Privacy Policy
This Privacy Policy explains how ShamVPN collects, protects, and processes limited operational information related to the use of its applications and services.
Information Collection
ShamVPN collects limited operational information necessary to provide the services, process purchases and activation, verify payments, provide support, and secure user accounts. This may include account identifiers, email address, phone number, payment references, and technical information. ShamVPN also commits to collecting information related to legal compliance in accordance with the directives imposed by the Syrian Telecommunications and Postal Regulatory Authority.
VPN Logs and Usage Data
ShamVPN does not store browsing content or transmitted data. However, in compliance with Syrian laws, user activity logs (such as connection times and IP addresses) are retained for the period set out in the Data Retention section below.
Payments and Billing
Payments are processed exclusively through approved payment service providers and banking services in Syria. We do not share user data with electronic payment service providers. Electronic payment providers may independently request information about the user, separate from our services, and financial transaction information may be processed in accordance with their own policies and standards.
Notifications and Communications
ShamVPN may send service-related notifications via email, push notifications, Telegram, or other official channels regarding billing, payments, account security, or important policy updates.
Data Sharing with Third Parties
We are committed to protecting the data and privacy of our subscribers, and we do not sell or share user data with any third party. We also clarify that, in compliance with the restrictions imposed by the Syrian Telecommunications and Postal Regulatory Authority to combat electronic crimes and cybersecurity threats, user data is not shared with government institutions unless an official request is submitted by the competent judiciary. Such a request must be specific to a particular identified subscriber only and shall not be a request to hand over the data of all users.
Data Retention
Billing data and operational data of subscribers are retained in a manner that ensures the proper provision of services to subscribers. In compliance with the laws of the Syrian Telecommunications and Postal Regulatory Authority, user activity logs are retained to be used as criminal evidence and to ensure legal compliance in the event that a user is involved in piracy or cybercrime activities. The retention period for this data is set at 6 months, which is the minimum required by the Syrian Telecommunications and Postal Regulatory Authority. These logs are shared with law enforcement agencies exclusively in accordance with the data sharing policy set out above.
Security and Encryption
We implement all possible security measures and practices within reasonable capabilities to protect the infrastructure and communication channels, with the aim of preserving the privacy of user data and their activity logs.
Privacy Policy Updates
Digital Arrow Company reserves the right to update the Privacy Policy when necessary without referring back to users or obtaining their consent. The Company will send a notification to users regarding updates to the Privacy Policy, and continued use of any of our services constitutes implicit acceptance by the user of the Privacy Policy and its updates.