VPSRox Personal Information Processing & Privacy Policy

This policy explains how VPSRox collects, processes, stores, and protects personal information relating to you when you visit vpsrox.com, register an account, rent a dedicated Mac mini M4 physical machine, and use remote access via the console, VNC, or SSH — and describes the choices and rights available to you under applicable law.

Effective: July 27, 2026 Related:Terms of Service
No sale of personal information

Your data is never sold to advertisers or data brokers.

Encrypted in transit

Website and API communications use TLS; passwords are stored with strong hashing.

Secure wipe after return

User data on rented machines is cleared within 72 hours after service termination.

01

Scope & relationship to other policies

VPSRox ("we") treats user privacy and data security as foundational to platform operations. This Privacy Policy ("this policy") applies to all related services you access, register for, or use through vpsrox.com and its subdomains (collectively, the "Services"), explaining how we handle personal information relating to you.

By accessing or using the Services, you acknowledge that you have read, understood, and agree to this policy. If you disagree with any terms, please stop using the Services. This policy together with the Terms of Service constitutes the complete agreement between you and VPSRox. In case of conflict on personal information processing, this policy prevails.

Important distinction: business content you store, run, or transmit on rented machines (source code, build artifacts, databases, AI model files, etc.) is primarily managed by you as the data controller. This policy focuses on account, transaction, access log, and operational information collected on the platform side.

02

Categories of information we process

To provide Mac mini M4 dedicated physical machine cloud rental and related services, we may process the following categories of information. Some is provided by you; some is automatically recorded during normal use.

Information you provide

Account information

Registration email, login password (stored as encrypted hash — we cannot read plaintext), and other information you voluntarily provide.

Orders & configuration

Selected data center node, rental period, SSD expansion or Thunderbolt 5 cluster add-ons, and order notes.

Payments & billing

Transaction amounts, payment status, order numbers, and redacted billing summaries. Full card numbers or on-chain wallet private keys are handled by Stripe, USDT payment channels, and other third parties — we do not store them.

Support communications

Issue descriptions, attachments, and correspondence submitted via tickets or email, used to troubleshoot and track resolution.

Information collected automatically

  • Access logs:IP address, request time, access path, browser type, operating system, and referrer
  • Client identifier:Device identifier generated for security verification and anomaly detection (vpsrox_ssaid, stored in browser local storage)
  • Usage behavior:Login times, console activity, feature usage frequency, and resource consumption statistics such as bandwidth
  • Interface preferences:Settings such as language preference (stored locally via preferred_language, etc.)
03

Use & sharing of information

We use your personal information only to the extent necessary for the following purposes, and do not process beyond what is consistent with this policy:

Service delivery Security & risk control Customer support Transactional notifications Product improvement Legal compliance

Covers account creation, Mac mini M4 instance allocation, payment renewal, SSH / VNC remote access, OpenClaw sandbox, ticket response, verification codes and billing notifications, plus aggregated anonymized product improvement and legal compliance.

Unless you opt out, we may send product updates or offers we believe are relevant. You can unsubscribe anytime via email links. Billing and security notifications cannot be opted out of.

We do not sell your personal information

Service providers we engage

  • Payment processors (Stripe, USDT-TRC20)
  • Email delivery provider
  • Self-hosted Matomo analytics
  • Infrastructure providers at five data center locations

Other sharing circumstances

We may disclose necessary information when required by law or legal process. In mergers, acquisitions, or asset transfers, user information may transfer as business assets — the recipient must continue to be bound by this policy. With your explicit consent, we may share with designated third parties for authorized purposes.

04

Retention & deletion

We retain your information only as long as necessary for the purposes described in this policy:

Basic account information During active period; up to 12 months after closure
Transactions & billing At least 7 years as required by law
Access & security logs Typically 90 days
Ticket correspondence During active period; 12 months after account closure
Rented machine data Erased within 72 hours after termination

Information required by law to be retained longer will be kept as legally required. After the retention period, we delete or anonymize the relevant information.

05

Security & cookies

We implement industry-standard technical and organizational measures to protect your personal information from unauthorized access, disclosure, alteration, or destruction:

  • Website and API communications use TLS encryption in transit
  • Account passwords stored with strong hashing — plaintext cannot be recovered
  • Internal staff access operational data on least-privilege basis with auditing
  • Data centers with 24×7 physical access controls and redundant infrastructure
  • Data stored on dedicated physical hardware during rental; securely wiped upon return
  • Regular security assessments and vulnerability scans

No internet transmission or electronic storage method is absolutely secure. If a data security incident may affect your rights, we will promptly notify you of the situation, potential impact, and measures taken, as required by applicable law.

Cookies & local storage

You can manage or clear cookies and local storage through browser settings, but this may affect login persistence and some features.

06

Your rights & preference management

Under applicable data protection laws, you may have the following rights. Submit requests via ticket or email — we will respond within a reasonable period (rights requests generally within 30 days):

Access & copy Request a copy of personal information we hold about you
Correction & supplementation Request correction of inaccurate or incomplete information; some details can be updated in the console
Deletion Request deletion after account closure; transaction records required by law are excluded
Opt out of marketing Stop promotional emails via unsubscribe links; billing and security notifications cannot be opted out of
Withdraw consent Withdraw consent at any time where processing is consent-based; withdrawal does not affect prior lawful processing
Restrict processing Request restriction of further processing in certain circumstances

While your account is active with outstanding orders, some deletion requests may not be executed immediately so we can fulfill service contracts and legal obligations.

07

Additional notes

Protection of minors

This service is not directed at minors under 18 years of age. We do not knowingly collect personal information from minors. If you are a guardian and believe a minor provided personal information without consent, contact us via ticket or email — we will delete it promptly after verification.

Cross-border data transfers

VPSRox operates data centers in Singapore, Japan (Tokyo), South Korea (Seoul), Hong Kong, and US East. Your personal information may be stored or processed on servers outside your country or region. We use data processing agreements, encrypted transmission, and access controls to ensure adequate protection for cross-border transfers.

External websites & services

Our website may contain links to third-party websites or services (e.g., payment redirect pages, documentation links). We are not responsible for third-party content, privacy practices, or security measures. Review their privacy policies before providing personal information.

Policy updates

We may revise this policy from time to time. Updated versions will be posted on this page with a revised effective date. For material changes (e.g., substantial changes to how we use information), we will notify you via registered email or in-platform notice.

Continued use of the service after changes are published constitutes acceptance of the revised policy. If you disagree, stop using the service and disable auto-renewal. Services already purchased and not yet expired will generally remain subject to the pre-change policy, unless otherwise required by law or stated by us.

Privacy inquiries

[email protected](please include "Privacy" in the subject)
Sign inConsoleSubmit ticket (recommended)
General inquiries within 2 business days; data rights requests within 30 days