1. Hosting
  2. Privacy Policy
Data Processing Rules

Privacy Policy: Why Each Data Category Is Processed

This policy explains how VMArm processes data when you visit the website, verify an account, order a dedicated physical Mac node, manage delivery, confirm payment, or contact support. We use data only for its stated purposes and do not use support logs for unrelated purposes.

Version status Current version
Covered services Website, console, orders, and support
Privacy contact support@vmarm.com
Quick navigation

Policy contents

  1. 01Scope
  2. 02Data collected
  3. 03Purposes
  4. 04Payment data
  5. 05Sharing and processors
  6. 06Retention
  7. 07Cross-region processing
  8. 08User rights
  9. 09Security and updates
Submit a ticket in the console
01
Scope

What processing activities does this policy cover?

This policy applies to data processing when you visit vmarm.com, create or use a VMArm console account, configure a Cloud Mac order, receive dedicated physical node connection details, manage renewals and billing, or contact support by email or console ticket.

Website browsing, account and order management, node delivery, and support communications are related but distinct processing contexts. We process only the information needed for the feature you use. Viewing a public page does not automatically give us access to project files, source code, or build artifacts on your node.

Public website

We process basic access and security logs to deliver pages, detect anomalies, and protect the service.

Accounts and orders

We process identity and contact details, selected configuration, node region, billing period, and order status.

Node delivery

We process allocation records, connection-information generation status, and delivery-related activity records.

Support communications

We process issue descriptions, reproduction steps, and sanitized diagnostic materials that you choose to provide.

This policy does not change your rights to your code, build artifacts, or business data. Follow your team’s internal rules when deciding what to include in a ticket or store on a rented node.

02
Data types

What data we collect and where it comes from

We mainly obtain data you submit, records generated during order and node delivery, and technical logs needed to secure the website and console. The data required varies by feature.

Account information
This may include your login email, verification status, account-security settings, session status, and necessary contact details maintained in the console.
Order information
This may include the order number, VMArm M4 Core or VMArm M4 Plus configuration, rental period, node region, storage expansion, Thunderbolt 5 pairing option, and order status.
Payment status
This may include the amount due, USD settlement records, payment-method category, payment confirmation status, transaction identifiers, and reconciliation records needed to resolve processing issues.
Device and access logs
These may include IP address, browser and device type, access time, request path, session identifier, security events, and failed requests. We use this data to deliver pages, protect accounts, and investigate anomalies.
Node activity records
These may include node allocation, system initialization, connection-information generation, renewal, expiry handling, and management actions initiated in the console.
Support ticket content
This may include the order number, node, incident time, system and Xcode versions, reproduction steps, error messages, and sanitized logs or screenshots you upload or paste.
Sanitize diagnostic materials before submitting

Remove private keys, access tokens, signing private keys, repository credentials, database passwords, and other sensitive content unrelated to troubleshooting. Support will not ask you to submit these materials on a public page.

03
Purposes

Specific purposes of data processing

We do not use the broad phrase “service improvement” to expand data use indefinitely. Our main purposes and the related data are listed below.

Account verification

Verify your email, maintain login sessions, detect suspicious attempts, and help restore normal console access.

Order fulfillment

Confirm the selected model, rental period, node region, and add-ons; record payment status; and generate verifiable order results.

Node delivery

Allocate the dedicated physical Mac node, initialize the system, generate connection details, and manage renewals.

Security protection

Detect unauthorized access, malicious requests, credential misuse, and anomalies that could affect node or platform stability.

Troubleshooting

Use order status, node records, incident times, and sanitized logs to locate connection, build, network, storage, or billing issues.

Customer support

Receive questions, confirm acknowledgments, provide diagnostic updates, record resolutions, and check context when similar issues recur.

Legal obligations

Meet applicable recordkeeping, dispute-handling, security-investigation, and lawful-request obligations while retaining the necessary processing basis.

When processing purposes materially change, we assess whether to update this policy, provide additional information, or obtain authorization required by applicable rules.

04
Billing

How payment data is handled

All orders are settled in USD. VMArm supports only USDT-TRC20 and Visa, Mastercard, or Amex processed through Stripe. The available gateway is determined by the result returned in the console.

USDT-TRC20

Transaction identifiers recorded

To confirm payment, we may process the transaction identifier, amount, confirmation status, submission time, and order association. Do not send wallet keys or other control credentials in tickets.

Stripe card payments

Payment processors handle sensitive card data

When you use Visa, Mastercard, or Amex, Stripe handles card-data processing in its payment interface. VMArm receives the payment status and limited transaction information needed for order completion, reconciliation, and dispute handling.

VMArm does not infer the content of your development projects from payment records. Payment status is used only for order confirmation, node delivery, renewals, accounting reconciliation, refunds or disputes, and required recordkeeping.

05
Disclosure boundaries

Data sharing and processors

We share data only as necessary to deliver services, process payments, protect the platform and nodes, resolve issues, or respond to lawful requests. We minimize sharing to the fields needed for the specified task.

  • Infrastructure and delivery processing:Process relevant data to host the website, operate the console, allocate nodes, send necessary notices, or retain service records.
  • Payment processing:Provide the relevant payment processor with information needed to complete transactions, confirm results, and handle disputes.
  • Security monitoring:Process necessary logs and incident records when identifying malicious requests, account anomalies, network attacks, or node abuse.
  • Professional services:When genuinely necessary for audits, compliance, dispute handling, or security investigations, provide limited information to professional processors bound by confidentiality.
  • Lawful requests:Verify the scope of a request under valid and applicable legal process and disclose only data legally required.

