PRIVACY POLICY
Last updated: July 16, 2026
Contents
- 1. Introduction
- 2. Our no-logs commitment
- 3. Personal data we process
- 4. How we use your personal data
- 5. Sharing your personal data
- 6. Data security
- 7. Data retention and deletion
- 8. Your privacy rights
- 9. Your marketing choices
- 10. Children’s data
- 11. Do Not Track signals
- 12. Updates to this Privacy Policy
- 13. Contact us
1. Introduction
This document (“Privacy Policy”) explains how TrinitariaVPN (“we,” “us,” or “our”) collects, uses, protects, discloses, and deletes your personal data when you download and use our mobile application, or use any other application of ours that links to this Privacy Policy (together, the “Services”).
We are responsible for making decisions about how your personal data is processed. We built our Services to need as little information about you as possible, and we collect only the bare minimum required to create your account, take your payment, and keep the Service running. We do not log any VPN traffic or usage details. What we do collect, why we collect it, and how long we keep it are described in full below.
If you do not agree with the practices described in this Privacy Policy, please do not use our Services. If you have questions or concerns, contact us at support@trinitaria.tech.
About the summaries in this document. Most sections below open with a short “Summary” written in everyday language to help you understand what the section says. These summaries are not legally binding and are not a substitute for the full text of the section. Where a summary and the full text differ, the full text governs.
2. Our no-logs commitment
Summary
We do not keep records of what you do while connected to our VPN. An independent audit confirmed this. The only exception is your IP address, which is kept briefly in hashed form for billing.
We do not log any VPN traffic or usage details. When you connect to our VPN service, we do not monitor, record, or store your browsing activity, connection timestamps, bandwidth usage, DNS queries, or the content of your communications. Our VPN infrastructure has been independently audited to confirm that no traffic logs are kept.
IP address handling. User IP addresses are only stored for a limited period in a hashed (non-reversible) form solely for billing purposes. This means your actual IP address cannot be recovered or linked back to your browsing activity.
3. Personal data we process
Summary
We collect the account details you give us when you sign up, basic technical information needed to support your account across devices, and limited payment metadata. Your full card number and security code go to our payment processor and never reach our servers. We do not process sensitive data.
The personal data we collect depends on how you interact with us and the Services, the choices you make, and the features you use. All personal data that you provide to us must be true, complete, and accurate, and you must notify us of any changes to it.
Information you provide to us
We collect personal data that you voluntarily provide when you register on the Services, participate in activities on the Services, or otherwise contact us. This may include:
- Email addresses
- Usernames
- Passwords
- Debit/credit card numbers
- Billing addresses
Technical and account information
To provide technical support, improve service reliability, and manage your account across devices, we also collect:
- Device information — device name, operating system version, and app version, used for troubleshooting and ensuring compatibility.
- Connected devices — a list of devices logged into your account, so you can manage your sessions. This list is deleted from our database when you log out from a device or when your account is deleted.
- User preferences — your favorite servers and recent connections, synced across your devices for convenience.
- Support communications — messages you submit through our Contact Us or Feedback features, used to respond to your requests.
- Consent records — when you accept our Terms of Service and Privacy Policy at sign-up, we record the version you accepted, a timestamp, and the IP address from which the acceptance was submitted. This is retained as proof of consent for legal compliance.
- Trial usage flag — a boolean marker on your profile that records whether you have ever used our free trial. Used to determine whether you are eligible for a new trial and to prevent free-trial abuse.
This information is needed to maintain the security and operation of our application and for troubleshooting.
Payment data
When you make a purchase, your full card number and security code are transmitted directly to Azul, our payment processor, and are never stored by TrinitariaVPN. We only store non-sensitive information needed to display your saved payment methods and process recurring billing: the first six digits of your card (BIN), the last four digits, the card brand (Visa, Mastercard, American Express, Discover), the expiration date, the cardholder name, and an opaque payment token issued by Azul. This limited payment metadata is reported to us by Azul in the payment callback.
Payments made through Google Pay (Android) or Apple Pay (iOS) are also processed by Azul; the wallet returns a tokenized payment credential directly to Azul, which we never see in cleartext. You may find Azul’s privacy notice at: azul.com.do (https://www.azul.com.do/Documents/WEB-AZUL-POLITICAS-SEGURIDAD.pdf).
