Simply Proxies
  • Features
  • Pricing
  • Docs
  • Blog
  • About
  • Sign in / Sign up

Privacy Policy

Last updated: August 2026


1. Introduction

This Privacy Policy describes how Hunt-Benito Ltd. ("Company", "we", "us", "our") collects, uses, and protects your personal data when you use the Simply Proxies service ("Service").

We are committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Data Controller

The data controller responsible for your personal data is Hunt-Benito Ltd., a company registered in Scotland, United Kingdom (company No. SC728400, VAT No. GB435392292).

Registered office: Newseat of Gowanwell, Ellon, Aberdeenshire, AB41 7JQ, United Kingdom.

Privacy contact: privacy@simplyproxies.com (general enquiries: support@simplyproxies.com).

3. What Data We Collect

3.1 Data you provide directly

DataPurposeLegal Basis
Email addressAccount identification, email verification, supportContract performance (Art. 6(1)(b) UK GDPR)
Password (hashed)Account securityContract performance (Art. 6(1)(b) UK GDPR)
Billing details (name, company, address, city, postcode, country, VAT number)VAT-compliant invoicing where you provide themContract performance and legal obligation — VAT (Art. 6(1)(c) UK GDPR)
Proxy credential labelsOrganising your credentialsContract performance (Art. 6(1)(b) UK GDPR)

3.2 Data generated by service use

DataPurposeLegal Basis
Credit balance and historyService delivery, billing recordsContract performance (Art. 6(1)(b) UK GDPR)
Proxy credential pairsService deliveryContract performance (Art. 6(1)(b) UK GDPR)
Traffic volume per credentialUsage tracking, credit deductionContract performance (Art. 6(1)(b) UK GDPR)

3.3 Data collected automatically

DataPurposeLegal Basis
Session cookiesMaintain login state across page loadsLegitimate interest (Art. 6(1)(f) UK GDPR)
Server logs (IP address, timestamps)Security, fraud prevention, abuse defenceLegitimate interest (Art. 6(1)(f) UK GDPR)
Website analytics (self-hosted, cookieless)Aggregate audience measurement (page views, referrer). No cookies, no cross-site tracking, no advertising.Legitimate interest (Art. 6(1)(f) UK GDPR)
Anti-bot challenge (Cloudflare Turnstile)Confirming a human created the account, preventing automated abuseLegitimate interest (Art. 6(1)(f) UK GDPR)

3.4 Data processed by third parties

DataProcessorPurpose
Payment card detailsStripe (PCI Level 1)Payment processing (card never touches our servers)
Payment transactions & billingStripeBilling and invoicing
Payment transactions (PayPal account email, country, amount)PayPalPayment processing for PayPal checkout
Content delivery, DDoS protection, TLS terminationCloudflareServing and securing simplyproxies.com and the customer portal
Anti-bot challenge tokenCloudflare TurnstileConfirming a human at account activation (bot/abuse prevention)

We never see, store, or have access to your card details. All card data is handled directly by Stripe. PayPal processes its own checkout; we receive only the confirmed payment and your PayPal account's country (for VAT allocation).

4. How We Use Your Data

We use your personal data to:

  • Provide and maintain the Service
  • Process payments and manage your credit balance
  • Send service-related emails (verification, security alerts)
  • Prevent fraud and abuse
  • Comply with legal obligations

5. Data Sharing

We do not sell, rent, or trade your personal data.

We share data only with:

  • Stripe — payment processing (Stripe's Privacy Policy)
  • PayPal — payment processing for PayPal checkout (PayPal's Privacy Policy)
  • Cloudflare — content delivery network, security, and TLS termination for simplyproxies.com and the customer portal, plus the Turnstile anti-bot challenge (Cloudflare's Privacy Policy)
  • BetterStack — external uptime monitoring of our public status page (BetterStack Privacy Policy)
  • Law enforcement / regulators — when required by law or to protect our rights

6. Data Retention

Data TypeRetention Period
Account data (email, hashed password)Until account deletion + 30 days
Credit, billing and invoice history6 years (HMRC / VAT Act 1994 requirement for tax records). On account deletion, your personal data is erased but invoice financial records are retained and anonymised so they can no longer be linked to you.
Proxy credentialsUntil account deletion
Usage history (aggregated daily volume)24 months
Server / connection logs (raw metadata, IP)Up to 30 days
Login-attempt records (email, IP)Up to 30 days (security / abuse defence)
Audit log (security events)Up to 12 months
Session cookies24 hours (browser-side)
Email verification tokensUntil verified or re-sent (max 72 hours)

