Privacy and data handling

What data we process and how you control it

This policy explains what information MiniDeploy processes when you visit the website, manage your account in the console, receive Cloud Mac resources, or contact support. We collect only what is needed for clear business purposes and provide verifiable paths for access, correction, deletion, and privacy inquiries.

Scope Website, console, and support processes
Contact channels Email and console tickets
Data principles Clear purpose, data minimization, controlled access

01

Scope

This policy applies to data processing when you visit minideploy.com, manage your account and nodes through Console, or contact MiniDeploy through support email or console tickets. It covers browsing the website, creating or using an account, selecting a model and region, paying for orders, receiving node credentials, renewing resources, viewing invoices, submitting tickets, and requesting data rights.

Public website

This includes page visits, language selection, basic security records, and features you actively use. You do not need to submit personal information to read about plans, nodes, support, or legal information on the public website.

Console workflows

This includes authentication, order configuration, payment status, physical node allocation, instance management, billing records, and ticket handling. The related data connects each order with the correct account and resources.

Support communications

This includes the sender address, ticket content, node number, issue time, reproduction steps, and sanitized logs you voluntarily provide. Support staff should receive only the information needed to locate the issue.

Outside the scope of this policy:Software you install yourself, code repositories, team storage, and other tools are governed by their respective providers’ rules. Review their data practices before connecting to them.

02

Data we collect

The data we process depends on what you do. Browsing public pages generates a different data set from placing an order, managing a node, or submitting troubleshooting logs. The table below lists the main categories, typical fields, and sources.

Data category Typical content Primary source Why it is needed
Account and contact information Email address, account identifier, verification status, preferred language Submitted by you or generated through account activity Needed for authentication, notifications, and support replies
Order metadata Model, term, region, storage add-ons, order status, USD amount, payment-status identifier Generated by ordering and billing workflows Needed to reserve, deliver, and reconcile resources
Node management records Node number, assigned region, delivery time, status changes, renewal records, management-operation times Generated by the console and resource systems Needed to provide and manage dedicated physical machines
Access and security logs Timestamps, request results, basic browser or client information, network address, security-event identifiers Generated by the website, console, and security systems Needed to prevent abuse, audit anomalies, and protect account security
Support and diagnostic materials Ticket text, node number, reproduction steps, screenshots, command output, sanitized logs you submit Provided by you by email or ticket Processed as needed to diagnose a specific technical issue

Do not include unrelated private keys, complete access credentials, source code, customer data, or unsanitized configuration files in support materials. If logs contain paths, repository names, internal addresses, or people’s information, preserve the error context first, then remove unrelated identifying details.

03

Processing purposes

Each data category must serve an explainable purpose. We do not use data arbitrarily for purposes unrelated to the context in which it was collected. Our main processing activities are described below.

DELIVERY

Service provision and resource delivery

Based on the M4 Core model, term, region, and add-ons in your order, we reserve resources, assign a Cloud Mac physical node, generate required credentials, and display instance and subscription status in the console.

IDENTITY

Authentication and account protection

We confirm that login requests belong to the relevant account, record important management actions, identify unusual authentication, repeated attempts, or unauthorized access, and send necessary security and service notifications to the account email address.

AUDIT

Security auditing and troubleshooting

We use timestamps, request statuses, node events, and diagnostic context you provide to reconstruct the issue path. Troubleshooting is limited to specific problems such as connection failures, authentication errors, abnormal node status, or billing inconsistencies.

RECORDS

Billing records and legal obligations

We retain order amounts, payment status, billing identifiers, and necessary transaction links for reconciliation, dispute handling, fraud detection, and applicable recordkeeping obligations related to operations.

04

Payment information

MiniDeploy supports only USDT-TRC20 and Visa / Mastercard / Amex (via Stripe). All orders are settled in US dollars (USD). Available gateways are determined by the result returned during checkout.

