01Scope
This policy applies to the rentmymini.com website and to data processing carried out by RentMini when handling service inquiries, Cloud Mac rental orders, node selection, delivery support, billing checks, security incidents, and privacy requests.
Our services provide access to dedicated physical Mac mini systems for the agreed rental period. Each order corresponds to a specific configuration, term, and node. Related order information appears in the console to complete delivery, show service status, and provide support.
This policy covers visitors, prospective customers, ordering users, order contacts, and people submitting support requests on behalf of a team. If you use the service for an organization, ensure that relevant members understand their data may be processed under this policy.
Service touchpoints covered by this policy
- Website visits, language selection, and basic security checks.
- Configuration, rental term, and node selection, plus order delivery and billing verification.
- Inquiries and privacy requests sent to support@rentmymini.com.
- Order issues, technical support, and security reports submitted after signing in to the console.
- Security logs needed to identify unusual access, failed connections, and unauthorized actions.
This policy does not change the data practices of third-party software. Software, code repositories, and project tools that you install or use on a Cloud Mac may process data under their own rules. You are responsible for reviewing their settings and permissions.
02Data collected
We follow a necessity principle and process only the data needed for inquiries, orders, delivery, support, security, and compliance. The specific fields vary with the features you use, the plan you select, and the type of request.
Contact and account information
Name or preferred form of address, work email, account identifier, language preference, and contact details you voluntarily include in an inquiry or support request.
Order and configuration information
Order number, RentMini M4 16 or RentMini M4 24 configuration, daily or other rental term, additional SSD, number of Thunderbolt 5 connections, and order status.
Node and delivery information
Your selected Singapore, Tokyo, Seoul, or Hong Kong node, plus the device name, node identifier, and connection-parameter status needed to deliver the service.
Device and browser information
Browser type, operating-system category, page access time, language, network address, security identifiers, and basic technical information used to troubleshoot compatibility issues.
Support records
Issue category, order number, time of occurrence, reproduction steps, redacted screenshots, email correspondence, ticket content, resolution, and follow-up verification records.
Connection and security logs
Connection attempt time, target node, session result, security incidents, permission changes, and necessary audit records used to protect accounts and dedicated physical nodes.
Do not submit login passwords, keys, private certificate keys, recovery codes, or complete payment credentials in email or tickets. If troubleshooting requires configuration details, remove tokens, personal content, and other sensitive fields first, leaving only information needed to reproduce the issue.
| Data category | Common examples | Primary purpose | Retention basis |
|---|---|---|---|
| Account and contact | Email, account identifier, language preference | Identity verification, notifications, support communications | Account relationship, request handling, and legal obligations |
| Orders and billing | Order number, configuration, term, node, amount | Service delivery, order verification, and billing | Service relationship, financial records, and compliance requirements |
| Connections and security | Connection time, result, security incidents, permission changes | Troubleshoot connections, identify abuse, protect physical nodes | Security needs, audit records, and dispute handling |
| Support content | Reproduction steps, redacted screenshots, ticket correspondence | Troubleshoot issues, continue processing, confirm results | Ticket lifecycle and necessary follow-up verification |
| Website technical information | Browser, device category, page events, network address | Compatibility analysis, security protection, service improvement | Necessary period, security incidents, and aggregated analysis |
03Purposes of processing
We do not use data arbitrarily outside the service purpose. Processing focuses on delivering dedicated physical Mac mini systems, keeping accounts and nodes secure, handling user requests, and meeting applicable obligations.
- Provide Cloud Mac services:Create orders, match configurations and nodes, generate delivery information, display rental status, and handle necessary service changes.
- Handle identity and account actions:Verify account actions, keep sign-ins secure, record material permission changes, and reduce the risk of unauthorized access.
- Process orders and billing:Verify the selected model, term, node, add-ons, amount due, payment result, and order delivery status.
- Protect physical nodes:Detect unusual connections, abuse attempts, malicious activity, and conduct that could affect the security of other nodes.
- Respond to support requests:Locate connection, environment, disk, or billing issues using the order number, node, time of occurrence, and reproduction steps.
- Improve the website and processes:Analyze page usability, browser compatibility, and process failure points, without creating speculative user profiles or publishing personal usage records.
- Meet legal obligations:Retain necessary transaction, financial, security, and compliance records, and respond to valid and lawful requests.
Processing may be based on performing the service agreement, taking pre-order steps at your request, protecting the legitimate security interests of the platform and users, meeting legal obligations, and obtaining explicit consent where applicable.
If a later use is incompatible with the original purpose, we will provide the necessary explanation before starting the new processing and obtain authorization again when required.
04Payment data
All plans, add-ons, quotes, and invoices are settled in US dollars (USD). We currently support only USDT-TRC20 and Visa / Mastercard / Amex (via Stripe). Actual available gateways are determined by the result returned in the console.
Payment processing may involve the order number, amount due, currency, payment method category, transaction status and time, and transaction identifiers used for reconciliation. Stripe processes card payments. We use payment results and necessary reconciliation information to complete orders and do not require complete card numbers or security codes in support forms.
