Privacy, Security and GDPR FAQs


Detailed answers on data retention, metadata logging, and our non-storage proxy design for security and compliance teams.

Close-up of a weathered red door with a vertical black and white sign reading 'PRIVATE'.

🔒 QuotaGuard Privacy, Security, and GDPR FAQs

What Personal Information do you collect for my account?

If you are part of our direct service (Subscribed directly via our QuotaGuard site), then we collect your email address (for your account “user name”) and billing information (to be processed and kept at Stripe, we do not store full credit card numbers.).

If you are part of our service from Heroku, then we collect your “app_name” and “owner_email” address from Heroku, no billing information.

If you are part of our service from Amazon Web Services or Microsoft Azure, then we collect your "owner_email" address, no billing information.

If you are part of our IBM or AppDirect service, then we collect the “creator_email” address.

When you contact us via Support, we collect your email address and IP address to verify the authenticity of the requester.

Any details you send us about your account may be stored in our support software and can be deleted upon verified request, subject to legal or operational retention requirements.

Do you collect any private data that you don’t need to run your service?

We collect personal data sufficient to run the service for you, improve it over time, and support our customers successfully.

That means we don’t collect additional or unnecessary private data beyond the information described above.

We do not intentionally store or log request or response bodies.

We store limited operational metadata needed to operate, secure, troubleshoot, and bill for the service.

For QuotaGuard Shield HTTPS traffic, this metadata may include account identifier, source IP, destination host and port, proxy identifier, timestamp, status code, method, proxy type, byte counts, and related routing information.

Shield HTTPS traffic does not expose request paths, query strings, headers, cookies, authorization headers, response headers, or bodies to the proxy in ordinary operation.

For plain HTTP proxy requests, the proxy may need to read and log the full destination URL, including path and query string, as part of normal HTTP proxy operation.

Customers must not transmit PHI, personal data subject to a Data Processing Addendum, or other sensitive payloads over plain HTTP.

This is a contractual requirement under QuotaGuard's Terms of Service and any executed Data Processing Addendum, not only a technical recommendation.

Finally, we do not intentionally store PII about your end users.

The personal data we collect is limited to the customer/account information needed to provide the service, such as account email, billing records, support communications, and marketplace account details such as Heroku app name and owner email when applicable.

Describe the journey of my packets via your QuotaGuard system from my application to its destination. What services does it touch and what is left behind after my request has passed through your system?

Requests are routed through QuotaGuard proxy infrastructure running on AWS.

Depending on the product and configuration, traffic may pass through AWS load balancing and QuotaGuard proxy servers before reaching the destination selected by the customer.

QuotaGuard stores limited operational metadata needed to operate, secure, troubleshoot, and bill for the service.

The exact metadata depends on whether the customer is using QuotaGuard Static, QuotaGuard Shield, inbound traffic, outbound traffic, HTTPS, or plain HTTP.

For QuotaGuard Shield HTTPS traffic, customer application payload contents are not decrypted at the proxy in ordinary operation.

Do you see our data as it goes through the proxy?

For QuotaGuard Shield HTTPS traffic, QuotaGuard does not decrypt customer application payload contents in ordinary operation and does not receive customer private keys or certificates required to decrypt those payloads.

For QuotaGuard Static and plain HTTP proxy traffic, the proxy architecture is different.

Customers should use HTTPS, TLS, QuotaGuard Shield, or equivalent encryption where sensitive data is involved.

Please keep in mind that customers are responsible for securing their applications, endpoints, credentials, certificates, and data in transit.

What Personal Information do you collect when my data uses your proxies?

For proxy traffic, QuotaGuard stores limited operational metadata needed to operate, secure, troubleshoot, and bill for the service.

For QuotaGuard Shield inbound HTTPS traffic, the proxy operates at the TCP/TLS routing layer.

We log operational metadata such as frontend, backend, server identifier, byte counts, termination state, session time, client IP and port, and SNI hostname used for routing.

Shield inbound HTTPS traffic does not expose request paths, query strings, HTTP methods, headers, cookies, or bodies to the proxy in ordinary operation.

For QuotaGuard Shield outbound HTTPS traffic, the proxy uses CONNECT semantics.

We log the destination host and port and related operational metadata.

Request paths, query strings, headers, cookies, authorization headers, response headers, and bodies remain inside the TLS session between the customer’s application and the destination and are not visible to the proxy in ordinary operation.

For plain HTTP proxy traffic, the proxy may need to read and log the full destination URL, including path and query string, as part of normal HTTP proxy operation.

Customers must not transmit PHI, personal data subject to a Data Processing Addendum, or other sensitive payloads over plain HTTP.

This is a contractual requirement under QuotaGuard's Terms of Service and any executed Data Processing Addendum, not only a technical recommendation.

Plain HTTP proxy requests may expose the full destination URL, including path and query string, as part of normal proxy operation.

Customers should not place PHI or other sensitive information in hostnames, domains, proxy labels, endpoint labels, account names, URLs, query strings, headers, support tickets, screenshots, or other metadata fields.

Hostnames and domains are customer-controlled metadata and may be visible to QuotaGuard and other infrastructure providers as part of normal routing.

