Data Processing Overview

How We Handle Your Data

This policy explains what data VMOwn processes when providing its content website, responding to contact requests, supporting cloud Mac services, and maintaining related order records; why we process it, how long we keep it, and how you can exercise your rights.

Applies to
Website visitors, prospective customers, and service users
Version status
Current public version
Contact channels
Support email or portal ticket
01
Scope

Scope of this policy

This policy applies to data processing that occurs when you visit the vmown.com content site, read product and support materials, send us a contact request, submit a ticket through the portal, or rent and manage VMOwn cloud Mac services.

The content site primarily presents Apple Silicon cloud Macs, dedicated physical servers, non-virtualized services, configurations, locations, support resources, and usage rules. You do not need to provide your name or order details when viewing public pages, but our servers may still generate technical logs needed to maintain access and security.

When you enter the portal from the content site, login verification, order configuration, service delivery, billing records, device management, and ticket communications take place within the account-service context. Data processed in this context is generally linked to an account, order, or device identifier so we can identify the relevant service record.

Content outside the direct scope of this policy

Third-party payment providers process the data required to complete transactions under their own rules. We receive only the results and identifiers needed to fulfill orders, verify payments, handle refund disputes, or meet applicable obligations.

02
Data categories

What data may we collect

We process only the data needed for clearly defined business purposes. The specific fields depend on whether you browse content, request information, submit a technical issue, or manage an existing order.

Access and security logs

These may include request time, pages visited, referring page, IP address, response status, browser identifier, and security-event records used to detect abnormal traffic.

Device and browser information

This may include device type, operating-system category, browser version, language settings, viewport dimensions, and technical identifiers for necessary Cookies.

Contact request fields

These include the name, work email, issue category, target location, preferred rental term, order identifier, and issue description you provide.

Support communications

These include ticket subject, message content, incident time, system version, excerpts from error logs, reproduction steps, and processing status.

Order and service data

When a request relates to an existing service, we may process account and order identifiers, selected model, location, rental term, add-ons, payment status, service-delivery status, and support records. Remote access credentials are managed only as needed to provide access and address security requests.

Do not send private keys, full passwords, remote-control verification codes, or unrelated sensitive information by email or ticket. Before submitting logs, remove tokens, keys, personal file paths, and other unnecessary information.

03
Purposes and legal bases

Why we process this data

We determine processing purposes based on the nature of your request, the service relationship, and applicable obligations. Troubleshooting information collected for technical support is not automatically repurposed for unrelated uses.

Provide the website and services
Deliver page content, maintain necessary sessions, create and fulfill orders, deliver cloud Macs, manage renewals, and display service status.
Respond to inquiries and support requests
Understand the issue context, verify order ownership, reproduce problems, record handling steps, and send necessary responses.
Prevent abuse and protect security
Detect unusual logins, malicious requests, automated attacks, unauthorized access attempts, and activity that may affect service stability.
Fulfill transactions and service agreements
Verify payments, confirm configurations and locations, maintain billing records, deliver services, and resolve order-related disputes.
Meet applicable obligations
Retain transaction evidence, security records, and request-handling records as necessary, and respond to valid requests made under applicable requirements.

Legal bases may include performing our service agreement with you, responding to your request before taking order or support steps, protecting the legitimate security interests of the platform and its users, obtaining your consent, or complying with obligations applicable to the operating entity. The specific basis varies by processing context.

04
Payment records

How payment data is handled

VMOwn orders are settled in USD and support USDT-TRC20, plus Visa, Mastercard, and Amex card payments processed through Stripe. The payment gateways actually available are determined by the result returned in the portal.

Card payments

Full card numbers, security codes, and card verification data are handled by Stripe’s payment process. VMOwn does not store complete card details. We may receive the transaction result, payment status, amount, currency, time, and transaction identifier used to reconcile the order.

USDT-TRC20

To verify order payments, we may process the on-chain transaction hash, receiving address, payment amount, confirmation status, time, and linked order identifier. Transactions on a public ledger are queryable and cannot be deleted solely by VMOwn.

Payment records are used to confirm orders, handle billing inquiries, reconcile unusual transactions, prevent duplicate credits, and meet applicable financial-record obligations. We will not ask you to send complete card details by email.

05
Browser data

Cookies and basic analytics

We may use necessary Cookies or similar local-storage technologies to maintain login status, save language and interface preferences, protect form requests, identify sessions, and prevent duplicate or abnormal actions. These technologies are fundamental to the normal operation of the website and portal.

The content site may use aggregated visit analytics to understand page views, entry pages, device categories, and basic usage trends. Results help us improve information architecture, identify page errors, and assess whether content answers user questions; they are not used to build sensitive profiles unrelated to the service.

