Privacy Policy
This policy explains what Lisar processes to provide account access, VPN connection profiles, quota enforcement, payment handling, support and abuse prevention.
1. Service operator and contact points
Lisar is the product name used for the VPN and secure connectivity service available through lisar.io. Privacy requests must be sent to privacy@lisar.io. Legal notices must be sent to legal@lisar.io. Security reports must be sent to security@lisar.io.
2. Data we process
- Account identity data, such as phone number, email address, country/compliance status and account state.
- Connection profile data, such as generated username, profile DNS name, protocol eligibility, plan assignment, runtime options and profile status.
- Authentication and session metadata needed for VPN operation, such as timestamps, NAS/router metadata, assigned VPN IP, protocol, session identifiers, quota counters and connection status.
- Billing and payment records, such as invoice state, selected plan, provider reference, payment status, refunds, adjustments and support history.
- Support, legal, security and abuse correspondence sent to Lisar mailboxes or WhatsApp.
- Operational logs required for reliability, fraud prevention, quota enforcement, troubleshooting, rate limiting, abuse handling and security investigation.
3. Traffic content and DNS handling
Lisar is not designed to inspect user traffic payloads, store the content of user communications, or sell personal data. DNS AdBlock and DNS routing features may process DNS-level operational data where needed to deliver the selected feature, prevent abuse, troubleshoot service issues, and enforce product policy.
4. Why we process data
- To create and secure accounts and connection profiles.
- To authenticate VPN connections through RADIUS and apply the correct plan, quota, speed and runtime policy.
- To provide setup support and respond to user requests.
- To process invoices, payments, refunds and internal service credit adjustments.
- To prevent spam, abuse, fraud, malware, unauthorized access and harmful network activity.
- To comply with lawful requests, enforce terms, and protect Lisar infrastructure and other users.
5. Payment providers and third-party services
Lisar may use third-party providers for payment processing, email delivery, analytics, hosting, DNS, security controls and support tooling. These providers process data only as needed for their service role. Lisar Balance, if offered, is restricted internal service credit only and is not a withdrawable wallet, exchange, remittance product or stored-value account.
Cookies and analytics
Microsoft Clarity and Google Analytics 4 are used on the public Lisar Website for traffic measurement, campaign attribution, page interaction analysis, heatmaps and session behavior, and Website usability improvement. Analytics storage is optional. Users can accept or reject analytics and reopen Cookie settings in the footer to change the decision. Advertising storage is not approved, and advertising personalization is disabled. Analytics is excluded from the User Panel, Admin Panel, API, file service, authentication and payment flows, authenticated product flows, VPN configuration pages, and .ovpn contents. Sensitive product, account, payment, authentication, credential, and VPN configuration data must not be intentionally captured. Provider behavior and retention remain subject to provider services and configured settings.
6. Retention
Operational records are retained only for as long as reasonably needed for service delivery, account management, billing, support, quota accounting, security, dispute handling, abuse prevention and legal compliance. Some records may be kept longer where required to investigate abuse, resolve payment disputes, comply with law or protect the service.
7. User choices and requests
Users may request access, correction, deletion or review of their account data by contacting privacy@lisar.io. Some data cannot be deleted immediately if it is required for billing records, fraud prevention, abuse investigation, security logs or legal compliance.
8. Security
Lisar uses role-separated mailboxes, access controls, service-adapter separation, TLS-protected endpoints and operational security practices appropriate for an MVP launch. No internet service can be guaranteed fully secure. Report security concerns to security@lisar.io.
9. Contact
Privacy: privacy@lisar.io. Support: support@lisar.io. Billing: billing@lisar.io. Legal: legal@lisar.io.