Privacy Policy
Published: August 17, 2026 Updated: August 17, 2026
1. Introduction and Scope
1.1 Policy Overview
Welcome to the official IPbyte website (www.ipbyte.ai) and related services operated by IPbyte ("the Company", "we", "us", or "data controller"). This Privacy Policy explains how we collect, use, store, share, and protect personal information when we provide IP address lookup and related data products and services.
Please read this Privacy Policy carefully.By accessing or using the Services, you agree that your information will be processed in accordance with this Privacy Policy. Your use of the Services is also subject to the Terms of Service. If this Privacy Policy conflicts with the Terms of Service, the Terms of Service shall prevail.
1.2 Scope
This Policy applies to data interactions generated when you access or use our products through our website, application programming interfaces (APIs), and offline data download services. Our main products include:
(1) IP Geolocation API;
(2) IP Network Classification API;
(3) IP Risk Detection API. These products support both API calls and offline data downloads.
1.3 Nature of Data
IPbyte primarily provides IP-address-based network data analysis services. The IP addresses and related geolocation data we process usually describe network infrastructure and, in most cases, cannot directly identify or locate a specific natural person. However, when combined with other personal information, such data may constitute personal information or personal data under applicable privacy laws. We therefore protect personal information generated or provided through the Services in accordance with applicable global data protection laws.
2. Information We Collect
To provide accurate and efficient services, we may collect the following categories of information:
2.1 Service Data
When you call our APIs or download offline data, our systems may process network-layer data including:
(1) IP addresses and approximate geolocation, including country, region, city, postal code, latitude and longitude;
(2) network operator information, including ISP, enterprise network, data center, or mobile network identifiers;
(3) network environment and risk characteristics, including proxy, VPN, Tor node detection data, and risk scores generated from network behavior.
2.2 Website Visitor Data
When you visit www.ipbyte.ai, we may collect:
(1) Identity and contact information you voluntarily submit through forms or registration, including your name, email address, company name, phone number, and mailing address;
(2) Technical and interaction data, including your IP address, browser type, device information, cookie data, website browsing behavior, and interaction records.
2.3 Customer and User Data
When you register an account, purchase services, or request support, we may collect:
(1) Account and financial information, including account credentials, billing information, payment records, and subscription status;
(2) Service usage data, including API call logs, offline data download records, and quota usage;
(3) Communication records created when you contact us through email, ticketing systems, or other channels for technical support or customer service.
2.4 Sensitive Personal Information
We do not intentionally collect, process, or store sensitive personal information, including race, ethnicity, religious belief, political opinion, health status, biometric identifiers, or genetic data. If such information is inadvertently provided, we will delete, de-identify, or anonymize it where appropriate.
3. Legal Basis for Processing
For users subject to the GDPR, our processing is based on the following legal bases:
3.1 Contract performance: processing necessary to provide API services, deliver offline data, process payments, and provide technical support;
3.2 Legitimate interests: protecting network security, preventing fraud and abuse, improving product performance, and conducting internal analytics without overriding your fundamental rights;
3.3 Consent: sending marketing emails or using non-essential cookie technologies where you have given consent. You may withdraw consent at any time;
3.4 Legal obligations: complying with applicable laws, tax requirements, or lawful requests from government or law enforcement authorities.
4. How We Use Information
We use collected information mainly to:
4.1 Provide and maintain services, including stable API operations, accurate offline data delivery, and system maintenance;
4.2 Process orders and payments, verify transactions, issue receipts, and process refunds;
4.3 Provide technical support and customer service, respond to inquiries, troubleshoot issues, and improve service quality;
4.4 Analyze usage trends and improve products, including improving the accuracy of IP databases and algorithm models;
4.5 Protect security and prevent fraud, malicious attacks, API abuse, account compromise, and unlawful scraping;
4.6 Send marketing communications, product updates, new feature information, or industry insights only where you have expressly authorized us to do so;
4.7 Meet our legal and regulatory obligations in applicable jurisdictions.
5. Sharing and Disclosure
We take your privacy seriously and will never provide your personal information to unrelated third parties. We share information only where necessary in the following circumstances:
5.1 Service providers: to provide the Services, we may share information with third-party providers subject to strict confidentiality obligations, such as payment processors (Stripe and PayPal), cloud service providers, and analytics tool providers;
5.2 Affiliates: sharing necessary data with affiliates when required for internal restructuring or business integration;
5.3 Legal requirements: disclosing information where required by law, court order, or government regulator;
5.4 Business transfers: if IPbyte is involved in a merger, acquisition, or asset sale, your personal information may be transferred as a transaction asset. We will notify you and require the recipient to be bound by this Policy.
6. International Data Transfers
6.1 Global Data Flows
Due to the global nature of internet services, your data may be stored and processed in the Hong Kong Special Administrative Region, the United States, the European Union, and other jurisdictions where we or our service providers operate.
