1. Home
  2. Privacy Policy
Current version

Privacy Policy & Personal Data Practices

This policy explains how relevant information is collected, used, shared, retained, and protected when you browse the VMKeep website, submit an inquiry, rent a Cloud Mac, use the console, or request service support.

We process information only to the extent needed for clearly defined purposes, and aim to make each type of information’s use, retention basis, and available choices easy to understand.

Covered activities
Website, inquiries, orders, console, and support
Processing principles
Clear purpose, necessary scope, controlled access
Contact options
Contact page or console ticket
Policy contents

Review the information we process and your choices at each stage.

  1. 01Scope
  2. 02Information We Collect
  3. 03How We Use Information
  4. 04Payment Information Boundaries
  5. 05Sharing and Disclosure
  6. 06Retention and Security
  7. 07Your Choices and Contact
Submit a privacy request
01

Scope

This policy applies when you visit vmkeep.com, read public content, contact the service team, or interact with VMKeep regarding Cloud Mac rentals, order fulfillment, account management, or technical support.

Covered processing activities include access records needed to operate the website, contact details you provide, configuration and billing status associated with orders, management actions in the console, and support content sent through tickets or email.

If you submit member details, order information, or technical materials on behalf of a team or organization, you must have the authority to provide them and should submit only what is necessary to complete the inquiry, fulfillment, or troubleshooting.

This policy does not change your control over code, models, build artifacts, repository content, or other business data. Whether such content is placed on a rented dedicated physical machine, how it is backed up, and who can access it depend on your and your team’s deployment and permission arrangements.

Scope note

The public website, console, and rented physical nodes serve different functions. We determine the scope of processing based on the specific context, purpose, and necessity, rather than collecting information simply because it is accessible.

02

Information We Collect

The information we collect mainly comes from what you submit, what is generated during service delivery, and technical records needed to protect the website and accounts. The categories are as follows.

Contact and identity information

This may include your name or preferred form of address, work email, team affiliation, and contact details or background information you voluntarily provide in an inquiry. We do not ask you to submit account passwords, private keys, or the contents of signing certificates in ordinary inquiries.

Order-related information

This may include the selected machine model, rental period, node region, storage add-ons, order number, billing status, and necessary records created to deliver and manage a dedicated physical machine.

Support and troubleshooting materials

This may include problem descriptions, timestamps, node regions, reproduction steps, command output, and redacted logs. If materials contain tokens, keys, or personal data unrelated to the issue, remove them before submission.

Device and access logs

This may include IP address, browser and device type, access time, requested pages, and login and security event records. We use this information to keep the service available, identify unusual access, and analyze faults.

Console activity records

This may include events generated by account logins, order management, instance operations, and ticket interactions. We use them to fulfill your requests, protect accounts, and verify activity.

Website preferences and basic analytics

This may include language preferences, necessary session state, and statistics about page visits and key actions. We use it to maintain page functionality, understand content usage, and improve the experience.

03

How We Use Information

We use information for purposes directly related to the services you request and do not repurpose support materials or order data arbitrarily. Our main processing purposes include:

  • Responding to inquiries:Understand your target workload, configuration requirements, preferred node, and expected rental term, then provide a suitable plan.
  • Service delivery and management:Associate orders, configure rental terms, provide console capabilities, and support the day-to-day management of dedicated physical machines.
  • Resolving technical issues:Use the order number, node region, timestamp, logs, and reproduction steps to diagnose connection, build, or runtime issues.
  • Protecting accounts and services:Identify unusual logins, abuse, and unauthorized actions; enforce access controls; and maintain activity records.
  • Billing and recordkeeping:Confirm order amounts, payment status, and necessary transaction references, and handle billing-related requests.
  • Meeting legal obligations:Retain necessary records where required, respond to valid legal processes, and protect the legitimate interests of users, the platform, and relevant parties.
  • Improving the website experience:Analyze page usability, content access, and errors to improve navigation, documentation, and interaction flows.

When we need to use information for processing that is materially different from the original purpose, we assess its relationship to the original context, the nature of the information, its potential impact on you, and available safeguards, and obtain appropriate authorization where required.

04

Payment Information Boundaries

VMKeep orders support only USDT-TRC20 and Visa / Mastercard / Amex (via Stripe). All orders are billed in US dollars (USD). The payment gateway actually available is determined by the result returned by the billing backend at checkout.

