Scope and version
Which interactions does this cover?
This notice applies when you visit oakvm.com, use the OakVM console, create or manage an account, choose a cloud Mac plan, place an order, receive a dedicated Apple Silicon physical node, or contact us through support email or a console ticket.
Project files, build caches, certificates, provisioning profiles, keys, and build artifacts on your node are organized and managed by you. Renting a node does not give us ownership of this content; we process related data only when necessary to deliver the service, handle support materials you explicitly submit, protect service security, or meet legal obligations, and only within a limited scope.
Website and console
This includes page views, language settings, session state, account actions, and technical records used to identify anomalous requests.
Orders and nodes
This includes the selected model, rental term, region, add-ons, delivery status, task ID, and necessary records related to node access.
Support interactions
This includes issue descriptions, sanitized logs, attachments, handling records, and information needed to verify the requester’s identity.
Current version:This notice takes effect on August 22, 2026, and replaces the previous notice covering the same processing scope. The effective date at the top of the page identifies the version you are reading.
Data inventory
What data do we collect?
We collect only the minimum data needed to complete specific service steps. Because users access different features, not every category below will be generated for every user.
- Account information
- Email address used for registration, sign-in, and contact; account identifier, verification status, security settings, and account activity records. We do not ask you to submit node credentials on public pages.
- Order records
- The selected OakVM M4 or OakVM M4 Pro, rental term, node region, additional storage, Thunderbolt 5 parallel-connection option, order status, amount, creation time, and task ID.
- Payment status
- Payment method category, currency, amount due, payment status, transaction identifier, and limited information needed for reconciliation. OakVM does not store full card numbers or security codes.
- Device and access logs
- IP address, browser and device type, request time, page or API path, session identifier, sign-in result, error code, and request context needed for security analysis.
- Node activity records
- Node region, device identifier, delivery and return status, credential-generation status, connection events, resource anomalies, and technical records related to task isolation.
- Support requests
- Issue description, time of occurrence, task ID, node region, sanitized logs or screenshots you provide, and reply, escalation, resolution, and closure records.
- Information you choose to submit
- Team size, target systems, concurrent tasks, Xcode requirements, preferred region, and other context you choose to provide during purchasing or migration consultations.
Processing purposes
How data enters the service process
We do not arbitrarily extend the use of collected data to purposes unrelated to the original context. Every processing activity must address a specific need connected with service delivery, security, a user request, or a legal obligation.
Account and identity verification
Create accounts, send verification messages, maintain sign-in sessions, perform security checks, and verify the requester’s identity when changing a password or submitting a privacy request.
Orders and node delivery
Confirm the model, rental term, region, and add-ons; process payment status; assign a physical node; and generate the information needed for the first connection.
Troubleshooting
Correlate the task ID, node status, error time, and sanitized logs to determine whether an issue involves the account, network, disk, Xcode, or signing workflow.
Security
Identify suspicious sign-ins, automated abuse, unauthorized access, destructive scanning, and behavior that may affect node or network stability.
Service improvement
Analyze aggregated error types, delivery steps, and support topics to improve page explanations, node delivery workflows, and troubleshooting paths.
Legal compliance
Retain necessary order, transaction, and security records where required; respond to duly authorized requests; and maintain the audit trail needed for compliance.
When processing is necessary to fulfill an order, protect account and node security, respond to a user request, or comply with the laws of the jurisdiction where the platform operator is based, we limit data to what is needed for that purpose. If a materially different new purpose arises, we will provide appropriate notice before beginning the relevant processing.
Payment data
Payment processing retains only what is needed to complete an order
OakVM orders are settled exclusively in USD. Available payment methods are limited to USDT-TRC20 and Visa / Mastercard / Amex (via Stripe). Actual gateway availability is determined by the result returned by the console at checkout.
- We record
- Order amount, USD currency, payment method category, payment status, transaction identifier, order relationship, and completion time.
- We do not store
- Full card numbers, security codes, or complete financial credentials that OakVM is not required to hold during payment processing.
- Why we keep these records
- Confirm orders, reconcile payments, identify duplicate payments, answer payment-status questions, and meet necessary financial and compliance obligations.
Payment service providers receive the data necessary for the payment-processing responsibilities they perform. We share only the fields needed to initiate the transaction, return results, perform risk controls, and reconcile payments; payment processing does not give them access to project content on nodes.
Lifecycle
Retention, access controls, and end-of-life handling
There is no single fixed retention period for all data. We assess retention separately based on whether an account remains active, obligations for orders and transactions, security risks, support-request status, and dispute-handling needs, then delete, anonymize, or restrictively archive data when its purpose is complete.
