Your data is never sold to advertisers or data brokers.
Website and API communications use TLS; passwords are stored with strong hashing.
User data on rented machines is cleared within 72 hours after service termination.
Scope & relationship to other policies
VPSRox ("we") treats user privacy and data security as foundational to platform operations. This Privacy Policy ("this policy") applies to all related services you access, register for, or use through vpsrox.com and its subdomains (collectively, the "Services"), explaining how we handle personal information relating to you.
By accessing or using the Services, you acknowledge that you have read, understood, and agree to this policy. If you disagree with any terms, please stop using the Services. This policy together with the Terms of Service constitutes the complete agreement between you and VPSRox. In case of conflict on personal information processing, this policy prevails.
Important distinction: business content you store, run, or transmit on rented machines (source code, build artifacts, databases, AI model files, etc.) is primarily managed by you as the data controller. This policy focuses on account, transaction, access log, and operational information collected on the platform side.
Categories of information we process
To provide Mac mini M4 dedicated physical machine cloud rental and related services, we may process the following categories of information. Some is provided by you; some is automatically recorded during normal use.
Information you provide
Account information
Registration email, login password (stored as encrypted hash — we cannot read plaintext), and other information you voluntarily provide.
Orders & configuration
Selected data center node, rental period, SSD expansion or Thunderbolt 5 cluster add-ons, and order notes.
Payments & billing
Transaction amounts, payment status, order numbers, and redacted billing summaries. Full card numbers or on-chain wallet private keys are handled by Stripe, USDT payment channels, and other third parties — we do not store them.
Support communications
Issue descriptions, attachments, and correspondence submitted via tickets or email, used to troubleshoot and track resolution.
Information collected automatically
- Access logs:IP address, request time, access path, browser type, operating system, and referrer
- Client identifier:Device identifier generated for security verification and anomaly detection (vpsrox_ssaid, stored in browser local storage)
- Usage behavior:Login times, console activity, feature usage frequency, and resource consumption statistics such as bandwidth
- Interface preferences:Settings such as language preference (stored locally via preferred_language, etc.)
Use & sharing of information
We use your personal information only to the extent necessary for the following purposes, and do not process beyond what is consistent with this policy:
Covers account creation, Mac mini M4 instance allocation, payment renewal, SSH / VNC remote access, OpenClaw sandbox, ticket response, verification codes and billing notifications, plus aggregated anonymized product improvement and legal compliance.
Unless you opt out, we may send product updates or offers we believe are relevant. You can unsubscribe anytime via email links. Billing and security notifications cannot be opted out of.
Retention & deletion
We retain your information only as long as necessary for the purposes described in this policy:
Information required by law to be retained longer will be kept as legally required. After the retention period, we delete or anonymize the relevant information.
Security & cookies
We implement industry-standard technical and organizational measures to protect your personal information from unauthorized access, disclosure, alteration, or destruction:
- Website and API communications use TLS encryption in transit
- Account passwords stored with strong hashing — plaintext cannot be recovered
- Internal staff access operational data on least-privilege basis with auditing
- Data centers with 24×7 physical access controls and redundant infrastructure
- Data stored on dedicated physical hardware during rental; securely wiped upon return
- Regular security assessments and vulnerability scans
No internet transmission or electronic storage method is absolutely secure. If a data security incident may affect your rights, we will promptly notify you of the situation, potential impact, and measures taken, as required by applicable law.
Cookies & local storage
You can manage or clear cookies and local storage through browser settings, but this may affect login persistence and some features.
Your rights & preference management
Under applicable data protection laws, you may have the following rights. Submit requests via ticket or email — we will respond within a reasonable period (rights requests generally within 30 days):
While your account is active with outstanding orders, some deletion requests may not be executed immediately so we can fulfill service contracts and legal obligations.
Additional notes
Protection of minors
This service is not directed at minors under 18 years of age. We do not knowingly collect personal information from minors. If you are a guardian and believe a minor provided personal information without consent, contact us via ticket or email — we will delete it promptly after verification.
Cross-border data transfers
VPSRox operates data centers in Singapore, Japan (Tokyo), South Korea (Seoul), Hong Kong, and US East. Your personal information may be stored or processed on servers outside your country or region. We use data processing agreements, encrypted transmission, and access controls to ensure adequate protection for cross-border transfers.
External websites & services
Our website may contain links to third-party websites or services (e.g., payment redirect pages, documentation links). We are not responsible for third-party content, privacy practices, or security measures. Review their privacy policies before providing personal information.
Policy updates
We may revise this policy from time to time. Updated versions will be posted on this page with a revised effective date. For material changes (e.g., substantial changes to how we use information), we will notify you via registered email or in-platform notice.
Continued use of the service after changes are published constitutes acceptance of the revised policy. If you disagree, stop using the service and disable auto-renewal. Services already purchased and not yet expired will generally remain subject to the pre-change policy, unless otherwise required by law or stated by us.