Policy overview
SpinMac ("we") treats user privacy and data security as foundational to platform operations. This Privacy Policy ("Policy") applies to all services you access, register for, or use via spinmac.com and its subdomains (collectively, the "Services"), and explains how we handle personal information relating to you.
By continuing to use the Services, you have read, understood, and agree to this Policy.If you disagree with any provision, please stop using the Services. This Policy, together with theTerms of Service, forms the complete agreement between you and SpinMac; where they conflict on personal data processing, this Policy prevails.
Business data you store, run, or transmit on rented devices (e.g., source code, build artifacts, database contents) is primarily managed by you as the data controller; this Policy focuses on account, transaction, and access information collected on the platform side.
Information we collect
1.1 Information you provide
- Account details:email submitted at registration, login password (stored as encrypted hash—we cannot read plaintext), and other details you voluntarily provide
- Orders & configuration:selected data center node, rental period, SSD expansion or Thunderbolt 5 clustering add-ons, and order notes
- Payment-related:transaction amount, payment status, order ID, and redacted billing summary; full card numbers or on-chain wallet private keys are handled by third parties such as Stripe and USDT payment channels—we do not store them
- Support communications:issue descriptions, attachments, and correspondence submitted via tickets or email
1.2 Automatically collected information
- Access logs:IP address, request time, access path, browser type, operating system, and referrer page
- Client identifiers:device identifiers generated for security verification and anomaly detection (SSAID, stored in browser local storage)
- Usage behavior:login times, console action logs, feature usage frequency, and resource consumption stats such as bandwidth
- Preferences:interface preferences such as language choice (stored in local storage)
How we use information
We use your personal information only to the extent necessary for the following purposes:
- Provision & operations:create accounts, deliver Mac mini M4 instances, process payments and renewals, and provide SSH / VNC access
- Identity verification & security:verify login identity, detect anomalous access, and prevent fraud and abuse
- Customer support:respond to tickets and email inquiries, troubleshoot connectivity or billing issues
- Service notifications:send verification codes, billing reminders, expiry notices, maintenance announcements, and security alerts via transactional email
- Product improvement:analyze access and performance data in aggregated or anonymized form to improve platform stability and user experience
- Marketing:send product updates or offers we believe are relevant, unless you have opted out
- Legal compliance:fulfill legal obligations, respond to lawful requests from authorities, and protect the legitimate rights of the platform and users
Information sharing & disclosure
We do not sell your personal information.We may share necessary information with third parties only in the following limited circumstances:
3.1 Service providers
To operate the Services, we may engage the following types of partners to process the minimum necessary information:
- Payment processors (Stripe card payments, USDT on-chain collection services)
- Email delivery providers (for verification codes and service notifications)
- Self-hosted analytics (Matomo, data stored on infrastructure we control)
- Data center and network infrastructure providers
We require these partners to process information only for the entrusted purpose and to implement appropriate security safeguards.
3.2 Legal requirements
When required by laws, legal process, or competent government authorities, we may disclose necessary information to comply with legal obligations or protect the safety and rights of users, the public, and the platform.
3.3 Business reorganization
In mergers, acquisitions, asset transfers, or similar transactions, user information may transfer as a business asset. We will notify you via site announcements within a reasonable period; the recipient must remain bound by this Policy to the same extent.
3.4 With your consent
With your explicit consent, we may share information with designated third parties for purposes you authorize.
Data retention periods
We retain your information only as long as necessary for the purposes described in this Policy, according to the following principles:
| Information type | Retention period |
|---|---|
| Basic account info (email, preferences, etc.) | While account is active; up to 12 months after deletion |
| Transaction & billing records | At least 7 years per financial and tax regulations |
| Access & security logs | Typically 90 days for audit and troubleshooting |
| Tickets & support correspondence | While account is active; 12 months after deletion |
| User data on rented devices | Securely erased within 72 hours after service termination |
Information requiring longer retention by law will be kept as legally required; after the retention period, we delete or anonymize the data.
Security safeguards
We apply industry-standard technical and organizational measures to protect your personal information from unauthorized access, disclosure, alteration, or destruction:
- Encryption in transit:website and API communications use TLS encryption
- Credential protection:account passwords stored with strong hashing—plaintext cannot be recovered
- Access control:internal staff access operational data on least-privilege basis with operation auditing
- Physical security:data centers with 24×7 physical access controls and redundant infrastructure
- Device isolation:during rental your data resides on dedicated physical hardware; secure erase on return
- Ongoing review:regular security assessments and vulnerability scans
No internet transmission or electronic storage method is 100% secure. If a data security incident may affect your rights, we will notify you in a timely manner per applicable law with an overview, potential impact, and measures taken.
Cookies & local storage
We use cookies and browser local storage to keep the Services running and improve your experience:
You can manage or clear cookies and local storage in browser settings, but login persistence and some features may be affected.
Your rights & choices
Under applicable data protection laws, you may have the following rights. Submit requests via ticket or email—we will respond within a reasonable period (typically within 30 days for rights requests):
While your account is active with outstanding orders, some deletion requests may not execute immediately so we can fulfill service contracts and legal obligations.
Protection of minors
The Services are not directed at minors under 18. We do not knowingly collect personal information from minors. If you are a guardian and believe a minor provided us information without consent, contact us via ticket or email—we will delete it promptly after verification.
Cross-border data transfers
SpinMac operates data centers in Singapore, Japan (Tokyo), South Korea (Seoul), Hong Kong, and US East. Your personal information may be stored or processed on servers outside your country or region, where data protection standards may differ.
We use data processing agreements, encrypted transmission, access controls, and other measures to protect cross-border transfers and comply with applicable cross-border data transfer requirements.
Third-party links
Our site may link to third-party websites or services (e.g., payment redirects, external docs). We are not responsible for their content, privacy practices, or security. Review their privacy policies before providing personal information.
Policy updates
We may revise this Policy from time to time. Updated versions will be posted on this page with a revised "Last updated" date. Formaterial changes(e.g., substantial changes to how we use information), we will notify you via registered email or in-platform notice.
Continued use after publication means you accept the revised Policy.If you disagree, stop using the Services and disable auto-renewal; for purchased services not yet expired, the prior Policy generally still applies unless law or our notice states otherwise.
Contact us
For questions, complaints about this Policy, or to exercise data rights, contact us: