Scope
This policy applies when you visit the ZoomMini website, create or manage a console account, choose a cloud Mac plan, view orders and billing details, submit a support ticket, or prepare and send an enquiry through the contact page.
ZoomMini provides dedicated physical machines on Apple Silicon physical nodes, not virtual machines. To deliver devices, assign nodes, manage rental periods, enable remote connections, and resolve faults, we need to associate your account, order, and the status of the relevant device where necessary.
This policy does not change your control over your workloads
You are responsible for managing the code, build artifacts, repository credentials, test data, and application configuration that you deploy to a dedicated cloud Mac. Except where necessary to handle a support request, respond to a security incident, or comply with a legal obligation, ZoomMini does not access this data for the purpose of analysing customer code.
The enquiry generator on the contact page helps organise an email subject and message. The information enters the support process only after you send it through your system email application. Do not include passwords, private keys, complete payment credentials, or unredacted sensitive logs in an enquiry or support ticket.
Information we collect
We limit collection to information necessary to provide the service, protect account security, and handle requests. Different features involve different data, and unused features do not generate records in the corresponding categories.
Account & contact details
Includes your email address, account identifier, authentication status, language preference, and any name, team, or contact details you voluntarily include in an enquiry email or support ticket.
Order & billing metadata
Includes the order identifier, ZoomMini M4 Core or ZoomMini M4 Plus model, rental period, node, add-ons, USD amount, payment status, and reconciliation references.
Node & device status
Includes the selected node, device identifier, provisioning progress, connection availability, rental start and end details, restart status, and operational events used to troubleshoot delivery issues.
Support & enquiry records
Includes ticket subjects, issue categories, reproduction steps, redacted logs, attachments, response history, and verification results needed to confirm the requester's relationship to an order.
Access & activity logs
Includes access times, request results, browser and device type, network address, session identifier, and records of account sign-ins, order management, and ticket activity.
Essential security signals
Includes unusual sign-in patterns, repeated failed requests, permission changes, high-risk actions, and event indicators that could affect the security of an account, console, or physical node.
Before submitting logs or screenshots, remove tokens, private keys, passwords, complete payment credentials, and personal information unrelated to the issue. ZoomMini may ask for an order identifier, the relevant time, or node details, but will not ask you to send secrets by email.
Why we process this information
ZoomMini does not use collected information for purposes unrelated to the service. Processing is focused on delivery, management, security, support, and necessary compliance.
- Provide and manage the service
- Create accounts, display the two available models, record node and rental-period selections, configure dedicated physical machines, and provide device status and remote connection details.
- Confirm orders and payments
- Verify order amounts, payment status, add-ons, billing records, and service periods, and process information needed for renewals, refund checks, or payment disputes.
- Secure accounts and nodes
- Identify unusual sign-ins, unauthorised access, misuse of permissions, and activity that could compromise service stability; restrict risky actions and retain necessary investigation records.
- Respond to support requests
- Link tickets with orders, nodes, and device status, reproduce connection or build issues, record troubleshooting steps, and report outcomes to the requester.
- Meet legal obligations
- Retain necessary transaction and security records, respond to requests with a valid legal basis, and handle audits, dispute resolution, and compliance checks.
- Improve site reliability
- Use aggregated error, performance, and operational results to locate points of failure and improve ordering, delivery, console, and support workflows, without creating unrelated user profiles.
The legal basis depends on the specific context and may include fulfilling an order, responding to your request, protecting the legitimate interests of the account and service, obtaining consent, or complying with applicable legal obligations. Where processing relies on consent, you may withdraw it as permitted by applicable rules; withdrawal does not affect the lawfulness of processing carried out before withdrawal.
How payment data is handled
ZoomMini orders are settled in US dollars (USD). We support USDT-TRC20, as well as Visa, Mastercard, and Amex through Stripe. The payment gateways available for a specific transaction are indicated during checkout.
During payment, the data required for the transaction is handled through the relevant payment process. ZoomMini retains only the information necessary to deliver the service, confirm payment, reconcile records, handle disputes, and meet compliance obligations, such as the order identifier, amount, currency, payment method category, transaction status, and necessary transaction references.
ZoomMini retains
- The link between orders and payment status
- USD amounts, service periods, and add-ons
- References needed for reconciliation, refund checks, or disputes
- Transaction records required by applicable law
Do not submit through support channels
- Full card numbers or security codes
- Wallet private keys, recovery phrases, or signing secrets
- Account passwords or SSH private keys
- Unredacted screenshots of payment pages
If your payment confirmation does not match, provide the order identifier, payment time, amount, and a redacted transaction reference. The support team will verify the records only as needed and will not ask for complete payment credentials.
