Purpose limitation
Account details are used to verify identity, order identifiers to deliver services and reconcile payments, and technical logs to protect security and troubleshoot issues. These categories are not combined indiscriminately.
This policy explains what information HopVM handles when you visit the website, verify an account, place an order, contact support, or use an exclusive cloud Mac, and how that information is limited, protected, retained, and deleted.
We define the scope of data for each specific service purpose. Information is not reused for unrelated purposes simply because it was submitted, and users are not expected to provide project secrets in support requests.
Account details are used to verify identity, order identifiers to deliver services and reconcile payments, and technical logs to protect security and troubleshoot issues. These categories are not combined indiscriminately.
We collect only the information needed for verification, delivery, support, security, and accounting records. Support staff will generally request sanitized output rather than complete configurations or source code.
Internal access is assigned by role and managed through permission controls, activity records, and least-privilege principles. Project data is not automatically made available to support staff when you submit a routine support request.
This policy applies to data processing that occurs when you visit hopvm.com, create or use an account, view or manage orders, submit a support ticket through the console, contact support by email, or use HopVM cloud Mac services. A cloud Mac is an exclusive physical machine available for remote use; it is not a virtual machine.
The policy covers account and identity verification information, order and billing records, device and browser information, service operation and security logs, support communications, and content you voluntarily submit. It also covers necessary processing by processors handling data for infrastructure, security, payment, and service delivery.
You generally control and manage code, build artifacts, model files, and keys that you create, upload, or generate on your exclusive device. We process them within a limited scope only when you voluntarily submit relevant excerpts for troubleshooting, or when necessary to respond to a security incident, meet a lawful requirement, or protect the service.
Do not send passwords, complete private keys, payment credentials, unsanitized access tokens, or complete project source code by email or through a routine support ticket.
The specific data depends on the feature you use. Browsing the website alone does not generate the same scope of data as placing an order, accessing a device, or processing a support ticket; creating an order does not mean we need to read your project files.
Email address, account status, verification records, and necessary security settings used to identify the account and contact person.
Order number, selected model, rental period, node, add-ons, transaction status, and records needed for billing reconciliation.
Browser type, operating-system category, language, timestamps, network address, and basic device information used for security identification.
Login attempts, access-control events, device status changes, API errors, and operational records needed to keep the service secure.
Ticket subject, communications, time of the issue, reproduction steps, and sanitized logs or screenshots you voluntarily provide.
Pre-sales requirements, business requirements, privacy requests, and other information you choose to provide for a specific inquiry.
We will not require your complete code repository just to troubleshoot a failed build. Xcode and macOS versions, the command executed, exit code, issue time, actual node, and log excerpts with tokens and personal information removed are usually sufficient.
We process data to provide website and account functions, verify account identity, create and deliver orders, associate exclusive devices, process payments and reconcile accounts, diagnose connection or device issues, respond to support requests, detect unusual access, protect infrastructure, and meet applicable record-keeping and legal obligations.
| Processing activity | Primary data | Purpose and grounds |
|---|---|---|
| Account verification and access control | Email address, verification records, login security events | To perform the service agreement and prevent unauthorized access |
| Order and device delivery | Order identifiers, model, rental period, node, and device status | To fulfill your order and provide an exclusive physical machine |
| Troubleshooting and customer support | Ticket records, reproduction steps, sanitized logs | To respond to requests, identify issues, and maintain service quality |
| Security protection | Network address, access records, unusual activity signals | Legitimate security needs to protect users, devices, and infrastructure |
| Payment and billing records | Order amount, transaction status, necessary reconciliation identifiers | To complete transactions, verify payments, and meet accounting obligations |
When processing depends on your consent or voluntary request, you may stop providing optional information or withdraw your request through the channels listed in this policy. Withdrawal does not affect processing already lawfully completed and may prevent us from continuing the related optional function.
An exclusive cloud Mac provides a complete macOS graphical interface and command-line environment. You are responsible for managing code repositories, dependency caches, build artifacts, model files, temporary data, and access keys according to your project requirements, and for maintaining separate backups of content you need to retain.
If you need help determining which diagnostic information is sufficient to locate an issue, first submit an error summary containing no secrets. Support staff will explain the minimum evidence needed based on the symptoms.
HopVM orders are settled exclusively in USD. Supported payment methods are USDT-TRC20 and Visa, Mastercard, and Amex via Stripe. The checkout flow determines the gateways actually available.
