Privacy Policy

v1 · Effective 2026-04-27 · Operated under Washington (US) law

ViaductCDN is built around the idea that we should hold as little information about you as possible while still running a useful service. This page enumerates exactly what we collect, what we don’t, who sees it, and how to ask us to delete it. Plain English.

Two trust positions to keep separate. As a TLS-terminating CDN, we see plaintext bytes flowing through our edge in real time (URLs, headers, cookies, request and response bodies). We do not log bodies, but we can see them in flight. That’s the same trust position you give Cloudflare or any other CDN. The privacy story below is about what we persist — not what we observe.

What we collect

If you sign up with email

If you sign up anonymously

If you have any account

If you pay

Edge access metadata

When traffic flows through our edge, we keep request metadata for billing and abuse triage:

What we don’t collect

How long we keep things

WhatHow longWhy
Edge access metadata 90 days Billing reconciliation + abuse triage window.
Audit log 7 years US business-records norms.
Cryptocurrency deposit records 10 years US AML recordkeeping norms (we are not a money services business but we treat the records to that standard).
Site configuration + secrets Lifetime of the account Required to keep your sites running.
Account record Until you delete the account, then 30 days for accidental-deletion recovery, then permanent. Operational convenience for you.

Who else sees what

We use third-party services to operate the platform. Each is named here along with what it sees. We do not share your data with anyone outside this list, except where compelled by valid lawful process (see /abuse for our policy on legal requests).

ProcessorSeesWhere
Microsoft Azure Encrypted-at-rest data; metadata about resource usage. Used as our infrastructure provider (compute, storage, DNS, Key Vault). USA (East US region)
SendGrid (Twilio) Email addresses and message content of any email we send (password reset, account alerts, onboarding). USA
Buttondown Email addresses (and names, if you provide them) of newsletter subscribers, plus the subject and body of broadcasts we send through it. Used only if you opt in to the newsletter at newsletter.viaductcdn.com; never populated from your account data. Open- and click-tracking are disabled at the account level. USA
Stripe Card details, your name and address as supplied to Stripe’s checkout. Stripe is the merchant of record for card transactions. USA + Stripe’s global operations
BTCPay (self-hosted) Cryptocurrency invoice metadata. We run this ourselves on Azure infrastructure; it is not a third-party SaaS, but listed here for transparency. USA (East US, on our Azure subscription)
Let’s Encrypt Your custom domain hostnames (during certificate issuance). USA

We will update this list before adding any new processor and announce the change via in-portal notification.

Cookies

We use exactly one cookie: vd_session, set on the portal after successful login. It is strictly necessary for the service to function (it’s how we know you’re still logged in). It expires when your session ends.

No analytics cookies, no advertising cookies, no third-party cookies. Because the only cookie we set is strictly necessary under GDPR, we don’t show a cookie consent banner. If you’d like to verify this, your browser’s developer tools will show you exactly what we set.

Do Not Track

We have no third-party tracking to disable, so the DNT signal is moot for us. We respect it in the sense that we never started in the first place.

Your rights

Wherever you live, you can do the following from your account:

EU/UK residents have additional rights under GDPR (objection to processing, restriction of processing, data portability) and California residents under CCPA. To exercise any of these, email legal@viaductcdn.com. We respond within 30 days.

Breach notification

In the event of a security breach affecting your data, we will notify you (via in-portal notification and, where applicable, email) within 72 hours of confirming the breach. We will also publish an incident summary on /transparency. This matches GDPR’s 72-hour standard regardless of where you live.

Children

ViaductCDN is not intended for users under 13. We do not knowingly collect personal information from children under 13. If you believe a child has used the service, email legal@viaductcdn.com and we will delete the account.

Changes to this policy

We will announce material changes via in-portal notification and, where applicable, by email, at least 14 days before they take effect. The current version is always at /privacy; each version is timestamped at the top.

Contact

Privacy questions: legal@viaductcdn.com. Account/operational support: support@viaductcdn.com. Service of process: Inertial Navigation LLC, 626 NW 87th St, Seattle, WA 98117, USA.