7. Your Rights Under UK GDPR

You have the following rights:

RightDescription
AccessRequest a copy of the personal data we hold about you
RectificationRequest correction of inaccurate data
ErasureRequest deletion of your data. Note: invoice financial records are retained for 6 years as required by UK tax law (UK GDPR Art. 17(3)(b)); all personal data is removed and the records anonymised.
Data portabilityReceive your data in a structured, machine-readable format (a one-click export is available in your Account settings)
RestrictionRequest that we limit how we process your data
ObjectionObject to processing based on legitimate interests
Withdraw consentWithdraw consent where processing is based on consent (our processing is primarily on contract / legal-obligation / legitimate-interest bases, so this right has limited application)

To exercise any of these rights, email privacy@simplyproxies.com. You can also export or delete your data directly from the Account page in the customer portal.

8. Data Security

We implement appropriate technical and organisational measures to protect your data:

  • Passwords: Hashed with industry-standard cryptographic algorithms. Never stored in plain text.
  • Sessions: Server-side sessions with limited expiry, cryptographically random tokens.
  • Payments: Handled entirely by Stripe (PCI Level 1 compliant). Card data never touches our servers.
  • Transport: All connections encrypted via TLS (HTTPS).

9. Cookies

The Service uses the following essential cookies:

  • sp_session — Maintains your login session. Expires after 24 hours. Essential for the Service to function and cannot be disabled.
  • cookie_notice_dismissed — Remembers that you have dismissed the cookie notice. Expires after 1 year. Essential to the notice functioning and cannot be disabled.

We do not use tracking cookies, advertising cookies, or third-party analytics cookies. Our website analytics are cookieless and self-hosted (no data is shared with third-party advertising or analytics networks).

Cloudflare, which provides our content delivery network and security, may set essential technical cookies to protect the site (e.g. bot defence). Cloudflare Turnstile, used only on the account-activation page to confirm you are human, may set a temporary, privacy-preserving token. These do not track you across websites and are not used for advertising.

10. International Data Transfers

Your primary account and billing data is stored and processed on servers located in the United Kingdom (our database and application servers are UK/EU-hosted). Some processors we rely on may transfer data outside the UK:

  • Cloudflare operates a global edge network (TLS termination and security may occur at edge locations outside the UK).
  • Stripe and PayPal are global payment processors headquartered in the United States.
  • BetterStack (uptime monitoring) probes our endpoints from global locations.

Where your data is transferred outside the UK, we ensure appropriate safeguards are in place as required by UK GDPR Chapter V, including the International Data Transfer Agreement (IDTA) or Addendum to the EU Standard Contractual Clauses adopted by the processors concerned. We do not rely on the UK to process data in jurisdictions without such safeguards.

11. Automated Decision-Making

We do not use automated decision-making or profiling that produces legal or similarly significant effects about you (UK GDPR Art. 22). Rate-limiting, anti-bot challenges, and fraud-prevention rules may automatically restrict access in clearly abusive cases, but these do not evaluate personal characteristics and you can request human review by contacting privacy@simplyproxies.com.

12. Children's Privacy

The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by:

  • Posting the updated policy with a new "Last updated" date
  • Sending an email notification for significant changes

14. Contact and Complaints

For privacy-related inquiries or to exercise your data rights:

  • Email our privacy contact: privacy@simplyproxies.com
  • Or write to: Hunt-Benito Ltd., Newseat of Gowanwell, Ellon, Aberdeenshire, AB41 7JQ, United Kingdom

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

  • Website: ico.org.uk
  • Phone: 0303 123 1113

This Privacy Policy is governed by the laws of Scotland.

Simply Proxies

Real UK mobile proxies backed by real devices on UK mobile networks.

Product

  • Features
  • Pricing
  • Documentation

Company

  • About
  • Blog
  • Status
  • Engineering Blog

Legal

  • Terms of Service
  • Privacy Policy

© 2026 Simply Proxies. All rights reserved.

support@simplyproxies.com