Anti-abuse fingerprints
Summary
To stop the same person from claiming the free trial over and over, we store one-way hashes of your email and card details, separately from your profile. These hashes cannot be turned back into your original data, and we keep them even after your account is deleted. You can ask us to remove them.
When you sign up for a free trial, we compute two one-way SHA-256 hashes (each combined with a server-side secret before hashing):
- A hash of your email address (normalized to lower case).
- A hash of your card’s BIN (first six digits), last four digits, and expiration month and year, as reported to us by Azul in the payment callback.
These hashes are stored in a separate ledger table that is not linked to your customer ID or profile. Because SHA-256 is a one-way function, the original email address and card details cannot be reconstructed from the hash. We use these hashes only to check whether the same email or card has previously been used to start a free trial, so that we can enforce our “one free trial per person” policy.
These hashes are retained indefinitely, even after your personal profile is deleted (see “Data retention and deletion” below). Retaining anonymous hashes with no link back to your identity does not identify you personally; it only allows us to recognize a card or email that has already used its trial. If you want your hashes removed from this ledger, you may contact us using the email address in “Contact us” below.
Sensitive data
We do not process sensitive personal data such as health, biometric, religious, political, or genetic data. Sensitive card data (full card number and CVV) is handled exclusively by Azul and is never stored on our servers.
Notifications
The application may display notifications about the status of your VPN connection, such as when the connection is active, disconnected, or revoked. These notifications are generated locally on your device by the app itself; they do not involve collecting or transmitting personal data. If you do not wish to receive them, you may turn them off in your device’s settings.
4. How we use your personal data
Summary
We use your data to run your account, respond to you, keep the Service secure, prevent free-trial abuse, and meet our legal obligations. We use it for marketing only in line with your preferences, and you can opt out at any time.
We process your personal data for the following purposes:
- To facilitate account creation and authentication and otherwise manage user accounts, so you can create and log in to your account and keep it in working order.
- To process payments and manage your subscription, including recurring billing, displaying your saved payment methods, and determining your free-trial eligibility.
- To prevent fraud and abuse, including enforcing our one-free-trial-per-person policy as described under “Anti-abuse fingerprints” above.
- To respond to your support requests and to request feedback, and to contact you about your use of our Services.
- To send you marketing and promotional communications, where this is in accordance with your marketing preferences. You can opt out of our marketing emails at any time.
- To evaluate and improve our Services, products, marketing, and your experience.
- To comply with our legal obligations, respond to legal requests, and exercise, establish, or defend our legal rights.
5. Sharing your personal data
Summary
We share your data only with the three providers we need to run the Service — Supabase, Azul, and Resend — and potentially with a buyer if our business is sold.
Service providers. We use trusted third-party services to operate and improve our Services. These providers may process your personal data on our behalf:
- Supabase. We use Supabase as our backend infrastructure for account management, data storage, and user preferences syncing. For more details, please read the Supabase Privacy Policy (https://supabase.com/privacy).
- Azul. We use Azul as our payment processor to handle and store payment transactions. For more details, please read the Azul Privacy Policy (https://www.azul.com.do/Documents/WEB-AZUL-POLITICAS-SEGURIDAD.pdf).
- Resend. We use Resend as our email service provider for account-related communications, including password reset codes, account confirmations, and support notifications. Your email address is shared with Resend solely for the purpose of delivering these communications. For more details, please read the Resend Privacy Policy (https://resend.com/legal/privacy-policy).
Business transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
6. Data security
Summary
We use organizational and technical measures to protect your data, but no system can be guaranteed completely secure.
We have implemented appropriate and reasonable technical and organizational security measures designed to protect the security of any personal data we process. However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information. Although we will do our best to protect your personal data, transmission of personal data to and from our Services is at your own risk. You should only access the Services within a secure environment.
7. Data retention and deletion
Summary
We keep your personal data only as long as your account is active or a recovery window allows. After that, an automated process anonymizes your account. The anonymous anti-abuse hashes are the one thing we keep indefinitely.
Active subscription. While you have an active subscription (trialing, active, cancelled with time remaining, or past-due within the 14-day grace period), we retain your profile, saved payment methods, and connected devices for as long as they are needed to provide the Service.
