Processing scope

Data is processed only to deliver, secure, and support the service

This policy explains what data is involved in VMMini’s public site, order console, and customer support interactions, why it is needed, who may access it when necessary, and how you can exercise applicable data rights.

Coverage Site, orders, support
Processing principles Necessary, restricted, traceable
Contact channels Email or console tickets
Policy version Current effective version
Reading guide

Find the data practice relevant to you

If you are only browsing the site, focus on the scope and website usage data sections. If you have placed an order, also read the sections on order records, device logs, retention, and rights requests.

01 · Processing scope

Scope

Whether data enters a processing workflow depends on whether you are using public content, order management features, or working with the service team to resolve a specific issue.

Public site

When you visit vmmini.com, read plans, help documentation, or legal pages, we may process page requests, browser type, language settings, access time, referring page, and network information used for security decisions.

This data is used to deliver pages, detect unusual requests, and measure whether documentation is useful. You do not need to place an order first.

Orders and node management

When you verify access in the console, place an order, or select VMMini M4, a billing cycle, a node, or add-ons, we process the account, order, payment-status, and node-association records needed to complete the transaction and deliver the service.

Instances, subscriptions, invoices, and tickets in the console are associated with your login account so we can display the correct service status and prevent unauthorized access.

Customer support interactions

When you email us or submit a ticket through the console, we process the order ID, node, issue description, time of occurrence, reproduction steps, and redacted logs that you provide.

Support requests should not include passwords, private keys, recovery information, or complete business data unrelated to troubleshooting. If unnecessary sensitive content is found, we may ask you to resubmit redacted materials.

02 · Field categories

What data we collect

We collect only what is needed for the current action. Different features use different fields, and browsing public pages does not automatically require order information.

A

Account and contact information

This includes the email address used to verify access and receive service notifications, your name if provided during support communications, and account verification, login-time, and security-incident records.

Your email is used for login verification, order notifications, billing status, and support replies. We will not ask you to submit node passwords or private keys through public pages.

B

Order and transaction records

This includes order IDs, VMMini M4 configuration, daily, weekly, monthly, or quarterly billing-cycle selections, node selections in Singapore, Tokyo, Seoul, or Hong Kong, SSD and Thunderbolt 5 parallel add-ons, USD amounts, payment status, and transaction reference information.

Payment processing involves only USDT-TRC20 or Visa, Mastercard, and Amex through Stripe. The relevant payment process handles full card security information; VMMini receives only the status and reference fields needed to complete the order and reconcile transactions.

C

Device and security logs

This includes login attempts, session status, access sources, node connection events, system alerts, resource anomalies, service-operation records, and technical signals used to detect abuse or unauthorized access.

Logs help answer “who performed which service operation, and when?” and help distinguish platform failures, external network issues, and user software behavior.

D

Support request content

This includes the issue type, order ID, related node, time of occurrence, reproduction steps, command output, error messages, attachment details, and communication records. Technical materials should first have keys, tokens, personal data, and unrelated business content removed.

If a ticket requires collaborative troubleshooting, only authorized personnel assigned to the task may access the relevant content within their responsibilities.

E

Website usage data

This includes aggregated or technical data such as pages visited, click paths, page responses, device type, browser, and language preferences. It is used to find broken links, understand whether help content solves problems, and improve usability.

Website usage data is not used to build sensitive profiles unrelated to cloud Mac services.

03 · Purpose mapping

Purposes and legal bases

Every processing activity must serve a clear task. If the purpose materially changes, we will assess whether to update this explanation, narrow the scope, or obtain applicable authorization again.

Service provision and delivery

Verify accounts, create orders, associate physical nodes, display subscription and billing status, and provide instance-management capabilities to the correct account.

Basis: fulfilling service requests and orders

Access verification

Send verification codes, detect unusual logins, manage sessions, and prevent unauthorized access to accounts or the console.

Basis: security needs and service integrity

Order and payment processing

Confirm USD order amounts, payment status, add-ons, billing cycles, and transaction references to complete delivery, reconciliation, refunds, and dispute reviews.

Basis: order fulfillment and financial record requirements

Technical troubleshooting

Use node events, user-provided reproduction steps, and redacted logs to identify connection, build, disk, or service-response issues.

Basis: user requests and service support

Platform security

Detect abuse, unusual access, destructive operations, and behavior affecting other services, while retaining the necessary audit trail.

Basis: legitimate security interests and risk control

Compliance with applicable obligations

Retain necessary order, transaction, compliance, and dispute records, and respond to legally valid, clearly scoped requests.

Basis: applicable legal obligations

Documentation and process improvement

Analyze common error paths, searches with no results, and repeated support issues to improve help content and reduce unnecessary data submission.

