AI answers are enabled, the relevant question, recent conversation and selected VersusVPN guidance are sent securely to OpenAI through its API with response storage disabled. Do not enter passwords, card details, PINs, private keys or recovery codes. Chat records follow the support-message retention period below.
Connection exposure check
The home page can display the public IP address and approximate location already made available with your web request. This happens when the page loads so the result can be shown to you. We do not add that result to the customer, order or marketing database or use it to build a marketing profile. Our hosting and security providers may still process IP addresses in ordinary technical logs to deliver and protect the website.
Website traffic reports
We keep privacy-focused daily totals for page views, page paths, approximate request country, broad device type, referring domain and selected customer actions such as a business review started or submitted, checkout reached, checkout form started, payment attempted, trial created and purchase confirmed. These are separate aggregate counters: we do not store a visitor identifier, full IP address, cookie, full referrer URL or a sequence of pages attributable to one person for this reporting. Automated bots and admin pages are excluded, and browser Do Not Track or Global Privacy Control signals are respected.
Optional advertising measurement
If you consent, the Meta Pixel may process page views, selected enquiry or checkout stages, completed trials or purchases, browser and device information, advertising identifiers and referring-ad information to measure results and improve advertising relevance. Stripe may also send completed-payment event information to Meta through its connected integration. We do not send passwords, VPN browsing activity, assessment answers or full card details through these tools. You can reject or later change this choice using the website’s Privacy choices control.
VPN service operation
The website and billing systems do not collect the websites you visit, DNS queries or the content of your internet traffic. VPN access is delivered through the VPNShop/VPNPanel platform. That platform necessarily processes limited technical connection data to authenticate an account, operate the requested connection, protect the network and diagnose faults. This may include account identifiers, source IP address, selected VPN server, connection times and data volume. We do not use this operational information to build advertising profiles or sell it.
3. Why we use information
- To provide a requested trial, paid VPN access and customer support.
- To attribute referral codes, show programme progress and issue or reverse earned renewal rewards.
- To review business online safety assessments and supply relevant, prioritised guidance.
- To carry out an authorised Domain Shield public-record check, respond with findings, assess monitoring fit and provide agreed monitoring, alerts and reports.
- To qualify and scope requested AI Governance or Cyber Essentials readiness support without making an automatic compliance or certification decision.
- To process payments, prevent fraud, maintain records and comply with law.
- To keep the service secure, diagnose faults and manage capacity.
- To send marketing only where consent or another lawful basis permits it.
- To establish, exercise or defend legal claims.
4. Lawful bases
We generally process account and order information because it is necessary to perform the contract or take steps you request before a contract. Referral administration is necessary to provide the requested programme benefit to participating referrers, while accurate attribution, duplicate-identity review, fraud prevention, security and service improvement may rely on legitimate interests. Legal record-keeping relies on legal obligation. Optional marketing and Meta advertising measurement rely on consent where required.
5. Service providers and international transfers
We use Stripe for payments, Meta for optional advertising measurement, WHMCS and BuyFast for billing and customer-account hosting, Resend for transactional email, OpenAI for website hosting, AI-assisted support and scheduled Domain Shield assistance, Cloudflare for website security and public DNS checks, IANA-designated registry RDAP services for authorised registration checks, and VPNShop/VPNPanel for VPN infrastructure and provisioning. These providers process only the information needed for their role. Some providers may process information outside the United Kingdom; where that happens we rely on the provider’s contractual safeguards and recognised transfer mechanisms. We do not sell personal information.
6. How long we keep information
- Invoice, payment and accounting records are normally kept for six years after the relevant accounting period.
- Customer account and service records are kept while the account is active and then for up to two years, unless a longer period is needed for tax, fraud prevention or a dispute.
- Support, contact messages and completed business assessments are normally kept for up to two years after the matter is closed.
- Trial eligibility records may be kept while the free-trial programme operates so repeated applications can be prevented; access is restricted and the information is used only for eligibility, security and support.
- Marketing consent is kept until it is withdrawn; a minimal suppression record may then be retained so the request continues to be honoured.
- Aggregate website traffic counters are automatically removed after 400 days.
Operational VPN connection records are controlled by the live VPNShop/VPNPanel service configuration and are kept only for network operation, security and troubleshooting. You may ask admin@versusvpn.co.uk for the current retention information that applies to your service.
7. Your rights
UK data protection law may give you rights to access, correct, erase or restrict personal information, object to certain uses, receive portable data and withdraw consent. Contact admin@versusvpn.co.uk to make a request. You may also complain to the Information Commissioner’s Office at ico.org.uk.
8. Security and changes
We use appropriate technical and organisational measures, but no online service is entirely risk-free. We may update this policy when the service, providers or law changes; material changes will be highlighted where appropriate.