Scope
Which access and service activities are covered by this policy.
This policy applies to publicly available website content on ownamac.com and to the data activities required when you register an account, choose a configuration, pay for an order, initialize a dedicated physical node, receive credentials, manage an instance, view billing details, or submit a support ticket through the console.
OwnAMac provides remotely accessible cloud Macs. Each valid order corresponds to one dedicated physical machine in the selected region, not a virtual machine. To complete delivery, we need to link the order ID, selected configuration, node region, rental period, and delivery status. We do not proactively inspect what users work on in the macOS graphical interface or command line as part of providing computing services.
This policy also covers information you voluntarily send through support email or console tickets, including issue descriptions, log excerpts, screenshots, order IDs, and reproduction steps. Do not include passwords, private keys, recovery codes, or other secrets that could directly provide system access in an email or ticket.
Software you install, code repositories you connect, build tools, and other services may process data under their own rules. Before using them, you or your organization should review their data flows, permissions, and retention settings.
Data We Collect
We process only the information needed for access, ordering, delivery, security, and support.
Contact & Account Information
Work email address, account ID, language preference, and the name or team context you voluntarily provide during inquiries or support communications.
Order & Configuration Information
Order ID, rental period, OAM M4 16, OAM M4 24, or OAM M4P 64 configuration, selected node, storage add-ons, Thunderbolt 5 parallel connection count, and order status.
Delivery & Node Records
Node assignment, initialization status, credential delivery status, instance status changes, and records of administrative actions required to fulfill your requests.
Access Logs
Access time, request path, response status, security events, and session-related identifiers used to maintain sign-in status, detect unusual access, and troubleshoot service errors.
Device & Browser Information
Browser type, operating system category, screen or viewport information, language settings, network address, and necessary technical identifiers used for compatibility, security decisions, and troubleshooting.
Support Communication Records
Email and ticket content, timestamps, reproduction steps, screenshots and screened log excerpts you voluntarily upload, plus the handling process and outcome.
Remove personal information unrelated to the issue, access tokens, keys, complete environment variables, and project secrets. If sensitive material is genuinely needed for troubleshooting, support staff will explain the controlled submission method and required scope.
Processing Purposes
Each data category should have a clear, necessary, and explainable business purpose.
| Processing activity | Primary data | Specific purpose |
|---|---|---|
| Account & order management | Email, account ID, order ID, configuration, and rental period | Create accounts, record selections, display order status, and process renewal or cancellation requests |
| Physical node delivery | Order ID, machine model, node, add-ons, and initialization status | Assign a dedicated physical machine, perform system initialization, deliver access credentials, and display instance status |
| Identity & security verification | Sign-in events, session identifiers, network address, device, and browser information | Verify request origin, prevent abuse, detect unusual sign-ins, and protect accounts and nodes |
| Troubleshooting | Order ID, node, timestamp, log excerpts, screenshots, and reproduction steps | Identify connection, performance, build, disk, network, or order issues and record the resolution |
| Service improvement | Aggregated access, error, compatibility, and support issue information | Identify common failure paths and improve interface messages, documentation, and delivery processes |
| Legal obligations | Necessary account, order, payment status, and communication records | Maintain financial records, handle disputes, conduct security investigations, and meet applicable obligations |
We do not repurpose information collected for node delivery or support troubleshooting for uses incompatible with its original purpose. If a new purpose would materially change how data is used, we will provide an appropriate explanation before implementation and obtain any required authorization where applicable.
Payment Data Boundaries
There is a clear boundary between order records and complete payment credentials.
OwnAMac supports only USDT-TRC20 and Visa / Mastercard / Amex (via Stripe). All orders are settled in US dollars (USD). The actually available gateway is determined by the console response.
To reconcile orders, confirm payments, and handle disputes, we may retain the order amount, currency, payment method category, transaction status, payment time, necessary transaction reference identifiers, and refund or exception status. Card payments are handled through the applicable payment-processing flow; we do not ask users to submit full card numbers, security codes, or card photos by email or ticket.
May be linked to an order
- US dollar order amount and settlement status
- Payment method category and transaction reference identifier
- Payment confirmation, failure, or refund status
- Timestamps needed for reconciliation and dispute handling
Not collected in ticket content
- Full card number and security code
- Payment account password or private key
- Wallet recovery code or complete signing secret
- Financial materials unrelated to order verification
Retention & Security
Retention periods depend on the purpose of the data, not on indefinite storage by default.
Data needed for accounts and active orders is generally retained while the account or order remains active. After an order ends, necessary records related to settlement, dispute handling, security investigations, and legal obligations remain for the period required for those purposes. Data that no longer has a reasonable use is deleted, anonymized, or isolated from routine systems.
Support records are retained based on whether the issue is resolved, may recur, or involves an order dispute or security incident. Temporary diagnostic materials should be removed from routine processing once troubleshooting is complete and they are no longer needed. When a user requests deletion, we will check for ongoing orders, disputes, or legal obligations before determining what can be deleted.
Access controls
We restrict data access according to job responsibilities and prevent unrelated personnel from accessing orders, nodes, and support materials.
Log auditing
We record necessary administrative and security events to detect unusual activity, reconstruct processing paths, and verify outcomes.
Least privilege
We grant only the system and data permissions needed to deliver nodes, reconcile billing, or troubleshoot issues.
Technical and organizational measures must be continuously adjusted to the specific data types, access paths, and risks involved. If we discover a data security incident that may affect user rights, we will investigate, limit its impact, remediate the cause, and provide any required notice under applicable rules.
User Rights & Contact
You may submit clear, verifiable requests concerning data relating to you.
Access
Ask whether we process data relating to you and request information, within a reasonable scope, about its categories, purposes, and sources.
Correction
Request correction of inaccurate or incomplete contact, account, or order information. Some order records may need to retain their original change history.
Deletion
Request deletion of data that is no longer needed. Deletion may be limited where records are still used for active orders, dispute handling, security investigations, or legal obligations.
Restricted processing
Request temporary restriction of further use of specific data while its accuracy, processing basis, or a dispute is being reviewed.
Raise a privacy question
Ask about specific data flows, retention periods, or security measures, or object to a processing activity and provide additional context.
When submitting a request, specify the request type, associated email address, relevant order ID, and the scope of data to be addressed. To prevent unauthorized access to or changes in records, we may require identity verification proportionate to the risk. We will not ask you to send an account password, private key, or recovery code in the body of an ordinary email.
Use the dedicated external contact email
Please email support@ownamac.comwith “Privacy Request” in the subject line and specify whether you are requesting access, correction, deletion, restricted processing, or general information.
Send a privacy request emailRequests concerning existing orders
Sign in to the console and submit a ticket with the order ID, node, and scope of data to be checked. This can reduce errors when linking your identity.
Processing and disputes
Processing under this policy is governed by the laws of the jurisdiction where the platform operator is based. Disputes that cannot be resolved through communication may be submitted to a court with jurisdiction in that jurisdiction.
If data categories, processing purposes, payment boundaries, or user rights materially change, we will update this page and display the new effective date. When continuing to process data necessary for existing orders, we will still follow purpose limitation and data minimization principles.