Processing Scope
Scope of This Policy
This policy applies to information processing when you visit hirevm.com, read product or help content, use the contact page to send an inquiry, create or manage Cloud Mac orders, view billing information, or communicate with our support team. Orders, instances, subscriptions, billing, and ticket workflows in the console are also covered by this policy.
HireVM provides dedicated Apple Silicon physical nodes for daily, weekly, monthly, or quarterly rental. Information directly related to service delivery may be processed throughout ordering, payment confirmation, connection-detail delivery, support, renewal, and the end of the rental term.
Website Visits
Page requests, basic device information, referring pages, same-domain analytics events, and necessary security records.
Inquiries and Support
Contact details, issue descriptions, order context, error messages, and steps already taken in emails or tickets.
Orders and Billing
Model, node, term, add-ons, USD amount, payment result, and order status.
Code, build artifacts, media files, and business data that users create, import, or process on dedicated physical machines are controlled by users, who determine the processing purposes and access members. Only excerpts necessary to resolve an issue should be submitted for support troubleshooting.
Information Directory
What Information We Collect
The scope of collection depends on the features you use. Browsing public pages alone does not create an order record; information needed to complete the relevant action is processed only when you place an order, complete payment, or submit a support request.
Account and Contact Information
Name or preferred form of address, work email, account identifier, team size, and contact details you voluntarily provide for service notices or support replies.
Order and Service Configuration
Selected HireVM M4 or HireVM M4 Pro, billing term, node, SSD add-on, number of Thunderbolt 5 interconnects, order number, creation time, and service status.
Billing and Payment Records
USD amount due, payment method category, payment status, and reconciliation identifiers. For USDT-TRC20 payments, we may process the transaction hash. For Visa, Mastercard, or Amex payments processed through Stripe, complete card credentials are handled by the payment processor under its procedures.
Device and Access Logs
IP address, browser and device type, access time, request path, session identifier, login result, unusual-request characteristics, and operational records needed to protect account and platform security.
Support Communications
Issue category, node, time of occurrence, error text, relevant screenshots, reproduction steps, and troubleshooting actions already taken. Do not submit passwords, private keys, repository tokens, or other sensitive credentials in emails, tickets, or screenshots.
Information You Voluntarily Provide
Selection context, intended workflows, team collaboration needs, data protection requests, and other context you voluntarily provide to explain an organizational use case.
Purpose Limitation
How We Use Information and Our Legal Bases
Information is used only for the purpose explained when collected, compatible purposes necessary to fulfill your request, or legal obligations applicable to the platform operator. Support materials are not repurposed for uses unrelated to the original request.
Providing and Managing Services
Create accounts, generate orders, assign selected nodes, deliver connection details, manage terms and add-ons, and display service status in the console.
- Primary Basis
- Necessary to perform the order and service agreement.
Processing Payments and Billing
Confirm USD amounts, match payment results, create billing records, handle billing inquiries, and complete necessary financial reconciliation.
- Primary Basis
- Necessary to perform orders, maintain financial records, and meet applicable compliance obligations.
Protecting Account and Platform Security
Detect unusual logins, identify abusive requests, investigate security incidents, restrict unauthorized access, and retain enough operational history to review how incidents were handled.
- Primary Basis
- Necessary to protect users, physical nodes, and platform operations.
Responding to Inquiries and Troubleshooting
Identify issues using the model, node, time, error information, and steps already taken, then provide actionable solutions.
- Primary Basis
- Necessary to process user requests or provide purchased services.
Improving Website Experience
Analyze page performance, navigation paths, and functional errors; assess whether help content is clear enough; and fix problems affecting ordering or support workflows.
- Primary Basis
- Improving the website and services without overriding users' fundamental rights.
Responding to Compliance Requirements
Retain records that must legally be kept, handle valid rights requests, and complete necessary verification and responses when presented with legally valid requirements.
- Primary Basis
- Applicable legal obligations or binding procedural requirements.
If a new purpose is incompatible with the original purpose, we will first assess whether separate notice, consent, or an opt-out is required rather than automatically expanding the original authorization.
