Legal · data protection

Personal information & data protection policy

This document explains how SpinMac collects, uses, stores, and protects personal information when you browse our site, register an account, rent a Mac mini M4 cloud device, or use related features, and the rights you may exercise under applicable law.

Last updated: July 15, 2026 Applies together with Terms of Service Using the service means you accept this policy
00

Policy overview

SpinMac ("we") treats user privacy and data security as foundational to platform operations. This Privacy Policy ("Policy") applies to all services you access, register for, or use via spinmac.com and its subdomains (collectively, the "Services"), and explains how we handle personal information relating to you.

By continuing to use the Services, you have read, understood, and agree to this Policy.If you disagree with any provision, please stop using the Services. This Policy, together with theTerms of Service, forms the complete agreement between you and SpinMac; where they conflict on personal data processing, this Policy prevails.

Business data you store, run, or transmit on rented devices (e.g., source code, build artifacts, database contents) is primarily managed by you as the data controller; this Policy focuses on account, transaction, and access information collected on the platform side.

01

Information we collect

1.1 Information you provide

  • Account details:email submitted at registration, login password (stored as encrypted hash—we cannot read plaintext), and other details you voluntarily provide
  • Orders & configuration:selected data center node, rental period, SSD expansion or Thunderbolt 5 clustering add-ons, and order notes
  • Payment-related:transaction amount, payment status, order ID, and redacted billing summary; full card numbers or on-chain wallet private keys are handled by third parties such as Stripe and USDT payment channels—we do not store them
  • Support communications:issue descriptions, attachments, and correspondence submitted via tickets or email

1.2 Automatically collected information

  • Access logs:IP address, request time, access path, browser type, operating system, and referrer page
  • Client identifiers:device identifiers generated for security verification and anomaly detection (SSAID, stored in browser local storage)
  • Usage behavior:login times, console action logs, feature usage frequency, and resource consumption stats such as bandwidth
  • Preferences:interface preferences such as language choice (stored in local storage)
02

How we use information

We use your personal information only to the extent necessary for the following purposes:

  • Provision & operations:create accounts, deliver Mac mini M4 instances, process payments and renewals, and provide SSH / VNC access
  • Identity verification & security:verify login identity, detect anomalous access, and prevent fraud and abuse
  • Customer support:respond to tickets and email inquiries, troubleshoot connectivity or billing issues
  • Service notifications:send verification codes, billing reminders, expiry notices, maintenance announcements, and security alerts via transactional email
  • Product improvement:analyze access and performance data in aggregated or anonymized form to improve platform stability and user experience
  • Marketing:send product updates or offers we believe are relevant, unless you have opted out
  • Legal compliance:fulfill legal obligations, respond to lawful requests from authorities, and protect the legitimate rights of the platform and users
03

Information sharing & disclosure

We do not sell your personal information.We may share necessary information with third parties only in the following limited circumstances:

3.1 Service providers

To operate the Services, we may engage the following types of partners to process the minimum necessary information:

  • Payment processors (Stripe card payments, USDT on-chain collection services)
  • Email delivery providers (for verification codes and service notifications)
  • Self-hosted analytics (Matomo, data stored on infrastructure we control)
  • Data center and network infrastructure providers

We require these partners to process information only for the entrusted purpose and to implement appropriate security safeguards.

3.2 Legal requirements

When required by laws, legal process, or competent government authorities, we may disclose necessary information to comply with legal obligations or protect the safety and rights of users, the public, and the platform.

3.3 Business reorganization

In mergers, acquisitions, asset transfers, or similar transactions, user information may transfer as a business asset. We will notify you via site announcements within a reasonable period; the recipient must remain bound by this Policy to the same extent.

3.4 With your consent

With your explicit consent, we may share information with designated third parties for purposes you authorize.

04

Data retention periods

We retain your information only as long as necessary for the purposes described in this Policy, according to the following principles:

Information type Retention period
Basic account info (email, preferences, etc.) While account is active; up to 12 months after deletion
Transaction & billing records At least 7 years per financial and tax regulations
Access & security logs Typically 90 days for audit and troubleshooting
Tickets & support correspondence While account is active; 12 months after deletion
User data on rented devices Securely erased within 72 hours after service termination

Information requiring longer retention by law will be kept as legally required; after the retention period, we delete or anonymize the data.

05

Security safeguards

We apply industry-standard technical and organizational measures to protect your personal information from unauthorized access, disclosure, alteration, or destruction:

  • Encryption in transit:website and API communications use TLS encryption
  • Credential protection:account passwords stored with strong hashing—plaintext cannot be recovered
  • Access control:internal staff access operational data on least-privilege basis with operation auditing
  • Physical security:data centers with 24×7 physical access controls and redundant infrastructure
  • Device isolation:during rental your data resides on dedicated physical hardware; secure erase on return
  • Ongoing review:regular security assessments and vulnerability scans

No internet transmission or electronic storage method is 100% secure. If a data security incident may affect your rights, we will notify you in a timely manner per applicable law with an overview, potential impact, and measures taken.

06

Cookies & local storage

We use cookies and browser local storage to keep the Services running and improve your experience:

You can manage or clear cookies and local storage in browser settings, but login persistence and some features may be affected.

07

Your rights & choices

Under applicable data protection laws, you may have the following rights. Submit requests via ticket or email—we will respond within a reasonable period (typically within 30 days for rights requests):

Access & copy
request a copy of personal information we hold about you.
Correction & supplementation
request correction of inaccurate or incomplete information; some details can be edited in the console.
Deletion
request deletion of personal information after account closure; records we must retain by law (e.g., transactions) are excluded.
Opt out of marketing
use email unsubscribe links to stop promotional messages; billing and security notifications cannot be opted out.
Withdraw consent
where processing is based on your consent, you may withdraw anytime; withdrawal does not affect the lawfulness of prior processing.

While your account is active with outstanding orders, some deletion requests may not execute immediately so we can fulfill service contracts and legal obligations.

08

Protection of minors

The Services are not directed at minors under 18. We do not knowingly collect personal information from minors. If you are a guardian and believe a minor provided us information without consent, contact us via ticket or email—we will delete it promptly after verification.

09

Cross-border data transfers

SpinMac operates data centers in Singapore, Japan (Tokyo), South Korea (Seoul), Hong Kong, and US East. Your personal information may be stored or processed on servers outside your country or region, where data protection standards may differ.

We use data processing agreements, encrypted transmission, access controls, and other measures to protect cross-border transfers and comply with applicable cross-border data transfer requirements.

10

Third-party links

Our site may link to third-party websites or services (e.g., payment redirects, external docs). We are not responsible for their content, privacy practices, or security. Review their privacy policies before providing personal information.

11

Policy updates

We may revise this Policy from time to time. Updated versions will be posted on this page with a revised "Last updated" date. Formaterial changes(e.g., substantial changes to how we use information), we will notify you via registered email or in-platform notice.

Continued use after publication means you accept the revised Policy.If you disagree, stop using the Services and disable auto-renewal; for purchased services not yet expired, the prior Policy generally still applies unless law or our notice states otherwise.

12

Contact us

For questions, complaints about this Policy, or to exercise data rights, contact us:

Privacy email:[email protected](please include "Privacy" in the subject)
Ticket system:Log inConsolesubmit a ticket (recommended for tracking progress)
Response time:general inquiries within 2 business days; data rights requests processed within 30 days

Want to know the usage rules?

The Terms of Service cover account obligations, billing and renewals, data responsibilities, and dispute resolution.