Scope: where data enters the system
This policy applies to the vmdebug.com website, the ordering and account-management flows accessed through it, the delivery and connection records for Physical Mac Cloud devices, and communications through console tickets or support email. Whether you are comparing plans, placing an order, using a device, or requesting support, we process relevant information for the purposes and within the boundaries described here.
Browsing the website generally involves basic request logs, browser, and device information. Ordering involves account, order, node, and billing status data. Device use may generate access-verification, connection, and security logs. During support interactions, we process the issue details, device identifiers, redacted logs, and correspondence that you choose to provide.
When a link takes you to a payment page operated by an independent service provider, that provider processes the necessary data under its own procedures. VMDebug receives only the outcome information needed to complete the order, verify its billing status, and handle disputes. We do not ask you to resubmit sensitive payment-page fields through public support channels.
Information collected: only what delivery and troubleshooting require
Account details we may process include your email address, account identifier, authentication status, and records related to access you have authorized. Order information may include the order number, selected VMDebug M4 or VMDebug M4 Pro, rental term, node, additional storage, billing currency, payment status, and service start and end status.
To protect access and diagnose connection issues, the system may record device and browser type, operating-system category, request time, network address, session identifier, login result, host connection time, target node, error codes, and necessary security audit events. These records help verify requests, identify anomalies, and reconstruct failure paths. They are not used to build profiles unrelated to the Physical Mac Cloud service.
When you submit a support request, we process the ticket subject, issue description, device identifier, time of occurrence, macOS version, reproduction steps, redacted logs, and troubleshooting actions already completed. Do not submit account passwords, private keys, full payment-card details, recovery codes, or unredacted business secrets by email or ticket.
| Information category | Typical fields | Common scenarios |
|---|---|---|
| Account details | Email, account ID, authentication and authorization records | Registration, sign-in, console access |
| Order details | Order number, model, term, node, add-ons, and status | Ordering, delivery, renewal, and order lookup |
| Technical records | Browser type, network address, time, and error codes | Security checks, connection diagnosis, and troubleshooting |
| Support content | Issue description, redacted logs, reproduction steps, and handling records | Tickets, email, and follow-up troubleshooting |
| Content you submit | Selection requirements, compatibility details, feedback, and attachment notes | Pre-sales questions, documentation feedback, and partnership discussions |
How we use information: each processing activity supports a service action
We use relevant information to create and manage accounts, verify access requests, create and process orders, assign dedicated physical nodes, display service status, provide billing records, and keep Physical Mac Cloud devices connected and manageable during the order term.
Security data helps detect suspicious sign-ins, automated abuse, unauthorized access attempts, and behavior that could affect node stability. Connection and error records help determine whether an issue lies with the local network, authentication, node connection, system environment, or a specific toolchain, shortening the path to resolution.
Support communications and usage feedback may also help us correct documentation, add connection checks, improve error messages, and streamline service workflows. For documentation improvements, we prioritize aggregated information or remove unnecessary direct identifiers. We do not publish private code, keys, or complete logs from tickets as case studies.
- Provide the serviceManage accounts, orders, node assignment, connections, and status.
- Verify accessConfirm request origin, session status, and authorization scope.
- Process ordersVerify plans, terms, add-ons, payment results, and service status.
- Protect securityIdentify unusual behavior and protect accounts and physical nodes.
- Troubleshoot issuesCorrelate time, device, node, error code, and troubleshooting steps.
- Meet obligationsHandle legally valid requests and retain necessary records.
- Improve documentationTurn recurring issues into actionable checklists.
Payment data boundaries: order status stays separate from sensitive credentials
Visa, Mastercard, and Amex card transactions are processed by Stripe. The full card number, security code, and other sensitive authentication information required during payment are handled by the payment provider in its controlled environment. VMDebug receives only the limited outcome information needed to complete the order, identify the transaction status, reconcile the payment, and handle disputes.
For USDT-TRC20 payments, the system may process the public transaction identifier associated with the order, amount, confirmation status, and records needed to verify the order. We will never ask for a wallet private key, recovery phrase, or account password through support email or console tickets.
Information you can provide
- Order number shown in the console
- Transaction status or error code
- Redacted screenshot of the payment page
- Public transaction ID and time of the issue
Never send through support
- Full payment-card number or security code
- Wallet private key or recovery phrase
- Account password or recovery code
- Unredacted identity or financial documents
Retention and security: periods depend on purpose, disputes, and obligations
We do not apply one fixed retention period to every type of data. Account and order details are retained as needed for the service relationship, billing reconciliation, and dispute handling. Security and connection logs are retained as needed to detect anomalies, investigate incidents, and preserve an audit trail. Support records are retained as needed for issue follow-up, identifying recurring failures, and reviewing service quality.
Once a business purpose is complete and there is no continuing legal, dispute-resolution, or security need to retain the information, we delete it, disconnect it from the account, or convert it into aggregated records that cannot reasonably be linked to a specific user. Data in backups leaves active use according to backup rotation and recovery controls.
We reduce risk through role-based access control, least privilege, sign-in and activity-log audits, data-in-transit protection, credential management, environment isolation, and anomalous-event checks. Access to support materials is limited to authorized roles that need them to complete the relevant troubleshooting or request.
Access control
Limits visibility of accounts, orders, logs, and support materials by role and task.
Log auditing
Records key access and processing actions to detect anomalies and trace incidents.
Least privilege
Shares data only with roles that need it for delivery, billing, security, or troubleshooting.
Your choices and contact: specify the data and scope of your request
You may request access to information associated with your account, correction of inaccurate information, or, where applicable, deletion, restriction of processing, or an explanation of how your information is processed. To reduce the risk of mistaken deletion or unauthorized inquiries, include your account email, relevant order number, request type, data scope, and a time range that will help us verify the request.
Send privacy requests to support@vmdebug.com, or sign in to the console to submit a ticket. For requests involving an existing order, device identifier, or past ticket, submit the ticket from the associated account whenever possible so we can verify the connection between the requester and the records.
Before processing a request, we may require identity or account-control verification proportionate to the risk. If a request concerns another person’s information, an active dispute, a security investigation, billing records, or information that must be retained by law, we will explain what can be done and limit any information that should not be disclosed.
Processing activities, rights requests, and disputes related to this policy are governed by the laws of the jurisdiction where the platform operator is established. Where judicial proceedings are required, the matter will be handled by a court with jurisdiction in that jurisdiction.
-
01
Identify the request type
Tell us whether you are requesting access, correction, deletion, restriction, or processing details.
-
02
Define the data scope
Provide your account email, order number, time range, and relevant service area.
-
03
Complete verification
We verify account control according to the request risk to prevent disclosure to unrelated parties.
-
04
Receive the outcome
The response explains what was completed, what was restricted, and why.