Beta Looking for beta testers · 100 spots · Join & get free access 100 spots · Join free →
Sv SericaVPN
  • Features
  • Customers
  • Pricing
  • Download
  • About
  • Journal
  • FAQ
Sign in Get started
  • Features
  • Customers
  • Pricing
  • Download
  • About
  • Journal
  • FAQ
  • Sign in
← SericaVPN Legal

Privacy Policy

Last updated: June 5, 2026

Legal documents
Privacy Policy Terms of Service Cookie Policy Refund Policy Acceptable Use Imprint

1. Introduction

Serica LLC ("Serica," "we," "our," or "us") operates SericaVPN. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and your rights regarding that data.

We are committed to data minimization. We collect only what is necessary to provide the service, and we never sell your data to third parties.

The most important thing: we do not log your VPN traffic, browsing history, DNS queries, connection timestamps, or IP addresses. We collect only aggregate bandwidth metrics to power your dashboard and enforce plan data limits. Our no-traffic-logs policy is the foundation of the service.

2. Data We Collect and Why

2.1 Account Data

Data elementWhy we collect itLegal basis (GDPR)Retention
Email addressAccount creation, login, support communications, renewal noticesContract performanceUntil account deletion + 30 days
Password (hashed)Authentication. Stored as bcrypt hash, never in plaintextContract performanceUntil account deletion
Account creation dateSubscription management, fraud preventionContract performance / Legitimate interestsUntil account deletion + 30 days

2.2 Payment Data

Data elementWhy we collect itLegal basis (GDPR)Retention
Payment method (last 4 digits, card brand)Displaying saved payment method in dashboardContract performanceUntil removed by user or account deletion
Billing addressTax compliance and fraud preventionLegal obligation / Contract performance7 years (tax records)
Transaction recordsAccounting, dispute resolution, legal complianceLegal obligation7 years

Note: We do not store full card numbers, CVVs, or bank account credentials. All payment processing is handled by our PCI-DSS compliant payment processor. We receive and store only tokenized references.

2.3 Subscription Data

Data elementWhy we collect itLegal basis (GDPR)Retention
Plan name and priceService delivery, billingContract performanceDuration of subscription + 7 years (billing records)
Subscription start/end datesAccess control, renewal processingContract performanceDuration of subscription + 30 days
Billing cycleRenewal schedulingContract performanceDuration of subscription

2.4 VPN Provisioning Data

Data elementWhy we collect itLegal basis (GDPR)Retention
Number of active device slots usedEnforcing simultaneous connection limitsContract performanceReal-time only. Not persisted after session ends
VPN configuration credentials (keys)Authenticating VPN connectionsContract performanceUntil revoked by user or account deletion
Server region selectionsDisplaying your active connections in the dashboardContract performanceStored locally in your dashboard only; cleared when session ends

What we do NOT log: source IP address, destination IP address, DNS queries, URLs visited, browsing history, session start/end times, session duration, or any content of your traffic.

We collect aggregate bandwidth metrics per billing cycle to display usage in your dashboard and enforce plan data limits. These metrics contain no personal data, IPs, or traffic details. You can request deletion of these metrics at any time by contacting support.

2.5 Authentication Sessions

Data elementWhy we collect itLegal basis (GDPR)Retention
Session token (hashed)Maintaining your logged-in state in the web dashboardContract performanceUntil logout or 30-day inactivity expiry
Browser user-agent (for security)Detecting session anomalies and suspicious accessLegitimate interests (security)Duration of session

2.6 Support Tickets

Data elementWhy we collect itLegal basis (GDPR)Retention
Ticket content and correspondenceResolving your support requestContract performance / Legitimate interests2 years after ticket close
Attachments (e.g. screenshots)Diagnosing technical issuesContract performance2 years after ticket close
Email address (from ticket submission)Sending repliesContract performance2 years after ticket close

2.7 Website Analytics

Data elementWhy we collect itLegal basis (GDPR)Retention
Anonymized page views and navigation pathsUnderstanding how visitors use our marketing website to improve itLegitimate interests (analytics are anonymized and self-hosted)13 months, then aggregated

We use self-hosted Matomo with IP anonymization enabled. No data is sent to third-party analytics providers. You can opt out via our cookie settings or by enabling Do Not Track.

2.8 Usage Metrics

Data elementWhy we collect itLegal basis (GDPR)Retention
Aggregate bandwidth per billing cycleDisplaying usage in your dashboard and enforcing plan data limitsContract performanceDuration of billing cycle + 30 days. Deletable on request via support
Active device countEnforcing simultaneous connection limits per planContract performanceReal-time only. Not persisted after session ends

Usage metrics contain no personal data, IP addresses, or details about what you accessed. They are aggregate numbers only. You can request deletion at any time by contacting support.

2.9 Security and Abuse Logs

Data elementWhy we collect itLegal basis (GDPR)Retention
Failed login attempts (rate-limited)Preventing brute force attacks on accountsLegitimate interests (security)72 hours, then automatically purged
Abuse reports receivedInvestigating and responding to reports of AUP violationsLegal obligation / Legitimate interests1 year

3. Google Sign-In and Google User Data

SericaVPN may allow users to sign in with their Google account through Google OAuth on dashboard.sericavpn.com. When a user chooses Google Sign-In, we may receive basic account information such as name, email address, and profile identifier needed to authenticate the user and link the sign-in to a SericaVPN account. This information is used only for login, account access, and account management.

