TunnelFox Global
How it works Pricing FAQ Support
Open Telegram Bot

TunnelFox Global Privacy Policy

Last updated: 9 July 2026
Service: TunnelFox Global

1. Introduction

This Privacy Policy explains how TunnelFox Global collects, uses, stores, shares and protects personal data when you use our Telegram bot, Telegram Mini App, website, support pages, connection profile management tools and related interfaces (together, the “Service”).

Controller / Service Provider: an individual service provider; full legal details (legal name, registration status and registration number where applicable) are provided on request via the support contacts below.
Legal notices address: provided on request via the support contacts listed in this document.
Support: support@tunnelfox.tech / @tunnel_fox_global_bot.
Privacy requests: privacy@tunnelfox.tech.
Abuse reports: abuse@tunnelfox.tech.

In this Policy, “we”, “us” and “our” mean the controller listed above. “You” means the person using the Service.

2. Summary

We collect only the data reasonably needed to provide and secure a digital connection-profile service, process payments, prevent abuse, support users, comply with law and enforce our terms.

We do not collect or store your full card number, CVV/CVC, bank passwords, seed phrases, private keys or Telegram password. We do not sell your personal data.

3. Data we collect

3.1 Telegram account data

When you start the bot or open the Mini App, we may receive and store:

  • Telegram user ID;
  • Telegram username;
  • Telegram display name, if provided by Telegram;
  • language code and Telegram interface data, if provided;
  • bot interaction events needed to operate the Service.

3.2 Activity and usage data

We may collect and store:

  • first visit date and time;
  • last visit date and time;
  • last Mini App open date and time;
  • subscription, plan and service-period status;
  • promo-code activation events;
  • trial activation events;
  • terms acceptance date, time and version;
  • referral or invite relationship, if invite mode is enabled;
  • support interaction metadata.

3.3 Payment records

For purchases, we may store:

  • payment provider;
  • amount;
  • currency or virtual item type;
  • payment status;
  • payment date and time;
  • provider payment ID, charge ID, invoice ID, transaction ID or similar identifier;
  • refund status and refund metadata;
  • chargeback, dispute or failed-payment status, if any.

Payment providers, banks, app stores, Telegram, digital-asset providers or other payment intermediaries may process additional payment data under their own terms and privacy policies.

3.4 Connection profile data

To provide the Service, we may store:

  • technical connection profile identifier;
  • connection profile status;
  • service-period expiry date;
  • access status, including active, expired, suspended or terminated;
  • technical configuration data needed to deliver and manage access.

3.5 Device and network data

For security, abuse prevention, access control and troubleshooting, we may collect:

  • technical device fingerprint or device identifier generated by our systems;
  • platform;
  • device model;
  • IP address of the request;
  • approximate location inferred from IP address, where used for security, compliance or troubleshooting;
  • user agent, request metadata, timestamps and server logs;
  • error logs and diagnostic data.

3.6 Support and abuse reports

When you contact support or report abuse, we may collect:

  • your contact details;
  • Telegram ID or username;
  • payment ID or transaction details you provide;
  • message content;
  • screenshots, logs, URLs, timestamps or other evidence you provide;
  • internal notes needed to handle the request.

Do not send unnecessary sensitive data, passwords, private keys, seed phrases, card details, government IDs or confidential third-party data unless we specifically request it and the request is lawful and necessary.

4. Data we do not intentionally collect

We do not intentionally collect:

  • Telegram passwords;
  • full bank card numbers;
  • CVV/CVC codes;
  • bank login credentials;
  • private keys or seed phrases;
  • precise GPS location, unless a future feature clearly asks for it;
  • content of your personal Telegram chats outside your interaction with our bot or support;
  • browsing history outside the technical logs required to operate and secure the Service.

5. Sources of data

We collect data from:

  • you;
  • Telegram, when you interact with the bot or Mini App;
  • our servers and technical systems;
  • our connection profile management panel;
  • payment providers, including Telegram Stars and other providers shown at checkout;
  • support and abuse reporting channels;
  • security, hosting and infrastructure providers.

6. How we use data

We use personal data to:

  1. create and manage your Service account and connection profile;
  2. provide trial access, paid access, promo-code access and expiry management;
  3. process payments, refunds, disputes, chargebacks and payment support requests;
  4. prevent fraud, repeated trial abuse, unauthorised access, spam and prohibited use;
  5. secure the Service, detect technical issues and investigate abuse reports;
  6. provide customer support;
  7. send service messages through Telegram or other available channels;
  8. maintain logs and records required for legal, tax, accounting, security and dispute purposes;
  9. comply with law, sanctions, court orders, regulator requests, Telegram rules, payment provider rules and infrastructure provider rules;
  10. improve reliability, performance, support quality and user experience.

7. Legal bases for processing

Where laws such as the GDPR or UK GDPR apply, we rely on one or more of the following legal bases:

  • Contract: to provide the Service, manage your account, activate access, process payments and handle refunds.
  • Legitimate interests: to secure the Service, prevent abuse, troubleshoot errors, improve reliability, enforce terms and respond to support requests.
  • Legal obligation: to comply with tax, accounting, consumer-protection, sanctions, regulatory and lawful-request obligations.
  • Consent: where we ask for optional consent, for example for optional communications, optional analytics or certain cookies if introduced.
  • Legal claims: to establish, exercise or defend legal claims.

