01Who we are
RayCentral LLC (“RayCentral”, “we”, “us” or “our”) is a Limited Liability Company organised under the laws of the State of New Mexico, United States, with its principal place of business at 1209 Mountain Road Pl NE, Albuquerque, NM 87110, United States and D-U-N-S Number 149921732.
We are the party responsible for the personal information described in this policy. For any question about this policy or about how we handle personal information, contact us at contact@raycentral.net. For questions relating to one of our applications, including RayX VPN, contact support@raycentral.net.
02Scope of this policy
This policy covers three distinct contexts:
- This website — visitors browsing raycentral.net and people who submit the enquiry form.
- Our applications — including RayX VPN, our secure connectivity client, and our other published mobile and desktop software.
- Our client services — custom software development, network engineering and cloud work delivered under contract.
Where we build or operate software on behalf of a client, that client determines what personal information is processed and for what purpose; we act on their documented instructions under the terms of the relevant agreement, and their own privacy notice governs that processing.
03RayX VPN: what the app does and does not process
RayX VPN is designed around data minimisation. This clause sets out exactly what the app and the service behind it do not touch, and the limited data they do process in order to work.
What the app does not collect
The app does not collect, inspect, log, store or monitor:
- user data;
- network traffic passing through the tunnel, or its contents;
- browsing history, visited websites or page content;
- DNS queries or resolved domain names;
- IP addresses, including the destinations you connect to.
No user data from the app is transferred to, sold to or stored by third parties.
What the service does process
To operate the service, RayCentral LLC processes a device key, its entitlement and the connection metadata necessary to operate the servers. The records the service keeps for your device fall into the following categories:
- Device key — an identifier for your device, derived from identifierForVendor and kept in the keychain, and a hash of a device secret used to prove that requests come from that device. The device key is the identifier the service uses for you. The app has no accounts and no registration, and asks for no email address and no password.
- Entitlement — the records that determine whether your device currently holds valid access to the service: its access status and expiry date, how the access was granted (by access code, by the operator, or by transfer from another device), any revocation or transfer markers, and the date the device last checked in. Alongside these, the operator keeps the access code itself and the history of its activations, and may attach a free-text note and an audit log of the actions it has taken on your access. Your access is also associated with a customer login: a reference assigned by the operator when it issues your access, shown in the app’s Settings as “Login”. You do not choose or register it, and it has no password; because the operator assigns it, it is the one record that may contain a name or other reference by which the operator knows you.
- Connection metadata necessary to operate the servers — the connection configuration the app needs to reach our servers (server addresses and a per-device connection identifier), a push notification token for the device, a daily activity marker (the date on which the device last used the service), and the server-management records described in the next paragraph.
Our own control plane — the part of the service that issues entitlements and connection configuration — does not record when a tunnel is connected or disconnected or which server it is routed through. The management panel that runs the VPN servers does keep, for each device, the time of its last activity, the server it last connected to, and counters of the volume of traffic it has passed. These are necessary to operate the servers. Beyond this, the only place such details appear is a diagnostics log you choose to send (see below). The contents of your traffic, the addresses you visit and your DNS queries are not logged in normal operation: the servers run without an access log, and none of the records above is linked to browsing activity, traffic contents or DNS queries.
These records are retained while your access is active and for a period afterwards, so that a returning device can find its access again. To have them deleted, email support@raycentral.net quoting your login or access code; the operator then deletes the customer record, entitlement, connection configuration, push tokens, transfer records, diagnostic bundles, login records and the device’s record in the server management panel. Activation history and the operator audit log are retained.
Infrastructure request logs and diagnostic bundles
Hosting provider logs. The service runs on Google Cloud Run. As with any hosted service, the platform keeps standard technical request logs, which include the IP address from which each request to our service was made, for 30 days. These are platform logs generated by the hosting provider: the app does not access them, and we do not read, analyse or otherwise use their contents to operate the service.
Diagnostic bundles. If you choose to send a diagnostic report from the app, it uploads a bundle containing technical information about the operation of the tunnel on your device — including the device model and operating system version, the server the app attempted to reach and the time of the attempt. Bundles are uploaded only on your explicit action, are used solely to investigate the problem you reported, and are deleted after 7 days.
We do not employ tracking or advertising SDKs in RayX VPN, we do not build behavioural profiles of users, and we do not sell or share personal information for cross-context behavioural advertising. RayX VPN does not claim to provide anonymity: it encrypts and routes your traffic, and nothing more.
