Skip to content

ProRDP policy

Privacy Policy

A clear account of the information used to prepare orders, verify payments, provide support, and protect the service.

This starter policy is provided for general informational purposes and is not professional legal advice. It should be reviewed by a qualified legal professional before commercial launch.

Effective date: July 22, 2026

01Information you provide

Checkout asks for your name, email address, Telegram username, server-location preference, Windows-version preference, optional notes, selected plan, payment method, and transaction reference. Avoid placing secret credentials or unnecessary sensitive information in any field.

02Payment screenshots

Your payment screenshot is validated for supported image type and size in the browser and again on the server. It is uploaded to a private Supabase Storage bucket under a randomized path. It is not written to localStorage and is never published through a permanent public URL. You and authorized administrators may receive short-lived access links.

03Accounts and sessions

Supabase Auth processes account email addresses, password authentication, confirmation, and recovery. The website uses secure authentication cookies so sessions can be validated on the server. Passwords are not stored in the ProRDP orders or profiles tables.

04Supabase order storage

Validated profiles and orders are stored in Supabase PostgreSQL for fulfillment, payment verification, support, and order history. Row Level Security limits customers to their own information. Authorized administrators can review customer orders, private proof, status, and internal fulfillment notes.

05How information is used

  • Prepare and verify an order.
  • Communicate about payment, setup, support, and service delivery.
  • Prevent abuse, investigate security issues, and enforce policies.
  • Meet applicable recordkeeping or legal obligations.
  • Improve reliability and customer experience.

06Hosting and service providers

Deployment, database, network, and communication providers may process limited information as necessary to operate their services. For example, a hosting platform may retain access and security logs, Supabase may process configured order records, and Telegram processes messages under its own privacy terms.

07Sharing

Customer information should not be sold. It may be shared with infrastructure or support providers when needed to deliver the service, address abuse, protect users, comply with lawful requests, or complete a business transition subject to appropriate safeguards.

08Retention

Order and support records should be retained only as long as reasonably needed for fulfillment, accounting, dispute handling, security, and applicable legal obligations. The final commercial operator must adopt and document specific retention periods appropriate to its jurisdiction.

09Security

The project uses input and file validation, server-side authorization, Row Level Security, server-only credentials, private storage, and short-lived proof links. No method of online processing is risk-free. Customers should never disclose private keys, seed phrases, passwords, API secrets, or RDP credentials in order fields.

10Cookies and technical data

The application uses essential Supabase authentication cookies for login, session refresh, and protected routes. It does not intentionally add advertising or behavioral-tracking cookies. Hosting providers may process IP addresses, browser details, timestamps, and request logs for delivery and security. Any future analytics or cookie tools should be disclosed and configured in accordance with applicable requirements.

11Your choices and rights

Depending on your location, you may have rights to request access, correction, deletion, restriction, or a copy of certain personal information. Contact support at @Theytproo. Identity may need to be verified before a request is completed.

12Children and changes

The service is not directed to children who cannot legally enter a service agreement in their jurisdiction. This policy may be updated when processing practices change; the effective date should be revised when material updates are published.

Questions about this policy can be sent to @Theytproo.