Scope
This section defines which activities are covered by this policy and which data remains under the user’s control.
This policy applies to data processing that occurs when you access opsvm.com and its localized pages, create or manage an OpsVM account, configure a Cloud Mac order, complete billing, use the console, or submit a request to the support team.
The console handles account verification, order configuration, billing status, instance information, and support tickets. Whether an action starts on the website or in the console, data used to deliver OpsVM services is processed for the purposes and under the principles described in this policy.
The physical node you rent is dedicated exclusively to you. You generally decide what source code, build dependencies, test data, artifacts, and project files you upload and how they are used. Such content enters support or compliance workflows only when you voluntarily submit it to the support team, authorize troubleshooting, or processing is strictly necessary to meet a specific legal obligation.
Minimize what you submit
Do not send private keys, account passwords, recovery codes, or unsanitized signing materials in tickets or email. Remove tokens, keys, personal addresses, and project secrets from troubleshooting logs before sharing them.
Data We Collect
The data collected depends on the features you use; simply viewing a page does not require you to submit complete order details.
We collect only the minimum data needed to provide the service. Account and order workflows identify users, configure services, and record fulfillment status; logs protect systems and help diagnose anomalies; support content is provided voluntarily when you request assistance.
| Data category | Typical contents | How it is generated | Primary uses |
|---|---|---|---|
| Account and contact information | Email address, account identifier, verification status, preferred language | Registration, sign-in, identity verification | Identify accounts, send essential notices, protect access |
| Order information | Order ID, model, node, rental term, add-ons, status | Order configuration and fulfillment | Deploy physical nodes, manage rental terms, verify service scope |
| Device and access logs | Access time, IP address, browser or client information, request result | Website and console access | Security checks, error analysis, session protection, capacity diagnostics |
| Billing records | USD amount, payment-method category, transaction time, result, linked order | Order billing and reconciliation | Confirm payments, resolve billing issues, meet recordkeeping obligations |
| Support requests | Issue description, node region, reproduction steps, sanitized logs, correspondence | Console ticket or support email | Diagnose faults, respond to requests, record outcomes |
| Content submitted voluntarily | Migration requirements, environment details, attachments, and other information you choose to provide | Pre-sales assessment or technical assistance | Assess configurations, reproduce issues, provide targeted guidance |
We do not require complete project data unrelated to an ordinary inquiry. If support staff need more information, they will explain the required fields, purpose, and recommended sanitization method.
Processing Purposes
Each data category is tied to an identifiable service, security, or legal purpose.
Deliver physical-node services
Deploy, display status, and manage services according to the OpsVM M4 Core, OpsVM M4 Plus, or OpsVM M4 Pro configuration in your order, together with the selected node and rental term.
Verify accounts and actions
Confirm that sign-ins and sensitive actions come from the relevant account, and process verification codes, session status, password changes, and unusual-access checks.
Fulfill orders and process billing
Link orders, USD payment results, and service periods to confirm deployment, maintain billing records, process renewals, and reconcile transactions.
Troubleshoot connectivity and build issues
Use the node region, time of occurrence, reproduction steps, and sanitized logs to diagnose SSH, graphical-session, Xcode, dependency, or disk-related issues.
Protect the platform and users
Detect automated attacks, credential abuse, unusual requests, malicious traffic, and unauthorized access, while retaining necessary incident records.
Meet legal obligations
Retain necessary transaction, account, or security records under applicable requirements and respond to requests with a valid basis and defined scope.
If we plan to use existing data for a materially different purpose, we will first assess necessity, data scope, and the applicable basis, and where required provide an updated notice or obtain the appropriate choice.
Billing Data
Orders are settled exclusively in USD. Records held by the site and by payment processors serve different functions.
OpsVM supports only USDT-TRC20 and Visa / Mastercard / Amex (via Stripe). The gateway available to you is determined by the billing flow. We record the order ID, USD amount, payment-method category, transaction time, result status, and necessary reconciliation references to confirm orders, resolve billing issues, and maintain transaction records.
Order and service records
- Model, region, term, and add-ons
- Amount due in USD and order status
- Link between payment result and order
- Ticket correspondence and outcome for billing issues
Authorization and transaction execution
- Payment fields required to authorize a card payment
- Transaction verification on the relevant network
- Returned successful, failed, or pending-confirmation status
- Necessary transaction records retained under payment rules
Sensitive card fields are handled by the relevant payment flow. Data submitted to a payment processor is also subject to its applicable rules. OpsVM receives only the results and reference information needed to fulfill orders and reconcile payments, and does not use payment data for purposes unrelated to the order.
