Privacy Policy
This policy explains what Lisar collects, stores, processes and does not retain when you use lisar.io, Lisar Connect applications and Lisar services.
1. Service operator and contact points
Lisar Connect is a product operated by MONTAZERI COMPUTERS & REQUISITES TRADING CO. L.L.C. Privacy requests must be sent to privacy@lisar.io. Legal notices must be sent to legal@lisar.io. Security reports must be sent to security@lisar.io.
2. Data Lisar stores
Lisar uses data minimization and purpose limitation. The current service may store the following categories when they are needed for the applicable product or service flow:
- Account and authentication: UserId, email address, authentication provider, provider subject identifier, account status, and session or token state.
- Installation and application context: InstallationId, ApplicationType, DistributionChannel, ApplicationVersion, ApplicationBuild, and operating-system family.
- Service and profile: ProfileId, PlanId and entitlement status, profile status, expiration date, selected entry and exit routers, DNS feature configuration, and quota or entitlement counters.
- Connection operations: ConnectionSessionId, connection start and end times, connection status, entry and exit router IDs, protocol, uploaded and downloaded byte counts, disconnect reason, and sanitized technical error codes.
- Security and abuse prevention: authentication and security events needed to protect accounts and the service.
- Commerce, support and legal records: where a Website commerce, support, refund, dispute or legal flow is used, Lisar may retain the transaction, correspondence and accounting records required for that flow.
3. Data processed transiently and data Lisar does not retain
Your public source IP may be processed only as necessary for the active request, active VPN connection or real-time security checks. Lisar does not retain historical source IP after that real-time need ends.
To deliver network traffic, Lisar infrastructure may transiently process destination IP addresses, destination domains or URLs where visible to protocol infrastructure, DNS queries when Lisar DNS processing is used, network traffic content and packet payloads, and transferred files, messages or page contents. These are not retained as browsing or traffic history.
Lisar does not retain visited domains, visited URLs, web browsing history, DNS query history, traffic content, packet payloads, Advertising ID, cross-app tracking identifiers, GPS or precise location, contacts, photos, personal files, or message contents as service history.
4. Location
Lisar does not collect GPS or precise location for the current release. A public IP may be used transiently when a routing or security decision requires it, but Lisar does not maintain a persistent source-IP history or IP-derived location profile.
5. Why Lisar processes data
- Authentication and account management.
- VPN, profile, routing and DNS functionality.
- Quota and entitlement enforcement.
- Security and abuse prevention.
- Support and sanitized troubleshooting.
- Payment, refund, dispute and accounting administration where a commerce flow is used.
- Legal retention or disclosure only where required.
Lisar does not sell personal data and does not use service data for advertising, profiling or cross-app tracking.
6. Website cookies and analytics
Microsoft Clarity and Google Analytics 4 are used on the public Lisar Website for traffic measurement, campaign attribution, page interaction analysis, heatmaps, session behavior and Website usability improvement. Analytics storage is optional. Users can accept or reject analytics and reopen Cookie settings in the footer to change the decision. Advertising storage is not approved and advertising personalization is disabled.
Website analytics is excluded from the User Panel, Admin Panel, API, file service, authentication and payment flows, authenticated product flows, VPN configuration pages, and .ovpn contents. Sensitive product, account, payment, authentication, credential and VPN configuration data must not be intentionally captured. The current native Lisar Connect release has no approved analytics SDK, advertising SDK, third-party crash-reporting SDK or diagnostic upload. Provider behavior and Website analytics retention remain subject to the configured provider services and settings.
7. Service providers and sharing
Lisar may use contracted infrastructure, hosting, payment, email, DNS, security and support providers only as necessary to operate the applicable service. Providers are limited to their service role and applicable confidentiality or purpose restrictions. Lisar does not sell service data, does not share it for advertising or profiling, and discloses data to authorities only when legally required.
8. Retention schedule
- Public source IP: not persisted; discarded when the real-time request, active connection or security need ends.
- Connection-session metadata: 30 days.
- Usage and quota counters: the current Plan cycle plus 30 days.
- Sanitized technical errors: 30 days.
- Authentication and security events: 90 days.
- Aggregated non-identifiable operational metrics: up to 12 months.
- Active account, profile and entitlement data: until account/profile deletion or earlier operational expiry.
- Legally required financial records: only for the minimum period required by applicable law, kept separately with restricted access and deleted after the required period expires.
9. Account deletion and privacy requests
Users may request access, correction, deletion or review of their account data by contacting privacy@lisar.io. Information about permanent account deletion is available at lisar.io/account-deletion, which links to the authenticated deletion flow. Permanent deletion revokes sessions and tokens, removes account profiles and operational account data, ends active Plan access and forfeits remaining Plan time or unused service credit. Only legally required financial records may remain for the restricted period described above.
10. Security
Lisar uses access controls, role separation, TLS-protected service endpoints and operational security measures intended to protect account and service data. No internet service can be guaranteed completely secure. Report security concerns to security@lisar.io.
11. Changes to this policy
If Lisar changes the data inventory, retention schedule, approved SDKs, processors or service behavior in a way that affects this policy, the policy and applicable Store privacy declarations must be reviewed and updated before the affected release is submitted or published.
12. Contact
Privacy: privacy@lisar.io. Support: support@lisar.io. Billing: billing@lisar.io. Legal: legal@lisar.io.