Retention & deletion
We do not retain information indefinitely simply because it might be useful in the future. Retention periods are determined by service fulfilment, account status, dispute handling, security investigations, and applicable legal requirements, with the shortest reasonable period needed to fulfil the relevant purpose as the guiding principle.
| Information category | Primary retention basis | After the period ends |
|---|---|---|
| Account & contact details | While the account is active, and for as long as needed after closure to handle outstanding orders, requests, or disputes. | Deleted, de-identified, or retained on a restricted basis where required by law. |
| Orders & billing records | For as long as needed to complete fulfilment, reconcile records, verify refunds, maintain financial records, and meet legal obligations. | Non-essential fields are deleted, with only the minimum records required by law retained. |
| Device & node status | For as long as needed to manage the rental period, confirm delivery, troubleshoot faults, and handle related disputes. | Device associations unrelated to active services are deleted or converted into aggregated data that does not identify individuals. |
| Support records | For as long as needed to handle requests, review outcomes, prevent recurring faults, and resolve related disputes. | Attachments and non-essential details are deleted, or historical records are de-identified. |
| Access & security logs | For as long as needed to detect anomalies, investigate security incidents, protect accounts, and meet necessary audit requirements. | Logs are deleted on a rolling basis, aggregated, or de-identified, except where the law requires retention. |
Deletion may be paused when information relates to an unresolved order, payment dispute, security investigation, rights request, or legally required retention. Once the reason for the restriction ends, we will resume the deletion or de-identification process.
Before your rental period ends, you are responsible for moving your code, build artifacts, configuration, and other workload data off the cloud Mac. Deleting an account does not mean that data migration from the device has been completed, and it does not replace your responsibility to maintain backups.
Your rights and contact options
To the extent permitted by applicable rules, you may request access to relevant personal information held by ZoomMini, ask us to correct inaccurate information, delete information that is no longer necessary, restrict specific processing, or explain how your information is processed.
Requests you can make
- Confirm whether information about you is being processed
- Access applicable information categories and processing purposes
- Correct inaccurate or incomplete account details
- Delete information retained beyond the necessary period
- Restrict or object to processing where applicable
- Ask about cross-border processing and recipient categories
Please include
- The email address associated with your account
- The request type and information covered
- The relevant order or ticket identifier
- The necessary time range to help locate the records
- Information that can verify your relationship to the account
- How you would like to receive a response
To prevent someone else from impersonating you to access or delete your information, we will carry out verification proportionate to the risk of the request. Verification is used only to confirm the relationship between the requester and the relevant account, order, or record. We may ask for additional information when verification is not possible, the request is unclear, or another person's rights are involved.
Use the designated support channels
You can prepare a privacy request through the contact page or email support@zoommini.com. Existing customers can sign in to the console to submit a support ticket and check its status.
Processing time depends on the scope of the request, verification complexity, the number of records, and whether unresolved orders, security incidents, or legal retention obligations are involved. We will use the original request channel to explain progress, any additional information needed, or the outcome.
Cross-border processing & policy updates
ZoomMini provides services across different node regions. When you select a specific node, connect to a device remotely, process an order, or request technical support, your account, order, device-status, and support records may need to be processed between the relevant regions where necessary.
Cross-border processing is carried out to fulfil orders, provide connectivity, protect security, and respond to support requests, and is limited to the information required for the relevant workflow. We apply access controls, transfer safeguards, permission restrictions, logging, and necessary contractual measures based on the data type, processing purpose, and recipient's role.
Service delivery may involve processors responsible for hosting, payments, communications, security, or infrastructure. Their processing is limited to the relevant task and they may not use information for purposes unrelated to the services entrusted to them. ZoomMini reviews necessary data protection arrangements based on risk and applicable requirements.
If the information categories, processing purposes, sharing scope, or rights channels change materially, we will notify you through a prominent notice on the site, a console notification, or another method consistent with your existing service relationship.
Clarifications, page structure improvements, or updates that do not materially change processing will be published on this page. You can review the current version before continuing to use the service.
This policy is interpreted and enforced under the laws of the jurisdiction where the platform operator is established. Any related dispute will be handled by a court with jurisdiction in that jurisdiction.
If you have questions about cross-border processing, recipient categories, retention rules, or policy changes, submit specific questions through the contact page or a console ticket. Include the relevant order, node, information category, and concern so that we can route your request directly for review.