Privacy Policy

Last Updated: September 3, 2026

At Nstdata, data is our business, which is exactly why we take privacy seriously. NST LABS TECH LTD ("Nstdata", "we", "us", or "our"), a company incorporated in Hong Kong, operates the website at https://nstdata.io and provides the Nstdata platform, APIs, dashboard, SDKs, proxy network, crawling infrastructure, routing tools, support, and related services (collectively, the "Services").

This Privacy Policy explains what personal information we collect, how we use it, how we share it, how we use cookies and similar technologies, and the choices and rights you may have. We design our privacy practices to align with applicable privacy laws, including the EU General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"), and other privacy laws where they apply.

Nstdata was formerly known as Nstproxy. The operating legal entity is unchanged.

Scope and roles

This Privacy Policy applies to personal information we process when you visit our websites, create or use an account, purchase or use the Services, contact support, receive communications from us, or otherwise interact with Nstdata.

For account, billing, website, security, analytics, marketing, and business operations data, Nstdata generally acts as the controller or business responsible for determining why and how personal information is processed.

If you use the Services to collect, submit, route, crawl, extract, or process personal information from third-party websites or other sources, you are responsible for that data and for ensuring that you have all rights, permissions, notices, consents, and lawful bases required for your use. Where Nstdata processes personal information on your behalf as a processor or service provider, that processing is governed by our Data Processing Agreement ("DPA"), if applicable.

Information we collect

We may collect the following categories of information:

  • Account and contact information, such as name, email address, company name, job title, phone number, country, billing address, account credentials, and workspace settings.

  • Billing and transaction information, such as plan, subscription, invoices, tax information, payment status, credits, balance, usage charges, refunds, and payment method details. Full payment card details are generally processed by our payment processors, not stored directly by Nstdata.

  • Identity and compliance information, such as business verification details, identity-verification documents, sanctions or fraud-screening information, and other information required for KYC, abuse prevention, legal compliance, or risk management.

  • Service usage and log data, such as API keys, request metadata, target domains or URLs, proxy type, routing settings, bandwidth, request counts, status codes, timestamps, IP addresses, device identifiers, browser type, operating system, pages visited, time on page, session data, errors, latency, crawl settings, output formats, and security logs.

  • Communications information, such as support tickets, emails, chat messages, call notes, survey responses, attachments, and other information you choose to provide.

  • Cookies and similar technology data, as described below.

  • Customer-provided data and outputs, such as URLs, crawl instructions, configuration, files, logs, and outputs generated through the Services, to the extent they contain personal information.

We collect information directly from you, automatically from your use of the website and Services, from your organization or Authorized Users, from service providers such as payment processors and analytics providers, and from public or commercially available sources where lawful.

How we use information

We use personal information to:

  • create, operate, secure, and manage your account;

  • provide, maintain, troubleshoot, and support the Services;

  • process payments, subscriptions, credits, refunds, taxes, invoices, and billing;

  • verify identity, conduct compliance screening, detect fraud, prevent abuse, and enforce our Terms of Use and Acceptable Use Policy;

  • monitor performance, reliability, security, and usage of the Services;

  • provide documentation, support, notices, service updates, security alerts, and administrative messages;

  • improve, analyze, develop, and measure the effectiveness of our website, products, Services, and support;

  • personalize settings and remember preferences;

  • send marketing communications where permitted by law, with opt-out options where required;

  • comply with legal obligations, respond to lawful requests, protect rights and safety, and resolve disputes; and

  • carry out other purposes disclosed to you at the time of collection.

Where GDPR or similar laws apply, our legal bases may include:

  • performance of a contract, including providing the Services, account access, support, billing, and customer communications;

  • legitimate interests, including securing, improving, analyzing, and operating the Services; preventing fraud and abuse; enforcing agreements; and communicating with business users;

  • legal obligations, including tax, accounting, sanctions, KYC, law-enforcement, and regulatory obligations; and

  • consent, where required, including for certain cookies, marketing communications, or optional processing.

You may withdraw consent where processing is based on consent, but this will not affect processing that occurred before withdrawal or processing based on other lawful grounds.

How we share information

We do not sell your account personal information for money. We may share personal information with:

  • service providers and processors that help us provide hosting, infrastructure, analytics, security, payment processing, customer support, communications, compliance screening, fraud prevention, and business operations;

  • affiliates, contractors, advisors, auditors, insurers, and professional service providers;

  • your organization, administrators, or Authorized Users where your account is part of a business workspace;

  • law enforcement, regulators, courts, government authorities, rights holders, infrastructure providers, payment processors, or affected third parties where legally required or reasonably necessary to protect rights, safety, security, network integrity, or prevent abuse;

  • parties involved in a merger, acquisition, financing, reorganization, sale of assets, or similar business transaction; and

  • other parties with your direction, consent, or as otherwise disclosed at the time of collection.