Basis: reasonable service-improvement needs
04 · Restricted collaboration

Sharing and cross-border processing

Data access is assigned by task. A provider’s involvement in one stage does not open access to the entire account, order, or support record.

Infrastructure and service delivery

To provide the public site, account verification, order records, node delivery, log storage, and support capabilities, necessary infrastructure providers may process data directly related to their tasks in controlled environments.

Access is limited by role, system boundary, and operational purpose. Contractual obligations, identity verification, logging, and access reviews reduce unnecessary access.

Payment processing

When you select a supported payment method, the data required to complete payment is submitted to the relevant processor. VMMini receives order confirmation, amount, status, and transaction reference information for reconciliation and service delivery.

Payment processors perform fraud prevention, security verification, and transaction processing within their responsibilities and may not use the data for purposes unrelated to those tasks.

Data minimization

Only provide the fields required for the specified task, not complete datasets unrelated to it.

Purpose limitation

Provider access must be governed by contracts, confidentiality requirements, permission boundaries, and auditable records.

Cross-border safeguards

When infrastructure, node delivery, or support collaboration involves cross-border processing, we use contractual safeguards, access restrictions, transfer protections, and risk assessments under applicable rules.

Lawful requests

We assess disclosure only when a request is lawful, valid, and clearly scoped, and limit the disclosed fields where permitted.

05 · Data lifecycle

Retention logic and security measures

We do not apply one retention period to all data. We assess each category based on whether the service is ongoing, the record still has a business purpose, applicable obligations exist, and dispute handling requires retention.

Retention decisions and deletion triggers by data category
Data category Retention decision Primary uses Deletion or de-identification condition
Account and verification records For as long as the account is active and as needed to handle security incidents Login, verification, and unusual-access detection The account is closed and no ongoing security, compliance, or dispute need requires retention
Order and transaction records For as long as needed to fulfill the order, reconcile finances, and meet applicable recordkeeping obligations Delivery, reconciliation, refunds, or dispute review Delete or de-identify after related obligations and dispute-handling periods end
Device and security logs For as long as needed to identify risks, audit operations, and investigate incidents Security monitoring, fault diagnosis, and operational tracking The risk window has ended and the logs no longer support an investigation or applicable obligation
Support request content For as long as needed to handle tickets, review outcomes, and improve documentation Responding to issues and preserving support context The request is closed and no recurring-issue analysis, dispute, or applicable obligation requires retention
Website usage data For a limited period needed to assess page quality and security trends Performance analysis, documentation improvement, and unusual-request detection Delete detailed records after aggregate analysis or convert them into statistics that cannot be directly linked to a user

Access controls

Permissions are granted by role and task, limiting access to administrative features, order data, and support materials. We regularly review and remove permissions that are no longer needed.

Transfer protection

We use encrypted transmission to protect data in site, console, and support interactions, reducing the risk of interception or alteration over the network.

Log auditing

We record key account, order, and service operations to support incident investigations, access reviews, and dispute handling, while limiting unnecessary sensitive content in logs.

Deletion process

When data is no longer needed and no applicable retention requirement exists, we remove it from use through deletion, overwriting, or de-identification, followed by cleanup of relevant backups.

06 · Request process

User rights and contact

Depending on the rules that apply to you, you may request access to, correction of, deletion of, or restricted processing of relevant data. You may also object to processing, request an applicable data copy, or withdraw consent-based processing.

What requests can you make?

  • Access:Confirm whether we process data relating to you and learn its main categories, purposes, and recipient groups.
  • Correction:Correct inaccurate or incomplete account, contact, or order-related information.
  • Deletion:Request deletion when the data is no longer necessary and no basis for continued retention exists.
  • Restricted processing:Request temporary restriction of a specific use while accuracy, legality, or a dispute is being reviewed.
  • Objection or withdrawal:Submit an applicable request concerning processing based on legitimate interests or consent.
  • Data copy:Request a clear, readable copy of your data within the applicable scope.

Why identity verification is required

To prevent account, order, or support data from being disclosed to someone without authorization, we verify identity using the account email, order ID, recent service information, or another risk-appropriate method.

Verification requires only enough information to confirm the requester’s relationship to the data. Do not send passwords, private keys, verification codes, or recovery phrases by email.

Request checklist

Include these four details

  1. 01
    Request type

    Access, correction, deletion, restricted processing, or another applicable right.

  2. 02
    Scope

    Account, order, support request, or website usage data.

  3. 03
    Reference details

    Account email, order ID, or ticket ID. Do not include access keys.

  4. 04
    Expected outcome

    Specify what should be verified, corrected, exported, restricted, or deleted.

Need to verify specific data-processing records

Provide your account email and relevant order ID, and we will investigate within the defined scope

Privacy requests can be sent to support@vmmini.com. For questions about an existing order, you can also log in to the console and submit a ticket. Do not send passwords, private keys, or unredacted logs.