Current version

Privacy Policy & Personal Data Processing

This policy explains what information ZoomMini collects when providing cloud Mac rentals, order management, remote access, and support services, how that information is used, how long it is retained, and how you can exercise your rights.

Applies to the ZoomMini website, console, enquiry process, and support services Effective immediately upon publication and replaces all previous versions
01

Scope

This policy applies when you visit the ZoomMini website, create or manage a console account, choose a cloud Mac plan, view orders and billing details, submit a support ticket, or prepare and send an enquiry through the contact page.

ZoomMini provides dedicated physical machines on Apple Silicon physical nodes, not virtual machines. To deliver devices, assign nodes, manage rental periods, enable remote connections, and resolve faults, we need to associate your account, order, and the status of the relevant device where necessary.

This policy does not change your control over your workloads

You are responsible for managing the code, build artifacts, repository credentials, test data, and application configuration that you deploy to a dedicated cloud Mac. Except where necessary to handle a support request, respond to a security incident, or comply with a legal obligation, ZoomMini does not access this data for the purpose of analysing customer code.

The enquiry generator on the contact page helps organise an email subject and message. The information enters the support process only after you send it through your system email application. Do not include passwords, private keys, complete payment credentials, or unredacted sensitive logs in an enquiry or support ticket.

02

Information we collect

We limit collection to information necessary to provide the service, protect account security, and handle requests. Different features involve different data, and unused features do not generate records in the corresponding categories.

Account & contact details

Includes your email address, account identifier, authentication status, language preference, and any name, team, or contact details you voluntarily include in an enquiry email or support ticket.

Order & billing metadata

Includes the order identifier, ZoomMini M4 Core or ZoomMini M4 Plus model, rental period, node, add-ons, USD amount, payment status, and reconciliation references.

Node & device status

Includes the selected node, device identifier, provisioning progress, connection availability, rental start and end details, restart status, and operational events used to troubleshoot delivery issues.

Support & enquiry records

Includes ticket subjects, issue categories, reproduction steps, redacted logs, attachments, response history, and verification results needed to confirm the requester's relationship to an order.

Access & activity logs

Includes access times, request results, browser and device type, network address, session identifier, and records of account sign-ins, order management, and ticket activity.

Essential security signals

Includes unusual sign-in patterns, repeated failed requests, permission changes, high-risk actions, and event indicators that could affect the security of an account, console, or physical node.

Before submitting logs or screenshots, remove tokens, private keys, passwords, complete payment credentials, and personal information unrelated to the issue. ZoomMini may ask for an order identifier, the relevant time, or node details, but will not ask you to send secrets by email.

03

Why we process this information

ZoomMini does not use collected information for purposes unrelated to the service. Processing is focused on delivery, management, security, support, and necessary compliance.

Provide and manage the service
Create accounts, display the two available models, record node and rental-period selections, configure dedicated physical machines, and provide device status and remote connection details.
Confirm orders and payments
Verify order amounts, payment status, add-ons, billing records, and service periods, and process information needed for renewals, refund checks, or payment disputes.
Secure accounts and nodes
Identify unusual sign-ins, unauthorised access, misuse of permissions, and activity that could compromise service stability; restrict risky actions and retain necessary investigation records.
Respond to support requests
Link tickets with orders, nodes, and device status, reproduce connection or build issues, record troubleshooting steps, and report outcomes to the requester.
Meet legal obligations
Retain necessary transaction and security records, respond to requests with a valid legal basis, and handle audits, dispute resolution, and compliance checks.
Improve site reliability
Use aggregated error, performance, and operational results to locate points of failure and improve ordering, delivery, console, and support workflows, without creating unrelated user profiles.

The legal basis depends on the specific context and may include fulfilling an order, responding to your request, protecting the legitimate interests of the account and service, obtaining consent, or complying with applicable legal obligations. Where processing relies on consent, you may withdraw it as permitted by applicable rules; withdrawal does not affect the lawfulness of processing carried out before withdrawal.

04

How payment data is handled

ZoomMini orders are settled in US dollars (USD). We support USDT-TRC20, as well as Visa, Mastercard, and Amex through Stripe. The payment gateways available for a specific transaction are indicated during checkout.

During payment, the data required for the transaction is handled through the relevant payment process. ZoomMini retains only the information necessary to deliver the service, confirm payment, reconcile records, handle disputes, and meet compliance obligations, such as the order identifier, amount, currency, payment method category, transaction status, and necessary transaction references.

ZoomMini retains

  • The link between orders and payment status
  • USD amounts, service periods, and add-ons
  • References needed for reconciliation, refund checks, or disputes
  • Transaction records required by applicable law

Do not submit through support channels

  • Full card numbers or security codes
  • Wallet private keys, recovery phrases, or signing secrets
  • Account passwords or SSH private keys
  • Unredacted screenshots of payment pages

If your payment confirmation does not match, provide the order identifier, payment time, amount, and a redacted transaction reference. The support team will verify the records only as needed and will not ask for complete payment credentials.

