How Your Information Enters, Stays in, and Leaves VMOrbit

This policy follows the data flow across website visits, inquiries, orders, and support. We process only the information needed to deliver cloud Macs, manage dedicated physical nodes, and respond to support requests.

Current version
2026.09
Last updated
Contact channels
Email or console ticket
Data processing flow PRIVACY / 09
  1. 01
    Collect only what is needed Account, order, access, and support records
  2. 02
    Process for defined purposes Delivery, billing, security, and issue response
  3. 03
    Retain as needed Delete or de-identify when the purpose ends

You can submit access, correction, and deletion requests by email or through the logged-in console.

01

Scope

First, see which interactions fall under this policy.

This policy applies to information processing connected with visiting vmorbit.com, browsing product and node information, using the inquiry page, and managing orders, accounts, and support conversations through the console.

VMOrbit provides cloud Macs for development and experimental workloads. Each active order is assigned a dedicated Apple Silicon physical node, not a virtual machine. This policy covers the information needed to deliver and manage the service; it does not change the customer’s responsibility for managing project code, build artifacts, keys, signing materials, or business data.

Website visits Page requests, basic device information, and security logs
Inquiries Information and contact details you choose to provide
Orders Model, node, term, billing, and delivery records
Support Ticket content, log excerpts, and handling history
02

What Information We Collect

The data we collect depends on the features you actually use.

Account and contact information Used to identify the requester and maintain service communications.

This may include your email address, account identifier, verification status, team or organization name, and contact details entered in an inquiry or support ticket.

Order and service information Used to configure, bill, and manage nodes.

This includes your selected VMOrbit M4 or VMOrbit M4 Pro, rental term, node region, storage add-ons, order identifier, payment status, renewal and termination records.

Device and access logs Used for security checks and troubleshooting.

This may include IP address, browser and device type, request time, pages visited, login events, operation results, and anomaly records. Logs help identify abuse, troubleshoot connection issues, and keep the service reliable.

Support and incident records Used to reproduce issues and track resolution progress.

This includes node region, time of the issue, impact, reproduction steps, log excerpts, ticket correspondence, and necessary operation records. Do not submit passwords, private keys, recovery codes, or complete payment credentials.

Content you submit Used to answer specific requests.

This may include team size, primary workloads, toolchain, CI platform, expected term, regional preferences, and any other details you choose to provide.

03

How We Use This Information

Each processing activity should serve a clear service purpose.

  • Provide and deliver the service

    Create accounts, confirm orders, configure dedicated physical machines, provide connection details, and maintain instance and subscription status.

  • Process orders and billing

    Verify the model, node, term, add-ons, and payment result, and create necessary order and billing records.

  • Protect accounts and nodes

    Detect unusual logins, unauthorized access attempts, resource abuse, and activity that may affect service security.

  • Respond to support requests

    Use the region, timeline, logs, and reproduction steps in a ticket to troubleshoot connection, build, node, or billing issues.

  • Improve service documentation

    Aggregate common issues and resolutions to refine connection guides, troubleshooting sequences, and operating instructions.

  • Meet necessary obligations

    Maintain security, dispute-handling, and necessary business records, and respond to requests with a valid basis.

04

How We Handle Payment Data

All orders are billed in US dollars (USD).

VMOrbit supports only USDT-TRC20 and Visa, Mastercard, and Amex processed through Stripe. Actual gateway availability is determined during checkout.

Digital asset payments

USDT-TRC20

Order records may include the amount due, payment status, network type, transaction identifier, and information needed to verify receipt.

Card payments

Visa / Mastercard / Amex

Card data is handled through Stripe’s payment flow. VMOrbit receives the payment status and related identifiers needed to complete orders, resolve billing issues, and identify unusual transactions.

Do not send complete card numbers, security codes, wallet private keys, recovery codes, or other information that could directly control a payment account through regular email or support tickets.

05

When We Process or Share Information

The scope is limited to the information needed to complete a specific task.