Data Minimization
Sharing Scope and Processors
HireVM does not sell personal information. We share only the fields needed with processors responsible for the relevant task when completing payments, operating infrastructure, providing necessary support, or complying with valid legal requirements. The information provided to each processor is limited to what directly relates to its task.
| Processor Category | Information Potentially Involved | Limited Purpose | Control Principle |
|---|---|---|---|
| Payment Processing | Order number, USD amount, payment result, reconciliation identifier, and fields necessary for the payment process | Complete and reconcile USDT-TRC20 or Stripe-processed Visa, Mastercard, and Amex payments | Not shared with unrelated parties; users are not asked to submit complete payment credentials in support requests |
| Infrastructure Operations | Node identifier, service status, operational logs, and technical information needed for fault diagnosis | Deliver dedicated physical machines, keep nodes running, and diagnose network or hardware-level faults | Access authorized by role and limited to data needed for the operational task |
| Necessary Service Support | Account identifier, order context, ticket content, error information, and reproduction steps | Answer inquiries, resolve connection or billing issues, and investigate security incidents | De-identified information used where possible; ticket access limited to participating staff |
| Legal or Regulatory Requirements | Information specifically identified in a valid, verified request as required for disclosure | Respond to legally valid procedures, protect legitimate rights, or investigate serious abuse | Verify authority, scope, and necessity, and retain processing records where permitted |
Cross-Regional Processing
Users can choose Cloud Mac nodes in Singapore, Japan (Tokyo), South Korea (Seoul), Hong Kong, or the western United States. Order management, payment reconciliation, log analysis, or technical support may take place in a different region from the selected node. When processing crosses regions, we limit fields, personnel access, and purposes according to data-minimization principles and apply security measures appropriate to the transfer context.
Lifecycle
Retention Periods and Protection Measures
Retention periods vary by service delivery, billing reconciliation, security investigations, dispute handling, and applicable legal obligations. Once the purpose is fulfilled, information is deleted, de-identified, or moved to restricted archival storage.
Account, Order, and Service Records
Used to handle renewals, billing inquiries, service disputes, and historical order reconciliation. Records may be retained until an unresolved matter is closed.
Support Communications and Troubleshooting Materials
Used to review solutions, identify recurring faults, and handle subsequent disputes. Sensitive content unrelated to the issue is prioritized for access restriction or removal when identified.
Website and Security Access Logs
Used to detect unusual requests and investigate security incidents. Logs connected to an incident under investigation may be retained until the investigation and necessary review are complete.
Billing and Compliance Records
Orders, payment reconciliation, and financial records that must be retained by law are kept for the statutory period applicable to the platform operator, after which they are deleted or placed in restricted archives.
Protection Measures
- Access Controls: Access is assigned by job responsibility to prevent people unrelated to the task from accessing orders, logs, or support materials.
- Operational Auditing: Key administrative operations and security-response actions are recorded so access can be reviewed against its authorization scope.
- Transmission Protection: The website, console, and remote connections use encrypted connections appropriate to the context to reduce interception risks during transmission.
- Data Minimization: Forms, tickets, and troubleshooting workflows request only fields needed to achieve the purpose and do not proactively request passwords, private keys, or repository tokens.
- Incident Response: After unusual access is detected, we respond by confirming the scope, limiting impact, preserving evidence, fixing the cause, and notifying affected parties.
Requests and Verification
Your Rights and How to Contact Us
Where permitted by applicable rules, you may request access to information relating to you, correction of inaccurate content, deletion of information no longer needed, restriction of specific processing, or details about processing purposes, sources, sharing categories, and retention rules.
Access
Request confirmation of whether we process information relating to you and obtain available categories, purposes, and copies.
Correction
Update inaccurate or incomplete account, contact, order-context, and support records.
Deletion
Request deletion of information that is no longer needed and has no continuing basis for retention.
Restrict Processing
Request temporary restriction of a specific purpose while accuracy, lawfulness, or dispute handling is being confirmed.
How to Submit a Request
-
1
Choose a Contact Channel
Email support@hirevm.com or sign in to the console to submit a ticket. Tickets are best for requests related to existing accounts, orders, or support records.
-
2
Describe the Request Scope
Provide the account email, relevant order number, request type, time period involved, and desired action. You do not need to send a password or complete payment credentials.
-
3
Complete Identity Verification
To prevent unauthorized access to or deletion of information, we may verify the relationship between the requester and the data subject using the account, order, or an existing contact channel.
-
4
Receive the Result
We will explain the actions taken, information that must still be retained and why, or request necessary additional details when the scope is unclear.
Applicable Restrictions and Dispute Handling
Deletion or restriction requests may be limited by billing retention, security investigations, unresolved disputes, protection of rights, or other applicable legal obligations. We will limit restrictions to what is necessary and explain which data categories must remain and why.
This policy and related disputes are governed by the laws of the jurisdiction where the platform operator is located. Disputes that cannot be resolved through communication may be submitted to a court with jurisdiction in that jurisdiction.
Account email, order number, data categories involved, time period, and desired action. First remove unrelated keys, tokens, and personal information from screenshots or logs.