Processors may handle data only for agreed purposes and must apply security measures appropriate to the task’s risks. We do not sell account information, order information, node activity records, or support ticket content.

06
Lifecycle

How retention periods are determined

Data is not all deleted at the same moment when an order ends. Retention depends on purpose, account status, order fulfillment, dispute handling, security audits, and applicable obligations. Once the purpose ends, we delete, anonymize, or isolate the data with restricted use.

Data category, primary retention basis, and end-of-retention handling
Data category Primary retention basis End-of-retention handling
Account information The active account period and the period needed after closure to complete security verification and resolve outstanding matters Delete, de-identify, or retain only fields that must be kept by law
Order and billing records The period needed for order fulfillment, reconciliation, dispute handling, and applicable recordkeeping obligations Restrict access, then delete or anonymize when the retention basis ends
Access and security logs The period needed to detect anomalies, investigate security incidents, protect accounts, and verify system integrity Rotate, aggregate, or delete under the security policy
Node activity records The period needed for delivery, renewals, expiry handling, troubleshooting reviews, and activity audits Clear or de-identify after the service relationship ends and no matters remain outstanding
Support tickets The period needed to resolve issues, record outcomes, handle later disputes, and identify recurring failures Delete attachments, remove unnecessary content, or restrict access to historical records

If data relates to an incomplete order, security incident, payment dispute, or valid legal request, relevant records may be retained with restricted access beyond the usual period until the matter ends. Retention does not permit use for new, unrelated purposes.

07
Node regions

Cross-region processing when selecting a node

VMArm offers 5 node regions: Singapore, Japan (Tokyo), South Korea (Seoul), Hong Kong, and the Western United States. After you select a node, data related to allocation, connection details, runtime status, troubleshooting, and activity audits may be processed in the selected region or the region where support services operate.

SingaporeSuitable for Southeast Asian teams and repositories
Japan (Tokyo)Suitable for Japan and East Asian workflows
South Korea (Seoul)Suitable for South Korean and Northeast Asian workflows
Hong KongSuitable for South China and Southeast Asian connectivity
Western United StatesSuitable for teams and repositories on the North American West Coast

Cross-region processing does not change the purpose of the data. We apply access controls, transmission safeguards, audit logs, and processor requirements based on data type, purpose, and risk. Choose a region based on team locations, repository location, internal compliance requirements, and remote-connection quality.

A node region indicates the service-delivery location; it does not mean that all account, payment, or support records are processed only there. To ask about the data path for a specific order, submit a console ticket with the order number.

08
Request process

Access, correction, deletion, and processing restrictions

You may request access, correction, deletion, restriction of processing, or other applicable privacy actions for data related to your account or orders. You may also ask about the source, purpose, retention basis, or processor category for specific data.

  1. 1
    Describe the request scope

    Provide your account email, relevant order number, data categories requested, and preferred action. Do not submit your account password, node credentials, or keys.

  2. 2
    Complete identity verification

    We verify the requester using information matching the account and order. When necessary, we may ask you to confirm through a verified email address or a logged-in console.

  3. 3
    Assess the applicable scope

    We determine whether the request affects an order in progress, an outstanding payment, a security investigation, another user’s rights, or records that must be retained.

  4. 4
    Take action and report the result

    After verification, we explain the action taken, any restricted parts and the reasons, and provide the processing status through the original request channel.

Privacy requests can be sent to support@vmarm.com, or you can submit a ticket from the console. To avoid repeated verification, please keep the same matter in one communication thread whenever possible.

Requests involving applicable law or dispute handling are handled under the law of the jurisdiction where the platform operator is based. Matters requiring judicial resolution will be handled by a court with jurisdiction in that jurisdiction.

09
Protection measures

Security controls, incident response, and policy updates

We configure safeguards based on data sensitivity, processing context, and foreseeable risk. Security must be implemented through access, records, transmission, and response procedures—not merely stated.

Access controls

Grant access to account, order, node, and support data according to job responsibilities, and restrict unnecessary bulk access.

Log auditing

Record key login, order-management, node-delivery, and support actions to detect anomalies and reconstruct processing activity.

Transmission protection

Use encrypted connections for data transmitted through the website, console, and service interfaces, while reducing sensitive-data exposure in logs.

Incident response

Confirm, isolate, assess, remediate, and review suspicious activity, and provide required notices where applicable.

You should also protect console login details, system accounts, VNC credentials, signing certificates, and access tokens; limit internal sharing; and maintain separate backups of code, build artifacts, and business data.

We update the policy text and version status when service features, data types, processors, or applicable rules materially change. A new version applies from the effective status shown on the page; significant changes will be highlighted through reasonable channels. Historical processing remains governed by the rules effective at the time and continuing obligations.

If you identify a security issue that may involve account, order, or node data, email support@vmarm.com or submit a console ticket with the time, relevant order number, scope of impact, and sanitized reproduction details.

Privacy requests and data questions

Include account and order context to reduce back-and-forth verification

State the requested data category, relevant order number, and preferred action. Do not send passwords, private keys, access tokens, or unsanitized build logs.

Send a privacy request Submit a ticket in the console