In addition, this Privacy Policy outlines what security measures we take to safeguard your information and who you can contact if you have any queries or complaints about the contents of this Privacy Policy.
Our guiding principle toward data collection is to collect only the minimal data required to operate world-class Services at scale. We designed our systems (and strive to constantly improve them) to not have sensitive data about our customers. We cannot disclose, misuse, or abuse, even when compelled, data that we do not possess. We do not collect logs of your online activity while you are connected to our Services, including no logging of browsing history, traffic destination, data content, or DNS queries. We also never store connection logs, meaning no logs of your IP address, your outgoing VPN IP address, connection timestamp, or session duration.
This Privacy Policy must be read in conjunction with the FortisVPN Terms of Service (the "Terms"). Together, they form a legally binding agreement between you and FortisVPN, so please read them carefully. Unless otherwise stated, the capitalized terms in this Privacy Policy shall have the same meaning given to them in the Terms.
FortisVPN's core mission is to keep your information private. In service of this mission, FortisVPN's headquarters and registered place of business is in the British Virgin Islands (BVI). operates under BVI jurisdiction, in accordance with BVI laws.
Learn more about KPMG's recent independent audit of our privacy policy and the privacy protections of our server technology.
General Information
(i) Personal data submitted in association with your Account ("Personal Data")
(ii) Aggregate Apps and VPN connection summary statistics ("Usage Statistics Data")
(iii) Data added to FortisVPN Keys ("Keys Data") (applicable only to FortisVPN Keys users)
(iv) Anonymous App diagnostics, including crash reports ("App Diagnostic Data") (optional)
(v) IP addresses authorized to use MediaStreamer Services ("MediaStreamer Data") (applicable only to MediaStreamer users)
(vi) Data for marketing purposes exclusively when using our App
(vii) Identity Defender data
Personal Data
Specific Personal Data collected will depend on the payment method you choose and may include information such as name, billing country, billing address, and/or credit card number. For some forms of payment, you may be redirected to external websites operated by third-party payment processors (e.g., PayPal, BitPay, Paymentwall, Stripe, or other specific payment processors, depending on your location) to complete the transaction. To understand what personal data these processors collect and store, please refer to the respective processor's terms and privacy policy. Payment methods that help to minimize the amount of Personal Data you submit to us, such as giftcards and Bitcoin, are also available for you to use to subscribe to our Services. In addition, we engage with trusted partners for the purposes of simplifying the login process, detecting fraudulent signups, preventing account hijacking, and optimizing our marketing efforts. These partners may obtain user IP addresses, but these addresses are always stored separately from systems unrelated to these purposes and can never be connected to the online behavior of any user, because no record of any such behavior is collected.
FortisVPN uses your email address for the following reasons:
- To provide you with access to our Services, including through password reset or verification emails.
- To send emails related to your payment transactions.
- To send you updates and announcements.
- To communicate with you about your Account or respond to your communications.
- To send marketing information, such as offers, surveys, invitations, and content about other matters in connection with FortisVPN that we believe may be of interest to you ("Marketing Emails"). You may choose to not receive Marketing Emails by following the unsubscribe procedure described in these emails.
FortisVPN uses your Personal Data only for the purposes listed in this Privacy Policy, and we do not sell or lease your Personal Data to third parties. We collect and process your Personal Data for legitimate interest under the applicable law, more specifically to fulfill our contractual obligations to you (i.e., according to the Agreement between you and FortisVPN).
Any personal information associated with FortisVPN accounts is controlled only by FortisVPN, including being stored on systems, servers, and services owned or leased by FortisVPN and its subsidiaries. In the limited circumstances where this data may need to be processed by other related entities, it may be shared only when required, and for the duration required, for processing solely related to the purposes and legitimate interests outlined in this Privacy Policy, while ensuring at all times the same data protection standards. For avoidance of doubt, these circumstances do not include any situations where control of personal information of FortisVPN users will be transferred to any other related entities, including but not limited to our ultimate holding company, Kape Technologies PLC, for any duration of time.
