PhantomPathVPN Ltd | Privacy Policy & Technical Manifesto | Updated: August 8, 2026.

PhantomPathVPN Ltd | Company Number: 16958507

1. RESELLER ROLE

PhantomPathVPN Ltd operates as a reseller. We do not directly own or operate the underlying network infrastructure but partner with trusted providers to deliver our privacy-focused services. PhantomPath services are strictly for users aged 18 and over.

2. REGULATORY COMPLIANCE

We respect user privacy but must comply with UK law. Data may be disclosed only when legally mandated by a valid court order, warrant, or other binding legal directive from authorized UK authorities. SMS Consent and Mobile Data: PhantomPathVPN does not sell, rent, or share mobile phone numbers or SMS opt-in data with third parties or affiliates for marketing or promotional purposes. All SMS consent data is used solely for service-related communication.

3. DATA MINIMISATION & PRIVACY

We adhere to a strict data minimization philosophy. The information we collect may include:

  • Payment Info: Processed securely via third-party gateways. We do not store full credit card numbers.
  • Technical Data: Minimal technical metrics required to enforce data caps and ensure service health.
  • Contact Info: Email addresses or phone numbers provided voluntarily for customer support. Phone: 0333 313 0127.

Collected data is used exclusively to provision your service, process payments, provide customer support, and prevent network abuse. We do not sell your personal data to advertisers.

Payment Processing & Data Isolation

Payments are processed by independent third-party payment providers, including Stripe, PayPal, and supported carrier-billing providers. Payment credentials are entered directly into the selected provider's payment environment. PhantomPathVPN does not store complete card numbers, security codes, or payment credentials.

PhantomPathVPN receives only the limited transaction information required to confirm payment, activate the purchased service, manage refunds or chargebacks, prevent fraud, and comply with applicable accounting and legal obligations. Depending on the payment method, this may include a transaction reference, payment status, amount, selected product, and fraud-screening result.

Payment information is kept operationally separate from VPN traffic, browsing activity, session keys, message content, call content, and virtual-number communications. We do not use payment information to profile service activity.

Payment providers process and retain their own transaction records under their respective privacy policies and applicable financial, fraud-prevention, accounting, and legal obligations. Their records and retention practices are separate from PhantomPathVPN's service-data retention.

Lawful Bases for Processing

Where personal data is processed, PhantomPathVPN relies on the lawful basis appropriate to the specific purpose. This may include performance of a contract to supply and support a purchased service, compliance with legal obligations such as accounting and regulatory requirements, legitimate interests in securing the platform and preventing fraud or abuse, and consent where consent is specifically requested for communications.

Website Analytics & Advertising Measurement

On public website pages, PhantomPathVPN uses Google Analytics 4 with Google Consent Mode v2. Analytics and advertising storage are denied by default. Google may receive consent-state and cookieless measurement signals before optional consent, while full analytics and advertising storage is enabled only after a visitor accepts optional cookies.

Meta Pixel and TikTok Pixel are loaded only after optional consent is granted. These tools help us understand public-page engagement and advertising performance. They remain disabled throughout the private customer portal. Following backend confirmation of a successful purchase, the payment-success page may send the product, duration, GBP value, quantity and a randomly generated anonymous conversion reference. PhantomPathVPN does not send access codes, recovery keys, payment-provider session tokens, message content, call content, payment credentials, or USA verification numbers to these analytics platforms.

Visitors may reject optional tracking, close the cookie banner to reject it, or reopen Cookie Settings from the website footer. Consent choices are stored locally so they can be respected on future visits.

4. TECHNICAL MANIFESTO

We work with trusted telecommunications partners, including Telnyx and eSIM Go, to provision virtual numbers, messaging services, and data connectivity.

We do not log, store, or monitor browsing activity, DNS queries, or traffic content. Any automated systems used for security and abuse prevention operate on limited technical metadata and do not inspect personal data content.

Zero-Retention Messaging

Numbers are provisioned instantly. PhantomPathVPN uses an Immediate Deletion API so that message payloads processed by PhantomPathVPN-controlled systems are automatically deleted server-side within 30 seconds of delivery. No message history is retained in the PhantomPathVPN customer database.

Virtual numbers, messaging, voice, and eSIM services rely on third-party telecommunications providers. Those providers may process limited technical, routing, compliance, and transaction information under their own legal obligations, service terms, and privacy policies.

US Number Verification

For supported USA numbers, a mobile number may be required for telecommunications compliance, fraud prevention, and service activation. Global mobile numbers may be accepted where supported. PhantomPathVPN processes this information only for the verification and service-protection purposes described here and does not use it for marketing.

The submitted number may be transmitted to the relevant verification or telecommunications provider. PhantomPathVPN applies data-minimisation and purpose-limitation principles to this process and does not intentionally associate verification information with VPN traffic, browsing activity, session keys, or message content.

5. DATA RETENTION & SECURITY

Data is retained only as long as necessary to fulfill the purpose for which it was collected or to comply with legal, tax, or regulatory requirements. Operational application and system logs are automatically rotated, size-capped and subject to scheduled cleanup. These records are limited to payment, provisioning, error, security, system and administrative events. They do not contain browsing activity, traffic content or message content.

Limited payment references, payment status information, and associated financial records may be retained where necessary for service fulfilment, refunds, chargebacks, fraud prevention, dispute handling, accounting, and legal or regulatory obligations. Complete payment-card credentials are not retained by PhantomPathVPN.

Verification and telecommunications data is retained only for the period necessary to perform the relevant verification, provide the requested service, prevent misuse, or meet an applicable legal or provider requirement. Where a fixed period does not apply, retention is determined by the purpose of processing, the sensitivity of the information, operational necessity, contractual requirements, and applicable limitation periods.

Automated fraud-prevention and security systems may assess limited transaction or technical signals to protect customers, payment providers, telecommunications partners, and the PhantomPathVPN platform. These systems are not used to analyse browsing content or build advertising profiles.

6. YOUR RIGHTS

Under the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018, you have the right to access, rectify, or request the deletion of your personal data. To exercise these rights, please contact our support team at support@phantompathvpn.com or call 0333 313 0127.

Depending on the lawful basis and circumstances, you may also have rights to restrict processing, object to processing, request data portability, and withdraw consent where processing relies on consent. Exercising a right does not affect processing that was lawful before a consent withdrawal.

Some service providers may process information outside the United Kingdom. Where an international transfer is subject to UK GDPR transfer restrictions, the relevant provider arrangements may rely on an applicable adequacy regulation or approved contractual safeguards. You may contact PhantomPathVPN for further information about safeguards relevant to your personal data.

If you have concerns about how PhantomPathVPN handles your personal data, please contact us first so that we can investigate. You also have the right to lodge a complaint with the Information Commissioner's Office at ico.org.uk/make-a-complaint.