04RayX VPN: use of the platform VPN APIs on Android and iOS
RayX VPN establishes its tunnel using the VPN mechanism each operating system provides for that purpose, and nothing beyond it:
- On Android, the client uses the operating system’s VpnService API (
android.net.VpnService) — the standard, documented Android mechanism that allows an application to establish a virtual network interface. - On iOS, the client uses Apple’s Network Extension framework (
NEPacketTunnelProvider) — the equivalent Apple-sanctioned mechanism for establishing a packet tunnel.
What these VPN APIs are used for
On both platforms, RayX VPN uses the platform VPN API exclusively to establish an encrypted tunnel between your device and our servers and to route your network traffic through it.
We do not use this capability to inspect, read, decrypt, filter, modify, redirect, intercept or analyse the contents of your traffic. We do not use it to collect data about the applications you use, to serve or inject advertising, or for any purpose unrelated to establishing and maintaining the secure tunnel you asked for.
Both operating systems require your explicit consent before any application may establish a VPN connection. On Android the consent prompt is presented by the system itself; on iOS you must approve the addition of a VPN configuration before the tunnel can be created. Neither prompt comes from us, and no tunnel exists until you grant it. You can revoke that consent at any time by disconnecting within the app or by removing the VPN profile in your device settings.
Traffic passing through the tunnel is routed, not retained. The client requests only the permissions technically necessary to establish and maintain that connection. It does not request access to your contacts, messages, call logs, photos, precise location or other unrelated personal data.
05RayX VPN: access codes, no in-app purchases
No in-app purchases on either platform
RayX VPN contains no in-app purchases, displays no prices and contains no links to any payment page. It does not process any payment, purchase, subscription, renewal or in-app transaction through Google Play Billing or Apple In-App Purchases (IAP), integrates no Google Play Billing Library and no StoreKit in-app purchase functionality, offers no in-app products, and has no subscription offerings configured in Google Play or the Apple App Store.
The app is a free client. Access to the service is granted by an access code issued by RayCentral LLC, the operator, outside the app. Entering an access code grants the device key an entitlement; the app does nothing else with it.
Because no transaction is processed through either store, we receive no purchase records, order or transaction identifiers, subscription state or payer information from Google or Apple in connection with RayX VPN.
There is no self-service sign-up and no registration: access codes are issued by RayCentral LLC directly, outside the app (see clause 6 of our Terms of Service). Any correspondence or billing records that arise from issuing an access code are held as described in clause 6 below, and are not linked to your use of the service.
06Information we do collect
Beyond the RayX VPN service data described in clause 3, the following limited categories of information may be processed:
- Enquiry data — the name, organization, email address and message you submit through the contact form on this website, or send to us by email.
- Access code correspondence — the contact details you give us when requesting an access code outside the app, and the code issued in response.
- Support correspondence — the content of messages you send to our support desk, together with any diagnostic detail you choose to include.
- Billing records — invoices and transaction records for development services and, where applicable, for access codes, retained for accounting and tax compliance.
- Website server data — transient request logs generated by our hosting infrastructure for security and diagnostic purposes, and a short-lived in-memory record of request timing used to rate-limit the contact form against automated abuse.
We do not intentionally collect sensitive or special category information, and we ask that you do not submit such information to us through this website or our support channels.
07How we use information
We use the limited information described above only to:
- respond to your enquiry and provide the services you ask for;
- operate the RayX VPN service — validate a device key’s entitlement, establish and maintain its tunnel, and deliver service notifications — and issue access codes;
- provide technical support and investigate faults you report to us;
- operate, secure and maintain this website and our infrastructure, including defending against abuse;
- meet our accounting, tax and other legal obligations, and to establish, exercise or defend legal claims.
Where the EU or UK General Data Protection Regulation applies, we rely on the performance of a contract (to supply and support what you have requested from us), our legitimate interests (to respond to enquiries and to secure our systems), compliance with a legal obligation (accounting and tax), and consent where we ask for it — which you may withdraw at any time without affecting the lawfulness of prior processing.
08Disclosure of information
We do not sell personal information, and we do not share it for cross-context behavioural advertising. The rules below differ between the RayX VPN app and the rest of our business, so they are set out separately.
RayX VPN app: no third parties
No user data from the RayX VPN app is transferred to, sold to or stored by third parties for their own purposes. The device key, entitlement and connection metadata described in clause 3 are processed only by RayCentral LLC for the purpose of running the service, and are not shared with any advertiser, analytics vendor or other third party. The only outside party involved is Google, acting as a processor on our behalf in two roles: as our hosting provider (Google Cloud), which runs the servers and keeps the platform request logs described in clause 3; and as the operator of Firebase Cloud Messaging, which holds the push notification token and relays our service notifications to your device through Apple’s Push Notification service.