To complete transactions, confirm payments, and reconcile accounts, we process the order amount, currency, transaction status, time, order identifier, and necessary references returned by the payment channel. Sensitive card information is handled by the applicable payment process; we will not ask you to send a full card number, security code, or other payment credentials through a ticket or email.
Record the model, rental period, node, add-ons, and amount due in USD.
The selected payment process handles the transaction and returns the necessary status.
Use the order identifier and transaction status to confirm subsequent device delivery.
We do not set one retention period for all data. Retention depends on whether an account is active, an order is complete, a support matter is closed, a security investigation has ended, and whether accounting, dispute-resolution, or legal obligations apply.
| Data category | Primary retention criterion | Deletion or restriction condition |
|---|---|---|
| Account details | For as long as needed for account operation, identity verification, and security management | Processed after account closure and the end of related accounting, security, and legal obligations |
| Order and transaction records | For as long as needed for delivery, reconciliation, dispute resolution, and legally required records | Deleted, anonymized, or access-restricted once necessary obligations end |
| Support records | For as long as needed to resolve requests, verify outcomes, and identify recurring issues | Cleared once the matter is closed and no longer needed for security or dispute resolution |
| Security logs | For as long as needed to detect anomalies, investigate incidents, and protect infrastructure | Deleted or aggregated after risk assessment ends and the necessary security purpose has passed |
| Voluntarily submitted content | For as long as needed to complete the relevant inquiry, request, or authorized purpose | Processed after the purpose is complete, the request is withdrawn, and no other necessary ground applies |
If you request deletion, we first verify the relationship between the requester and the account or information, then determine whether accounting, security, dispute, or legal records must be retained. Deletable content enters a verifiable process; content that cannot yet be deleted is restricted in purpose and access, with the reason explained.
To the extent permitted by applicable rules, you may ask whether we process information about you, obtain relevant details, correct inaccurate data, delete data no longer needed, restrict specific processing, or complain about our privacy practices.
Specify the account, order, or support records you want to review.
Identify the inaccurate fields and provide enough information to verify the correction.
Describe the data categories you want deleted and your relationship to them.
Identify the disputed processing activity and the purpose you want temporarily restricted.
Provide what happened, when it happened, and the outcome you want.
Stop optional inquiries or communications based on information you voluntarily submitted.
Privacy requests can be sent to support@hopvm.com. Existing customers can also sign in to the console to submit a ticket so it can be linked to the relevant account and order. To protect your account, we may require reasonable identity verification.
Do not send passwords, complete private keys, payment credentials, unsanitized source code, or long-lived access tokens. An account email, relevant order identifier, request scope, and verifiable background are usually sufficient.
HopVM offers six selectable nodes. Depending on your selected node, account-management workflow, payment processing, and support arrangements, relevant data may be transferred to or processed in different jurisdictions. The scope of cross-border processing depends on the actual path required to deliver the service, not on copying all data to every node.
We use layered access controls, separation of responsibilities, least privilege, activity records, log auditing, unusual-access detection, and transmission safeguards to reduce the risks of unauthorized access, misuse, loss, or disclosure. Personnel who can access account, order, or service records should do so only to the extent required for their assigned tasks.
Permissions are granted by role and task to keep unrelated personnel away from account and service records.
Key access events and status changes are recorded to identify anomalies and review processing activities.
Website, account, payment, support, and device processing activities are separated by responsibility and purpose.
Your security practices matter too. Limit authorized members, use controlled credentials, promptly revoke access that is no longer needed, and avoid saving connection details on public devices. If you detect unusual access, revoke the relevant permissions in the console immediately and submit a ticket.
When data categories, processing purposes, sharing scope, user rights, or security arrangements materially change, we will update this page and state the new version’s effective date and main revisions. Text changes that only correct formatting or links, without changing actual processing, may not receive a separate material-change notice.
HopVM provides eight language versions for users in different regions. If the wording of the same provision is ambiguous across language versions, the interpretation version specified in the Terms of Service applies; this does not reduce any statutory rights granted under applicable rules.
This policy and related disputes are governed by the laws of the jurisdiction where the platform operator is established and handled by a competent court in that jurisdiction. Data processing must also comply with applicable requirements binding on the specific activity.
To ask about this policy, submit a privacy request, or report a data-processing issue, email support@hopvm.com, or existing customers can use theconsole to submit a ticket. Put “Privacy Request” in the subject line and briefly describe the request category and scope.
Existing customers can use the console to link an account and order; general privacy inquiries can use the one public support email. Do not send passwords, complete private keys, or payment credentials through either channel.