Website Privacy Policy
Effective Date: 10 August 2026
This Privacy Policy describes how REZRAF LTD ("we", "us", or "our") processes personal data in connection with the 1323vpn.com website. It covers the website only. For the 1323vpn iOS application, see the App Privacy Policy.
By using this website, you agree to the practices described below.
1. Data Controller
The data controller for this website is:
REZRAF LTDRegistered in England and Wales
124-128 City Road · London EC1V 2NX · United Kingdom
[email protected]
2. What This Website Collects
This website includes a personal account area used to authenticate users, show VPN subscription status, manage devices and sessions, and start hosted checkout. We do not place tracking cookies, advertising tags, or behavioural analytics services.
2.1 Technical Data via Cloudflare
This website is delivered through Cloudflare's content delivery and security infrastructure. When you visit any page, Cloudflare may process:
- IP address;
- browser type and version;
- operating system;
- referring URL;
- pages requested and timestamp;
- HTTP headers and request metadata.
This data is processed by Cloudflare to deliver content, protect against DDoS attacks and malicious traffic, and maintain service security. We receive aggregated, non-identifiable performance data. We do not receive raw access logs identifying individual users from Cloudflare.
2.2 Account and Transaction Data
When you use the personal account area, the service may process the account identity you choose (Telegram, Apple, email, or passkey), subscription status, billing channel, payment status, and device or session information needed to provide and secure the service. Card and cryptocurrency payment details are entered on the payment provider's hosted page; this website receives the resulting order and payment status, not full card details or private wallet credentials.
2.3 Security and Error Reports
To maintain reliability and enforce browser security policy, the site may send coarse operational reports to our own API. Reports are limited to an error category, normalised page or API path, HTTP status or internal error code, release version, and Content Security Policy directive. Query strings, email addresses, authentication tokens, payment URLs, subscription URLs, cookies, and stable device identifiers are not included. These reports are used for security and fault diagnosis, not analytics.
2.4 Data We Do Not Collect for Analytics
Through this website, we do not collect:
- behavioural or analytics data;
- advertising identifiers.
- cross-site tracking identifiers.
Passwords are not collected by the website. Authentication uses the selected identity provider, one-time links, or passkeys, and payment credentials remain with the hosted payment provider.
3. Legal Basis for Processing
We process the technical and security data described in sections 2.1 and 2.3 on the basis of our legitimate interests in delivering the website securely, protecting against abuse, and maintaining service availability (Article 6(1)(f) UK GDPR).
We have assessed that these interests are not overridden by your rights and freedoms, given the limited nature of data processed and the security purpose it serves.
4. Cookies
This website uses only strictly necessary cookies set by Cloudflare for security and CDN functionality. No consent is required for strictly necessary cookies under PECR. For full details, see our Cookie Policy.
5. Data Sharing
We do not sell or rent your personal data.
Cloudflare
Cloudflare, Inc. acts as a data processor for CDN delivery, DDoS protection, and security services. Cloudflare processes data in accordance with its own privacy policy and applicable data protection agreements. Data may be processed in the United States and other countries where Cloudflare operates.
Identity and Payment Providers
When you choose an external identity or payment method, the corresponding provider processes the data needed to authenticate you or complete the hosted payment under its own privacy terms. We receive only the identity assertion, order reference, and status needed to provide the account and subscription.
We may disclose data if required by law, court order, or regulatory request.
6. International Transfers
Cloudflare operates a global network. Data processed by Cloudflare may be transferred internationally. Cloudflare uses Standard Contractual Clauses and other approved mechanisms for transfers outside the UK and EEA.
7. Retention
Cloudflare's retention of CDN and security logs is governed by Cloudflare's own data retention policies. Operational error and CSP reports are retained only for security and fault investigation and are designed not to contain direct identifiers or secret URL parameters.
8. Your Rights
Under UK GDPR, you may have the right to:
- access personal data we hold about you;
- request correction of inaccurate data;
- request erasure of your data;
- object to processing based on legitimate interests;
- request restriction of processing;
- lodge a complaint with the ICO.
Security reports are intentionally not linked to an account or stable device identifier, so we may have limited ability to retrieve a specific report. Account-related requests can be matched after appropriate identity verification.
To exercise your rights, contact us at [email protected].
The supervisory authority for the United Kingdom is the Information Commissioner's Office (ICO), reachable at ico.org.uk.
9. Changes
We may update this policy from time to time. Changes will be indicated by a new Effective Date at the top of this page.
10. Contact
REZRAF LTD · 124-128 City Road · London EC1V 2NX · United Kingdom[email protected]