Data Processing Rules

How Each Data Type Moves Through Our Services

This policy explains how OrbVPS processes data when you visit the website, manage an account or order, interact with support, or use a dedicated physical node. We collect only the information needed for clearly defined purposes and limit access, retention, and use.

Covered services
Website, account console, orders, support, and node operations
Contact channel
support@orbvps.com
Policy status
Effective from the date of publication
01

Service boundaries

Policy scope

This policy applies to data activities that occur when you visit orbvps.com, use the account console, configure or manage Cloud Mac orders, send an inquiry through our contact channels, or work with the support team on a ticket. It also covers the backend records OrbVPS needs to deliver, protect, and operate dedicated Apple Silicon physical nodes.

Website browsing, account registration, identity verification, order configuration, payment-status checks, node delivery, remote-access security records, and support troubleshooting form one service workflow. Each stage processes only the data needed for its current task. Website analytics data does not automatically provide access to code, build artifacts, or business files stored on a node.

When someone operates an account or submits team-member information on behalf of a team, they must confirm that they are authorized to provide it and notify the relevant members about this policy. Console permissions should be assigned by role so team members do not share personal credentials.

Scope note

User content on dedicated physical nodes and website account data have separate access boundaries. Support staff do not access node content merely because a user submits a general inquiry.

02

Data minimization

What Data We Collect

The data we collect depends on the features you actually use. If you do not use a feature, we do not request unrelated information simply to build a more complete profile.

Account information
Information used to identify the account and verify access, including name, work email, account status, verification records, and configured security settings.
Contact information
Name, email address, team size, target region, target model, expected term, and requirements that you choose to submit.
Order records
The selected Orb M4 16, Orb M4 24, or Orb M4 Pro configuration, rental term, node region, add-ons, order status, and delivery records.
Payment status
Order amount, USD settlement records, payment-method category, transaction status, necessary transaction identifiers, and reconciliation results.
Device and access logs
Access times, source network information, browser and device category, verification results, account actions, node connection events, and security alerts.
Support materials
Ticket content, node number, incident time, reproduction steps, command output, redacted logs, screenshots, and follow-up records.

Support troubleshooting generally does not require a complete repository, private keys, or unredacted business data. Before submitting logs or screenshots, remove access tokens, keys, personal information, and content unrelated to the issue.

03

Purpose limitation

Purposes and Legal Basis

OrbVPS uses data only for a clearly defined service purpose and with an appropriate legal basis. Primary purposes include providing services, verifying identity, managing orders, protecting accounts and nodes, resolving incidents, and meeting applicable obligations.

  • Service provision and delivery:Confirm the model, region, term, and add-ons; create the order record; assign a physical node; and display service status.
  • Identity verification and access control:Send verification information, detect unusual logins, confirm who initiated sensitive actions, and apply account security settings.
  • Order and billing management:Verify payment status, process renewals or configuration changes, retain fulfillment evidence, and respond to billing questions.
  • Security protection:Analyze unusual requests, block unauthorized access, review high-risk actions, and maintain audit records.
  • Incident resolution:Use the node number, time range, command output, and service logs to locate connection, build, network, or storage issues.
  • Legal obligations:Retain necessary records where required, respond to valid requests, and maintain compliance evidence.

Relevant bases may include performing a service contract with you, taking pre-order steps at your request, meeting applicable obligations, protecting the service and users’ legitimate interests, or obtaining consent when a specific feature clearly requires it. Where processing relies on consent, you may withdraw it; withdrawal does not affect the validity of earlier processing.

04

USD settlement

How We Process Payment Data

All OrbVPS orders are settled in USD. The only available payment methods are USDT-TRC20 and Visa, Mastercard, and Amex processed through Stripe. Actual availability is determined by the result returned during checkout.

Full card numbers, security codes, and payment authentication information required for card payments are handled by the relevant payment process. OrbVPS does not retain complete card credentials as part of ordinary order data. We retain only the order amount, payment-method category, transaction status, transaction identifiers, and timestamps needed for fulfillment, reconciliation, disputes, and necessary audits.

The USDT-TRC20 process may generate records such as a transaction address, transaction identifier, amount, and confirmation status. These records match orders to payments and are not used to infer asset activity unrelated to fulfillment.

USD Settlement currency
2 types Supported payment routes
Required records What OrbVPS retains
05

Physical node boundaries

Nodes and User Content

Each active order corresponds to a dedicated Apple Silicon physical node: a remotely usable Cloud Mac, not a virtual machine. You decide which repositories, code, keys, build caches, models, assets, and business files to place on the node and are responsible for appropriate access controls and backups.

OrbVPS does not use content on nodes for advertising, profiling, or training general-purpose models. Node status, resource health, connection events, and hardware alerts generated to deliver the service may be processed, but operational records remain separate from user file content.

