Privacy & Data Processing

Why each type of data is processed—and how you can manage it

This policy covers the OfficeVPS website, console, contact processes, and support tickets. We limit data use to what is necessary for account management, dedicated physical-node delivery, security verification, billing reconciliation, and engineering support, and do not use support attachments or workload content for unrelated purposes.

Policy version
2026.09
Covered services
Website, console, contact, and support tickets
Privacy contact
support@officevps.com
01

Scope

This policy applies to data processing that occurs when you visit officevps.com, create or use a console account, submit pre-sales contact information, purchase or manage a Cloud Mac, or contact our support team through a console ticket or email.

The console supports account verification, order configuration, node selection, billing reconciliation, instance information, and support-ticket management. Public website pages primarily process basic access data. Account, order, and communications data is processed only when you actively begin a purchase, contact, or support process and it is needed to fulfill your request.

Public website

Limited technical information is processed to handle page visits, browser type, device category, security events, and performance diagnostics.

Console

Account verification, order configuration, selection among six locations, physical-node delivery, billing, and instance-management information are processed.

Contact process

We process the team size, intended use, target configuration, rental term, location preferences, and migration needs that you provide.

Support tickets

We process order numbers, incident times, error descriptions, troubleshooting steps, screenshots, and necessary diagnostic attachments.

This policy does not require you to submit passwords, private keys, recovery credentials, or other secrets that could directly control a node in public contact messages or support tickets. If troubleshooting requires configuration verification, provide redacted screenshots, log excerpts, and reproducible steps whenever possible.

02

What information we collect

We collect different categories of information depending on the features you use. Not every visitor generates all of the data below; the scope depends on whether you create an account, place an order, connect to a physical node, or request support.

Account information
The email address used to identify your account, send verification codes, maintain your sign-in session, and contact the account holder, together with status records related to identity verification and security checks.
Order information
The selected Office M4 Start, Office M4 Build, or Office M4 Pro Lab configuration; rental terms selected by day, week, month, or quarter; additional storage; Thunderbolt 5 parallel connections; order status; and USD amounts.
Node selection
The Singapore, Tokyo, Seoul, Hong Kong, US East, or US West node selected for the order, plus node identifiers needed for delivery and support.
Device and browser information
Browser type, operating-system category, language settings, page-request times, referring pages, basic network information, and security signals used to detect unusual access.
Connection-log summaries
Diagnostic information such as connection time, target node, protocol category, success or failure status, and session-anomaly summaries. These summaries help assess network reachability, authentication, and session status; they are not intended for continuous monitoring of your work.
Contact records
The subject, message body, and reply history of emails sent to support@officevps.com, plus information you voluntarily provide for pre-sales configuration advice, migration assessments, node recommendations, billing questions, or partnership requests.
Support attachments
Screenshots, log excerpts, configuration summaries, and other attachments you voluntarily upload for troubleshooting. Support attachments should be minimized and should not contain keys, passwords, or unrelated work data.

For security purposes, we may also record significant account actions, such as verification-code requests, credential updates, SSH key changes, ticket-status changes, and order-management actions. These records help verify the source of an action, investigate anomalies, and restore service status.

03

How data supports delivery and support

We use data only for defined service activities and limit access to the people and systems needed to complete each activity. Our main processing purposes are:

A

Account management

Create accounts, send sign-in verification codes, maintain sessions, handle account-security requests, and assign orders, instances, billing records, and tickets to the correct account.

B

Physical-node delivery

Confirm the model, rental term, node, and add-ons; associate an order with a dedicated physical machine; and generate the access information required for delivery.

C

Identity and security verification

Determine whether sign-ins and sensitive actions are expected, prevent unauthorized access, and review unusual requests, key changes, and session risks.

D

Troubleshooting

Use the node, time, protocol, error summary, and completed steps to diagnose connectivity, SSH, macOS sessions, Xcode, CI/CD, or storage issues.

E

Billing reconciliation

Reconcile the rental period, host configuration, target node, added storage, parallel connections, payment status, and related records for USD orders.

F

Service improvement

Analyze de-identified or aggregated error types, page performance, and support-issue patterns to improve delivery guidance, troubleshooting paths, and console usability.

When we need to process identifiable data for a new purpose that is materially different from the original purpose, we first assess its relationship to the original collection context, data sensitivity, potential impact, and available safeguards, and provide additional information or obtain appropriate authorization when required.

04

Payment information and record boundaries

All orders are settled in USD. Available payment methods are limited to USDT-TRC20, plus Visa, Mastercard, and Amexprocessed through Stripe. The console determines which payment gateways are available.

USDT-TRC20

On-chain payment reconciliation

We retain the transaction references needed to match orders, confirm amounts, update status, and reconcile accounts. Do not send wallet-control information through public pages or ordinary email.

Card payments

Processed by Stripe

Payment steps for Visa, Mastercard, and Amex are handled by Stripe. The website retains the records needed for fulfillment, order status, amounts, and reconciliation; retaining complete card details is not a business purpose.

Payment records are linked to the order number, rental term, node, host configuration, and add-ons to support physical-node delivery, answer billing questions, and perform necessary financial reconciliation. Support staff should request only the references needed to locate a transaction and will not ask for passwords or complete sensitive payment credentials through a ticket.

05

When necessary data is shared

We do not expand sharing simply because data has been collected. We provide the minimum information to relevant service providers only when necessary for delivery, payment processing, infrastructure operations, compliance obligations, or your explicit request.

