Data Processing Overview

We process only the data needed to deliver cloud Mac services

This policy explains what information HopVM handles when you visit the website, verify an account, place an order, contact support, or use an exclusive cloud Mac, and how that information is limited, protected, retained, and deleted.

Current version: Initial release Effective upon publication Applies to HopVM services
The bottom line

Three principles applied throughout our data processing

We define the scope of data for each specific service purpose. Information is not reused for unrelated purposes simply because it was submitted, and users are not expected to provide project secrets in support requests.

Purpose limitation

Account details are used to verify identity, order identifiers to deliver services and reconcile payments, and technical logs to protect security and troubleshoot issues. These categories are not combined indiscriminately.

Data minimization

We collect only the information needed for verification, delivery, support, security, and accounting records. Support staff will generally request sanitized output rather than complete configurations or source code.

Controlled access

Internal access is assigned by role and managed through permission controls, activity records, and least-privilege principles. Project data is not automatically made available to support staff when you submit a routine support request.

Scope

What data processing activities does this policy cover?

This policy applies to data processing that occurs when you visit hopvm.com, create or use an account, view or manage orders, submit a support ticket through the console, contact support by email, or use HopVM cloud Mac services. A cloud Mac is an exclusive physical machine available for remote use; it is not a virtual machine.

The policy covers account and identity verification information, order and billing records, device and browser information, service operation and security logs, support communications, and content you voluntarily submit. It also covers necessary processing by processors handling data for infrastructure, security, payment, and service delivery.

You generally control and manage code, build artifacts, model files, and keys that you create, upload, or generate on your exclusive device. We process them within a limited scope only when you voluntarily submit relevant excerpts for troubleshooting, or when necessary to respond to a security incident, meet a lawful requirement, or protect the service.

Content not intended for public support materials

Do not send passwords, complete private keys, payment credentials, unsanitized access tokens, or complete project source code by email or through a routine support ticket.

Data categories

What information may we collect?

The specific data depends on the feature you use. Browsing the website alone does not generate the same scope of data as placing an order, accessing a device, or processing a support ticket; creating an order does not mean we need to read your project files.

Account details

Email address, account status, verification records, and necessary security settings used to identify the account and contact person.

Order identifiers

Order number, selected model, rental period, node, add-ons, transaction status, and records needed for billing reconciliation.

Device and browser information

Browser type, operating-system category, language, timestamps, network address, and basic device information used for security identification.

Service logs

Login attempts, access-control events, device status changes, API errors, and operational records needed to keep the service secure.

Support records

Ticket subject, communications, time of the issue, reproduction steps, and sanitized logs or screenshots you voluntarily provide.

Voluntarily submitted content

Pre-sales requirements, business requirements, privacy requests, and other information you choose to provide for a specific inquiry.

We will not require your complete code repository just to troubleshoot a failed build. Xcode and macOS versions, the command executed, exit code, issue time, actual node, and log excerpts with tokens and personal information removed are usually sufficient.

Purpose of use

We process data to deliver, protect, and reconcile our services

We process data to provide website and account functions, verify account identity, create and deliver orders, associate exclusive devices, process payments and reconcile accounts, diagnose connection or device issues, respond to support requests, detect unusual access, protect infrastructure, and meet applicable record-keeping and legal obligations.

Primary processing activities, required data, and processing grounds
Processing activity Primary data Purpose and grounds
Account verification and access control Email address, verification records, login security events To perform the service agreement and prevent unauthorized access
Order and device delivery Order identifiers, model, rental period, node, and device status To fulfill your order and provide an exclusive physical machine
Troubleshooting and customer support Ticket records, reproduction steps, sanitized logs To respond to requests, identify issues, and maintain service quality
Security protection Network address, access records, unusual activity signals Legitimate security needs to protect users, devices, and infrastructure
Payment and billing records Order amount, transaction status, necessary reconciliation identifiers To complete transactions, verify payments, and meet accounting obligations

When processing depends on your consent or voluntary request, you may stop providing optional information or withdraw your request through the channels listed in this policy. Withdrawal does not affect processing already lawfully completed and may prevent us from continuing the related optional function.

Device responsibilities

You manage your code, keys, and build artifacts

An exclusive cloud Mac provides a complete macOS graphical interface and command-line environment. You are responsible for managing code repositories, dependency caches, build artifacts, model files, temporary data, and access keys according to your project requirements, and for maintaining separate backups of content you need to retain.

  • Before you start Confirm team-member authorization scopes, project directories, key permissions, and log-sanitization rules.
  • During use Avoid storing long-lived plaintext credentials in scripts, terminal history, or shared directories.
  • When submitting a support request Provide only the minimum excerpts needed to reproduce the issue, removing access tokens, personal information, and unpublished business data.
  • Before the rental period ends Export build artifacts and model results you need to keep, stop background tasks, and remove temporary credentials and project copies.

If you need help determining which diagnostic information is sufficient to locate an issue, first submit an error summary containing no secrets. Support staff will explain the minimum evidence needed based on the symptoms.

Transaction data

Payment processing covers only the information needed to complete and reconcile transactions

HopVM orders are settled exclusively in USD. Supported payment methods are USDT-TRC20 and Visa, Mastercard, and Amex via Stripe. The checkout flow determines the gateways actually available.

To complete transactions, confirm payments, and reconcile accounts, we process the order amount, currency, transaction status, time, order identifier, and necessary references returned by the payment channel. Sensitive card information is handled by the applicable payment process; we will not ask you to send a full card number, security code, or other payment credentials through a ticket or email.