Browser controls

You can view, clear, or restrict Cookies in your browser settings and adjust site-storage permissions.

Impact on functionality

Disabling necessary Cookies may prevent login, order management, security verification, or preference saving from working properly.

Resetting preferences

After clearing site data, your language, interface choices, and session status may need to be set up again.

06
Recipients

Data sharing and international processing

We do not disclose personal data to third parties for sale. We provide the minimum data to relevant service providers only when necessary to deliver services, protect security, complete payments, or meet applicable obligations.

Recipient category Processing purpose Data that may be involved Limitation principle
Hosting and infrastructure providers Deliver the website, store business data, and operate security protections Access logs, service records, technical identifiers Processed only as needed to provide infrastructure
Email service providers Send verification messages, inquiry responses, and service notifications Email address, message content, delivery status Used only for message delivery and troubleshooting
Support-system providers Record tickets, collaborate on troubleshooting, and track processing status Account identifier, order identifier, ticket content Access controlled as needed to handle tickets
Payment service providers Process card payments, return transaction results, and handle disputes Transaction data, payment status, linked order identifiers Complete card details are handled by payment providers

Because infrastructure, email, support, or payment services may operate in different locations, data may be processed outside your location. We apply measures such as contractual controls, access restrictions, transfer safeguards, vendor assessments, and data minimization based on the nature of the data, the recipient’s role, and applicable requirements.

If data must be disclosed due to a corporate reorganization, business transfer, or valid request made under applicable requirements, we limit the disclosure and require the recipient to continue meeting confidentiality and security obligations appropriate to the nature of the data.

07
Retention and protection

Data retention and security measures

We do not retain data indefinitely merely because it has been collected. Retention periods are determined by the processing purpose, service relationship, dispute-handling needs, security risks, backup cycles, and applicable recordkeeping obligations. When the purpose is complete and there is no basis for continued retention, data is deleted, de-identified, or placed in restricted archives.

Inquiry records
Generally retained until the response is complete, follow-up communications have ended, and a reasonable quality-assurance and dispute-handling period has passed.
Support records
Retained as needed to reproduce issues, maintain service continuity, identify recurring faults, and handle order disputes.
Order and payment-verification records
Retained for the period needed to provide services, reconcile billing, handle transaction disputes, and meet applicable recordkeeping obligations.
Access and security logs
Retained for the period needed to detect attacks, investigate anomalies, protect accounts, and maintain infrastructure security.

Our security measures

  • Use transfer protections to reduce the risk of interception or alteration while data is transmitted over networks.
  • Set access permissions by role and task, apply least-privilege principles, and restrict unnecessary internal access.
  • Log key administrative actions and monitor unusual logins, bulk requests, and suspicious permission use.
  • Conduct necessary vendor assessments and limit provider processing through permissions, procedures, and contractual requirements.
  • Use isolation, backups, recovery validation, and incident-response measures according to data sensitivity.

No technical or organizational measure can eliminate all risk. If a data-security incident may affect your rights, we will investigate its scope, contain the risk, and take notification or remedial measures as required.

08
Your choices

User rights and how to contact us

To the extent permitted by applicable rules, you may request access to data about you, obtain a copy, correct inaccurate information, delete data that is no longer needed, restrict specific processing, or object to processing based on legitimate interests.

Access and copies

Confirm whether we process data about you and learn about the data categories, purposes, recipients, and retention principles.

Correction and completion

Ask us to correct inaccurate account, contact, or order-related information and provide necessary details that affect the processing outcome.

Deletion or restriction

Request deletion when data is no longer necessary and there is no basis for continued retention, or request restricted processing while a dispute is being verified.

Object to processing

Explain your specific circumstances and object to particular processing based on legitimate interests.

How to submit a request

You can email support@vmown.com or log in to the portal to submit a ticket. To help us locate the relevant data, state the request type, email address used, related order identifier, and the scope of data you want us to handle. Do not send passwords, private keys, or complete payment details.

Before carrying out an access, correction, deletion, or restriction request, we may ask you to verify control of the email address, account ownership, or order association. Verification is used only to prevent others from accessing or changing your data without authorization. If a request is too broad, we may ask you to clarify the time period, service records, or data categories.

Some requests may be limited by transaction-record obligations, dispute preservation, security investigations, the rights of others, or other applicable requirements. Where a limitation applies, we will explain the result we can provide and the reason.

Applicable rules and dispute handling

This policy and related data-processing disputes are governed by the laws of the jurisdiction where the platform’s operating entity is located. Disputes that cannot be resolved through communication may be submitted to a court with jurisdiction in that jurisdiction.

Next steps

Review the configuration and data scope before choosing a rental plan

Compare three available configurations, five locations, rental terms, and add-ons. If you have an existing order or need to submit a data-rights request, go to the portal.