1. Home
  2. Privacy Policy
Current policy version

Privacy Policy & Data Processing

This policy explains how OpsVM processes data generated through website access, account verification, order fulfillment, billing, and support requests when providing Cloud Mac dedicated physical machines.

Covered workflows Website, console, orders, and support
Privacy request channel Console ticket or support email
Effective date August 21, 2026

On this page

  1. 01Scope
  2. 02Data We Collect
  3. 03Processing Purposes
  4. 04Billing Data
  5. 05Logs and Retention
  6. 06Sharing and International Transfers
  7. 07User Choices and Rights
  8. 08Security and Updates

To request specific order or account records, sign in to the console and submit a ticket so we can verify your identity.

01

Scope

This section defines which activities are covered by this policy and which data remains under the user’s control.

This policy applies to data processing that occurs when you access opsvm.com and its localized pages, create or manage an OpsVM account, configure a Cloud Mac order, complete billing, use the console, or submit a request to the support team.

The console handles account verification, order configuration, billing status, instance information, and support tickets. Whether an action starts on the website or in the console, data used to deliver OpsVM services is processed for the purposes and under the principles described in this policy.

The physical node you rent is dedicated exclusively to you. You generally decide what source code, build dependencies, test data, artifacts, and project files you upload and how they are used. Such content enters support or compliance workflows only when you voluntarily submit it to the support team, authorize troubleshooting, or processing is strictly necessary to meet a specific legal obligation.

Minimize what you submit

Do not send private keys, account passwords, recovery codes, or unsanitized signing materials in tickets or email. Remove tokens, keys, personal addresses, and project secrets from troubleshooting logs before sharing them.

02

Data We Collect

The data collected depends on the features you use; simply viewing a page does not require you to submit complete order details.

We collect only the minimum data needed to provide the service. Account and order workflows identify users, configure services, and record fulfillment status; logs protect systems and help diagnose anomalies; support content is provided voluntarily when you request assistance.

OpsVM Primary Data Categories and Typical Fields
Data category Typical contents How it is generated Primary uses
Account and contact information Email address, account identifier, verification status, preferred language Registration, sign-in, identity verification Identify accounts, send essential notices, protect access
Order information Order ID, model, node, rental term, add-ons, status Order configuration and fulfillment Deploy physical nodes, manage rental terms, verify service scope
Device and access logs Access time, IP address, browser or client information, request result Website and console access Security checks, error analysis, session protection, capacity diagnostics
Billing records USD amount, payment-method category, transaction time, result, linked order Order billing and reconciliation Confirm payments, resolve billing issues, meet recordkeeping obligations
Support requests Issue description, node region, reproduction steps, sanitized logs, correspondence Console ticket or support email Diagnose faults, respond to requests, record outcomes
Content submitted voluntarily Migration requirements, environment details, attachments, and other information you choose to provide Pre-sales assessment or technical assistance Assess configurations, reproduce issues, provide targeted guidance

We do not require complete project data unrelated to an ordinary inquiry. If support staff need more information, they will explain the required fields, purpose, and recommended sanitization method.

03

Processing Purposes

Each data category is tied to an identifiable service, security, or legal purpose.

Deliver physical-node services

Deploy, display status, and manage services according to the OpsVM M4 Core, OpsVM M4 Plus, or OpsVM M4 Pro configuration in your order, together with the selected node and rental term.

Verify accounts and actions

Confirm that sign-ins and sensitive actions come from the relevant account, and process verification codes, session status, password changes, and unusual-access checks.

Fulfill orders and process billing

Link orders, USD payment results, and service periods to confirm deployment, maintain billing records, process renewals, and reconcile transactions.

Troubleshoot connectivity and build issues

Use the node region, time of occurrence, reproduction steps, and sanitized logs to diagnose SSH, graphical-session, Xcode, dependency, or disk-related issues.

Protect the platform and users

Detect automated attacks, credential abuse, unusual requests, malicious traffic, and unauthorized access, while retaining necessary incident records.

Meet legal obligations

Retain necessary transaction, account, or security records under applicable requirements and respond to requests with a valid basis and defined scope.

If we plan to use existing data for a materially different purpose, we will first assess necessity, data scope, and the applicable basis, and where required provide an updated notice or obtain the appropriate choice.

04

Billing Data

Orders are settled exclusively in USD. Records held by the site and by payment processors serve different functions.

OpsVM supports only USDT-TRC20 and Visa / Mastercard / Amex (via Stripe). The gateway available to you is determined by the billing flow. We record the order ID, USD amount, payment-method category, transaction time, result status, and necessary reconciliation references to confirm orders, resolve billing issues, and maintain transaction records.

OpsVM processing

Order and service records

  • Model, region, term, and add-ons
  • Amount due in USD and order status
  • Link between payment result and order
  • Ticket correspondence and outcome for billing issues
Payment processor processing

Authorization and transaction execution

  • Payment fields required to authorize a card payment
  • Transaction verification on the relevant network
  • Returned successful, failed, or pending-confirmation status
  • Necessary transaction records retained under payment rules

Sensitive card fields are handled by the relevant payment flow. Data submitted to a payment processor is also subject to its applicable rules. OpsVM receives only the results and reference information needed to fulfill orders and reconcile payments, and does not use payment data for purposes unrelated to the order.