We do not expand information sharing for purposes unrelated to the service. Relevant information is processed by the service workflows or partners responsible for the corresponding task only when necessary to complete one of the following:

Service delivery
Confirm orders, assign nodes, send necessary notifications, and maintain account status.
Payment processing
Complete billing, confirm payment results, handle refunds or billing disputes, and retain necessary records.
Security
Detect unusual activity, investigate security incidents, restrict unauthorized access, and retain an incident timeline.
Support collaboration
Route an issue to personnel able to handle the relevant node, connection, build, or billing matter.
Applicable requirements
Process information requests that we must answer when they have a valid basis and clearly defined scope.

Regardless of which necessary workflow processes the information, we limit access to the purpose at hand and require everyone who handles it to follow appropriate confidentiality and security requirements.

06

Retention, Deletion, and De-identification

Retention periods are determined by the purpose and necessary recordkeeping requirements.

Different types of information are not assigned one mechanical retention period. We determine what to retain based on whether the service is ongoing, whether orders and disputes have been resolved, whether security incidents require tracking, and whether necessary recordkeeping requirements apply.

  1. A
    While the service is active

    We retain account, order, node, and support information to deliver the service, manage renewals, resolve issues, and keep operations traceable.

  2. B
    After the service ends

    We remove access that is no longer needed and retain limited information as required for billing, disputes, security, and necessary records.

  3. C
    When the purpose ends

    We delete information through applicable processes or de-identify it to reduce the possibility of linking it back to a specific user.

You should migrate your project data and retain necessary copies before the rental term ends. Deleting an account or ending an order does not mean that all necessary billing, security, or dispute records can be removed immediately.

07

Cross-Regional Processing and Node Selection

The region determines where the workload is hosted.

VMOrbit offers six nodes: Singapore, Japan (Tokyo), South Korea (Seoul), Hong Kong, US East, and US West. Both available models can be ordered in all six nodes; real-time availability is shown by the console.

SGSingapore
JPJapan (Tokyo)
KRSouth Korea (Seoul)
HKHong Kong
US-EUS East
US-WUS West

When choosing a node, consider the primary developers’ locations, remote connection network, code repository path, dependency download sources, internal team requirements, and project data-processing needs. Do not choose based solely on geographic distance; test from your actual office network before ordering.

To complete orders, process payments, secure accounts, and respond to support requests, necessary account and business records may be processed across regions by the workflows responsible for those tasks. We limit processing to what is needed for these purposes.

08

What You Can Request

The outcome depends on identity verification and necessary recordkeeping limits.

Access

Ask whether we hold information about you, including its main categories, purposes, and processing scope.

Correction

Request correction of inaccurate or incomplete account, contact, or order-related information.

Deletion

Request deletion of information no longer needed, although necessary billing, security, dispute-handling, and operational records may need to be retained.

Communication preferences

Adjust preferences for non-essential notifications. Order status, security alerts, and service-operation notices may not be disabled.

To prevent impersonation, we may ask the requester for enough information to verify their relationship with the account. Send requests from the email address linked to the account or submit a related ticket while logged in to the console. Do not include sensitive content unrelated to the request in identity-verification materials.

If a request could affect another person’s rights, service security, dispute handling, or necessary records, we may limit its scope and explain the available outcome in the original conversation.

09

Policy Updates, Contact, and Applicable Rules

Version changes and privacy requests always have a traceable point of contact.

We update this policy when there is a material change to the service scope, information types, processing purposes, or user choices, and record the new update date on this page. Significant changes are communicated through the website, account notices, or order-related conversations; necessary explanations will not be replaced by silent changes.

Privacy questions, data access, correction, or deletion requests can be sent to support@vmorbit.com. Existing-order users can also sign in to the console and submit a ticket so the request can be securely linked to the relevant account and order. The only external contact channels are this support email and console tickets.

This policy and related matters are governed by the laws of the jurisdiction where the platform operator is based. If a dispute arises, the parties should first seek resolution through an existing support conversation; if it cannot be resolved, it will be handled by a court with jurisdiction in that jurisdiction.

Include with your request Account-linked email address, request type, relevant order identifier, and desired outcome
Do not submit Passwords, private keys, recovery codes, complete payment credentials, or unrelated project data

Need to verify information about you?

Existing-order users should submit requests through a console ticket first; general privacy questions can be sent to the sole support email.