Last updated: August 2026
Privacy Policy
CavaVPN processes data only as needed to provide accounts, subscriptions, network acceleration, customer support, and site maintenance. This policy explains the data categories, purposes, retention practices, and requests users may make. Continued use of the service means that the user has read this policy.
Data Collected and Processing Purposes
No email address is required to register; an account can be created with a username and password. CavaVPN does not make an email address mandatory for registration. The account system processes usernames, authentication information, and account status for login verification, subscription delivery, unusual access detection, and ticket association. Passwords are used for identity verification and are never displayed as readable text on pages.
When a subscription or data package is purchased, the system stores order items, amounts, payment channels, payment results, refund status, and necessary transaction identifiers to complete orders, verify delivery, handle disputes, and meet financial record obligations. The service also processes total plan usage to apply monthly subscription resets or calculate remaining package usage; this data does not include the content of websites visited by the user.
To maintain marketing pages and the user panel, CavaVPN may process analytics such as page visits, referring pages, browser and device categories, and error events. These statistics help diagnose page issues, improve compatibility, and understand feature usage. They are not used to build browsing profiles of users on international websites.
Network Activity and the No-Logs Principle
CavaVPN does not record which websites users visit, or retain web content, search content, message bodies, or data that could be used to reconstruct specific browsing activity. While network services operate, temporary technical information may be generated to complete connections, measure traffic, and troubleshoot faults. This information is limited to the current processing purpose and is not retained as long-term connection logs.
Temporary technical information is cleared or de-identified after connection maintenance, capacity assessment, or troubleshooting is complete. Usage records are used only to calculate account allowances and cannot identify specific destinations. Diagnostic information voluntarily attached by a user to a support ticket is used only to resolve that issue and is not repurposed for marketing.
Cookies and Local Storage
The site may use Cookies or browser local storage to save login sessions, interface language, menu state, and necessary security markers, allowing the correct state to persist between pages. Disabling this storage may sign users out, prevent language preferences from being retained, or affect some user panel features.
Authentication information in local storage is used only to identify the current session and call account functions. Users can remove local information by signing out or clearing browser site data; after clearing it, they must log in again to use account features.
Payments and Third-Party Processing
CavaVPN supports Alipay, WeChat Pay, and USDT. Payments may be processed by the relevant payment provider, whose privacy rules and security measures govern the payment information it requires. CavaVPN typically receives the order identifier, payment channel, payment status, and information needed to verify the transaction, but does not directly control data collected on third-party payment pages.
Payment providers may retain relevant records for transaction processing, risk control, or compliance purposes. Users should review the terms displayed on the payment page before paying. CavaVPN uses returned payment results only to confirm orders, deliver subscriptions, process refunds, and reconcile accounts.
Data Retention and Deletion
Account data is retained while the account remains in use. Order and refund records are kept only as needed for transaction processing, dispute resolution, and necessary record-keeping obligations. Analytics and error information is deleted, aggregated, or de-identified after its analysis or troubleshooting purpose is complete. Tickets and their attachments are not used for other purposes after the support matter ends.
Users can use the ticket function in the user panel to request access to, correction of, or deletion of account-related data. After receiving a request, CavaVPN first verifies account ownership and then processes data eligible for deletion. Data that cannot yet be deleted because of an incomplete order, refund dispute, security investigation, or necessary record-keeping obligation will be cleared under applicable rules after the relevant purpose ends. Deleting account data may also end account access and any incomplete service delivery.
Policy Updates and Scope
CavaVPN may update this policy when service features, data processing practices, or applicable rules change. The revised text will be published on this page, together with an updated “Last updated” notice. Important changes affecting user rights may also be explained through site announcements or notices in the user panel.
This policy applies to CavaVPN marketing pages, the user panel, subscription services, and related support processes. Third-party payment pages and external services that users choose to access are governed by their own policies. Before continuing to use the service after a policy update, users should review the latest version and confirm the relevant changes.