1. Scope and definitions
This policy applies to the VPSGit public website, pre-sales and support communications, account and order features in the console, and the dedicated Apple Silicon Cloud Mac services delivered to users. The data required differs by context, and we process data only to the extent necessary for the relevant purpose.
“Public website” means product, plan, location, guide, and legal pages accessible without signing in. “Communications” includes emails sent to support@vpsgit.com and tickets submitted after signing in to the console. “Order services” include the model, term, location, add-ons, payment status, renewals, and billing records.
“Cloud Mac services” means the dedicated Apple Silicon physical node assigned to an order, together with its system, network, and access configuration. Code, models, assets, build artifacts, and other files that users create, upload, or generate on a node are collectively referred to as “node content.”
This policy does not replace theTerms of Service. Read both documents when dealing with order formation, acceptable use, availability, renewal, termination, or limitations of liability.
2. Data we collect
Account and contact information may include an email address, account identifier, verification results, authorized member information, and the name or contact details you voluntarily provide in a ticket or email. We will not ask you to submit passwords, private keys, or other secrets that could directly access a node in public communications.
Order and payment status may include the selected model, term, location, storage add-ons, Thunderbolt 5 expansion options, order number, amount due, payment method category, payment status, transaction reference, renewal status, and billing records. All order amounts are recorded in USD.
Device and log information may include access times, IP address, browser and device type, session identifiers, login results, API call records, security events, node status, network diagnostics, and necessary audit records. We use this data to identify unusual access, troubleshoot delivery issues, and keep the service secure.
Support records include ticket subjects, issue descriptions, linked orders, node details, impact, reproduction steps, completed checks, and correspondence. Attachments, diagnostic output, and screenshots submitted by users are also support records; remove unrelated keys, signing materials, and personal content before submitting them.
3. Purposes and legal bases
We process account, order, and node configuration data to verify identity, create orders, reconcile payments, assign physical nodes, configure systems and networks, issue access credentials, process renewals, and provide billing records. These activities are necessary to fulfill orders and provide the services.
We process access logs, security events, and necessary device information to prevent unauthorized access, detect abuse, protect accounts and infrastructure, maintain audit trails, and respond to security incidents. Processing is limited according to risk, impact, and legal obligations and is not used to sell personal profiles.
We process emails, tickets, and diagnostic materials to answer pre-sales questions, troubleshoot network or system issues, assess order impact, restore service, and improve support workflows. If information is not needed to resolve an issue, we will ask users not to submit it or, where feasible, remove it from support materials.
Where applicable, our legal bases include performing a contract, taking necessary pre-contract steps, protecting the legitimate interests of the platform and users, complying with the laws of the jurisdiction where the platform operator is established, and obtaining consent where legally required.
4. Payment information
VPSGit orders are settled in USD. Available payment methods are USDT-TRC20 and Visa, Mastercard, and Amex (via Stripe). The payment gateways actually available are determined by the result returned by the console at checkout.
When you pay by card, card data such as the card number, expiry date, and security code is processed directly by the relevant payment provider. VPSGit receives only the payment result, amount, transaction reference, and risk status needed to complete orders, reconcile payments, process refunds, or handle disputes; it does not store full card data in its own systems.
When you pay with USDT-TRC20, we may process the order amount, receipt status, on-chain transaction identifier, and information needed for reconciliation. Transaction records on public blockchains may remain visible for a long time; their visibility and retention are not controlled solely by VPSGit.
To meet financial, tax, fraud-prevention, audit, or dispute-resolution requirements, order and payment status may need to be retained after an order ends. Retention is limited to necessary records and determined by applicable legal obligations and reasonable dispute periods.
5. Data sharing and international processing
We share data with service providers responsible for the relevant tasks only as necessary to deliver Cloud Mac services, operate infrastructure, process payments, provide security, support customers, and comply with legal obligations. Shared data is minimized by role; providers are not given node content or support records unrelated to their tasks.
Infrastructure and nodes are located in Singapore, Japan (Tokyo), South Korea (Seoul), Hong Kong, the US East, and the US West. After you select a location, data related to delivery, operation, networking, and support may be processed in that location or in regions providing necessary operational capabilities.