  • Delivery coordination Order identifiers, configuration, and node information are provided to controlled systems or personnel involved in delivery to confirm the target node, configure the physical equipment, and link the order to the instance.
  • Payment processing Information needed to complete payment in USD, confirm status, perform risk checks, and reconcile accounts is passed to the payment-processing stage; the scope depends on the payment method selected.
  • Infrastructure operations When genuinely needed for network, storage, monitoring, security, or node operations, we provide technical summaries directly related to a fault or security incident rather than unrestricted account content.
  • Compliance obligations Where required by the law of the jurisdiction in which the platform operator is established, we handle necessary requests under valid, appropriate, and binding procedures and assess their scope.
  • Explicit user requests When you ask us to assist with migration, joint troubleshooting, or providing records to a specified recipient, we act according to the recipient, scope, and purpose you confirm.

When selecting service providers, we consider their access controls, confidentiality obligations, security measures, and data-processing boundaries. Sharing must correspond to a defined task, and access must be revoked or unneeded copies deleted after the task is complete, subject to applicable retention requirements.

06

Retention, deletion, and de-identification

Different data serves different functions, so we do not use a single retention period. Retention depends on account status, order fulfillment, security investigations, dispute handling, billing reconciliation, and legal obligations in the jurisdiction where the platform operator is established.

Retention basis and end-of-period handling by data category
Data category Primary retention basis End-of-period handling
Account information Maintaining account access, order ownership, security verification, and handling user requests Deleted or de-identified after account closure and completion of necessary matters
Order and billing records Fulfillment, payment-status confirmation, financial reconciliation, and dispute handling Deleted, aggregated, or de-identified after the legally or operationally necessary period
Connection-log summaries Security checks, anomaly investigations, and network and session troubleshooting Deleted or aggregated after diagnostic and security needs end
Contact and ticket records Responding to requests, preserving processing context, and reviewing support conclusions Deleted or de-identified after the issue is closed and follow-up needs end
Support attachments Reproducing and locating specific issues Deleted where possible after troubleshooting is complete and continued retention is unnecessary
Security-incident records Preventing unauthorized access, investigating risks, and documenting remediation Cleared according to applicable rules after risk handling and necessary review are complete

After receiving a valid deletion request, we verify the applicant’s relationship to the account or order and determine whether fulfillment, security, billing, or legal obligations require continued retention. Deletable data enters the deletion process; data that cannot yet be deleted is restricted in use and processed further once the retention basis ends.

Aggregated data used for trend analysis is designed to remove direct identifiers where possible and reduce the likelihood of linking it back to a specific account, order, or individual. De-identified data must not be used to re-identify users.

07

How we reduce unauthorized-access risk

Security measures are designed around the actual risks associated with accounts, orders, nodes, connection summaries, and support materials. We use technical, organizational, and process controls to reduce the risk of unauthorized access, misuse, accidental disclosure, alteration, or loss.

Access controls

System permissions are assigned according to job responsibilities, access to accounts, orders, logs, and attachments is limited, and permissions are adjusted or revoked when responsibilities change.

Least privilege

People and systems receive only the permissions needed for the current task, avoiding indiscriminate combinations of delivery, billing, and support-attachment access.

Transmission protection

Appropriate protections are used for data transmitted through the website, console, and support processes to reduce the risk of interception or alteration in transit.

Log review

We record event summaries related to account security, sensitive actions, and unusual access to identify unexpected behavior and support investigations.

Attachment isolation

Support attachments are handled separately from ordinary public content, access is restricted, and materials no longer needed are cleared according to retention rules after troubleshooting ends.

If you suspect unusual activity involving your account, SSH keys, signing materials, or node-access information, submit a ticket in the console first and include the order number, node, time, and behavior observed. Do not continue distributing sensitive content through public email.

08

Your data rights and contact options

Subject to applicable rules and circumstances, you may request confirmation of whether we process data about you, access to available records, correction of inaccurate information, deletion of data no longer needed, or restriction of specific processing during a dispute or review. Some requests may be reasonably limited by fulfillment, security, billing, or legal obligations.

Access

Request confirmation of the processing scope and available information related to your account, orders, contacts, or support records.

Correction

Identify inaccurate or incomplete account, order-ownership, contact, or support information and provide the basis needed for correction.

Deletion

Request deletion of data that is no longer needed and has no continuing retention basis. We will explain what has been completed or why data is temporarily retained.

Restriction of processing

When accuracy, processing grounds, or a dispute is still under review, request that data not be used for activities beyond the original purpose.

How to submit a request

  1. 01

    Choose a contact route

    If you are signed in, submit a ticket in the console. If you cannot access your account, email support@officevps.com.

  2. 02

    Describe the request scope

    Specify the categories of data you want to access, correct, delete, or restrict, and provide a related order number, ticket number, or approximate date and time. Do not submit passwords or private keys.

  3. 03

    Complete identity verification

    To prevent disclosure to an unauthorized person, we may confirm the applicant’s relationship to the target account using the account email, linked order information, or another necessary method.

  4. 04

    Receive the outcome

    We will explain the actions taken, any additional information needed, anything that cannot be completed immediately, and the reason, and will continue processing once any restriction ends.

If you dispute our data processing, you may first raise the issue through the channels above. The dispute is governed by the law of the jurisdiction where the platform operator is established and handled by a competent court in that jurisdiction under applicable procedures.

Next steps

Confirm your data boundaries, then choose the right Cloud Mac

Compare configurations for three tiers of dedicated physical machines, four rental terms, and six locations. To exercise your data rights or resolve an existing order issue, submit a ticket in the console.