1. Data controller
This policy covers personal data processed when you use https://vpnadvisor.net, operated by VPN Advisor ("we", "our site"). We act as the data controller under the relevant data-protection laws (including Türkiye's KVKK and, where applicable, the EU GDPR).
2. What data we process
2.1. Automatic technical data (server logs)
Our Hostinger hosting infrastructure may process standard web server logs needed to deliver and protect the site:
- IP address
- Browser type and version (User-Agent)
- Access date/time
- Requested URL
- HTTP response code
Hostinger controls the infrastructure-level retention and security settings for these records. VPN Advisor does not use server logs to build advertising or behavioural profiles.
2.2. Analytics (Google Analytics)
We use Google Analytics 4 to measure site traffic, running with Google Consent Mode v2:
- before you consent on the cookie banner, analytics storage remains denied; the Google tag may send cookieless Consent Mode signals
- on "Accept" the
_gacookies are set; on "Decline" none are set - aggregated page views, approximate location, device and browser
- the processor is Google LLC; data may be transferred to the US
Analytics data is used to evaluate the site's performance. See the Cookie Policy for details.
2.3. Per-article readership counter
After a blog article remains visible for at least 8 seconds, its aggregate readership total may increase once. To suppress repeated refreshes, the IP address, User-Agent and language signal are immediately HMACed on our server with a secret key into a daily rotating pseudonymous token. Raw IP or browser signals are not written to the counter store; the token expires within 48 hours. Only the aggregate total remains. This counter uses no cookie or localStorage.
2.4. Contact email
If you email us, the contents and address of your message are processed solely to respond. After the reply, the message is not processed further, but it may be retained for up to 1 year as a business record.
2.4. Interactive diagnostic tools
Tool results are returned with no-store response headers and are not intentionally saved in a VPN Advisor account or database. Some checks require limited server-side or third-party processing:
- Email Security Check: the full address is sent to our server for validation. The domain is queried for live MX, SPF and DMARC records. A breach lookup is sent server-to-server to Have I Been Pwned when configured, otherwise to XposedOrNot. We return a masked address and do not intentionally retain the submitted address or result.
- VPN/IP Diagnostic: the public IP already visible to the site may be sent to ipapi.is for network, ASN, approximate location and VPN/proxy classification. VPN Advisor does not intentionally retain the lookup result.
- Homepage Internet Snapshot: the public IP may be sent server-to-server to ipwho.is to resolve an approximate country, city, capital and time zone for the location preview. The lookup is used for that response only and is not intentionally retained by VPN Advisor; GPS permission is never requested.
- Browser diagnostics: DNS and speed checks contact Cloudflare endpoints as disclosed on the relevant tool page. WebRTC checks run in the browser. Each result describes a limited signal, not a security certification.
Do not submit an email address unless you agree to that limited data flow. The relevant third party's privacy terms also apply to its processing.
3. Why we process data (legal basis)
- Server logs: legitimate interest (security and abuse prevention).
- Google Analytics storage: consent (GDPR Art. 6(1)(a) and KVKK explicit consent via the cookie banner). Storage remains denied unless you accept; limited cookieless Consent Mode signals may still be sent.
- Article readership counter: legitimate interest in understanding aggregate content performance and preventing artificial repeats; it is not used for reader profiling or ad targeting.
- Contact email: contract/precontract necessity (answering your request).
- Diagnostics: your request to run the selected tool and our legitimate interest in preventing abuse and returning a reliable result.
4. Data sharing
We do not sell personal data. Delivering the site and requested tools involves these service providers:
- Hostinger (web hosting) — processes server logs. Standard data-processing agreement.
- Google — processes consent-state signals and, if you accept analytics storage, measurement data. Data may be transferred to the US under Google's published safeguards.
- Google AdSense — serves and measures advertising according to your consent choices and Google's policies.
- Configured Redis service — stores only the aggregate article total and a short-lived, irreversible pseudonymous token; no raw IP address is sent to that store.
- Have I Been Pwned or XposedOrNot — receives the submitted email address only when you run the breach check.
- ipapi.is — receives the public IP when the VPN/IP diagnostic requests network classification.
- ipwho.is — may receive the public IP for the homepage location and local-time preview.
- Cloudflare — provides endpoints used by the DNS and speed diagnostics.
Our pages display Google AdSense ads; AdSense may use cookies to serve and measure ads (details in our cookie policy). When you click a VPN provider link you go directly to the provider's official site; from that point on the provider's own privacy policy applies.
5. Your rights
Under applicable data-protection law you have rights including:
- Knowing whether your personal data is being processed
- Requesting information about the processing
- Learning the purpose of the processing and whether the data is used for that purpose
- Learning which third parties (domestic or abroad) the data is transferred to
- Requesting correction of incomplete or inaccurate processing
- Requesting deletion or destruction of the data
- Objecting to automated analysis outcomes
- Requesting compensation for harm
To exercise these rights, reach us via the contact page.
6. Data security
Server traffic is protected with HTTPS. HTTP headers include HSTS, Content Security Policy, frame restrictions and MIME-sniffing protection. Strictly necessary preference storage and consent-based Google cookies may be used as described in the Cookie Policy; no security control can reduce risk to zero.
7. Policy updates
We may update this policy from time to time. Significant changes are indicated by the "Last updated" date at the top of the page.