Transactional communications
We retain the data associated with these communications for a period of ten (10) years to ensure compliance with legal requirements and to protect our interests. We ensure that these communications are kept to a minimum and are only sent when essential to maintain transparency and compliance with applicable laws. Your continued use of our services constitutes your consent to receive these communications.
How We Protect and Retain Your Personal Data
- Security. We have implemented best-in-class physical, procedural, and technical security measures with respect to our offices and information storage facilities so as to prevent any loss, misuse, or unauthorized access, disclosure, or modification of your Personal Data. Although we believe these systems are robust, it is important to understand that no data security measures in the world can offer completely infallible protection. For this reason, our guiding principle is to collect minimal data.
- Servers and data centers. Servers are housed in data centers with strong security practices. None of these data centers require us to collect or store any traffic data or Personal Data related to your use of the Services. If any data center were to ask us to log such data, we would immediately cease operations with said service provider and find alternative options. Even if a government were to physically seize one of our VPN servers, there would be no logs or information that would tie any individual user to a particular event, website, or behavior.
- Retention of your Personal Data. Your Personal Data—which, to reiterate, never includes any sensitive data such as browsing history, DNS queries, or IP addresses linked to that information or any other online behavior—is retained for a limited period in accordance with applicable data protection law (for as long as we have your consent or a legitimate reason for holding such data). You may request to have your data deleted by sending a valid deletion request. Please note that if you request the deletion of your Personal Data, we will maintain records necessary for legal compliance, and you will no longer be able to use the Services.
- Dedicated IP add-on. FortisVPN's Dedicated IP was built with your privacy in mind. Zero-knowledge encryption is used to allocate IP addresses, ensuring that there is no link between your Account and your allocated Dedicated IP. Your allocated IP address and its configuration settings remain encrypted and protected by an access code of your choice, and this code is the only way to unlock your Dedicated IP on any of your devices. We recommend using a strong and unique code, different from your Account password, to ensure that it is not easily guessed. No FortisVPN staff or Service Providers can view or retrieve the access code or the Dedicated IP address allocated to you (not even if you authorize us to do so).
- Legal. Your Personal Data is controlled by and stored under FortisVPN, and not by its ultimate holding company, Kape Technologies PLC (UK) or other related entities. Express Technologies Ltd. operates under BVI jurisdiction, in accordance with BVI laws (pursuant to Section 16 of the Terms). Consequently, any demand via legal means for Personal Data (or other types of data) is subject to BVI jurisdiction and laws. We fight vigorously to defend our rights (and those of our users) if an attempt is made to bypass the privacy protections provided for by the BVI. A parent, subsidiary, or related entity cannot be compelled to, nor would it voluntarily, provide Personal Data stored by Express Technologies Ltd.
To learn more about how we protect your privacy and security, visit the FortisVPN Trust Center.
How We Safeguard Your Personal Data With Relation to Service Providers
Service Providers only have access to the data necessary for the services they are performing on behalf of FortisVPN, which in any case will never include VPN activity or connection data as we do not collect such data.
In addition to Service Providers, we may share your Personal Data where you have provided your consent to us for sharing or transferring your Personal Data (e.g., marketing consents or opt-in to optional additional services or functionality).
Keys Data
Your Keys Data is your property. You may add, modify, and delete Keys Data at your discretion by accessing your FortisVPN Keys dashboard. For your protection, you should create a strong and unique primary password for FortisVPN Keys to ensure that it is not easily guessed. It should also be different from the password used to access your Account.
You can import data from other password management tools into FortisVPN Keys by following the instructions in your Account. Before doing so, we strongly suggest that you review the data portability rules of your former password manager provider, as these are not under FortisVPN's control.
Usage Statistics Data and App Diagnostic Data
We ensure that Usage Statistics Data and App Diagnostic Data never include any sensitive information, in line with our overall commitment to never logging browsing history, traffic destination, data content, IP addresses, or DNS queries.