Logs and Retention
Retention periods are not based on one fixed duration; they depend on service status, record purpose, security risks, and applicable obligations.
| Record type | Retention purpose | Deletion or anonymization principle |
|---|---|---|
| Account records | Maintain sign-in, order ownership, security verification, and request history | Delete or remove identifiable links after account closure and completion of necessary obligations |
| Order and billing records | Deliver services, reconcile payments, handle disputes, and meet recordkeeping obligations | Delete, aggregate, or restrict access after the necessary period ends |
| Access and security logs | Detect attacks, investigate anomalies, and protect accounts and infrastructure | Clean up on a rolling basis or anonymize after risk investigation ends and the data is no longer needed |
| Support requests | Continue troubleshooting, confirm resolution, and identify recurring faults | Remove attachments and nonessential content after the request is closed and the necessary review period has passed |
| Files submitted by users | Complete a specified assessment or reproduce a technical issue | Delete promptly after the task is complete; do not retain as general reference material |
Before a deletion request takes effect, we will check whether the data remains connected to an active order, unresolved matter, security investigation, or legal obligation. If some records must be retained, we will restrict their purpose and access and stop using them for routine processing beyond the original service.
Data in backups may remain during the normal rotation cycle. These copies are used only for recovery and integrity protection and remain subject to the same deletion and access-control requirements when restored to active systems.
Sharing and International Transfers
Data is transferred only when necessary to deliver services, operate infrastructure, handle security incidents, or meet legal requirements.
OpsVM offers six node locations: Singapore, Japan (Tokyo), South Korea (Seoul), Hong Kong, the US East Coast, and the US West Coast. After you select a node, necessary information directly related to order fulfillment and infrastructure operations may be processed in the relevant region. Account management, billing confirmation, and support collaboration may also involve access across regions.
- Service delivery:We provide the minimum order and technical information to service providers needed for node deployment, networking, storage, or operational support.
- Infrastructure security:We process relevant logs and incident records to detect attacks, block abuse, remediate vulnerabilities, or restore services.
- Billing processing:We transmit the information required to complete the transaction through the selected payment flow and receive the transaction result.
- Legal requirements:We verify and respond only when a request has an applicable basis, clearly defined authority, and a necessary scope.
International processing uses safeguards including purpose limitation, data minimization, access authorization, transfer protection, and traceable records. We do not use complete account details when aggregated data is sufficient, or require raw sensitive materials when sanitized logs are sufficient for troubleshooting.
We do not provide account, order, log, or support content to unrelated parties for the purpose of selling personal data. If our organization changes, the data remains subject to the existing purpose limitations, security requirements, and user rights.
User Choices and Rights
You may request access to, correction or deletion of, or restrictions on processing of relevant data, and may ask us to explain the specific scope of processing.
The most direct way to submit a request is to sign in to the console and create a ticket marked “Privacy request,” specifying the relevant account or order scope and the action you want us to take. If you cannot sign in, you may email support@opsvm.com.
-
01
Specify the request type
Choose access, correction, deletion, processing restriction, or processing information, and identify whether the request concerns account, order, log, or support records.
-
02
Provide minimal identifying information
Provide an account email address, order ID, or ticket number. Do not include passwords, private keys, or other unrelated sensitive information.
-
03
Complete identity verification
We may use your active session, account-linked email, order information, or another necessary method to confirm the requester’s relationship to the data subject.
-
04
Receive the result
The result will state what action was taken, which records must still be retained and why, or what minimum additional information is needed.
Some requests may be limited by active orders, incomplete transactions, security investigations, the rights of others, or applicable recordkeeping obligations. In such cases, we will narrow the retention scope, restrict processing purposes, and explain specifically why the data cannot be deleted immediately or provided in full.
Security and Updates
Safeguards cover identity, access, transfers, logs, incident response, and policy changes.
Access controls
We grant access to systems and support data according to responsibilities, authenticate sensitive actions, and record necessary activity trails.
Least privilege
People and systems receive only the permissions needed for the current task. Temporary access is removed when the task ends, and long-term permissions are reviewed.
Transfer protection
Websites, the console, and necessary service communications use transfer protections to prevent credentials and order information from being exposed directly in transit.
Incident response
When an anomaly is detected, we verify it, limit its impact, remediate it, document it, and review what happened. When notification is required, we provide actionable information through account-linked channels.
Policy updates
When service workflows, data categories, or applicable requirements materially change, we will update this page and its effective-date information. Important changes affecting user choices will be announced through the website, console, or account-linked email. Before continuing to use the service, you can review the revised processing scope and privacy request channels.
Governing law and disputes
This policy is interpreted and governed by the laws of the jurisdiction where the platform operator is based. Disputes related to this policy that cannot be resolved through the support process may be submitted to a court with jurisdiction in that jurisdiction.
If you have questions about the scope of data processing, security measures, or request status, submit a ticket in the console or email support@opsvm.com. Use “Privacy request” in the subject line and avoid attaching sensitive material unrelated to your request.