Scope
This policy applies when you visit vmkeep.com, read public content, contact the service team, or interact with VMKeep regarding Cloud Mac rentals, order fulfillment, account management, or technical support.
Covered processing activities include access records needed to operate the website, contact details you provide, configuration and billing status associated with orders, management actions in the console, and support content sent through tickets or email.
If you submit member details, order information, or technical materials on behalf of a team or organization, you must have the authority to provide them and should submit only what is necessary to complete the inquiry, fulfillment, or troubleshooting.
This policy does not change your control over code, models, build artifacts, repository content, or other business data. Whether such content is placed on a rented dedicated physical machine, how it is backed up, and who can access it depend on your and your team’s deployment and permission arrangements.
The public website, console, and rented physical nodes serve different functions. We determine the scope of processing based on the specific context, purpose, and necessity, rather than collecting information simply because it is accessible.
Information We Collect
The information we collect mainly comes from what you submit, what is generated during service delivery, and technical records needed to protect the website and accounts. The categories are as follows.
Contact and identity information
This may include your name or preferred form of address, work email, team affiliation, and contact details or background information you voluntarily provide in an inquiry. We do not ask you to submit account passwords, private keys, or the contents of signing certificates in ordinary inquiries.
Order-related information
This may include the selected machine model, rental period, node region, storage add-ons, order number, billing status, and necessary records created to deliver and manage a dedicated physical machine.
Support and troubleshooting materials
This may include problem descriptions, timestamps, node regions, reproduction steps, command output, and redacted logs. If materials contain tokens, keys, or personal data unrelated to the issue, remove them before submission.
Device and access logs
This may include IP address, browser and device type, access time, requested pages, and login and security event records. We use this information to keep the service available, identify unusual access, and analyze faults.
Console activity records
This may include events generated by account logins, order management, instance operations, and ticket interactions. We use them to fulfill your requests, protect accounts, and verify activity.
Website preferences and basic analytics
This may include language preferences, necessary session state, and statistics about page visits and key actions. We use it to maintain page functionality, understand content usage, and improve the experience.
How We Use Information
We use information for purposes directly related to the services you request and do not repurpose support materials or order data arbitrarily. Our main processing purposes include:
- Responding to inquiries:Understand your target workload, configuration requirements, preferred node, and expected rental term, then provide a suitable plan.
- Service delivery and management:Associate orders, configure rental terms, provide console capabilities, and support the day-to-day management of dedicated physical machines.
- Resolving technical issues:Use the order number, node region, timestamp, logs, and reproduction steps to diagnose connection, build, or runtime issues.
- Protecting accounts and services:Identify unusual logins, abuse, and unauthorized actions; enforce access controls; and maintain activity records.
- Billing and recordkeeping:Confirm order amounts, payment status, and necessary transaction references, and handle billing-related requests.
- Meeting legal obligations:Retain necessary records where required, respond to valid legal processes, and protect the legitimate interests of users, the platform, and relevant parties.
- Improving the website experience:Analyze page usability, content access, and errors to improve navigation, documentation, and interaction flows.
When we need to use information for processing that is materially different from the original purpose, we assess its relationship to the original context, the nature of the information, its potential impact on you, and available safeguards, and obtain appropriate authorization where required.
Payment Information Boundaries
VMKeep orders support only USDT-TRC20 and Visa / Mastercard / Amex (via Stripe). All orders are billed in US dollars (USD). The payment gateway actually available is determined by the result returned by the billing backend at checkout.
For card payments, processing follows the applicable processor’s procedures. VMKeep may receive payment status, transaction reference, amount, currency, and time needed to reconcile an order, but does not ask you to submit a full card number, security code, or other payment credentials in inquiries, email, or tickets.
For USDT-TRC20 payments, transaction confirmation information may include the wallet address, transaction ID, amount, and confirmation status. Blockchain transaction records are publicly searchable; do not include personal information unrelated to payment in transaction notes or support materials.
- Settlement currency
- US dollars (USD)
- Digital asset payment
- USDT-TRC20
- Card payment
- Visa / Mastercard / Amex (via Stripe)
- Status basis
- Actual result returned by the billing process
Sharing and Disclosure
We process or provide relevant information only as necessary for service delivery, payment processing, infrastructure operations, compliance requirements, security investigations, or with your authorization. Recipients may access only the information needed for the specified task and are subject to corresponding confidentiality, security, and purpose limitations.
Information may be processed to complete order payments, send essential service emails, operate the website and console, troubleshoot infrastructure issues, respond to valid legal processes, and investigate security incidents that may affect an account, node, or other users.
If an organizational change involves the transfer of information, we require the receiving party to continue meeting protection obligations consistent with this policy and, where applicable, provide affected users with the necessary information.
When disclosure is legally required, we verify the validity and scope of the request and, where permitted, limit the information disclosed. Applicable legal matters are governed by the law of the jurisdiction where the platform operator is based; disputes will be handled by a court with jurisdiction in that jurisdiction.
Retention and Security
We retain necessary records based on the relevant service period, support needs, security purposes, dispute handling, and legal obligations. Retention periods may differ by information type; we do not apply one period to every category.
When determining retention periods, we consider whether an order is still being fulfilled, an account remains active, a support matter has been closed, the information is needed for a security investigation, and whether applicable requirements mandate record retention. Once the purpose is fulfilled and no basis for continued retention remains, we delete the information, make it no longer reasonably linkable to an individual, or archive it with restricted access.
We reduce the risks of unauthorized access, alteration, disclosure, or loss through access controls, least privilege, authentication, activity logging, and separation of duties. Personnel who can access order or support information receive permissions only as required for their roles.
You should also protect console credentials, SSH keys, repository tokens, signing materials, and business data. Assign team members separate, necessary permissions; revoke access promptly when someone leaves a project; and export data and clear credentials before the rental term ends.
Order, support, and activity records are available only to personnel responsible for the corresponding tasks.
Important account and administrative actions are recorded to verify requests and investigate anomalies.
We determine the appropriate next step based on service, support, security, and legal obligations.
Your Choices and Contact
To the extent permitted by applicable rules, you may request access to relevant information we hold, ask us to correct inaccurate content, request deletion of information no longer needed, or ask questions about specific processing activities.
When submitting a request, describe the request type, associated email address, relevant order or inquiry background, and the information to be accessed, corrected, or deleted. To avoid disclosing account or order information to an unauthorized person, we may need to verify a reasonable connection between the requester and the relevant records.
You can submit a privacy request through the service team contact page, or log in to the console to create a ticket. Our public contact email is support@vmkeep.com. Do not send account passwords, private keys, complete payment credentials, or the contents of signing certificates in ordinary email or tickets.
If a request concerns records that must be retained by law, an order still being fulfilled, an account security investigation, or the legitimate rights of another person, we will determine the actionable scope under applicable requirements and explain the result to you.
Describe your request
Choose access, correction, deletion, or processing information, and specify the information involved.
Provide identifying details
Provide the associated email address, order number, or inquiry background; do not send the original sensitive credentials.
Complete necessary verification
Confirm the connection between the requester and the records while protecting account and order information.