Scope
What data activities are covered by this policy
This policy applies to data processing that occurs when you visit xcodevm.com, create or verify an account, view or manage cloud Macs, submit and pay for orders, use console features, or communicate with XcodeVM through tickets or support email.
The services covered by an order include dedicated physical machines at selectable nodes. To deliver the service, we link the account, order, node, rental period, and instance status. This linkage is used to provision devices, display subscription status, process billing, verify authorized actions, and diagnose service issues.
Website Access
This includes page requests, necessary session information, browser and device type, referring page, access time, and basic security events, used to deliver pages, maintain sessions, analyze traffic, and prevent abuse.
Accounts & Console
This includes account identifiers, email addresses, verification results, login records, instance actions, billing status, and ticket history, used for identity verification and service management.
Orders & Service Delivery
This includes the selected model, node, term, additional configuration, order amount, payment status, provisioning status, and renewal records, used to fulfill orders and provide devices.
Support Communications
This includes issue descriptions, order identifiers, incident times, reproduction steps, redacted logs, and attachments you voluntarily provide, used to investigate and respond to requests.
Data We Collect
We collect only the information needed at each stage
The scope of collection depends on the feature you use. Browsing the website alone does not require order information; placing an order or requesting technical support requires data that identifies the order, node, and incident context. We do not require personal information unrelated to the service you request.
- Account & Contact Information
- Account identifier, support email address, verification-code delivery and verification results, login sessions, account security status, and any name or team information you voluntarily provide in communications.
- Order & Subscription Records
- Order number, selected XVM M4 Core or XVM M4 Plus, node, billing cycle, storage expansion, Thunderbolt 5 parallel-connection option, amount, creation time, payment status, and service status.
- Device & Access Logs
- IP address, browser type, operating-system category, request time, session identifier, security-verification result, pages visited, action type, error code, and technical identifiers associated with an instance.
- Service Operation Information
- Instance online status, network and resource metrics, remote-connection events, power-on, shutdown, and restart actions, task results, and troubleshooting information. We focus on operational status and event metadata, not analysis of user file contents.
- Support Tickets & Email
- Subject, issue category, order identifier, node, occurrence time, reproduction steps, error text, communication history, and logs or attachments you submit after removing sensitive data.
- Content You Voluntarily Submit
- Pre-sales requirements, expected concurrency, build frequency, target node, storage needs, compliance questions, and other information you voluntarily provide to address a request.
Before submitting support materials, remove account passwords, private keys, complete payment credentials, access tokens, and unredacted business data. If sensitive fields in a log are not needed to diagnose the issue, delete or replace them first.
Purposes of Processing
Every processing activity serves a defined purpose
Provide & Manage Services
Create accounts, generate orders, configure nodes, deliver dedicated physical machines, display instance and subscription status, and perform authorized actions initiated in the console.
Verify Accounts & Actions
Send and verify codes, maintain login sessions, detect unusual access, and confirm that credential resets, instance management, billing views, and other actions come from authorized users.
Security & Troubleshooting
Detect attacks, automated abuse, and unauthorized access; correlate error events; analyze connection, network, capacity, and instance status; and restore normal service.
Process Orders & Improve the Product
Reconcile payment results, create billing records, respond to support requests, and improve operational processes based on aggregated error types, feature usage, and capacity trends.
We may also process necessary data to meet applicable legal obligations, respond to legally binding requests, or protect the platform and users’ legitimate interests. Processing is limited to the information and period required for that purpose.
Payment Data
Payment information is processed separately by channel
All orders are settled in U.S. dollars (USD). The only available payment methods are USDT-TRC20 and Visa / Mastercard / Amex (via Stripe). The console determines which gateway is available for a given transaction.
USDT-TRC20
On-chain Transaction Information
To match orders and confirm payments, we process the sender address, recipient address, transaction hash, network type, amount, submission time, confirmation status, and associated order identifier. Some of this information is recorded on a public blockchain.
Do not include passwords, private keys, seed phrases, or other information unrelated to order confirmation in transfer memos or support materials.
Processed by Stripe
Card Settlement Information
When you use Visa, Mastercard, or Amex, the card data required to complete payment is handled through Stripe’s payment process. XcodeVM receives payment status, transaction identifiers, amount, currency, risk results, and necessary billing information related to order fulfillment.
XcodeVM does not store full card numbers or card security codes in its own systems. Refunds, disputes, or failed-payment handling may require retaining the relevant transaction identifier and communication records.