For card payments, processing follows the applicable processor’s procedures. VMKeep may receive payment status, transaction reference, amount, currency, and time needed to reconcile an order, but does not ask you to submit a full card number, security code, or other payment credentials in inquiries, email, or tickets.

For USDT-TRC20 payments, transaction confirmation information may include the wallet address, transaction ID, amount, and confirmation status. Blockchain transaction records are publicly searchable; do not include personal information unrelated to payment in transaction notes or support materials.

Settlement currency
US dollars (USD)
Digital asset payment
USDT-TRC20
Card payment
Visa / Mastercard / Amex (via Stripe)
Status basis
Actual result returned by the billing process
05

Sharing and Disclosure

We process or provide relevant information only as necessary for service delivery, payment processing, infrastructure operations, compliance requirements, security investigations, or with your authorization. Recipients may access only the information needed for the specified task and are subject to corresponding confidentiality, security, and purpose limitations.

Information may be processed to complete order payments, send essential service emails, operate the website and console, troubleshoot infrastructure issues, respond to valid legal processes, and investigate security incidents that may affect an account, node, or other users.

If an organizational change involves the transfer of information, we require the receiving party to continue meeting protection obligations consistent with this policy and, where applicable, provide affected users with the necessary information.

When disclosure is legally required, we verify the validity and scope of the request and, where permitted, limit the information disclosed. Applicable legal matters are governed by the law of the jurisdiction where the platform operator is based; disputes will be handled by a court with jurisdiction in that jurisdiction.

06

Retention and Security

We retain necessary records based on the relevant service period, support needs, security purposes, dispute handling, and legal obligations. Retention periods may differ by information type; we do not apply one period to every category.

When determining retention periods, we consider whether an order is still being fulfilled, an account remains active, a support matter has been closed, the information is needed for a security investigation, and whether applicable requirements mandate record retention. Once the purpose is fulfilled and no basis for continued retention remains, we delete the information, make it no longer reasonably linkable to an individual, or archive it with restricted access.

We reduce the risks of unauthorized access, alteration, disclosure, or loss through access controls, least privilege, authentication, activity logging, and separation of duties. Personnel who can access order or support information receive permissions only as required for their roles.

You should also protect console credentials, SSH keys, repository tokens, signing materials, and business data. Assign team members separate, necessary permissions; revoke access promptly when someone leaves a project; and export data and clear credentials before the rental term ends.

Access Grant permissions by role and necessity

Order, support, and activity records are available only to personnel responsible for the corresponding tasks.

Records Retain necessary activity trails

Important account and administrative actions are recorded to verify requests and investigate anomalies.

Disposition Restrict or delete after the purpose ends

We determine the appropriate next step based on service, support, security, and legal obligations.

07

Your Choices and Contact

To the extent permitted by applicable rules, you may request access to relevant information we hold, ask us to correct inaccurate content, request deletion of information no longer needed, or ask questions about specific processing activities.

When submitting a request, describe the request type, associated email address, relevant order or inquiry background, and the information to be accessed, corrected, or deleted. To avoid disclosing account or order information to an unauthorized person, we may need to verify a reasonable connection between the requester and the relevant records.

You can submit a privacy request through the service team contact page, or log in to the console to create a ticket. Our public contact email is support@vmkeep.com. Do not send account passwords, private keys, complete payment credentials, or the contents of signing certificates in ordinary email or tickets.

If a request concerns records that must be retained by law, an order still being fulfilled, an account security investigation, or the legitimate rights of another person, we will determine the actionable scope under applicable requirements and explain the result to you.

1

Describe your request

Choose access, correction, deletion, or processing information, and specify the information involved.

2

Provide identifying details

Provide the associated email address, order number, or inquiry background; do not send the original sensitive credentials.

3

Complete necessary verification

Confirm the connection between the requester and the records while protecting account and order information.

Contact the service team Submit a ticket in the console
Continue with VMKeep

Choose a Cloud Mac for your workload

All three Apple Silicon dedicated physical machine tiers are available for daily, weekly, monthly, or quarterly rental. Before ordering, verify the configuration, node, and data migration plan.

Rent a Cloud Mac now View rental plans