When you use USDT-TRC20, transaction records may include the on-chain transaction identifier, sending address, receiving address, amount, and confirmation status. Blockchain records are public and technically irreversible, and related information may independently remain on a public ledger.
For failed payments, suspected duplicate charges, or billing discrepancies, we verify the issue using order records and the status returned by the payment processor. Some transaction records may need to be retained after an order ends for financial, tax, fraud-prevention, and dispute-handling purposes.
05Sharing and processors
We do not sell personal data. We provide only the minimum information needed to bound processors when necessary to provide services, complete payments, protect security, operate infrastructure, support professional compliance, or respond to lawful requests.
Service delivery and infrastructure
Infrastructure providers operating the website, console, order system, node connections, and necessary storage may process account identifiers, order status, technical logs, and data needed for delivery.
Payment processing
Stripe processes information needed for Visa / Mastercard / Amex payments; USDT-TRC20 transactions are recorded under the rules of the relevant network. Sharing is limited to payment, reconciliation, fraud prevention, and dispute handling.
Security protection
Security service providers that detect malicious requests, unauthorized access, and unusual connections may process network addresses, request characteristics, event times, and risk assessments.
Professional and compliance services
When necessary for audit, financial, legal, or compliance matters, relevant professional service providers may access strictly limited data and must follow confidentiality and purpose restrictions.
Valid legal requests
When required by applicable law, necessary to protect users and platform security, or needed to enforce lawful rights, we may disclose limited information after checking the request’s validity and necessity.
Because users can select nodes in Singapore, Tokyo, Seoul, or Hong Kong, order delivery and support investigations may involve cross-region data processing. We apply access restrictions, contractual controls, and security measures based on the data type, delivery needs, and applicable rules.
If our business structure changes and related data must be transferred with the business, we will require the recipient to continue processing it for the purposes described in this policy and under applicable rules, and provide notice where required.
06Retention and security
Retention periods differ by data type. We determine them based on the service relationship, order and billing verification, security risks, support-ticket lifecycle, dispute handling, and legal obligations, then delete, anonymize, or restrict access when data is no longer needed.
- Account and contact data is generally retained while the account relationship continues, then enters restricted retention after closure as needed for security, disputes, and legal obligations.
- Order, billing, and payment-status records are retained for the period needed for financial reconciliation, transaction evidence, fraud prevention, and applicable legal obligations.
- Support records are retained until the issue is closed and necessary follow-up is complete. Restricted retention may be extended for ongoing security incidents or disputes.
- Connection and security logs are retained according to risk level, audit needs, and investigation status, and are not kept indefinitely merely for convenience.
- Aggregated or anonymized data may be used for security trends, capacity planning, and process improvement once it can no longer reasonably be linked to an individual.
Access controls
System permissions are assigned by job responsibility, with identity verification and access restrictions for key accounts, orders, nodes, and support records.
Least privilege
Personnel and processors receive only the permissions needed for their assigned tasks, preventing unrelated roles from accessing complete datasets.
Log review
We record key actions and security incidents and check for unauthorized access, unusual connections, permission changes, and conduct that could affect physical nodes.
Protection in transit and at rest
Applicable data transfers are protected with encryption, while storage isolation, backups, and access auditing are configured according to sensitivity.
You also have a responsibility to protect your data. Use separate, sufficiently strong login credentials, manage project keys and certificates carefully, remove access permissions you no longer need, and migrate and back up required data before the rental term ends.
No system can eliminate every risk. If a security incident may significantly affect user rights, we will investigate, limit the impact, preserve necessary evidence, and provide notice as required.
07User requests and updates
You may request access to data relating to you, correction of inaccurate information, deletion of data no longer needed, restriction of specific processing, or object to processing based on legitimate interests. Some requests may be limited by order fulfillment, security investigations, financial records, or legal retention obligations.
When submitting a request, specify the request type, associated email, order number, or other information that can locate the records. To prevent impersonation, we may require reasonable identity verification, but we will not ask you to submit passwords, keys, private certificate keys, or complete payment credentials by email.
Submit by email
Send to support@rentmymini.com, put “Privacy Request” in the subject line, and describe the requested action and related order information.
Open system emailSubmit through a console ticket
If you have an account or order, sign in to the console and submit a ticket. This can reduce identity-verification steps and link the request to the relevant order record.
Submit a console ticketWe process requests based on their scope, identity-verification results, record location, and applicable requirements. If a request is too broad, we may ask for an order number, date range, or specific data category to locate records accurately.
This policy may be updated as our service processes, data practices, or applicable requirements change. The updated text, version, and effective date will appear on this page. If a change may materially affect user rights, we will provide additional notice through reasonable channels.
This policy and related data-processing matters are governed by the laws of the jurisdiction where the platform operator is established. Disputes arising from this policy that cannot be resolved through communication will be handled by a competent court in that jurisdiction.