Visible to MiniDeploy

Data visible to the site

  • Order number, account identifier, and payable USD amount
  • Selected model, term, node region, and add-ons
  • Payment method category, payment status, and completion time
  • Transaction reference or on-chain transaction identifier used for reconciliation
  • Status records needed for refunds, disputes, or billing checks

Handled in payment flow

Data handled in the payment flow

  • Card and verification information required for card payments is handled by the relevant payment flow.
  • USDT-TRC20 transfers create publicly verifiable on-chain transaction records.
  • Payment security checks may process device, network, and transaction-risk signals.
  • The site receives only the result fields needed to confirm order status and complete reconciliation.
Data boundary:The console needs to know whether an order has been paid, but ordinary order records do not need to display full card details. On-chain transactions are publicly verifiable; avoid adding unrelated personal information to transfer notes or support communications.

05

Devices and workloads

A Cloud Mac is a dedicated physical machine assigned to a single tenant, not a virtual machine. Data you create, download, sync, or generate on the node is your workload, including project files, code, build artifacts, models, media, keys, certificates, caches, and automation configuration.

Resources managed by the platform

  • Assign the physical node matching the ordered model and region
  • Provide node-status and subscription-management features in the console
  • Protect platform management systems, account workflows, and internal access permissions
  • Troubleshoot resource-delivery or connection issues based on verified support requests
  • Run resource-reclamation procedures when a term ends or service is terminated

Workloads managed by you

  • Choose which project data and tools enter the Cloud Mac
  • Manage system accounts, remote-access sources, and least-privilege settings
  • Protect private keys, signing materials, access tokens, and automation keys
  • Maintain independent backups of code, media, models, and build artifacts
  • Reconcile and migrate data and rotate credentials before the term ends

If you need support staff to troubleshoot an issue on the node, explain the scope of impact first and submit only the minimum material needed to reproduce it. Unless essential to diagnose a specific issue and expressly provided by you, do not attach complete project directories, production keys, or entire datasets.

06

Retention and deletion

Retention periods are assessed separately based on account status, order relationships, security-audit needs, billing-record requirements, and your request. Once the purpose ends, we delete, de-identify, or restrict further use of the relevant data. Data still needed for legal obligations, dispute handling, or security investigations is separated from routine business use.

Account information

Account lifecycle

During the account lifecycle, we retain your email address, account identifier, and verification status to support login and service notifications. After receiving a deletion request, we verify the requester’s relationship to the account and check for ongoing orders, unresolved billing matters, or security restrictions.

Order and billing records

Recordkeeping obligations

Order configuration, USD amounts, payment status, and transaction references are retained as needed for billing reconciliation, dispute handling, and applicable recordkeeping obligations. Deleting an account does not necessarily delete order records that must be retained by law or to resolve an existing dispute.

Access and security logs

Risk lifecycle

Logs are retained for the time needed to identify anomalies, investigate security incidents, and verify important actions. Retention is adjusted based on incident severity, investigation status, and log sensitivity. Security logs are not used as a long-term user-profile source unrelated to security.

Support tickets and attachments

Issue lifecycle

Ticket text and diagnostic attachments are retained for the period needed to resolve the issue, conduct a review, and check related incidents later. You may identify sensitive attachments for priority removal in a ticket; before deletion, we may retain non-sensitive conclusions and timestamps.

How deletion requests are handled

  1. 1
    Define the scope

    Specify the account, ticket, attachment, or other data categories you want deleted, and provide an order or ticket number that lets us locate the records.

  2. 2
    Complete verification

    We confirm the relationship between the requester and relevant records through the account email or a logged-in console, helping prevent impersonation-based deletion.

  3. 3
    Check restrictions

    We check for unfinished orders, billing disputes, security investigations, or recordkeeping obligations that must be fulfilled.

  4. 4
    Act and respond

    We delete or de-identify eligible content. If some fields must be retained, we explain the data category, retention basis, and applicable limits.

07

Service providers and cross-border processing

Providing Cloud Mac services requires a small number of recipients with clearly defined roles. They may include infrastructure and network providers, authentication and email-delivery services, payment processors, security and logging systems, and technical support staff involved in troubleshooting at your request.