3.1 Data Use

We use Google user data only to:

  • authenticate users,
  • create or link a SericaVPN account,
  • maintain account access,
  • improve account security.

3.2 Data Storage

When you sign in with Google, we store your email address and profile identifier in our database to associate your Google account with your SericaVPN account. This data is retained for the duration of your account and deleted within 30 days of account deletion. We do not store Google OAuth tokens beyond the duration of the active authentication session.

3.3 Data Sharing

We do not sell Google user data to third parties. We do not use Google user data for advertising. Google user data is not shared with any party outside of what is required to operate the SericaVPN service, as described in section 5 (How We Share Your Data) of this policy.

3.4 Google API Services User Data Policy

SericaVPN's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. Data We Never Collect

  • VPN connection logs (source IP, destination IP, timestamps)
  • DNS queries made through the VPN
  • Websites or services accessed through the VPN
  • Your real IP address when connected to the VPN
  • Device identifiers, hardware fingerprints, or MAC addresses
  • Information from third-party data brokers

Note on bandwidth metrics: We collect aggregate bandwidth usage per billing cycle to display in your dashboard and enforce plan data limits. This is operational metric data, not traffic data. It contains no personal information, IP addresses, or details about what you accessed. You can request deletion of these metrics at any time via support.

5. How We Share Your Data

We do not sell, rent, or trade your personal data. We share data only in these limited circumstances:

5.1 Service Providers

We engage carefully selected processors to operate the service:

  • Payment processor: Processes payments; receives only what is necessary for transaction completion. Subject to PCI-DSS compliance.
  • Email provider: Delivers transactional emails (receipts, password resets, support replies). Receives your email address and the content of the message.
  • Cloud infrastructure: Hosts our servers. Providers do not have access to decrypted customer data.

All processors are bound by data processing agreements (DPAs) and may only use your data as directed by us.

5.2 Legal Obligations

We may disclose data if required to do so by valid legal process, such as a court order, subpoena, or similar instrument served in accordance with applicable law. Due to our no-traffic-logs architecture, we typically cannot provide information about VPN activity because we do not have it.

We will notify you of any legal request for your data unless prohibited by law (e.g., a gag order).

5.3 Business Transfers

If Serica LLC is acquired or merges with another entity, your data may be transferred as part of that transaction. We will notify you before your data becomes subject to a materially different privacy policy, and you will have the option to delete your account.

6. Data Security

We protect your data with industry-standard measures:

  • All data in transit encrypted with TLS 1.3
  • Passwords stored as bcrypt hashes (never in plaintext)
  • VPN servers operate in RAM-only mode. No data written to disk
  • Strict access controls: employees access customer data only when necessary for support
  • Regular third-party security audits
  • Automated vulnerability scanning and incident response procedures

No system is perfectly secure. In the event of a data breach that poses a risk to your rights, we will notify you and applicable regulators within 72 hours as required by GDPR Article 33.

7. International Data Transfers

Serica LLC is incorporated in the United States. If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, your data may be transferred to and processed in the United States.

We conduct such transfers in compliance with applicable law. Where required, we rely on the EU–US Data Privacy Framework or Standard Contractual Clauses (SCCs) as the lawful transfer mechanism.

8. Your Rights

Depending on your location, you may have the following rights:

8.1 Rights Under GDPR (EEA Residents)

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Correct inaccurate or incomplete data
  • Erasure ("right to be forgotten"): Request deletion of your data, subject to legal retention obligations
  • Restriction: Ask us to pause processing in certain circumstances
  • Portability: Receive your data in a machine-readable format
  • Objection: Object to processing based on legitimate interests
  • Withdraw consent: Where processing is based on consent, withdraw it at any time
  • Lodge a complaint: With your national supervisory authority

8.2 Rights Under CCPA (California Residents)

  • Know what personal information we collect and how we use it
  • Delete personal information (with limited exceptions)
  • Opt out of the sale of personal information. We do not sell personal information
  • Non-discrimination for exercising privacy rights

8.3 Exercising Your Rights

Submit requests to legal@sericavpn.com. We respond within 30 days (GDPR) or 45 days (CCPA). We may need to verify your identity before fulfilling the request. There is no charge for reasonable requests.

9. Data Retention Summary

We retain personal data only as long as necessary for the purpose for which it was collected, or as required by law. When you delete your account, all personal data is permanently erased within 30 days, except billing records which are retained for 7 years to meet tax and legal obligations.

10. Children's Privacy

Our service is not directed to children under the age of 16. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, please contact us and we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and update the "Last Updated" date. For significant changes, we may request renewed consent where legally required.

Continued use of the service after changes constitutes acceptance of the updated policy.

12. Contact and Data Controller

Data Controller:
Serica LLC
1209 Mountain Road PL NE, Suite H
Albuquerque, NM 87110, USA

Privacy inquiries: legal@sericavpn.com
We respond to all privacy inquiries within 72 business hours.

Sv SericaVPN

A privacy-first VPN built for travelers, remote workers and expats. Engineered to keep your stack working in the most restricted networks on earth.

Product
  • Features
  • Pricing
  • Network
  • Download
Company
  • About
  • Beta program
  • Careers
  • Journal
  • Contact
Support
  • Help center
  • Server Status
  • Privacy
  • Terms
  • Dashboard
© 2026 SericaVPN · all rights reserved
Privacy Terms Cookies Refunds