05

Logs and Retention

Retention periods are not based on one fixed duration; they depend on service status, record purpose, security risks, and applicable obligations.

Data Retention Purposes and Deletion Triggers
Record type Retention purpose Deletion or anonymization principle
Account records Maintain sign-in, order ownership, security verification, and request history Delete or remove identifiable links after account closure and completion of necessary obligations
Order and billing records Deliver services, reconcile payments, handle disputes, and meet recordkeeping obligations Delete, aggregate, or restrict access after the necessary period ends
Access and security logs Detect attacks, investigate anomalies, and protect accounts and infrastructure Clean up on a rolling basis or anonymize after risk investigation ends and the data is no longer needed
Support requests Continue troubleshooting, confirm resolution, and identify recurring faults Remove attachments and nonessential content after the request is closed and the necessary review period has passed
Files submitted by users Complete a specified assessment or reproduce a technical issue Delete promptly after the task is complete; do not retain as general reference material

Before a deletion request takes effect, we will check whether the data remains connected to an active order, unresolved matter, security investigation, or legal obligation. If some records must be retained, we will restrict their purpose and access and stop using them for routine processing beyond the original service.

Data in backups may remain during the normal rotation cycle. These copies are used only for recovery and integrity protection and remain subject to the same deletion and access-control requirements when restored to active systems.

06

Sharing and International Transfers

Data is transferred only when necessary to deliver services, operate infrastructure, handle security incidents, or meet legal requirements.

OpsVM offers six node locations: Singapore, Japan (Tokyo), South Korea (Seoul), Hong Kong, the US East Coast, and the US West Coast. After you select a node, necessary information directly related to order fulfillment and infrastructure operations may be processed in the relevant region. Account management, billing confirmation, and support collaboration may also involve access across regions.

  • Service delivery:We provide the minimum order and technical information to service providers needed for node deployment, networking, storage, or operational support.
  • Infrastructure security:We process relevant logs and incident records to detect attacks, block abuse, remediate vulnerabilities, or restore services.
  • Billing processing:We transmit the information required to complete the transaction through the selected payment flow and receive the transaction result.
  • Legal requirements:We verify and respond only when a request has an applicable basis, clearly defined authority, and a necessary scope.

International processing uses safeguards including purpose limitation, data minimization, access authorization, transfer protection, and traceable records. We do not use complete account details when aggregated data is sufficient, or require raw sensitive materials when sanitized logs are sufficient for troubleshooting.

We do not provide account, order, log, or support content to unrelated parties for the purpose of selling personal data. If our organization changes, the data remains subject to the existing purpose limitations, security requirements, and user rights.

07

User Choices and Rights

You may request access to, correction or deletion of, or restrictions on processing of relevant data, and may ask us to explain the specific scope of processing.

The most direct way to submit a request is to sign in to the console and create a ticket marked “Privacy request,” specifying the relevant account or order scope and the action you want us to take. If you cannot sign in, you may email support@opsvm.com.

  1. 01

    Specify the request type

    Choose access, correction, deletion, processing restriction, or processing information, and identify whether the request concerns account, order, log, or support records.

  2. 02

    Provide minimal identifying information

    Provide an account email address, order ID, or ticket number. Do not include passwords, private keys, or other unrelated sensitive information.

  3. 03

    Complete identity verification

    We may use your active session, account-linked email, order information, or another necessary method to confirm the requester’s relationship to the data subject.

  4. 04

    Receive the result

    The result will state what action was taken, which records must still be retained and why, or what minimum additional information is needed.

Some requests may be limited by active orders, incomplete transactions, security investigations, the rights of others, or applicable recordkeeping obligations. In such cases, we will narrow the retention scope, restrict processing purposes, and explain specifically why the data cannot be deleted immediately or provided in full.

08

Security and Updates

Safeguards cover identity, access, transfers, logs, incident response, and policy changes.

Access controls

We grant access to systems and support data according to responsibilities, authenticate sensitive actions, and record necessary activity trails.

Least privilege

People and systems receive only the permissions needed for the current task. Temporary access is removed when the task ends, and long-term permissions are reviewed.

Transfer protection

Websites, the console, and necessary service communications use transfer protections to prevent credentials and order information from being exposed directly in transit.

Incident response

When an anomaly is detected, we verify it, limit its impact, remediate it, document it, and review what happened. When notification is required, we provide actionable information through account-linked channels.

Policy updates

When service workflows, data categories, or applicable requirements materially change, we will update this page and its effective-date information. Important changes affecting user choices will be announced through the website, console, or account-linked email. Before continuing to use the service, you can review the revised processing scope and privacy request channels.

Governing law and disputes

This policy is interpreted and governed by the laws of the jurisdiction where the platform operator is based. Disputes related to this policy that cannot be resolved through the support process may be submitted to a court with jurisdiction in that jurisdiction.

If you have questions about the scope of data processing, security measures, or request status, submit a ticket in the console or email support@opsvm.com. Use “Privacy request” in the subject line and avoid attaching sensitive material unrelated to your request.

Request data access or correction

Sign in to the console to submit a ticket linked to your account and orders. If you cannot sign in, contact us using your account-linked email.

Submit a console request Send a privacy email