When international processing occurs, we apply reasonable contractual, access-control, transfer-protection, and other safeguards based on the data type, processing purpose, access rights, and applicable requirements. Location selection affects where node content is located; choose an appropriate region before ordering based on your team policies and data requirements.
When we receive a valid legal request for data disclosure, we verify the requester’s authority and the scope of the request and respond only to the extent legally required. Unless restricted by law, we use reasonable methods to maintain request records and defined processing boundaries.
6. Retention and deletion
Account information is retained while the account is active to support sign-in, order management, ticket association, and security verification. After an account is closed, nonessential data is deleted or de-identified according to our processes; order, security, or dispute records that must be retained by law are managed separately from routine account data.
Orders, invoices, and payment status are retained for the periods needed to fulfill orders, reconcile finances, support audits, handle disputes, and meet legal obligations. Support records are retained based on issue complexity, order status, future troubleshooting needs, and reasonable dispute periods, then deleted or appropriately de-identified.
Security logs are retained for as long as needed to investigate unusual access, protect accounts, analyze incidents, and maintain audit trails. Retention considers log sensitivity and actual use; access to logs is restricted, and they are not used as long-term behavioral profiles unrelated to the service.
When a rental term ends, the node enters a decommissioning and data-clearing process. Users should migrate and independently back up code, models, assets, build artifacts, and other node content before the term ends. Short-term operational records created to perform secure clearing may be retained, provided they do not contain the substantive contents of the node.
7. Security measures
We use role-based access control, least privilege, and necessary authentication measures to limit access to accounts, orders, support records, and operational systems. Personnel permissions are granted according to responsibilities and adjusted or revoked when responsibilities change or access is no longer needed.
The website, console, and service interfaces use encrypted connections in transit. Processes involving access credentials, keys, and sensitive configuration use restricted storage, separate delivery, or equivalent safeguards to prevent secrets from being placed on public pages or in unnecessary support records.
We maintain audit records related to sign-ins, order delivery, permission changes, node operations, and security incidents, and identify potential risks through status monitoring and anomaly analysis. Audit logs are available only to authorized personnel responsible for security, support, or compliance.
When an incident may affect user data or service security, we investigate, contain, remediate, and review it, and provide required notice based on its scope and applicable requirements. If you detect an unusual login, unknown order, or signs of credential exposure, contact us immediately through a console ticket or support@vpsgit.com.
8. Your rights and contact
To the extent permitted by applicable law, you may request access to data associated with your account, receive necessary explanations, correct inaccurate information, delete data that is no longer needed, restrict specific processing, or object to processing and lodge a complaint. Some requests may be limited by order fulfillment, accounting retention, security investigations, or legal obligations.
To submit a request, sign in to the console to create a ticket or email support@vpsgit.com. Include the request type, associated account email, relevant order number, and the scope of the requested action, but do not send passwords, private keys, or other access secrets.
To prevent others from impersonating you to obtain or delete data, we conduct identity verification proportionate to the risk of the request. Verification may include confirming the account email, order association, or recent activity; if we cannot reasonably confirm the applicant’s relationship to the account, we may request necessary additional evidence.
We determine processing order and response times based on request complexity, impact, and applicable law. If you disagree with the outcome, you may provide additional reasons through the original ticket or email, or lodge a complaint with an authority entitled to receive it under applicable rules.
9. Policy updates
This is version 1.0 of the policy, effective September 1, 2026. We may update the policy when services, data processes, payment methods, security measures, or applicable requirements change, and will publish the new version, effective date, and key changes on this page.
For changes that materially affect user rights, data types, sharing scope, or retention principles, we will provide notice through the website, console notifications, account email, or another appropriate channel. Users should review the policy version in effect before continuing to use the services.
There are currently no historical policies dated earlier than this version. After a later version is published, prior versions will be retained for reference; to request the policy applicable during a specific order period, contact support@vpsgit.com or submit a console ticket.
This policy is governed by the laws of the jurisdiction where the platform operator is established. Any dispute arising from this policy that cannot be resolved through communication will be handled by a court with jurisdiction in that jurisdiction under the applicable procedure.