With regard to VPN Usage Statistics, our principle of minimal data collection means that:
- We do not know which user ever accessed a particular website or service.
- We do not know which user was connected to the VPN at a specific time or which VPN server IP addresses they used.
- We do not know the set of original IP addresses of any given user's computer.
Should anyone try to compel FortisVPN to release user information based on any of the above, we cannot supply this information because the data does not exist.
Apps and App Versions
Marketing
Successful Connection
Aggregate Sum of Data Transferred (in MB)
Usage Statistics Data Summary
We've engineered our systems to categorically eliminate storage of sensitive data. We may know THAT a user has used FortisVPN, but we are unable to single out the user, and we never know HOW they have utilized our Service. We stand by our firm commitment to our users' privacy by not possessing any data related to a user's online activities.
App Diagnostic Data
If you opt in to share this information with FortisVPN (in the settings menu of your Account), we will collect the following anonymized App Diagnostics Data:
- Diagnostic information about if and how a VPN connection attempt failed.
- Speed test data.
- App diagnostics, including crash reports and usability diagnostics, without any personally identifiable information. These are handled in an anonymized form by the following Service Providers bound by non-disclosure and other contractual obligations, dependent on the platform you are using FortisVPN on:
- Windows: Sentry, owned by Functional Software, Inc. See Sentry's Privacy Policy.
- Mac: Firebase Crashlytics, owned by Google, and Sentry, owned by Functional Software, Inc. See Firebase's Privacy and Security documentation and Sentry's Privacy Policy.
- Linux: Sentry, owned by Functional Software, Inc. See Sentry's Privacy Policy.
- iOS: Firebase Crashlytics, owned by Google, and Apple. See Apple's Privacy Policy and Firebase's Privacy and Security documentation. You can disable Apple's crash reporting in iOS settings as described here.
- Android: Firebase Crashlytics, owned by Google. See Firebase's Privacy and Security documentation.
- Browser extensions: Google Analytics, owned by Google. See Google's Privacy Policy.
Upon activation of any of our Apps, you will be asked if you would like to share App Diagnostics Data with FortisVPN. You can start or stop sharing this data at any time in your App's settings menu. On iOS, Apple's crash reporting can be turned off in iOS settings.
MediaStreamer Data
If you do not wish to use our MediaStreamer service but have devices that cannot run a VPN, we suggest using the FortisVPN App for routers. Like all of our Services outside of MediaStreamer, the App for routers does not require IP address registration. Please contact us via live chat at www.fortisvpn.com/support, and we will guide you through the steps.
How We Protect and Retain Information Related to Email, Live Chat, and Feedback Forms
We use two different third-party platforms for support correspondence: Zendesk for emails and support tickets and TeamSupport for live chat. When you correspond with us using these platforms, they will store your correspondence records—including your email address, as well as user and device attributes that help with troubleshooting, such as the country you are contacting us from and your device's operating system. Both platforms utilize modern security practices and SSL encryption. See Zendesk's Privacy Notice and TeamSupport's Privacy Policy.
Cookies and Third-Party Analytics
What is a Cookie?
Disabling Cookies
FortisVPN's Cookies
Third-Party Cookies
Cookies that are necessary for the proper functioning and optimization of the Site are known as Essential Cookies. For example, we use PayPal to allow users to make payments via that service. Other Essential Cookies in use include those that allow payments via Forter, Braintree, and Chargebee; those that allow us to analyze and improve page performance, including Google Analytics, Google Optimize, Visual Website Optimizer, and Google Tag Manager; those that allow us to manage traffic, deliver content, and combat malicious bots, including Cloudflare, Cloudfront, and Gstatic; and one that allows you to specify your Cookie preferences, Usercentrics Consent Management Platform. Essential Cookies cannot be disabled, and by using the Site, you are consenting to them.