Website, enquiries and business relationships. For the information described in clauses 5 and 6 — enquiry data, access code correspondence, support correspondence, billing records and website server data — we may disclose limited information to:
- service providers who support our business operations — website hosting, email delivery, payment processing and professional advisory services — each bound by written confidentiality and data protection obligations, and permitted to use the information only to provide that service to us;
- professional advisers, insurers and auditors where reasonably required;
- law enforcement or other authorities where disclosure is required by law or necessary to establish, exercise or defend legal claims;
- a purchaser or successor entity in connection with a merger, acquisition or sale of our business or assets, under equivalent confidentiality terms.
09International transfers
We are based in the United States, and information you send to us is processed there. Our infrastructure providers may operate facilities in other jurisdictions. Where personal information originating in the European Economic Area, the United Kingdom or Switzerland is transferred to us or our processors, we rely on an appropriate transfer mechanism, such as the European Commission standard contractual clauses together with the UK Addendum. Details applicable to a specific engagement are available on request.
10Retention
We retain personal information only for as long as necessary for the purpose for which it was collected. Enquiry correspondence that does not lead to an engagement is generally retained for up to 24 months. Billing and tax records are retained for a minimum of seven years, or longer where required by law. Website server logs are retained for a short period for security and diagnostic purposes and then discarded.
RayX VPN. The app does not create logs of user traffic, browsing history, DNS queries or IP addresses, so there are none to retain. The device key, entitlement and connection metadata described in clause 3 are retained while your access is active and for a period afterwards, so that a returning device can find its access again, and are deleted on request as described in clause 3 (activation history and the operator audit log are retained). Hosting provider request logs are kept by the platform for 30 days; diagnostic bundles you choose to send are deleted after 7 days.
11Security
We maintain technical and organizational measures appropriate to the risk, including encryption of data in transit, encryption of the VPN tunnel, access control on a least-privilege basis, network segmentation, supplier due diligence and staff confidentiality obligations. Data minimisation is itself a security control: the information we never collect cannot be breached. No method of transmission or storage is entirely secure, and we cannot guarantee absolute security; we will notify affected individuals and the relevant authority of a security incident affecting personal information where legally required to do so.
12Cookies and analytics
This website is designed to operate without non-essential cookies. It does not run third-party advertising or behavioural analytics. Any cookies used are strictly necessary for the operation and security of the site. Our applications, including RayX VPN, contain no advertising or tracking SDKs. Should we introduce analytics or other non-essential cookies, we will present a consent mechanism and update this policy accordingly.
13Your rights
Subject to the conditions and exemptions in applicable law, you may have the right to:
- know what personal information we hold about you and request access to it;
- request correction of inaccurate or incomplete information;
- request deletion of your personal information;
- request a portable copy of information you provided to us;
- opt out of the sale or sharing of personal information — we do neither, so there is nothing to opt out of;
- limit the use of sensitive personal information — we do not collect it;
- not be discriminated against for exercising any of these rights;
- where the GDPR applies, object to or request restriction of processing based on our legitimate interests, and withdraw any consent you have given.
California residents may exercise the rights afforded by the California Consumer Privacy Act as amended by the CPRA, and may use an authorised agent to do so. Residents of other US states with comparable privacy legislation have equivalent rights under their own state law.
To exercise any of these rights, contact contact@raycentral.net. We will acknowledge your request promptly and respond within the period required by applicable law. We may ask for information sufficient to verify your identity before acting on a request. Please note that the RayX VPN app does not keep records of user traffic, browsing history, DNS queries or IP addresses, so an access request cannot return them; the service data that does exist for a device key is described in clause 3.
14Children
Our website, applications and services are not directed at children, and we do not knowingly collect personal information from anyone under the age of 13, or under the age of 16 where a higher threshold applies. If you believe a child has provided us with personal information, contact contact@raycentral.net and we will delete it.
15Third-party websites and services
This website and our applications may link to third-party sites and services. We are not responsible for the content or privacy practices of those third parties, and we encourage you to review their own privacy notices. Traffic you send through RayX VPN reaches destinations we do not control, and this policy does not govern what those destinations do with the information you send them.
16Changes to this policy
We may update this policy from time to time to reflect changes in law or in our operations. The current version is always published on this page with the date it was last updated. We will not weaken the commitments in clause 3 or the platform VPN API limitation in clause 4 without giving clear, prominent notice to affected users in advance.
17How to contact us
Privacy questions and rights requests: contact@raycentral.net. Technical and product support: support@raycentral.net. By post: RayCentral LLC, 1209 Mountain Road Pl NE, Albuquerque, NM 87110, United States.
Company details
- Registered name
- RayCentral LLC
- Entity type
- Limited Liability Company, New Mexico, USA
- D-U-N-S Number
- 149921732
- Business address
- 1209 Mountain Road Pl NE, Albuquerque, NM 87110, United States