Scope of this policy
This policy applies to data processing that occurs when you visit the vmown.com content site, read product and support materials, send us a contact request, submit a ticket through the portal, or rent and manage VMOwn cloud Mac services.
The content site primarily presents Apple Silicon cloud Macs, dedicated physical servers, non-virtualized services, configurations, locations, support resources, and usage rules. You do not need to provide your name or order details when viewing public pages, but our servers may still generate technical logs needed to maintain access and security.
When you enter the portal from the content site, login verification, order configuration, service delivery, billing records, device management, and ticket communications take place within the account-service context. Data processed in this context is generally linked to an account, order, or device identifier so we can identify the relevant service record.
Third-party payment providers process the data required to complete transactions under their own rules. We receive only the results and identifiers needed to fulfill orders, verify payments, handle refund disputes, or meet applicable obligations.
What data may we collect
We process only the data needed for clearly defined business purposes. The specific fields depend on whether you browse content, request information, submit a technical issue, or manage an existing order.
Access and security logs
These may include request time, pages visited, referring page, IP address, response status, browser identifier, and security-event records used to detect abnormal traffic.
Device and browser information
This may include device type, operating-system category, browser version, language settings, viewport dimensions, and technical identifiers for necessary Cookies.
Contact request fields
These include the name, work email, issue category, target location, preferred rental term, order identifier, and issue description you provide.
Support communications
These include ticket subject, message content, incident time, system version, excerpts from error logs, reproduction steps, and processing status.
Order and service data
When a request relates to an existing service, we may process account and order identifiers, selected model, location, rental term, add-ons, payment status, service-delivery status, and support records. Remote access credentials are managed only as needed to provide access and address security requests.
Do not send private keys, full passwords, remote-control verification codes, or unrelated sensitive information by email or ticket. Before submitting logs, remove tokens, keys, personal file paths, and other unnecessary information.
Why we process this data
We determine processing purposes based on the nature of your request, the service relationship, and applicable obligations. Troubleshooting information collected for technical support is not automatically repurposed for unrelated uses.
- Provide the website and services
- Deliver page content, maintain necessary sessions, create and fulfill orders, deliver cloud Macs, manage renewals, and display service status.
- Respond to inquiries and support requests
- Understand the issue context, verify order ownership, reproduce problems, record handling steps, and send necessary responses.
- Prevent abuse and protect security
- Detect unusual logins, malicious requests, automated attacks, unauthorized access attempts, and activity that may affect service stability.
- Fulfill transactions and service agreements
- Verify payments, confirm configurations and locations, maintain billing records, deliver services, and resolve order-related disputes.
- Meet applicable obligations
- Retain transaction evidence, security records, and request-handling records as necessary, and respond to valid requests made under applicable requirements.
Legal bases may include performing our service agreement with you, responding to your request before taking order or support steps, protecting the legitimate security interests of the platform and its users, obtaining your consent, or complying with obligations applicable to the operating entity. The specific basis varies by processing context.
How payment data is handled
VMOwn orders are settled in USD and support USDT-TRC20, plus Visa, Mastercard, and Amex card payments processed through Stripe. The payment gateways actually available are determined by the result returned in the portal.
Card payments
Full card numbers, security codes, and card verification data are handled by Stripe’s payment process. VMOwn does not store complete card details. We may receive the transaction result, payment status, amount, currency, time, and transaction identifier used to reconcile the order.
USDT-TRC20
To verify order payments, we may process the on-chain transaction hash, receiving address, payment amount, confirmation status, time, and linked order identifier. Transactions on a public ledger are queryable and cannot be deleted solely by VMOwn.
Payment records are used to confirm orders, handle billing inquiries, reconcile unusual transactions, prevent duplicate credits, and meet applicable financial-record obligations. We will not ask you to send complete card details by email.
Cookies and basic analytics
We may use necessary Cookies or similar local-storage technologies to maintain login status, save language and interface preferences, protect form requests, identify sessions, and prevent duplicate or abnormal actions. These technologies are fundamental to the normal operation of the website and portal.
The content site may use aggregated visit analytics to understand page views, entry pages, device categories, and basic usage trends. Results help us improve information architecture, identify page errors, and assess whether content answers user questions; they are not used to build sensitive profiles unrelated to the service.
You can view, clear, or restrict Cookies in your browser settings and adjust site-storage permissions.
Disabling necessary Cookies may prevent login, order management, security verification, or preference saving from working properly.
