1. Home
  2. Privacy Policy
Data Processing Rules

Privacy Policy

This policy explains what data SureVM processes when providing dedicated physical Mac nodes, why we process it, how long we retain it, and how you can access, correct, or delete it.

Covered services Website, console, and support processes
Contact channels Email or console ticket
Version status Current version
Quick navigation

Policy contents

  1. 01Scope
  2. 02Data We Collect
  3. 03Processing Purposes
  4. 04Payment Data Boundaries
  5. 05Logs and Remote Access
  6. 06Retention and Deletion
  7. 07Cross-Regional Processing
  8. 08User Rights and Updates

For issues concerning an existing order or node, log in and submit a ticket so we can verify the service relationship and track progress.

Open Console
01

What this covers

Policy scope

This policy applies when you visit surevm.com, use the SureVM console, order or manage a Cloud Mac, or work with us through support email or console tickets. It also covers data processing needed to complete orders, initialize physical nodes, verify account status, handle billing, and troubleshoot service issues.

SureVM provides remotely accessible dedicated physical Mac minis, not virtual machines. Because each order is linked to a specific model, rental period, selected node, and add-ons, we process the account and order information required for delivery. Processing is limited to what is needed to provide the service and does not change in principle based on whether you select a Singapore, Japan (Tokyo), South Korea (Seoul), Hong Kong, or US West node.

This policy does not cover third-party software or services that you connect, install, or configure yourself. Those tools process data under their own policies. You control the purpose and access scope of projects, code, models, assets, and other content stored on your dedicated physical node.

02

Minimum necessary collection

Data We Collect

Account details include the email address used to register, sign in, verify identity, and receive service notices, along with account security status and necessary login records. We do not ask users to provide remote desktop passwords, private keys, or complete payment credentials in ordinary support requests.

Order information includes the selected SureVM M4 Core or SureVM M4 Plus, rental period, node region, storage expansion, Thunderbolt 5 linking option, order amount, payment status, and delivery status. Node configuration data may include the physical node ID, hardware specifications, system initialization status, network allocation, and management records associated with the order.

Service logs reflect account authentication, node initialization, console actions, network connection results, system events, and troubleshooting. Support records include ticket subjects, issue descriptions, timestamps, user-provided redacted logs, troubleshooting steps, and replies. In the event of anomalous access, abuse risk, or a service security incident, we may also record necessary source information, event times, affected resources, and response outcomes.

Account details Email, authentication status, and security records
Order details Model, term, node, and payment status
Node details Node ID, configuration, and initialization result
Support details Tickets, redacted logs, and handling records
03

Legal bases and purposes

Why We Process This Data

We use account and order data to confirm the purchase relationship, create orders, verify payment, initialize dedicated physical Mac nodes, and provide ongoing management. Without this necessary information, we cannot accurately link the selected model, region, and rental term to a specific service.

Authentication records and security event data help verify sign-ins, detect anomalous access, reduce the risk of unauthorized actions, and reconstruct the necessary event sequence when users report account issues. Node and service logs help determine whether a fault lies in credentials, networking, remote desktop services, system load, or the infrastructure layer, narrowing the troubleshooting scope.

We may also process relevant data to perform applicable contracts, handle billing disputes, retain necessary transaction records, respond to valid lawful regulatory requests, and comply with the laws of the jurisdiction where the platform operator is based. Such processing is limited to the reasonable scope required for the specific purpose.

  • Fulfill orders and deliver the selected physical node
  • Complete identity verification and protect account security
  • Diagnose connection, initialization, and node operation issues
  • Verify payments, billing, and service periods
  • Prevent abuse and meet necessary legal obligations
04

Payment information isolation

Payment Data Boundaries

All SureVM orders are settled in USD. Available payment methods are limited to USDT-TRC20 and Visa, Mastercard, and Amex processed through Stripe. The actual payment gateway available is determined by the checkout result.

Card payments are processed by Stripe. SureVM does not store full card numbers, security codes, or complete payment credentials that could be used to charge the card again. We retain only the information needed to complete orders, confirm payment results, reconcile accounts, and handle disputes, such as the order amount, transaction status, payment channel type, time, and necessary transaction identifiers.

For USDT-TRC20 orders, we retain the transaction records necessary to verify payment, match orders, reconcile accounts, and handle disputes. These records are not used for purposes unrelated to fulfilling the order. Do not send complete card details, wallet private keys, recovery phrases, or other credentials that could directly control funds through ordinary email or tickets.

SureVM retains records needed for order verification

Complete card credentials are handled by the payment processor; ordinary support processes will not request credentials that control funds.

05

Infrastructure and content boundaries

Logs and Remote Access

Infrastructure logs record service-layer events such as node initialization results, authentication results, network connection status, resource anomalies, console actions, and service security alerts. These logs help us determine whether the service is operating according to the order configuration, but they are not the content users store on physical nodes.

