What this policy covers
This policy applies to visits to vmoak.com, use of the VMOak console, creation or management of Cloud Mac orders, receipt of delivery information, support requests, and essential operational activities required to deliver dedicated physical nodes properly.
When an enterprise customer creates orders for team members, the enterprise customer must have an appropriate basis for providing VMOak with members’ contact details, task information, or support materials, and must explain how the data will enter the order and support workflows.
Code, build artifacts, media projects, and business files that customers store on dedicated physical machines remain, in principle, under the customer’s control. VMOak does not use this work content for advertising profiles and does not ask customers to submit complete business data unrelated to an incident in support requests.
Do not include remote access credentials, private keys, repository tokens, or unredacted business data in ordinary support emails. When troubleshooting is necessary, first confirm the required log scope through a console ticket.
What data do we process
We collect only the data needed to provide the service and do not add unrelated fields to expand user profiles. The specific categories depend on the features used when you visit the website, place an order, complete payment, or request support.
Account and contact information
This may include a name or display name, work email, team affiliation, account status, verification records, and contact context voluntarily provided by the user.
Order and configuration records
This may include the selected model, billing cycle, node, storage add-ons, Thunderbolt 5 pairing option, order number, and delivery status.
Billing status information
This may include the amount due, USD billing status, payment method category, transaction identifiers, and billing results, excluding data not needed to provide the service.
Access and security logs
This may include login times, basic source network information, session results, suspicious attempts, security incident records, and operational logs needed to protect accounts and nodes.
Support and operations records
This may include ticket content, the time an issue occurred, node codes, client environment details, user-provided redacted logs, and the troubleshooting process.
Device and browser information
This may include browser type, operating system category, language, page errors, and basic device information for compatibility, security decisions, and service improvements.
How we use data to deliver the service
Account and order information is first used to verify identity, create orders, match the selected model and node, and generate access details for a dedicated physical node. Order configuration is also used to verify the rental period, add-ons, and expiration status so that delivery matches the customer’s selections.
- Create and manage orders: Save the selected model, node, term, and add-ons, and show order progress and billing status.
- Deliver physical nodes: Check device status, network connectivity, storage capacity, and access accounts, then provide access details to the customer.
- Protect account security: Detect unusual logins, verify account actions, restrict unauthorized access, and record necessary security events.
- Handle questions and incidents: Locate issues using the order number, node, time of occurrence, and redacted logs, then share the resolution with the user.
- Fulfill service commitments: Handle renewals, expirations, billing status, data cleanup requests, and order-related notices.
- Improve the service: Aggregate incident categories and compatibility information that does not directly identify individuals to improve delivery checks and support documentation.
When processing is based on contract performance, account security, legal obligations, or a user request, we limit data use to the relevant purpose. If a new purpose requires separate consent, we will provide clear information before processing begins.
What we retain during billing
All VMOak orders are billed in US dollars (USD). Available methods are limited to USDT-TRC20 and Visa, Mastercard, and Amex processed through Stripe; the available gateway is determined by the console.
On-chain transaction verification
We may retain the transaction identifier, target amount, confirmation status, linked order information, and verification result to determine whether order payment is complete and handle billing inquiries.
Required order status
Visa, Mastercard, and Amex payments are processed by Stripe. VMOak receives the payment status, transaction reference, amount, and risk result needed to complete the order, without retaining full card details.
Billing records are linked to the order number to handle invoice reconciliation, disputes, refund outcomes, or compliance requirements. When contacting us about billing by email, provide the order number and billing date; do not send full card details or remote access credentials.
When we provide necessary data to processors
We provide necessary data to service processors responsible for the relevant function only to the extent required for Cloud Mac delivery, infrastructure hosting, service communications, security, payment processing, and compliance. The data provided must match the processor’s task.
- Infrastructure and node hosting
- May process node identifiers, network information, device status, and incident records to maintain physical node connectivity and delivery capability.
- Communications and support
- May process user email addresses, order references, ticket content, and message status to send delivery information and follow up on support requests.
- Payment processing
- Processes only the information needed to complete USD billing, confirm payment results, reconcile transactions, or meet billing requirements.
- Security and compliance
- May process access logs, unusual events, account verification information, and records required to be retained to investigate risks and meet applicable obligations.
We do not sell personal information or provide contact details to unrelated marketers because a user rents a particular model or selects a particular node. If an organizational restructuring or service transition occurs, the relevant data remains subject to purpose limitations and protection requirements consistent with this policy.
Retention depends on the purpose of the record
We do not apply one fixed period to all data. Retention is determined separately based on whether the account is active, the status of order fulfillment, whether a support issue is resolved, security investigation needs, and applicable legal obligations. Once the purpose ends, data is deleted, de-identified, or access-restricted.
| Data category | Primary retention basis | Deletion or restriction method |
|---|---|---|
| Account information | Maintain the account, verify actions, and handle open requests | Deleted or de-identified after account closure and completion of necessary matters |
| Order and billing records | Fulfill orders, reconcile accounts, handle disputes, and meet legal obligations | Deleted, archived, or access-restricted after the legally or operationally necessary period ends |
| Support records | Resolve issues, preserve context, and identify recurring incidents | Attachments reduced as necessary after resolution; unrelated sensitive content deleted |
| Security and access logs | Detect unusual activity, protect accounts, and investigate security incidents | Deleted, aggregated, or de-identified after the risk observation period ends |
| Customer data on nodes | Provide customers with dedicated workspace during the active rental period | Access is stopped and cleanup is performed after service ends in accordance with the order and service terms |
After a user submits a deletion request, we first verify the requester’s identity, the data scope, and any outstanding order or legal obligations. Records that cannot be deleted immediately are restricted to necessary purposes and enter the deletion process when the retention basis ends.
Regional processing and node selection
VMOak offers six service regions: Singapore, Japan (Tokyo), South Korea (Seoul), Hong Kong, the US East Coast, and the US West Coast. After a user selects a node, order configuration, delivery records, connection information, and necessary operational data may be transferred between the user’s region, the console service location, and the selected node.
When a project has specific requirements for data location, customer contracts, or internal compliance, customers should select a suitable node before ordering and prevent automated tasks from transferring sensitive data to unnecessary regions. Node selection does not replace the customer’s own data classification, access controls, or repository permission management.
We reduce the risks of regional processing through access restrictions, transfer protections, necessity reviews, and processor controls. Where regional processing is required by applicable rules, we take appropriate measures.
How to exercise your rights or raise a privacy concern
Users may request access to personal information associated with their account, correction of inaccurate information, deletion of data no longer needed, restriction of specific processing, or information about the basis for using and retaining a category of data. Requests can be sent to support@vmoak.com, or submitted as a ticket after signing in to the console.
To prevent account information from being given to an unauthorized person, we may ask the requester to confirm the account email, order number, recent order configuration, or other information sufficient to verify identity. Verification is limited to what is needed and never requires a private key or full remote access credentials.
When a team member in an enterprise account submits a request, we may need to confirm their relationship to the enterprise account and their permissions for the relevant order. For requests involving another person’s information, an open order, billing records, a security investigation, or legal obligations, we will explain what can be done and the next steps.
Suitable for privacy questions, account corrections, and confirmation of deletion scope.
Suitable for requests involving an order number, node, access logs, or support records.
This policy and related disputes are governed by the laws of the jurisdiction where the platform operator is based. Disputes that cannot be resolved through the support process may be submitted to a court with jurisdiction in that jurisdiction.