  • Use personal SSH keys and never share access credentials between team members.
  • Apply least-privilege access and rotation schedules to repository tokens, signing materials, and automation keys.
  • Back up important code, build artifacts, and business data to locations you control.
  • Redact support materials before submission, retaining only the output needed to diagnose the issue.
  • Before ending a rental, move out your data, verify that backups can be restored, and revoke the node’s credentials in external systems.

When you expressly request technical troubleshooting and status records cannot resolve the issue, the support team may ask you to provide specified logs or run diagnostic commands. Access must match the ticket’s purpose, and the materials will be handled under the retention rules after the issue is resolved.

06

Restricted access

Sharing and Cross-Region Processing

To operate the website, process payments, send necessary notices, protect the service, and deliver Cloud Macs on nodes in Singapore, Japan (Tokyo), South Korea (Seoul), and Hong Kong, OrbVPS may allow infrastructure, payment, and necessary service providers to process data directly related to their responsibilities.

Service providers may access data only for agreed purposes and within authorized limits. We restrict fields, account permissions, and retention periods by service type, and reduce unnecessary access risk through contractual controls, access restrictions, transmission safeguards, audit logs, and provider assessments.

When account users, team members, payment processes, and physical nodes are in different regions, necessary data may be processed across regions. This processing supports order completion, account security, support, or applicable obligations, with safeguards appropriate to the nature and risk of the data.

OrbVPS does not sell account information, order records, or support materials, and does not share them for independent third-party marketing. If our business structure changes, transfers of relevant data remain subject to this policy, applicable law, and necessary confidentiality requirements.

07

Record-type management

Retention and Deletion

We do not retain all data for one fixed period. Retention depends on whether the service continues, the purpose of the record, dispute-handling needs, security risks, and applicable obligations. Once the purpose ends, data is deleted, de-identified, or access-restricted to what is necessary to complete remaining obligations.

Account information

Retained while the account is active. After closure, we remove information needed for routine access; records still needed for order evidence, security investigations, or applicable obligations are retained with restricted access for the relevant period.

Order records

Retained as needed for fulfillment, reconciliation, dispute handling, and applicable recordkeeping obligations. Additional data unrelated to an order is not kept indefinitely simply because a historical order exists.

Support records

Retained during issue resolution, review, and reasonable follow-up. Logs, screenshots, and diagnostic output are prioritized for removal based on sensitivity and continuing need.

Security logs

Retained for a reasonable period needed to detect unauthorized access, investigate incidents, and validate control effectiveness; then deleted or aggregated.

After you request deletion, we first verify your identity and check for open orders, billing disputes, security investigations, or applicable retention obligations. Data that cannot be deleted immediately will be use-restricted and enter the deletion process once the reason for retention ends.

08

Layered controls

Security Measures

Security controls are established separately for accounts, orders, support records, and physical nodes. Measures are adjusted according to data sensitivity, access roles, and foreseeable risks; no single control is treated as complete protection.

Access controls

Assign administrative access by role and task, applying identity verification and least-privilege access to sensitive actions.

Transmission protection

Apply appropriate protection to data transmitted through the website, account console, and support interactions, reducing the risk of interception or alteration in transit.

Log auditing

Record key account and administrative actions to identify anomalies, review processing, and investigate security incidents.

Credential rotation

Update and revoke service credentials and review their permissions; users must also manage their node access keys securely.

Incident response

Confirm, contain, investigate, recover from, and document suspected security incidents, providing necessary notices where applicable.

You should also use separate credentials, promptly revoke access for departing members, limit automation-key scope, and keep verifiable backups. If you detect an unusual login or node access, submit a ticket through the account console as soon as possible.

09

Request and verification

User Rights and Contact

Where applicable, you may request access to data about you, completion or correction of inaccurate information, deletion of data that is no longer needed, restriction of specific processing, or withdrawal of consent for consent-based processing. Some requests may be limited by order fulfillment, security investigations, protection of rights, or applicable retention obligations.

When submitting a request, send an email from the address registered to your account to support@orbvps.comor log in to theaccount console to submit a ticket. State the account email, relevant data categories, requested action, and necessary order or node identifiers. Do not send passwords, private keys, or complete payment credentials.

To prevent data from being incorrectly disclosed or deleted, we verify identity according to the risk of the request. Verification may include confirming the registered email, order relationship, recent account activity, or other information sufficient to demonstrate control. If verification cannot be completed, we will explain what additional information is needed rather than disclose account content to an unverified requester.

If you disagree with the outcome, you may provide additional facts through the same channel and request a review. Applicable law for this policy is the law of the jurisdiction where the platform operator is established; disputes requiring judicial resolution will be handled by a court with jurisdiction in that jurisdiction.

1 Describe the request

Specify the scope of access, correction, deletion, or restriction requested.

2 Complete verification

Confirm your identity using your registered email and necessary account relationship information.

3 Receive the result

Receive the outcome, reasons for any restriction, or details of information still needed.

Configure a Dedicated Cloud Mac with Clear Rules

Review the three models, four nodes, and fixed-term pricing before configuring your service. Manage existing orders or data requests through the account console.