privacy://policy — Privacy Policy

How We Handle Privacy

> Loading privacy policy… 8 sections. By the end you'll know exactly what we collect, what we don't, how long we keep it, and how to have it deleted.

Version v1.2 Effective Jul 28, 2026 No hidden clauses, full stop
privacy://01-scope

01Scope & Effective Date

This policy covers the data processing that happens when you visit or use opsmac.com (our website, all language versions) and Console (the control panel) — including orders, activations, renewals, and support tickets submitted through those sites.

This policy takes effect on the date shown in the header above. When we update it, we bump the version number and effective date on this page; if a change materially affects how we process data, we'll notify you at your account email before it takes effect. Continuing to use the service after a change goes live counts as accepting the updated policy.

  • Covered: browsing the website, account registration and login, orders and billing, machine assignment and delivery of remote access credentials, and support communications.
  • Not covered: any third-party service you install, log into, or access from inside your dedicated physical machine — those are governed by their own privacy policies, not ours.
privacy://02-collect

02What We Collect

Since every machine is dedicated hardware, we keep our data appetite equally minimal: only the four categories needed to activate and bill your service. No profiling, no fields that aren't tied to actually running the service.

Account email account
Your login credential and the only channel we use to send boot credentials and billing notices. No real name or ID verification required to sign up.
Order & billing information billing
Model, billing cycle, location, add-ons, amount (USD), payment status, and invoice number — needed to activate the service and reconcile accounts.
Machine assignment records allocation
Which physical Mac mini was assigned to which account and when — used for troubleshooting, end-of-lease recovery, and scheduling the wipe.
Support communications support
Whatever you send to support@opsmac.com or through a control panel ticket, plus our replies — used to track how issues are progressing.

We do not collect: contacts, location trails, device fingerprints, social accounts, or any behavioral data used for ad targeting.

privacy://03-payment

03Payment Data Handling

We support exactly two payment methods — USDT-TRC20, and Visa / Mastercard / Amex via Stripe — everything billed in US dollars. Here's the privacy boundary for each:

Card payments (Visa / Mastercard / Amex, via Stripe)

  • Card number, expiry, and CVC are entered and processed entirely on Stripe's hosted payment page — none of it ever passes through or gets stored on our servers.
  • From Stripe, we only receive the minimal receipt needed for reconciliation: card brand, last four digits, charge amount, and result status.
  • When handling disputes or refunds, we work only from that receipt and your billing record — we can't, and don't, see the full card number.

USDT-TRC20

  • We generate a receiving address per order and only log the on-chain transaction hash, amount, and confirmation time for reconciliation — no wallet identity information required.
  • On-chain transaction data is maintained publicly by the blockchain network itself, visible to anyone, and cannot be deleted or altered by us — that's a property of the chain, not a choice we make.
privacy://04-machine-boundary

04Data Boundaries on Your Server

You're renting a dedicated physical machine, not a shared virtual instance — which makes the data boundary very clean:

  • Ownership: everything you put on the machine — code, certificates, build artifacts, model files — is yours. We claim no rights to it.
  • No access by us: we never log into your machine, scan its disk, or inspect its processes or network traffic. Routine operations rely only on power, network, and hardware health signals collected outside the machine.
  • Troubleshooting exception: we only log in, within the scope you describe, if you explicitly authorize it through a ticket and hand us temporary credentials — which you should rotate immediately after we're done.
  • End-of-lease wipe: once the lease ends and the retention buffer passes, the machine is fully wiped and macOS is reinstalled before it goes back into the pool. Data is unrecoverable after the wipe — back up before your term ends.

System note: we don't offer a managed backup service for anything on your machine. The wipe process doesn't sort files by importance — backups are on you.

privacy://05-logs-cookies

05Logs & Cookies

Access & activity logs

  • Website access logs (IP address, browser identifier, request path, and timestamp) are used for security monitoring and troubleshooting, and are automatically purged on a rolling basis after 90 days.
  • Control panel activity logs (login, orders, password changes, and other key actions) are kept for 180 days for account security audits and dispute resolution.
  • Analytics runs on a self-hosted, same-domain setup — data stays on our own servers and is never shared with a third-party analytics platform.

Cookies & local storage

  • We only use strictly necessary cookies: keeping your control panel session alive and blocking cross-site request forgery. No ad cookies, no cross-site tracking.
  • Your language preference and dismissed-banner state are saved in your browser's local storage — they stay on your device only and disappear when you clear browser data.
  • Blocking non-essential storage won't affect browsing the website; blocking session cookies will prevent you from staying logged into the control panel.
privacy://06-third-party

06Third-Party Sharing

We only hand data to third parties in the two scenarios below, with the categories and scope listed — nothing beyond that is shared, sold, or traded:

ScenarioRecipient categoryData sharedPurpose
Payment processing Payment provider (Stripe) Order amount, invoice number, and any card details you enter directly on their page Processing charges and refunds
Legal request Authorities with jurisdiction The minimum data necessary, within the scope defined by a lawful written request Complying with a legal obligation

When we receive a legal request involving user data, we verify it's procedurally valid and, where the law allows, notify the affected account.

privacy://07-retention

07Retention & Deletion

Each data category has its own retention window, tied to its purpose, and is deleted or anonymized automatically once it expires:

Data categoryRetention periodBasis
Account email & profileAccount lifetime + 30 daysBuffer after closure to prevent accidental loss
Order & billing recordsStatutory retention periodAccounting and tax retention requirements applicable in our operating jurisdiction
Machine assignment records180 days after lease endsDispute resolution and wipe-schedule traceability
Support communications24 months after ticket closureTracking recurring issues
Website access logs90 daysSecurity monitoring
Control panel activity logs180 daysSecurity auditing
On-chain transaction hashesSame as order & billing recordsReconciliation reference (on-chain data is public by nature and outside our control)

Account deletion process

  1. Email support@opsmac.com from your registered address, or submit a deletion ticket from the control panel;
  2. We verify the request against the registered email;
  3. Any outstanding invoices are settled and active leases terminated (machine data is wiped per Section 04);
  4. Deletion or anonymization is completed within 30 days of confirmation; billing data subject to statutory retention is deleted once that retention period expires.
privacy://08-your-rights

08Your Rights & How to Reach Us

For any data we hold tied to your account, you can request at any time to:

  • Access: get a copy of the data we hold about you and an explanation of how it's used;
  • Correct: fix inaccurate account or billing information;
  • Delete: erase specific data or close your account entirely (aside from anything under statutory retention).

There are two channels for this — use either one, and send it from your registered email so we can verify it's you:

Response times: general inquiries get a reply within 24 hours; access, correction, and deletion requests are acknowledged within 3 business days and completed — or explained if we can't complete them — within 30 days.

Disputes arising from this policy are governed by the laws of the jurisdiction in which our operating entity is based, and fall under the jurisdiction of the courts there.