Data Processing Overview · Current Version

How your information enters, moves through, and leaves OnceMac.

This notice does more than list data categories. It explains the service stage, reason for use, retention decision, and request path for each type of information. Our core principle is to process only what is needed to deliver cloud Macs, secure accounts and nodes, complete transactions, and provide support.

Scope
Website, console, orders, and support communications
Request channels
Support email or console ticket
Processing principles
Clear purpose, necessary scope, controlled access
01

Where Information Comes From

Scope

This notice applies when you visit oncemac.com, review cloud Mac plans, prepare an inquiry through the contact page, sign in to the console, create or manage an order, use a dedicated physical node, or communicate with our support team by email or console ticket, in each case involving necessary processing of personal information.

“Personal information” means information that directly identifies you or can be linked to you when combined with other reasonably available information. A device model, browser type, or node log may not identify a specific person on its own, but once linked to an account, order, IP address, or support record, it is protected under applicable rules.

Public Website

This includes page visits, language preferences, basic security logs, and information you provide when you actively select a contact option.

Console and Orders

This includes account verification, configuration choices, node region, rental term, payment status, billing records, and renewal actions.

Node Delivery and Operation

This includes node identifiers, connection records, security events, and operational diagnostic information needed to deliver a dedicated physical node.

Support Communications

This includes emails, tickets, incident timelines, redacted logs, and follow-up communications used to identify and resolve issues.

Content Outside Our Direct Control

You decide how to handle code, build artifacts, repository content, and business data that you deploy inside your cloud Mac. OnceMac accesses such information only when necessary to deliver the service, troubleshoot issues, respond to security events, or meet applicable obligations, and only with authorization and within the minimum required scope.

02

By Service Stage

What Information We Collect

The data categories we collect depend on the features you use. Simply browsing public pages does not automatically create a complete account profile; relevant fields enter the applicable process only when you register, place an order, manage a node, or request support.

Account and Contact Information
Name or preferred form of address, work email, verification results, account identifier, language preference, and records necessary to secure account access. Passwords are handled securely through the authentication process, and support staff will never request them by regular email.
Order Information
Order number, selected OnceMac configuration, rental term, node region, storage add-ons, payment method category, payment and refund status, and information needed for billing. We do not need to retain complete payment credentials in support records.
Device and Access Logs
Access time, IP address, browser and device type, sign-in result, session security identifier, request path, anomalous frequency, and audit events needed for node connections and management actions. This information helps identify unauthorized access and investigate service issues.
Support Records
Ticket subject, issue description, order number, node region, incident time, command output, redacted logs, troubleshooting steps, and communication outcomes. Before submitting, remove private keys, access tokens, signing materials, and business data unrelated to the issue.
Content You Choose to Provide
Your team size, expected concurrent build volume, Xcode version, storage needs, target user regions, and desired activation date in pre-sales inquiries, plus any explanations and supporting materials you choose to provide for partnership or privacy requests.

We may also generate derived information for technical security purposes, such as risk markers for repeated failed sign-ins, an activity trail for a session, or an incident reference number. This information is used only for security, auditing, and troubleshooting activities compatible with the original purpose, not to build profiles unrelated to the service.

03

A Necessary Basis for Every Purpose

Purposes and Legal Bases

We do not retain information simply because it is technically possible to collect it. Each processing activity must have a clear purpose and be based on fulfilling an order, taking pre-contractual steps you request, protecting service security, meeting legal obligations, or another applicable legal basis.

Providing and Managing the Service

Create accounts, confirm configurations, process orders, deliver physical nodes, display connection details, and manage rental terms and add-ons. The primary basis is fulfilling the service order you confirmed, or providing configuration advice at your request before purchase.

Protecting Account and Node Security

Verify sign-ins, detect unusual access, prevent abuse, track high-risk management actions, and restore affected access. Processing is limited to what is necessary to protect your account, the platform, and other customers.

Providing Customer Support

Link orders and tickets, reproduce issues, check connection paths, explain logs, and document resolution steps. The basis may be fulfilling our service obligations or responding to a technical or privacy request you initiate.

Retaining Transaction Records

Verify payment status, create billing records, handle disputes, and complete financial reconciliation. These records are processed to fulfill contractual, financial management, and applicable legal obligations.

Analyzing and Resolving Issues

Aggregate error events, compare node health, locate network or configuration problems, and verify that fixes work. When aggregated or de-identified data is sufficient, we do not additionally use identifiable information.

Meeting Legal Obligations

Respond to legally authorized requests, retain necessary transaction evidence, process rights requests, and record security events. We reasonably verify the scope, identity, and authority of a request before disclosure.

When processing requires your consent, we explain the specific purpose before collection and provide a way to withdraw consent. Withdrawal does not affect processing completed lawfully before withdrawal, nor does it prevent us from retaining necessary order, security, or compliance records on another applicable basis.

04

Permission by Function, Not Open Access to the Entire Database

Service Providers and International Processing

To operate the website, complete payments, send necessary emails, monitor node health, and respond to support requests, we may allow vetted service providers to process limited information. Sharing is restricted to the minimum fields needed for the specified function, with their use controlled through contracts, permissions, and access logs.

Hosting and Infrastructure

Hosts the website, console, database, and necessary logs; the processing scope depends on the system components it operates.

Payment Processing

Processes order status and necessary transaction information for USDT-TRC20 or Visa, Mastercard, and Amex through Stripe. Available gateways are determined by the console.

Email and Notifications

Sends verification codes, order updates, security alerts, and support replies. Service email lists are not used for unrelated marketing.

Monitoring and Support

Records service availability, error events, and ticket handling, with access limited to personnel responsible for the relevant functions.