A

Create an order

Record the model, rental period, node, add-ons, and amount due in USD.

B

Complete payment

The selected payment process handles the transaction and returns the necessary status.

C

Confirm delivery

Use the order identifier and transaction status to confirm subsequent device delivery.

Limited sharing

We provide processors only the minimum information necessary

We do not give unrelated parties access to account, order, or support records simply to accumulate data. Processors may access the minimum information directly relevant to their task only when necessary for service delivery, security, infrastructure operations, payment processing, professional audits, or a lawful requirement.

Infrastructure and device operations
Device identifiers, network information, and status records needed to host devices, maintain node connectivity, and handle operational events.
Security and access control
Necessary access events used to identify unusual logins, prevent abuse, and record permission changes.
Payment processing
Order references and amounts needed to complete transactions, return payment status, and reconcile accounts.
Legal requirements
Under a binding lawful request, we verify its scope and provide only the information that must be disclosed.

We constrain processing by processors through contracts, access restrictions, and separation of responsibilities. Processors may not use the information they receive for independent purposes beyond their authorized tasks.

Lifecycle

Retention and deletion are determined by different events for different data

We do not set one retention period for all data. Retention depends on whether an account is active, an order is complete, a support matter is closed, a security investigation has ended, and whether accounting, dispute-resolution, or legal obligations apply.

Data categories and retention criteria
Data category Primary retention criterion Deletion or restriction condition
Account details For as long as needed for account operation, identity verification, and security management Processed after account closure and the end of related accounting, security, and legal obligations
Order and transaction records For as long as needed for delivery, reconciliation, dispute resolution, and legally required records Deleted, anonymized, or access-restricted once necessary obligations end
Support records For as long as needed to resolve requests, verify outcomes, and identify recurring issues Cleared once the matter is closed and no longer needed for security or dispute resolution
Security logs For as long as needed to detect anomalies, investigate incidents, and protect infrastructure Deleted or aggregated after risk assessment ends and the necessary security purpose has passed
Voluntarily submitted content For as long as needed to complete the relevant inquiry, request, or authorized purpose Processed after the purpose is complete, the request is withdrawn, and no other necessary ground applies

If you request deletion, we first verify the relationship between the requester and the account or information, then determine whether accounting, security, dispute, or legal records must be retained. Deletable content enters a verifiable process; content that cannot yet be deleted is restricted in purpose and access, with the reason explained.

Your choices

You can request access, correction, deletion, or restriction of processing

To the extent permitted by applicable rules, you may ask whether we process information about you, obtain relevant details, correct inaccurate data, delete data no longer needed, restrict specific processing, or complain about our privacy practices.

Access

Specify the account, order, or support records you want to review.

Correction

Identify the inaccurate fields and provide enough information to verify the correction.

Deletion

Describe the data categories you want deleted and your relationship to them.

Restriction of processing

Identify the disputed processing activity and the purpose you want temporarily restricted.

Privacy complaint

Provide what happened, when it happened, and the outcome you want.

Withdraw an optional request

Stop optional inquiries or communications based on information you voluntarily submitted.

Privacy requests can be sent to support@hopvm.com. Existing customers can also sign in to the console to submit a ticket so it can be linked to the relevant account and order. To protect your account, we may require reasonable identity verification.

Do not include secrets with your request

Do not send passwords, complete private keys, payment credentials, unsanitized source code, or long-lived access tokens. An account email, relevant order identifier, request scope, and verifiable background are usually sufficient.

Processing location and protection

Data may be processed across borders depending on the selected node and service workflow

HopVM offers six selectable nodes. Depending on your selected node, account-management workflow, payment processing, and support arrangements, relevant data may be transferred to or processed in different jurisdictions. The scope of cross-border processing depends on the actual path required to deliver the service, not on copying all data to every node.

We use layered access controls, separation of responsibilities, least privilege, activity records, log auditing, unusual-access detection, and transmission safeguards to reduce the risks of unauthorized access, misuse, loss, or disclosure. Personnel who can access account, order, or service records should do so only to the extent required for their assigned tasks.

Access control

Permissions are granted by role and task to keep unrelated personnel away from account and service records.

Log auditing

Key access events and status changes are recorded to identify anomalies and review processing activities.

Scope separation

Website, account, payment, support, and device processing activities are separated by responsibility and purpose.

Your security practices matter too. Limit authorized members, use controlled credentials, promptly revoke access that is no longer needed, and avoid saving connection details on public devices. If you detect unusual access, revoke the relevant permissions in the console immediately and submit a ticket.

Version and interpretation

Material changes include an effective date and revision summary

When data categories, processing purposes, sharing scope, user rights, or security arrangements materially change, we will update this page and state the new version’s effective date and main revisions. Text changes that only correct formatting or links, without changing actual processing, may not receive a separate material-change notice.

HopVM provides eight language versions for users in different regions. If the wording of the same provision is ambiguous across language versions, the interpretation version specified in the Terms of Service applies; this does not reduce any statutory rights granted under applicable rules.

This policy and related disputes are governed by the laws of the jurisdiction where the platform operator is established and handled by a competent court in that jurisdiction. Data processing must also comply with applicable requirements binding on the specific activity.

To ask about this policy, submit a privacy request, or report a data-processing issue, email support@hopvm.com, or existing customers can use theconsole to submit a ticket. Put “Privacy Request” in the subject line and briefly describe the request category and scope.