Required recipient categories

  • Infrastructure:Systems needed to host the website and console and orchestrate resources and node connections.
  • Identity and notifications:Services needed to send verification codes, account notifications, and essential service messages.
  • Payment processing:Processing card-transaction results or verifying USDT-TRC20 transaction status.
  • Security and support:Identifying unusual access and analyzing troubleshooting context within the authorization of a ticket.

Cross-region processing scenarios

  • The node region you select may differ from where you access the service.
  • Account, order, and support workflows may transfer necessary fields between the regions hosting service systems.
  • Cross-region transfers do not mean that your entire workload is copied to every region.
  • Diagnostic materials should be sent only to the people and systems necessary to handle the ticket.
01Minimum fields

Transfer only the fields needed for identity, payment, delivery, or troubleshooting.

02Minimum recipients

Give access only to the corresponding data needed by people and systems performing a specific function.

03Minimum duration

Delete, de-identify, or restrict further use when the processing purpose ends.

08

Security measures

We use technical and organizational measures appropriate to the data type, processing context, and risk to reduce the risk of unauthorized access, accidental disclosure, alteration, and loss. Security controls are configured separately around accounts, the console, node management, and internal operations.

Access controls

Platform permissions are granted according to role and task. Account management, node operations, billing queries, and support data have separate access scopes to prevent one identity from accessing unrelated information.

Log auditing

We record key authentication, order, node, and internal management actions to identify anomalies, reconstruct event timelines, and verify who performed an action. Access to the logs is itself permission-controlled.

Transmission protection

The website and console transmit data over HTTPS. When connecting to a dedicated physical machine, use protected SSH, VNC, or macOS graphical-interface configurations and restrict unnecessary network sources.

Credential management

Credentials are issued and managed according to their purpose. After your first connection, replace temporary credentials, remove keys you no longer use, and avoid exposing active secrets in tickets, screenshots, or build logs.

Four checks for users

  1. Restrict SSH and VNC access to approved sources and expose only the connection paths you actually need.
  2. Use separate, least-privilege system accounts and short-lived keys for automation tasks.
  3. Before uploading logs, search for tokens, private keys, certificate contents, and internal addresses, then sanitize them.
  4. Before the term ends, migrate project data, revoke remote-access keys, and verify synchronization results in team storage.

09

User rights and contact

Subject to applicable rules and the specific data relationship, you may request access to, correction of, or deletion of data relating to you; ask about processing purposes, data categories, recipient categories, and retention grounds; or object to specific processing. Some requests may be limited by identity verification, existing orders, billing records, security investigations, or legal obligations.

Available requests

  • Confirm whether we hold data related to your account
  • Receive an explanation of the main data categories and processing purposes
  • Correct inaccurate or outdated account contact information
  • Delete data that is no longer needed and has no retention basis
  • Learn which categories and reasons apply when deletion is restricted
  • Ask about cross-region processing and required recipient categories

Include in your request

  • The email address used for the account
  • Request type and the data scope you want covered
  • Relevant order, node, or ticket number
  • The original field to correct and the correct information
  • Account context that helps verify your identity
  • Your preferred reply language and time zone

Two ways to contact us

EMAIL

Send a privacy email

Use this option if you cannot log in to the console, need to ask about policy scope, or want to request access, correction, or deletion. We suggest using “Privacy request” as the subject and listing your account email, request scope, and relevant record numbers.

support@minideploy.com
TICKET

Submit a console ticket

Use this option for data questions linked to an existing order, node, or invoice. Select the relevant resource in your ticket and include when the issue occurred and which data categories need review.

Log in to the console to submit a ticket
Identity verification:We primarily verify your identity through the account email or a logged-in console. Verification collects only what is needed for that confirmation. Do not send complete credentials, private keys, or unrelated project data by ordinary email.

Applicable rules and dispute handling

This policy and related data-processing matters are governed by the laws of the jurisdiction where the platform operator is based. Any dispute related to this policy that cannot be resolved through communication will be handled by a competent court in that jurisdiction under applicable procedures.

Privacy request

Have your record number ready before submitting a privacy request

State your account email, request type, data scope, and order or ticket number. The more specific the information, the easier it is to verify your identity and locate the relevant records.