Because nodes, team members, or service providers may be located in different jurisdictions, information may be transferred internationally or accessed remotely. When this occurs, we consider the data category, destination, recipient responsibilities, and applicable requirements, and use contractual controls, transfer safeguards, access minimization, log reviews, or other available protections.

If you need information about recipient categories related to your data or applicable safeguards, you may submit a request through the channels listed on this page. For system security and other individuals’ privacy, our response may describe categories, functions, and safeguards rather than disclose internal architecture details that could increase security risks.

Working with Partners Does Not Change the Purpose of Use

Service providers may process data only for agreed functions and may not use order, support, or node access data for unrelated advertising, resale, or user profiling.

05

Determined by the End of the Purpose

Retention and Deletion

We do not assign one unverified fixed period to all information. Retention is assessed separately based on whether the service relationship continues, whether the data is still needed for its original purpose, whether security or transaction disputes exist, and whether applicable financial, audit, or legal retention obligations apply.

Retention Decisions and Deletion Triggers by Information Category
Information Category Primary Retention Considerations Deletion or De-identification Conditions
Account Information The account remains active, has an active order, or requires ongoing identity and security management. After the account is closed and there are no open orders, disputes, security investigations, or legal retention requirements, we delete or de-identify non-essential fields.
Orders and Transaction Records Used to fulfill orders, reconcile accounts, process refunds, resolve disputes, and meet applicable recordkeeping obligations. After the relevant obligations end, we remove contact fields that are no longer necessary; transaction records that must be retained are limited to authorized purposes.
Support Tickets The issue remains unresolved, similar incidents require tracking, or the outcome of order-related support must be documented. After the support purpose ends, we delete unrelated attachments and sensitive content; necessary records may be de-identified for quality analysis.
Security and Access Logs Used to detect anomalies, investigate incidents, protect accounts and nodes, and verify that controls are effective. After risk monitoring and investigation needs end, logs are deleted, rotated, or aggregated; incident evidence is retained separately under applicable requirements.
Privacy Request Records Used to verify requests, demonstrate how they were handled, respond to follow-up inquiries, and prevent disclosure to the wrong person. After request-related responsibilities and applicable recordkeeping obligations end, we delete identification materials and communication attachments that are no longer necessary.

Deletion may require clearing active systems, rotating backups, and updating audit records. Information in restricted backups is not used for routine business before restoration; if restored, it remains subject to the original deletion and access restrictions.

06

Locate the Data First, Then Verify the Requester

What You Can Request

Under the rules applicable to you, you may request access, correction, deletion, restriction of processing, object to specific processing, or receive a transferable copy of your data. Whether a right applies and its scope depend on the request, processing basis, others’ rights, security requirements, and legal retention obligations.

Access

Confirm whether we process information about you and receive an explanation of the data categories, purposes, recipient categories, and retention considerations.

Correction

Update inaccurate or incomplete contact or account information, or identify factual errors in order and support records.

Deletion

Request deletion of information that is no longer necessary or lacks a basis for continued processing, although order, dispute, security, or legal records may need to be retained.

Restriction of Processing

During a dispute about accuracy, processing basis, or an objection, request temporary limits on non-essential use while retaining records needed to resolve the request.

Object

Explain the specific reasons for objecting to a processing activity, and we will assess whether a valid basis and necessity for continuing exist.

Receive a Data Copy

Where applicable, obtain a copy of data you provided that is associated with your account or order in a commonly used, machine-readable format.

Minimum Information to Include in a Request

  1. Request type

    Clearly state whether you are requesting access, correction, deletion, restriction, objection, or a data copy to avoid repeated clarification.

  2. Account Locator

    Use the email associated with your account and provide the order number when relevant; do not send passwords, complete keys, or access tokens.

  3. Scope and Time Period

    Explain whether the request concerns website access, your account, an order, node logs, or support records, and give an approximate date or period.

  4. Required Identity Verification

    We may verify your identity through account verification, email confirmation, or another method proportionate to the request’s risk, to prevent disclosure or deletion of data for the wrong person.

If a request is clearly repetitive, overly broad, or could affect others’ rights, we will first explain what needs to be narrowed. If we cannot fulfill the request as submitted, we will explain the limitation and any feasible alternative.

07

Security Measures and Request Channels

Security, Contact, and Notice Updates

OnceMac applies access controls, transfer protections, log reviews, and incident response based on data sensitivity, system roles, and foreseeable risks. Security measures evolve with system architecture, threats, and applicable requirements rather than relying on a single control.

Access Controls

Permissions are granted by role, visibility for support, billing, and system administration roles is limited, and sensitive actions are audited.

Transfer Protection

We use transfer protections for the website, console, and necessary service connections, and minimize the exchange of sensitive technical materials through regular email.

Log Review

We record sign-ins, permission changes, and key administrative events, check for unusual patterns based on risk, and restrict log access and export.

Incident Response

When a suspected incident is identified, we confirm it, contain its impact, restore service, and review the event, providing required notice to affected individuals where applicable.

Privacy requests, security reports, business matters, and general support all use the same public email address support@oncemac.com. If you already have an account or order, you can also sign in to theconsole to submit a ticket, so your request can be securely linked to your account or order.

If this notice changes materially, we will explain the updates through the website, console, or a notification method appropriate to our service relationship. If the basis, purpose, or scope of processing changes, we will provide additional information or obtain any authorization required under applicable rules.

The scope of rights related to this notice is determined under the laws of the jurisdiction where the platform operator is established. Disputes that cannot be resolved through communication will be handled by a court with jurisdiction in that jurisdiction under applicable procedures.

Privacy Requests and Account Issues

Tell us the request type, account email, and relevant scope, and we will start with information that can be verified.

Do not attach passwords, complete keys, access tokens, or unredacted build logs to regular email. For urgent account issues related to an existing order, submit a console ticket first.