Source code, build artifacts, model files, audio and video assets, configuration files, and other business data stored by users on dedicated physical Mac nodes are user-managed storage content. SureVM does not proactively read this content as part of routine operations and does not require complete projects or unredacted datasets for ordinary support.

When a user actively requests assistance and expressly authorizes necessary troubleshooting steps, we will first try to diagnose the issue using the node ID, time of occurrence, reproduction steps, and redacted logs. If further inspection is necessary, access must be limited by scope, purpose, and duration, with necessary processing records retained. Temporary materials no longer needed after support ends will be handled under our retention rules.

Do not submit remote desktop passwords, private keys, complete payment credentials, or unredacted production data by email or ticket. If logs contain email addresses, tokens, repository URLs, or business identifiers, remove or mask unrelated fields before submission.

06

Retention periods and cleanup

Data Retention and Deletion

Retention periods are determined by processing purposes. Account and active order data are retained while services are provided. After an order ends, records related to payment reconciliation, contract performance, dispute handling, and necessary legal obligations may be retained until the relevant purpose is complete. Security incident records are retained for the period needed for risk investigation, evidentiary integrity, and prevention of recurring incidents.

Tickets and support emails are retained for as long as needed to resolve issues, conduct quality reviews, and handle related disputes. Temporary diagnostic files provided by users should be removed from the support process when they are no longer needed for the current issue. We reduce unnecessary long-term retention through access controls, purpose limitations, and internal handling rules.

You may request deletion of account details or support materials that are no longer needed. If data is still required to fulfill an active order, complete billing reconciliation, handle a dispute, address a security risk, or meet a necessary legal obligation, we may defer deletion of the relevant portion and explain the reason. Other deletable data will enter the processing workflow after we verify your identity and request scope.

Deletion requests may be sent to support@surevm.com, or you may log in to the console and submit a ticket. State the account email, data categories involved, and requested scope, but do not include passwords, private keys, or complete payment credentials.

07

Node selection and service coordination

Cross-Regional Processing and Service Providers

The physical node region you select affects where node configuration, networking, and service data are processed. SureVM currently offers 5 nodes across Singapore, Japan (Tokyo), South Korea (Seoul), Hong Kong, and US West. Information directly related to node initialization, connection diagnostics, and operational security may be processed in the selected region or other regions necessary to support the service.

To process payments, operate infrastructure, send email, provide security protection, or deliver necessary technical support, we may use service providers responsible for specific functions. These providers may process data only for agreed purposes and within the necessary scope, and must apply security measures appropriate to the risks of their processing. Using service providers does not expand the purposes for which we use data.

For cross-regional processing, we apply safeguards appropriate to the data category, processing purpose, access permissions, and risk. These may include limiting authorized personnel, reducing transferred fields, using transmission protections, retaining necessary audit records, and requiring service providers to meet applicable data-processing obligations.

When choosing a node, users should also consider their team location, project data requirements, and internal compliance rules. If a type of data must be processed in a specific region, confirm before ordering that the selected node meets your requirements, and contact support by email about the necessary service boundaries.

08

Requests, objections, and notices

User Rights and Policy Updates

To the extent permitted by applicable rules, you may request access to data associated with your account, correction of inaccurate information, deletion of data that is no longer needed, information about the purposes of specific processing activities, or object to processing based on particular grounds. Some rights may be reasonably limited by order fulfillment, accounting records, security investigations, or legal obligations.

To prevent someone else from impersonating you to obtain or delete account data, we verify the relationship between the requester and the relevant account before processing a request. Verification generally focuses on the account email, order association, and request scope. We will not ask you to submit passwords, private keys, or complete payment credentials by ordinary email.

You can email support@surevm.com, or log in to the console and submit a privacy request. State the request type, data categories involved, and desired outcome. We will update you on progress after completing necessary verification; if we cannot fully fulfill the request, we will explain the applicable limitations.

We will update this policy when there are material changes to service processes, data categories, or legal requirements, and highlight important changes through the website, console notices, or another method appropriate to the service relationship. The updated version applies from the time stated in its publication or notice and will not use existing data for new purposes incompatible with the original collection purposes.

This policy is interpreted under the laws of the jurisdiction where the platform operator is based. Disputes that cannot be resolved through ordinary support processes will be handled by a court with jurisdiction in that jurisdiction, unless applicable rules require otherwise.

Prepare the necessary information before submitting a privacy request

Provide your account email, request type, data categories involved, and desired scope. Do not send remote desktop passwords, private keys, complete payment credentials, or unredacted project content.

Send privacy email Create console ticket

Check data boundaries before deploying a dedicated physical Mac

Compare two Mac mini M4 configurations, rental terms, and 5 nodes; when ready, proceed directly to checkout.

Compare rental plans Deploy Cloud Mac