We require service providers to protect personal information and use it only for authorized purposes.

Cookies and similar technologies

We use cookies and similar technologies on our websites and Services. Cookies are small text files placed on your device that help websites function, remember preferences, understand usage, improve performance, secure accounts, and measure campaigns.

We may use:

  • strictly necessary cookies, required for the website, dashboard, security, authentication, and core functionality;

  • preference cookies, which remember settings and choices;

  • analytics cookies, which help us understand and improve website and Service usage; and

  • marketing cookies, where enabled, to measure campaigns and deliver or evaluate relevant communications.

Where required by law, we provide a cookie banner or preference tool to accept, reject, or manage non-essential cookies. You may also manage cookies through your browser settings. Some cookies are set by third-party providers, whose processing may be governed by their own policies.

International transfers

Nstdata is based in Hong Kong, and we may process, store, or transfer personal information in Hong Kong and other jurisdictions where we, our affiliates, or our service providers operate. These jurisdictions may have data protection laws different from those in your location.

Where required, we use lawful transfer mechanisms, such as Standard Contractual Clauses, contractual safeguards, adequacy decisions, or other mechanisms recognized by applicable law.

Security

We use reasonable administrative, technical, and organizational measures designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure. These measures may include access controls, encryption, logging, monitoring, vulnerability management, internal policies, and vendor controls.

No system is perfectly secure. If you believe you have found a security issue or vulnerability, please contact privacy@nstdata.io or security@nstdata.io.

References to ISO 27001, SOC 2, or similar standards should be included only if the relevant certification, report, or alignment statement has been confirmed for Nstdata.

Retention

We retain personal information for as long as reasonably necessary to provide the Services, maintain accounts, process payments, comply with legal, tax, accounting, security, and regulatory obligations, resolve disputes, enforce agreements, prevent fraud and abuse, and maintain business records.

Retention periods vary depending on the type of information, the purpose of processing, legal requirements, product settings, and whether an account remains active. When information is no longer needed, we delete, anonymize, or aggregate it where reasonably practicable.

Your privacy rights

Depending on your location and applicable law, you may have the right to access, correct, delete, restrict, object to, or receive a copy of your personal information; withdraw consent; opt out of certain marketing; or lodge a complaint with a supervisory authority.

To exercise your rights, contact privacy@nstdata.io. We may need to verify your identity and authority before responding. We will respond within the timeframe required by applicable law.

If your personal information was processed by Nstdata on behalf of one of our customers, we may direct your request to that customer or process it according to the customer's instructions, as required by applicable law.

California Privacy Notice

This section applies to California residents and supplements the rest of this Privacy Policy. In the preceding 12 months, we may have collected the categories of personal information described in Section 2, including identifiers, commercial information, internet or electronic network activity, geolocation information at an approximate level, professional or employment-related information, inferences, and sensitive personal information where needed for account security, payment, compliance, KYC, or service delivery.

We collect these categories from the sources described in Section 2, use them for the purposes described in Section 3, and disclose them to the categories of recipients described in Section 5.

We do not sell personal information for money. If our use of advertising, analytics, or marketing cookies constitutes "sharing" or a "sale" under the CCPA, California residents may opt out through [DO NOT SELL OR SHARE URL] or by using cookie preferences where available. We honor legally required opt-out preference signals, such as Global Privacy Control, where required by applicable law and technically feasible.

California residents may request to know, access, correct, delete, or receive a copy of personal information; opt out of sale or sharing; limit certain uses of sensitive personal information where applicable; and exercise these rights without discrimination. You may submit requests by contacting privacy@nstdata.io or by using [PRIVACY REQUEST FORM URL].

We do not knowingly sell or share personal information of individuals under 16 years of age.

Children's privacy

The Services are intended for business users and are not directed to children. We do not knowingly collect personal information from children under the age required by applicable law. If you believe a child has provided personal information to us, contact privacy@nstdata.io and we will take appropriate steps.

Marketing communications

You may opt out of marketing emails by using the unsubscribe link in the email or contacting us. Even if you opt out of marketing, we may still send transactional, security, legal, billing, and service-related messages.

Changes to this Policy

We may update this Privacy Policy from time to time. The "Last Updated" date reflects the latest revision. If we make material changes, we will provide notice as required by law. After an updated Privacy Policy takes effect, our processing will be governed by the updated Policy.

Contact us

If you have questions about this Privacy Policy or want to exercise your privacy rights, contact us at:

NST LABS TECH LTD

Email: privacy@nstdata.io

Website: https://nstdata.io

Report abuse: abuse@nstdata.io

Legal: legal@nstdata.io

Privacy: privacy@nstdata.io

Nstdata

Register and Claim

Free Trial
Nstdata logo©2026 NST LABS TECH LTD. All RIGHTS RESERVED.