05

Retention & deletion

We do not retain information indefinitely simply because it might be useful in the future. Retention periods are determined by service fulfilment, account status, dispute handling, security investigations, and applicable legal requirements, with the shortest reasonable period needed to fulfil the relevant purpose as the guiding principle.

Key information categories and retention criteria
Information category Primary retention basis After the period ends
Account & contact details While the account is active, and for as long as needed after closure to handle outstanding orders, requests, or disputes. Deleted, de-identified, or retained on a restricted basis where required by law.
Orders & billing records For as long as needed to complete fulfilment, reconcile records, verify refunds, maintain financial records, and meet legal obligations. Non-essential fields are deleted, with only the minimum records required by law retained.
Device & node status For as long as needed to manage the rental period, confirm delivery, troubleshoot faults, and handle related disputes. Device associations unrelated to active services are deleted or converted into aggregated data that does not identify individuals.
Support records For as long as needed to handle requests, review outcomes, prevent recurring faults, and resolve related disputes. Attachments and non-essential details are deleted, or historical records are de-identified.
Access & security logs For as long as needed to detect anomalies, investigate security incidents, protect accounts, and meet necessary audit requirements. Logs are deleted on a rolling basis, aggregated, or de-identified, except where the law requires retention.

Deletion may be paused when information relates to an unresolved order, payment dispute, security investigation, rights request, or legally required retention. Once the reason for the restriction ends, we will resume the deletion or de-identification process.

Before your rental period ends, you are responsible for moving your code, build artifacts, configuration, and other workload data off the cloud Mac. Deleting an account does not mean that data migration from the device has been completed, and it does not replace your responsibility to maintain backups.

06

Your rights and contact options

To the extent permitted by applicable rules, you may request access to relevant personal information held by ZoomMini, ask us to correct inaccurate information, delete information that is no longer necessary, restrict specific processing, or explain how your information is processed.

Requests you can make

  • Confirm whether information about you is being processed
  • Access applicable information categories and processing purposes
  • Correct inaccurate or incomplete account details
  • Delete information retained beyond the necessary period
  • Restrict or object to processing where applicable
  • Ask about cross-border processing and recipient categories

Please include

  • The email address associated with your account
  • The request type and information covered
  • The relevant order or ticket identifier
  • The necessary time range to help locate the records
  • Information that can verify your relationship to the account
  • How you would like to receive a response

To prevent someone else from impersonating you to access or delete your information, we will carry out verification proportionate to the risk of the request. Verification is used only to confirm the relationship between the requester and the relevant account, order, or record. We may ask for additional information when verification is not possible, the request is unclear, or another person's rights are involved.

Privacy request

Use the designated support channels

You can prepare a privacy request through the contact page or email support@zoommini.com. Existing customers can sign in to the console to submit a support ticket and check its status.

Processing time depends on the scope of the request, verification complexity, the number of records, and whether unresolved orders, security incidents, or legal retention obligations are involved. We will use the original request channel to explain progress, any additional information needed, or the outcome.

07

Cross-border processing & policy updates

ZoomMini provides services across different node regions. When you select a specific node, connect to a device remotely, process an order, or request technical support, your account, order, device-status, and support records may need to be processed between the relevant regions where necessary.

Cross-border processing is carried out to fulfil orders, provide connectivity, protect security, and respond to support requests, and is limited to the information required for the relevant workflow. We apply access controls, transfer safeguards, permission restrictions, logging, and necessary contractual measures based on the data type, processing purpose, and recipient's role.

Service delivery may involve processors responsible for hosting, payments, communications, security, or infrastructure. Their processing is limited to the relevant task and they may not use information for purposes unrelated to the services entrusted to them. ZoomMini reviews necessary data protection arrangements based on risk and applicable requirements.

Material updates

If the information categories, processing purposes, sharing scope, or rights channels change materially, we will notify you through a prominent notice on the site, a console notification, or another method consistent with your existing service relationship.

Routine changes

Clarifications, page structure improvements, or updates that do not materially change processing will be published on this page. You can review the current version before continuing to use the service.

Applicable rules

This policy is interpreted and enforced under the laws of the jurisdiction where the platform operator is established. Any related dispute will be handled by a court with jurisdiction in that jurisdiction.

If you have questions about cross-border processing, recipient categories, retention rules, or policy changes, submit specific questions through the contact page or a console ticket. Include the relevant order, node, information category, and concern so that we can route your request directly for review.

Need to review your data processing

Submit a clear, verifiable privacy request

Include your account email, request type, and the relevant order or ticket identifier. Do not send passwords, private keys, or complete payment credentials.