Cancelled free trial. If you cancel your free trial, you enter a 14-day recovery window. During that window your profile is retained so that you can log back in and purchase a plan to keep your account. If you do not purchase a plan within 14 days of cancellation, an automated process will:
- Replace your email address in our authentication system with a randomly-generated anonymous value.
- Overwrite your profile name and username fields with anonymized values.
- Permanently delete your saved payment methods and connected-device records.
- Close your VPN account with our infrastructure provider so it cannot be used to authenticate.
Past-due paid subscription. If a renewal charge fails, your subscription is marked past-due and you have 14 days to update your payment method through the app. If 14 days pass without a successful charge, the same anonymization process described above runs against your account and your VPN access is permanently revoked.
Anti-abuse fingerprints. The SHA-256 hashes described under “Anti-abuse fingerprints” above are retained even after the anonymization described in this section runs. They are stored in a separate table with no reference to your customer ID and cannot be reversed back into your email or card details. Their sole purpose is to prevent the same person from repeatedly claiming a free trial.
Backups and legal holds. We may retain limited information in secure backups or as required by tax, accounting, fraud-prevention, or other legal obligations. When we have no ongoing legitimate need to process your personal data, we will either delete or anonymize it. If information has been stored in backup archives that cannot be selectively purged, we will securely isolate it from any further processing until deletion is possible.
8. Your privacy rights
Summary
Depending on where you live, you can ask us to show you your data, correct it, or delete it, and you can withdraw your consent. Email us and we will act on your request.
Based on the applicable laws of your country, province, or state of residence, you may have the right to request access to the personal data we collect from you, to receive details about how we have processed it, to correct inaccuracies, or to delete your personal data. You may also have the right to withdraw your consent to our processing. These rights may be limited in some circumstances by applicable law.
Withdrawing your consent. If we are relying on your consent to process your personal data, you have the right to withdraw your consent at any time by contacting us using the details in “Contact us” below. Withdrawing consent will not affect the lawfulness of the processing before its withdrawal nor, when applicable law allows, will it affect processing conducted in reliance on lawful grounds other than consent.
Reviewing or changing your account. If you would at any time like to review or change the information in your account, you can log in to your account settings and update it.
Deleting your account. Upon your request to terminate your account, we will deactivate or delete your account and information from our active databases, as described under “Data retention and deletion” above. However, we may retain some information to prevent fraud, troubleshoot problems, assist with any investigations, enforce our legal terms, and/or comply with applicable legal requirements.
How to exercise your rights. The easiest way to exercise your rights is by emailing us at support@trinitaria.tech. We will consider and act upon any request in accordance with applicable data protection laws.
9. Your marketing choices
Summary
You can unsubscribe from marketing emails at any time. We will still send you essential messages about your account.
You can unsubscribe from our marketing and promotional communications at any time by clicking on the unsubscribe link in the emails that we send, or by contacting us using the details in “Contact us” below. You will then be removed from the marketing lists. However, we may still communicate with you — for example, to send you service-related messages that are necessary for the administration and use of your account, such as password reset codes and account confirmations.
10. Children’s data
Summary
Our Services are for adults. You must be at least 18 to have an account.
Our Services are not directed to children. As set out in our Terms of Service, you must be at least 18 years of age to create an account and use the Service, and by registering you represent that you meet this age requirement. We do not knowingly collect personal data from anyone under 18. If you believe that a person under 18 has provided us with personal data, please contact us using the details in “Contact us” below so that we can take appropriate action.
11. Do Not Track signals
Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track (“DNT”) feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage, no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this Privacy Policy.
12. Updates to this Privacy Policy
Summary
We will update this policy as needed and tell you when the changes are significant.
We may update this Privacy Policy from time to time. The updated version will be indicated by an updated “Last updated” date at the top of this Privacy Policy. If we make material changes to this Privacy Policy, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. We encourage you to review this Privacy Policy frequently to be informed of how we are protecting your information.
13. Contact us
If you have questions or comments about this Privacy Policy, or wish to exercise any of the rights described above, you may reach us at:
TrinitariaVPN
Email: support@trinitaria.tech Phone: 809 961 6711 Address: Carr. Presa De Tavera, El Mamey 41000, Dominican Republic