8. Sharing of data

We may share data with the following categories of recipients where necessary:

  • Telegram, where your use of the Service occurs through Telegram;
  • payment providers, banks, app stores, digital-asset payment providers and payment intermediaries;
  • hosting, server, database, infrastructure, monitoring and security providers;
  • support, email, communication and ticketing providers;
  • professional advisers, including lawyers, accountants and auditors;
  • law-enforcement authorities, regulators, courts or government bodies where required or permitted by law;
  • third parties involved in investigating abuse, security incidents, payment disputes, network attacks or rights violations;
  • successor entities if we reorganise, sell, transfer or merge the Service, subject to appropriate safeguards.

We require service providers to process data only as needed to provide services to us, unless they act as independent controllers under their own legal obligations, such as certain payment providers or platforms.

9. International transfers

We may process and store data in countries other than your country of residence. Data protection laws in those countries may differ from your local laws.

Where GDPR, UK GDPR or similar laws apply, we use appropriate safeguards for international transfers where required, such as adequacy decisions, standard contractual clauses, contractual safeguards, technical measures, or another lawful transfer mechanism.

10. Retention periods

We keep data only as long as reasonably necessary for the purposes described in this Policy, unless a longer period is required or permitted by law.

Typical retention periods are:

  • account and Telegram ID data: while your account is active and for up to 24 months after inactivity or expiry, unless a longer period is needed for legal, security or dispute reasons;
  • connection profile data: during the service period and for up to 24 months after expiry, unless needed longer for security, abuse prevention or disputes;
  • device, IP and server logs: usually up to 12 months, but longer where needed for abuse, fraud, security incidents, legal claims or provider complaints;
  • payment and refund records: for the period required by tax, accounting, anti-fraud, payment-provider, chargeback and legal obligations, which may be up to 7 years or longer depending on applicable law;
  • terms acceptance records: while the account exists and for the limitation period applicable to potential claims;
  • support and abuse reports: usually up to 3 years after closure, but longer if needed for disputes, safety, law enforcement, abuse prevention or legal claims.

When data is no longer needed, we delete, anonymise or aggregate it where reasonably possible.

11. Your privacy rights

Depending on your country, you may have the right to:

  • access your personal data;
  • receive a copy of your personal data;
  • correct inaccurate data;
  • delete data;
  • restrict processing;
  • object to processing;
  • withdraw consent where processing is based on consent;
  • request data portability;
  • lodge a complaint with a data-protection authority;
  • appeal or challenge certain decisions, where applicable.

To exercise rights, contact privacy@tunnelfox.tech or support and include your Telegram ID or username. We may need to verify your identity before acting on your request.

Deletion is not absolute. We may retain data where needed for payment records, tax and accounting obligations, fraud prevention, security, legal claims, dispute handling, abuse prevention, compliance with law or other legitimate reasons permitted by applicable law.

12. EU/EEA and UK users

If GDPR or UK GDPR applies to your use of the Service, you may have the rights listed above and may contact us using the privacy contact details in this Policy.

If you are located in the EU/EEA or UK and believe your data protection rights have been violated, you may also contact your local supervisory authority. We encourage you to contact us first so we can try to resolve the issue.

If we are required to appoint an EU or UK representative or Data Protection Officer, we will publish the relevant contact details here.

13. California privacy notice

This section applies only to the extent the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies to us.

We may collect the following categories of personal information:

  • identifiers, such as Telegram ID, username, payment identifiers and IP address;
  • internet or electronic network activity, such as server logs, Mini App activity and device data;
  • commercial information, such as purchases, payment status, refunds and service periods;
  • geolocation information, limited to approximate location inferred from IP address where used;
  • inferences used for fraud prevention, abuse prevention, access control and support.

We use this information for the purposes described in this Policy. We do not sell personal information and do not knowingly share personal information for cross-context behavioural advertising. If this changes, we will update this Policy and provide required opt-out mechanisms.

California residents may have the right to know, access, delete, correct, opt out of sale or sharing, limit certain uses of sensitive personal information and not be discriminated against for exercising privacy rights, subject to legal exceptions.

To submit a request, contact privacy@tunnelfox.tech. Authorized agents may submit requests where permitted by law, but we may require proof of authorization and verification of the user’s identity.

14. Children

The Service is not intended for children. You must be at least 18 years old or the age of legal majority in your country, whichever is higher, to use the Service.

We do not knowingly collect personal data from children. If you believe a child has provided data to us, contact privacy@tunnelfox.tech and we will take appropriate action.

15. Cookies, local storage and similar technologies

The Service may use cookies, local storage, Telegram Mini App storage, session identifiers or similar technologies to keep you logged in, remember settings, secure the Service, prevent abuse and improve functionality.

If we introduce optional analytics, advertising or non-essential tracking technologies, we will provide additional notice and consent controls where required by law.

16. Security

We use reasonable technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration and disclosure. No online service is completely secure, and we cannot guarantee absolute security.

You are responsible for keeping your Telegram account, device and connection profile secure.

17. Automated decisions

We may use automated or semi-automated systems to detect fraud, repeated trial abuse, payment risk, security incidents or prohibited use. These systems may result in additional verification, refusal of payment, suspension or restriction of access.

You may contact support to appeal a suspension or restriction where applicable.

18. Changes to this Policy

We may update this Privacy Policy from time to time. The updated version will be posted in the Service or on our legal pages with a new “Last updated” date.

If changes materially affect your privacy rights, we will take reasonable steps to notify you or request renewed acceptance where required by law.

19. Contact

For privacy requests: privacy@tunnelfox.tech
For support: support@tunnelfox.tech / @tunnel_fox_global_bot
For abuse reports: abuse@tunnelfox.tech
For legal notices: provided on request via the support contacts listed in this document

© 2026 TunnelFox Global · @tunnel_fox_global_bot

Terms of Service Privacy Policy Acceptable Use Policy Refund Policy Abuse Contact Support Channel