What data do we store in the clear / unencrypted?

We store account information needed to authenticate users, operate the service, and provide support.

Direct login passwords are stored using password hashing.

Proxy credentials are stored in a form required for proxy authentication and should be treated as sensitive credentials by customers.

How long do you store log data?

For QuotaGuard Shield traffic logs, we write operational metadata to an active AWS DynamoDB store with a time-to-live target of sixty (60) days after insertion.

Actual deletion occurs through AWS DynamoDB TTL background processing after expiration and may occur after the sixty-day target.

Shield traffic logs are retained only in the active DynamoDB store and are not separately backed up, archived, or exported to secondary storage unless we separately agree in writing.

Other records, including account records, billing records, support communications, and administrative records, are separate from Shield traffic logs and may be retained for longer periods where needed to operate the service, meet legal obligations, resolve disputes, prevent abuse, or maintain business records.

The retention period for those records depends on the record type and applicable legal or operational requirements.

Customers should not place PHI or other sensitive information in hostnames, domains, proxy labels, endpoint labels, account names, URLs, query strings, headers, support tickets, screenshots, or other metadata fields.

Hostnames and domains are customer-controlled metadata and may be visible to QuotaGuard and other infrastructure providers as part of normal routing.

What do you share with marketers or other advertising and non essential companies?

We may use aggregated, de-identified operational data to understand service usage, improve reliability, plan capacity, and operate the business.

We do not sell or rent personal data to third parties for marketing purposes.

Is QuotaGuard GDPR Compliant?

QuotaGuard acts as a data processor for customer data transmitted through the QuotaGuard service, processing that data only on the instructions of the customer as data controller.

QuotaGuard maintains a Data Processing Addendum that incorporates the 2021 Standard Contractual Clauses for customers transferring personal data from the European Economic Area, the United Kingdom, or Switzerland.

Customers requiring a DPA should contact us at support@quotaguard.com.

For a full description of our privacy practices, data collection, and compliance posture under GDPR, CCPA, and other applicable regulations, please read our Privacy Policy.

All users must read and acknowledge the Privacy Policy to use our service.

If I'm based in the EU, does my data leave the EU?

We are a global company serving customers around the world and our infrastructure reflects that mission.

As a reflection of this mission, a majority of our services are outside the EU.

Even if you choose a EU-based proxy, there is a chance that your data may leave the EU in order for us to adequately provide our service to you and your clients.

We obviously have no control over whether a company or customer chooses to send data via our proxies outside the EU.

If you have specific data residency requirements, contact us at support@quotaguard.com.

Customers with data residency requirements must enter into a Data Processing Addendum and, where applicable, a Data Residency Addendum identifying the covered configuration, regions, and applicable limitations.

Data residency commitments are not available on standard plans and require Enterprise pricing and a written agreement.

How do we request to have our information deleted or ported to another service?

Simple, send us an email at Support and we’ll verify your identity (we don’t want your competitors tricking us into deleting your account now, do we?) and either port or delete your data as requested.

If I want to request to be ‘forgotten’ or deleted, what data would we delete and would we have to likely keep for legal reasons?

We mark all of your data as “removed” in our database and it will be deleted within 30 days.

Your payment information and transactions (if relevant) is kept at Stripe for tax and reporting purposes.

Can you send us a Data Protection Agreement?

Yes.

Customers requiring a Data Processing Addendum should contact us at support@quotaguard.com.

Execution of a DPA requires a written agreement signed by authorized representatives of both parties.

Payment of any subscription fee alone does not create DPA coverage.

What is the relationship between my Heroku account and QuotaGuard?

If you are using our service via a Heroku Addon, Heroku only “assists with the provisioning and billing of the add-ons”.

They do not make any contractual representations for third-party add-ons as they do not manage them (for example, QuotaGuard) directly, therefore “We (Heroku) direct customers to work with third-party add-on providers to negotiate any contractual terms (including GDPR)”.

If you need a Data Processing Agreement with QuotaGuard as a Heroku user, please contact us at Support.

Does QuotaGuard have a SOC 2 report, HITRUST certification, or ISO 27001 certification?

Not currently.

QuotaGuard plans to pursue a SOC 2 examination in late 2026. Please contact support@quotaguard.com for the latest information, as our compliance status and timeline may change.

As of early 2026, QuotaGuard does not currently maintain a SOC 2 report, HITRUST certification, AT-C 315 report, ISO 27001 certification, or equivalent third-party assurance report.

Upon reasonable written request and subject to confidentiality, we will respond to security questionnaires and provide available security documentation.

Customers requiring third-party audit certifications should assess whether QuotaGuard's current security posture meets their requirements before subscribing.

Still have questions?

We don’t outsource Support to non-Engineers.

Reach out directly to the Engineers who built QuotaGuard to discuss your specific architecture, integration challenges, or compliance constraints here 👇

Trusted by Engineering Teams Everywhere

Reliability Engineered for the Modern Cloud

For over a decade, QuotaGuard has provided reliable, high-performance static IP and proxy solutions for cloud environments like Heroku, Kubernetes, and AWS.

Get the fixed identity and security your application needs today.