Who is responsible for this data
Mikhmon Pro is a hosted tool for configuring and operating MikroTik RouterOS and Hotspot services. The operator of Mikhmon Pro at mikhmon.pro is responsible for the platform data described here. A Mikhmon tenant administrator is responsible for the personal data they enter into RouterOS or manage through their own Hotspot service.
This policy applies to the Mikhmon Pro website, provisioning flow, control panel, hosted tenant sites, Google account connection, and QRIS billing flow.
Data we process
We process only the data needed to create, secure, operate, and bill for a Mikhmon tenant. The exact data depends on the features you use.
Tenant and administrator data
Your tenant address, selected Mikhmon version, local administrator username, user-interface preferences, voucher templates, generated voucher state, and uploaded PNG logo files.
Router and Hotspot data
Router connection settings such as IP address or host, RouterOS username and password, DNS name, Hotspot configuration, and the RouterOS records needed to operate the service. This can include Hotspot user, host, active-session, traffic, and log records returned by your router.
Google account data
If you choose to connect Google, we store the Google account identifier, verified email address, display name, profile picture URL, and connection timestamps. Google sign-in is optional unless an enabled subscription flow requires an account connection.
Billing data
Plan, amount, payment reference and transaction identifiers, payment status and dates, QRIS expiry, subscription dates, and the payment-provider response or callback payload used to verify a transaction.
Technical and session data
Authentication session identifiers and refresh-token hashes, security cookies, a browser locale preference, rate-limit records, and standard server request logs. We do not use advertising SDKs or third-party behavioural analytics in this application.
How we use data
- To provision, authenticate, host, and secure each Mikhmon tenant.
- To connect to and operate the RouterOS services that a tenant administrator configures.
- To generate vouchers, render tenant content, save settings, and provide the control panel.
- To associate a Google account with a tenant, support Google sign-in, enforce trial eligibility, and operate referrals where used.
- To create QRIS payment requests, verify payment status, apply subscription access, prevent duplicate transactions, and keep transaction records.
- To prevent abuse, rate-limit provisioning and payment checks, troubleshoot errors, and protect the service.
We do not sell personal data, use it for targeted advertising, or use it to make automated decisions about you.
Retention and deletion
We retain active tenant data while it is needed to operate that tenant. You can remove router sessions, templates, generated data, and logo assets through the relevant product controls; replacing data updates the stored tenant configuration.
Browser authentication uses a short-lived access cookie (five minutes) and a refresh cookie that expires after seven days. Expired authentication-session records are removed by the service.
Where subscription enforcement is enabled, a tenant that remains pending or suspended past its configured deletion deadline is automatically removed. Tenant-scoped configuration, RouterOS data, sessions, templates, cached Hotspot records, and asset references are deleted through the tenant relationship. A limited deletion audit record (tenant key, hostname, connected Google identifier if any, deletion date, and reason) remains to record the deletion event. Payment, fraud-prevention, and legal-accounting records may be retained where necessary.
We do not promise a fixed retention period where the software does not enforce one. This avoids claiming a deletion schedule that the service cannot verify.
Your choices and controls
- You can choose not to connect a Google account unless a subscription flow requires it.
- You can edit or remove data that you manage in Mikhmon, including router sessions, templates, generated states, and logo assets.
- You can sign out to remove browser authentication cookies on that device.
- You can avoid using the QRIS checkout flow if you do not wish to send payment-request data to Tripay.
If you need access to, correction of, or deletion of platform data that you cannot control in the product, contact the Mikhmon Pro service operator through the support channel provided for your tenant. The operator may need to verify that you are the authorized tenant administrator before acting on a request.
Security and policy updates
We use tenant separation, authenticated service endpoints, secure HTTP-only authentication cookies, CSRF protections for control-panel changes, payment callback signature verification, and access controls designed to limit data to the relevant tenant. No method of transmission or storage is completely secure, so you should protect administrator and RouterOS credentials and avoid sharing them unnecessarily.
We may update this policy when the service or its legal obligations change. The current version and its last-updated date are published on this page.