After clearing site data, your language, interface choices, and session status may need to be set up again.
Data sharing and international processing
We do not disclose personal data to third parties for sale. We provide the minimum data to relevant service providers only when necessary to deliver services, protect security, complete payments, or meet applicable obligations.
| Recipient category | Processing purpose | Data that may be involved | Limitation principle |
|---|---|---|---|
| Hosting and infrastructure providers | Deliver the website, store business data, and operate security protections | Access logs, service records, technical identifiers | Processed only as needed to provide infrastructure |
| Email service providers | Send verification messages, inquiry responses, and service notifications | Email address, message content, delivery status | Used only for message delivery and troubleshooting |
| Support-system providers | Record tickets, collaborate on troubleshooting, and track processing status | Account identifier, order identifier, ticket content | Access controlled as needed to handle tickets |
| Payment service providers | Process card payments, return transaction results, and handle disputes | Transaction data, payment status, linked order identifiers | Complete card details are handled by payment providers |
Because infrastructure, email, support, or payment services may operate in different locations, data may be processed outside your location. We apply measures such as contractual controls, access restrictions, transfer safeguards, vendor assessments, and data minimization based on the nature of the data, the recipient’s role, and applicable requirements.
If data must be disclosed due to a corporate reorganization, business transfer, or valid request made under applicable requirements, we limit the disclosure and require the recipient to continue meeting confidentiality and security obligations appropriate to the nature of the data.
Data retention and security measures
We do not retain data indefinitely merely because it has been collected. Retention periods are determined by the processing purpose, service relationship, dispute-handling needs, security risks, backup cycles, and applicable recordkeeping obligations. When the purpose is complete and there is no basis for continued retention, data is deleted, de-identified, or placed in restricted archives.
- Inquiry records
- Generally retained until the response is complete, follow-up communications have ended, and a reasonable quality-assurance and dispute-handling period has passed.
- Support records
- Retained as needed to reproduce issues, maintain service continuity, identify recurring faults, and handle order disputes.
- Order and payment-verification records
- Retained for the period needed to provide services, reconcile billing, handle transaction disputes, and meet applicable recordkeeping obligations.
- Access and security logs
- Retained for the period needed to detect attacks, investigate anomalies, protect accounts, and maintain infrastructure security.
Our security measures
- Use transfer protections to reduce the risk of interception or alteration while data is transmitted over networks.
- Set access permissions by role and task, apply least-privilege principles, and restrict unnecessary internal access.
- Log key administrative actions and monitor unusual logins, bulk requests, and suspicious permission use.
- Conduct necessary vendor assessments and limit provider processing through permissions, procedures, and contractual requirements.
- Use isolation, backups, recovery validation, and incident-response measures according to data sensitivity.
No technical or organizational measure can eliminate all risk. If a data-security incident may affect your rights, we will investigate its scope, contain the risk, and take notification or remedial measures as required.
User rights and how to contact us
To the extent permitted by applicable rules, you may request access to data about you, obtain a copy, correct inaccurate information, delete data that is no longer needed, restrict specific processing, or object to processing based on legitimate interests.
Access and copies
Confirm whether we process data about you and learn about the data categories, purposes, recipients, and retention principles.
Correction and completion
Ask us to correct inaccurate account, contact, or order-related information and provide necessary details that affect the processing outcome.
Deletion or restriction
Request deletion when data is no longer necessary and there is no basis for continued retention, or request restricted processing while a dispute is being verified.
Object to processing
Explain your specific circumstances and object to particular processing based on legitimate interests.
How to submit a request
You can email support@vmown.com or log in to the portal to submit a ticket. To help us locate the relevant data, state the request type, email address used, related order identifier, and the scope of data you want us to handle. Do not send passwords, private keys, or complete payment details.
Before carrying out an access, correction, deletion, or restriction request, we may ask you to verify control of the email address, account ownership, or order association. Verification is used only to prevent others from accessing or changing your data without authorization. If a request is too broad, we may ask you to clarify the time period, service records, or data categories.
Some requests may be limited by transaction-record obligations, dispute preservation, security investigations, the rights of others, or other applicable requirements. Where a limitation applies, we will explain the result we can provide and the reason.
This policy and related data-processing disputes are governed by the laws of the jurisdiction where the platform’s operating entity is located. Disputes that cannot be resolved through communication may be submitted to a court with jurisdiction in that jurisdiction.