Logs & Monitoring
Necessary technical records support security, capacity, and troubleshooting
To keep nodes running reliably 365 days a year and identify anomalies, we record limited service logs and monitoring metrics. The focus is on requests, actions, status changes, and resource trends—not the specific contents of users’ work files.
| Record Category | Typical Fields | Primary Use | Access Control |
|---|---|---|---|
| Website & Sessions | IP, time, page, browser, session events |
Page delivery, session persistence, security checks | Limited to personnel responsible for platform operations and security |
| Accounts & Actions | Account identifier, action, object, result, error code |
Authorization checks, auditing, and locating mistaken actions | Granted by role and least privilege |
| Instances & Nodes | Instance identifier, node, status, network and capacity metrics |
Service delivery, capacity planning, and troubleshooting | Restricted access within technical operations |
| Support Requests | Order identifier, time, steps, redacted logs |
Reproduce issues, correlate events, and prepare responses | Limited to personnel needed to handle the request |
Log retention periods are determined by security risk, troubleshooting needs, account status, and applicable legal obligations. Once the processing purpose is fulfilled, logs are deleted, aggregated, or de-identified. Records of highly sensitive actions receive stricter access controls, with limits on export and secondary use.
Retention & Deletion
Retention periods depend on the data category and processing purpose
We do not retain data indefinitely simply because it was collected. When setting retention periods, we consider whether the account is active, whether the order is complete, whether billing and disputes are closed, whether security incidents are resolved, whether support requests still require follow-up, and whether applicable law requires continued retention.
Account Information
We retain information needed for login, verification, and service management while the account is in use. After account closure, data that can be deleted immediately enters the deletion process; records retained for security, disputes, or legal obligations are isolated and purpose-limited.
Order & Payment Records
Order numbers, configurations, amounts, currencies, payment statuses, and transaction identifiers are retained as needed for accounting reconciliation, refund disputes, fraud prevention, and applicable legal requirements. They are deleted or de-identified when the retention period ends.
Technical & Security Logs
Logs are retained for the period needed for troubleshooting, security investigations, and capacity trends. Fine-grained records unrelated to ongoing incidents and no longer useful for analysis are deleted, aggregated, or made less identifiable.
Support Tickets & Email
We retain these records for as long as needed to handle the request, review quality, and address related follow-up issues. Attachments and logs are cleared as a priority when no longer needed; communications that must be retained remain access-restricted.
Submit a Deletion or Correction Request
You can sign in to the console and submit a ticket describing your account identifier, the data categories involved, the action you want us to take, and the relevant order identifier; you can also use support@xcodevm.com to submit a request. Do not send passwords, private keys, or complete payment credentials.
After receiving a request, we verify identity and authorization, locate the relevant data across our systems, and notify you of the outcome. If some records must be retained for an order dispute, security investigation, or applicable legal obligation, we limit their purpose and access and take further action when the retention basis ends.
Security & User Rights
You can review, correct, and control data associated with your account
Access Controls
Internal access is role-based, with support, billing, security, and technical operations data managed separately. Sensitive actions require identity verification, and necessary action records are retained.
Transmission Protection
The website, console, and service interfaces transmit data over encrypted connections. Support attachments and export records should circulate only as needed to process the request.
Data Minimization
Fields, access permissions, and retention periods are set around specific purposes. When an issue can be diagnosed using error codes and redacted logs, we do not require complete business data.
Incident Response
When we detect unusual access or a data risk, we restrict relevant permissions, assess the scope of impact, preserve necessary evidence, and take corrective measures.
Requests You Can Make
- Access: Confirm whether we process data about you and obtain information about its categories, purposes, and sources.
- Correction: Correct inaccurate or incomplete account and contact information.
- Deletion: Request deletion of relevant data when the processing purpose is complete and no basis for continued retention remains.
- Restriction or Objection: Request restriction of or object to specific processing, explaining the data involved and your reasons.
- Obtain a Copy: Request a copy of data relating to you where technically feasible and required by applicable rules.
To exercise your rights, you can submit a ticket through the console or email support@xcodevm.com. To protect your account, we may ask for information that verifies your connection to the account or order, but we will never ask you to send passwords, private keys, or complete payment credentials by email.
Applicable Rules & Dispute Resolution
This policy is interpreted and enforced under the laws of the jurisdiction where the platform operator is established. Disputes related to this policy or data processing should first be addressed through the support channel; if unresolved, they may be submitted to a court with jurisdiction in that jurisdiction.
Privacy Request Portal
Provide specific data details to reduce follow-up
Include your account identifier, relevant order, data categories, and requested action. For technical issues, also provide the node, time of occurrence, reproduction steps, and redacted logs.