6.2 GDPR Safeguards
For data transferred from the European Economic Area, the United Kingdom, or Switzerland, we implement supplementary technical measures, such as encryption, to protect data in transit.
6.3 CCPA/CPRA Commitment
We strictly comply with the California Consumer Privacy Act and do not sell or share your personal information for money or other valuable consideration.
7. Data Retention
7.1 Retention Periods
We retain your personal information only for the shortest period necessary to achieve the purposes for which it was collected. Specific retention periods depend on the type of data:
(1) API call logs: usually retained for 30 to 90 days for billing and security audits, then de-identified, anonymized, or deleted;
(2) Account and billing data: retained for the life of the account and the statutory tax and financial retention period, usually seven years;
(3) Marketing consent records: retained after consent is withdrawn or an account is closed for compliance audits.
7.2 Deletion Process
When you request deletion of data, we will process the request within 30 days after verifying your identity. If we are legally required to retain information, such as for unsettled billing or an ongoing legal investigation, we will delay deletion of that information and tell you why.
8. Your Rights
We are committed to protecting the data rights available to you in your jurisdiction:
8.1 GDPR Rights (EU and UK Users)
(1) Right of access: obtain a copy of the personal data we hold about you;
(2) Right to rectification: request correction of inaccurate or incomplete data;
(3) Right to erasure: request deletion of your data in certain circumstances;
(4) Right to restrict processing: request that we restrict processing of your data in certain circumstances;
(5) Right to data portability: receive your data in a structured, machine-readable format;
(6) Right to object: object to processing based on legitimate interests, including direct marketing;
(7) Right to withdraw consent: withdraw consent you previously gave at any time.
8.2 CCPA/CPRA Rights (California Users)
(1) Right to know: understand the categories of personal information we collect, use, and disclose;
(2) Right to delete: request deletion of personal information we collect, subject to legal exceptions;
(3) Right to opt out of sale or sharing: we do not sell or share personal information, but you may confirm this status;
(4) Right to limit the use of sensitive personal information: request limits on the use of sensitive personal information;
(5) Right to non-discrimination: exercising your rights will not cause us to deny services or reduce service quality.
8.3 Asia-Pacific Rights
(1) Singapore PDPA: you may access and correct the personal data we hold, or ask how we used or disclosed it during the previous year.
(2) Malaysia, Thailand, and the Philippines PDPA: you have similar rights of data access, correction, and withdrawal of consent. Please refer to applicable local law for details.
8.4 How to Exercise Your Rights
Please submit your request through the contact information in Section 13 of this Policy. We will respond within the statutory time limit, usually 30 days. For requests that are manifestly unfounded or excessive, we may charge a reasonable fee or decline to process the request.
9. Cookies and Similar Technologies
9.1 Types of Use
(1) First-party cookies: used to maintain sign-in status, remember preferences, and protect website security;
(2) Third-party cookies: used for website traffic analytics, such as Google Analytics, and performance monitoring.
9.2 User Controls
You can refuse or manage cookies through your browser settings. Please note that disabling certain cookies may prevent some website features from working properly. For a detailed cookie list and management guidance, please see our separate Cookie Policy.
10. Data Security
10.1 Technical and Organizational Measures
We use industry-standard security measures to protect your data, including:
(1) Transport Layer Security (TLS) encryption;
(2) Encryption of data at rest;
(3) Strict access control and authentication mechanisms;
(4) Regular security audits and penetration testing.
10.2 Data Breach Notice
If a data breach could result in a high risk to your rights and freedoms, we will report it to the relevant regulator within 72 hours of becoming aware of it and directly notify affected users where necessary.
11. Children's Privacy
Our Services are intended for businesses and professional developers, not children under 16. We do not knowingly collect personal information from children. If you discover that we have inadvertently collected a child's data, please contact us immediately and we will delete it promptly.
12. Policy Updates
We may update this Policy from time to time to reflect changes in laws and regulations or our business model. We will notify you of material updates through a website notice or email. Your continued use of the Services means that you accept the updated Policy.
13. Contact Us
(1);
(2) Hong Kong registered address: Room 2505, 25/F, Wealth Commercial Centre, 42-56 Kwong Wa Street, Mong Kok, Kowloon, Hong Kong SAR, China.
We will provide an initial response to your inquiry within 15 business days.
14. Governing Law and Dispute Resolution
14.1 Governing Law
This Policy shall be governed by and interpreted in accordance with the laws of the Hong Kong Special Administrative Region.
14.2 Dispute Resolution
Any dispute arising out of this Policy or our services shall first be resolved through friendly consultation. If consultation fails, either party may submit the dispute to the Hong Kong International Arbitration Centre (HKIAC) in Hong Kong under its then-effective arbitration rules. The arbitration language shall be Chinese. The arbitral award shall be final and binding on both parties.