| Data category | Retention basis | Access scope | End-of-life handling |
|---|---|---|---|
| Account information | Needed while the account is active and for identity verification, security, and privacy-rights requests | Accessed by authorized account and support personnel according to their roles | Deleted or de-identified after account closure and necessary verification; records legally required to remain are placed in restricted archives |
| Order and payment records | Needed to fulfill orders, reconcile payments, handle disputes, and meet applicable financial obligations | Accessed by order, finance, and compliance personnel under least-privilege controls | Deleted or de-identified after legal or operational retention periods end, or retained as aggregated data that does not directly identify individuals |
| Security and access logs | Needed to detect suspicious sign-ins, investigate security incidents, and protect nodes and networks | Limited to personnel responsible for security, platform operations, and incident response | Rotated and deleted after the risk window ends and no continuing investigation is needed; incident-related records are retained restrictively according to case status |
| Support records | Needed to resolve requests, preserve handling context, review service outcomes, and avoid repeated troubleshooting | Accessed as needed by support and engineering personnel handling the relevant ticket | Attachments are deleted or sanitized after the request is closed and the necessary review period ends; necessary conclusions remain as restricted records |
| Node delivery records | Needed to complete assignment, connection checks, task isolation, return, and anomaly investigation | Accessed by delivery, platform operations, and security personnel within the task scope | Cleared after the rental ends and return verification is complete; security-incident records are handled under the applicable incident rules |
How safeguards work in practice
- Least privilege:Internal access is assigned by role; the ability to access a system does not automatically grant permission to view every account or support material.
- Transmission protection:The website, console, and service interfaces transmit data over encrypted connections, reducing the risk of interception or tampering in transit.
- Task isolation:Orders, nodes, and support records are linked by identifiers; troubleshooting personnel should access only the data needed to complete the current task.
- Log controls:Security logs are used to identify anomalies and reconstruct incidents, not to publicly display user activity.
- End-of-life handling:Deletion workflows cover online records, attachments, and logs entering the rotation cycle; records that must be retained by law are subject to restricted use and access.
Every safeguard also depends on your cooperation. Keep console and node credentials secure, limit team-member access, and maintain separate backup and offboarding-cleanup procedures for code, certificates, provisioning profiles, keys, and build artifacts.
Processing boundaries
Service providers and cross-regional processing
To operate the website, verify accounts, host physical nodes, settle orders, and respond to support requests, OakVM may use service providers that perform specific functions. These providers may process data only as needed for their assigned duties and must be bound by contractual, confidentiality, security, and purpose limitations.
Delivery and hosting
Process node region, device identifiers, assignment status, and technical information needed for dedicated physical node delivery, operational protection, and return.
Payments and reconciliation
Process order amount, currency, payment status, and transaction identifier to confirm and reconcile USDT-TRC20 or card transactions.
Support and security
Process task IDs, issue context, sanitized logs, and security-incident information to troubleshoot problems, respond to anomalies, and protect accounts and nodes.
When you choose a node in Singapore, Japan (Tokyo), South Korea (Seoul), Hong Kong, the US East, or the US West, necessary data related to node assignment, connection, and support may be processed in the relevant region or in the region where support collaboration takes place. Cross-regional processing does not change the purpose of the data, and selecting a node does not automatically mean you consent to unrelated uses.
When cross-regional transfers are required, we apply appropriate safeguards based on the data category, the recipient’s role, and applicable requirements, including access restrictions, encrypted transmission, contractual controls, record reviews, and other suitable measures. If a service provider no longer performs the relevant function, we stop providing data needed for further processing and handle the materials it holds as agreed.
Request process
How to exercise your rights to access, correct, delete, restrict processing, and export data
To the extent permitted by applicable rules, you may ask us to confirm whether we process data about you and request an access copy, correction of inaccurate information, deletion of data no longer needed, restriction of specific processing, or export of available account and order data.
-
01
Choose a request channel
Email support@oakvm.com from the email address associated with your account, or sign in to the console and submit a ticket. If you have an account, a console ticket is usually easier for verifying its connection to your account and orders.
-
02
Describe the scope
State the request type, associated account email, order or task ID, data involved, and desired outcome. Do not include passwords, private keys, or complete payment credentials in an email or ticket.
-
03
Complete identity verification
To prevent impersonation, we may verify your identity using account status, email verification, order information, or another method proportionate to the risk. We collect only the information needed for the current request.
-
04
Receive the result
We will explain the actions taken, the data we can provide, and any information that cannot be immediately deleted or disclosed because of order-record obligations, security incidents, other people’s rights, or legal obligations.
A deletion request does not necessarily remove every record immediately. Data still needed to fulfill an incomplete order, resolve a payment dispute, protect account security, or meet a legal obligation may be retained with restricted use; deletion or de-identification will occur when the relevant basis ends.
Notice and contact
How we update this notice and how to contact us
We may update this notice when the service scope, data categories, processing purposes, service-provider responsibilities, or applicable requirements change. New versions will show an effective date on this page. If a change materially affects user rights or how data is used, we will provide prominent notice through an in-account message, contact details associated with the account, or another appropriate method.
An update does not automatically extend the use of collected data to purposes unrelated to the original purpose. If new processing requires additional notice or a user choice, we will complete the relevant steps before starting it.
Contact us by support email
Best for cases where you cannot sign in, need to clarify the request scope first, or are submitting a formal privacy inquiry on behalf of an organization.
Email support@oakvm.comSubmit a ticket in the console
Best for requests related to an existing account, order, node, or task ID, reducing back-and-forth verification of identity and order relationships.
Open the consoleQuestions about this notice, privacy-rights requests, or formal communications may be submitted through either channel above. Disputes concerning privacy processing are governed by the laws of the jurisdiction where the platform operator is based and will be handled by courts with jurisdiction in that jurisdiction.