Information We Collect: Definition and Scope
We define "information collected" as data points acquired during your interaction with our service. The principle is minimisation. We do not collect logs of your browsing activity, connection timestamps, session durations, or IP addresses assigned to you. This is the foundation of our No-Logs Policy. The operational data we do collect falls into distinct, necessary categories for service provision, payment, and basic communication.
Account Information
To create an account, you provide an email address and password. This is the primary identifier. Optionally, you may provide a payment method. We do not require your real name, physical address, or telephone number. The email address functions as a contact point for service alerts and, if you opt-in, promotional communications. You can manage these preferences in your account dashboard.
Payment and Billing Data
Payment processing is delegated to specialised third-party gateways (e.g., Stripe, PayPal, Google Pay). PIA VPN does not store your full credit card number or bank account details. We receive and store a transaction identifier, the payment method type, the subscription plan purchased, the amount paid (e.g., A$89.95 for a 2-year plan), and the expiry date of your subscription. This data is essential for billing, fraud prevention, and fulfilling our 30-day money-back guarantee.
| Data Category |
Specific Data Points Collected |
Primary Purpose |
Retention Basis |
| Account Identity |
Email address, hashed password |
Service access, authentication |
Duration of active subscription |
| Payment Metadata |
Transaction ID, plan type, amount, renewal date |
Financial reconciliation, subscription management |
As required by financial regulations (typically 7 years) |
| Operational Diagnostics |
App version, connection success/failure (not content), aggregate server load |
Service stability, bug fixes, network optimisation |
Anonymised and aggregated; personal identifiers not retained |
| Voluntary Correspondence |
Contents of support tickets, chat logs, email enquiries |
Customer service, issue resolution |
Duration required to resolve enquiry plus a reasonable period for quality assurance |
Comparative Analysis: PIA VPN vs. Typical Data Collection
Many "free" VPN services and some premium ones operate on a data monetisation model. Their privacy policies often disclose collection of "aggregated usage data" or "diagnostic information" that can be de-anonymised. A 2022 study by the Australian Security Policy Institute (unverified due to the institute's non-publication of the raw dataset) suggested that over 70% of free VPN apps in the Google Play Store contained trackers for advertising purposes. PIA VPN's model is subscription-funded. We do not inject ads or trackers into your traffic. Our diagnostic data is anonymised at the point of collection. The difference is structural: we sell privacy, we do not trade in your data.
Practical Application for Australian Users
For an Australian researcher using the service to access global journals or a journalist communicating with sources, this collection scope is critical. Under Australian law, particularly the Privacy Act 1988 and the Notifiable Data Breaches (NDB) scheme, the type of data held determines risk and obligation. Because we do not hold logs of your activity or originating IP addresses, a potential data breach of our systems would not expose your research history or network location. The exposed data would be limited to your account email and payment metadata. This significantly reduces the potential harm scenario. You can further anonymise your account by using a dedicated, anonymous email service.