Cookies that enable us to properly display or manage elements on the Site are known as Functional Cookies. For example, we use Google Fonts to properly display text. Other Functional Cookies in use include those for displaying video, including YouTube Video and Vzaar; those that produce maps, including OpenStreetMap and Google Maps; those used in managing Cookies, including Google Ajax and jQuery; one for tracking and reporting errors, Sentry; one for displaying avatars, Gravatar; and one for presenting quizzes and questionnaires, Typeform. Functional Cookies can be disabled.
Cookies that are used by advertisers to serve ads that are relevant to your interests are known as Marketing Cookies. For example, we use Google Ads remarketing to show advertisements on third-party websites (including Google) to users who have visited our Site. We may show such users advertisements on a Google search results page or on a site in the Google Display Network. Other Marketing Cookies in use include those from DoubleClick Ad, Facebook Pixel, Facebook Social Plugins, Google AdServices, Google Syndication, Microsoft Advertising Remarketing, X, and PayPal Marketing Solutions. Marketing Cookies can be disabled.
Service Providers, including Google, use Cookies to serve ads based on someone's past visits to the Site. Any data collected will be used in accordance with our Privacy Policy and Google's privacy policy. In addition to setting Cookie preferences via your browser or the menu at the bottom of our Site, users also may opt out of Google's use of Cookies by visiting the Google Advertising Opt-out Page. Users may opt out of Google Analytics by visiting the Google Analytics Opt-out Page. Users may opt out of third-party use of cookies by visiting the Network Advertising Initiative Opt-out Page.
Device information
Disabling or resetting mobile identifiers
Email/communication analytics
Interactions With Third-Party Products
Users in the European Union
In line with the GDPR, we collect and process the Personal Data outlined in this Privacy Policy on one of the following bases, depending on the circumstances:
- For the purposes of fulfilling our contractual obligations, including:
- Providing Subscribers with the Services they have requested.
- Managing subscriptions and processing payments in connection with our Services.
- Providing customer support.
- For a legitimate interest associated with the operation of our business, including:
- Enhancing the quality, reliability, and effectiveness of our Services.
- Communicating with customers to provide information and seek feedback related to our Services.
- With the consent of users, which users can withdraw at any time.
Your Privacy Rights
- You have a right to access personal data held about you.
- You have the right to request that we rectify any personal data we hold that is inaccurate or incomplete.
- You have the right to request the deletion of your personal data. Please note that such deletion may result in us no longer being able to provide you with our Services.
- You have the right to request restriction of or object to the processing of your personal data.
- You have the right to request and receive your personal data in a commonly used format (data portability).
- You have the right to withdraw your consent on which processing is based at any time.
- You have a right to complain to your local data protection supervisory authority.
- You can exercise your rights above by contacting us as described in Section 16.
- You may have a third party submit a request on your behalf as an authorized agent. To confirm that the authorized agent is entitled to submit a request on your behalf, they must have written authorization signed by you, and you must provide us with a copy of the signed authorization. To ensure your privacy and security, we may take further steps to verify your identity.
- We will address any requests in accordance with applicable laws and to the best of our ability in a timely manner.
Users in California
The following rights (which may be subject to certain exemptions or derogations) shall apply to individuals covered by the California Consumer Privacy Act ("CCPA") and California Consumer Privacy Rights Act ("CCPRA"):
- You have the right to know what personal data is being collected about you and how it is used and shared.
- You have the right to request the deletion of your personal data. Please note that such deletion may result in us no longer being able to provide you with our Services.
- You have the right to opt out of the sale of your personal data. However, there is no need to exercise this right as ExpressVPN does not sell any data to third parties.
- You have the right not to be discriminated against for exercising any of these rights or other rights under the CCPA.
- You have the right to withdraw your consent on which processing is based at any time.
Use by Children
Changes to This Privacy Policy
How to Contact FortisVPN
You may also refer any questions regarding this Privacy Policy to our Group Data Protection Officer (DPO) by writing to dpo@fortisvpn.com.
One App. All Your Devices. Total Protection.
FortisVPN works seamlessly across all your platforms with the same clean, intuitive interface. One subscription covers everything—no extra setup needed.
