01Information We Collect
We collect exactly four categories of information, each tied to a specific service function. Anything not on this list, we don't collect.
1.1 Account details
The email address, login password, and interface language preference you provide at sign-up. Passwords are stored as salted hashes — no one can reverse them into plaintext. Your email doubles as your unique account identifier and is where we send VNC/SSH delivery credentials, expiry reminders, and security notices.
1.2 Order & payment records
Orders include the machine tier, rental term, node location, order and expiry timestamps, and the USD amount. We accept USDT-TRC20 and Visa / Mastercard / Amex (via Stripe) only, with corresponding records handled as follows:
- Card payments: card number, expiry, and CVV are captured and processed directly by Stripe — they never pass through or get stored on our servers. We only retain the transaction ID, card network, and last four digits returned by Stripe.
- USDT-TRC20: we only log the receiving address, on-chain transaction hash, and amount received — we don't collect any wallet identity information.
1.3 Support ticket & correspondence content
Text, attachments, and log snippets you send us via the dashboard's ticketing system or support@armmini.com. This content is used solely to resolve the issue you describe, and access is limited to the support engineer handling that specific ticket.
1.4 Node operating metrics (excluding on-machine user data)
To keep hardware available, we collect power status, network link status, room temperature, and port-level traffic counters (byte counts only, never content) from each Mac mini via out-of-band rack-side channels. These metrics come from the hardware and switches themselves — we don't need to, and don't, log into your macOS system. Files, code, certificates, keychain entries, and browsing history on your machine are never collected, because our technical pathway simply doesn't touch them.
02How We Use It
Each data category is used strictly for its stated purpose — nothing gets repurposed:
| Data category | Used for | Never used for |
|---|---|---|
| Account details | Login authentication, credential delivery, expiry & security notices | Selling to marketing lists |
| Order & payment records | Billing, invoicing, processing refunds | Spending behavior analysis |
| Support ticket content | Troubleshooting, migration assistance | Training any model |
| Node operating metrics | Hardware failure prediction, abuse prevention (e.g. anomalous traffic detection) | Inferring your on-machine workload |
Two things we explicitly rule out: we never build user profiles from any data we hold, and we never serve ads to you or share your data with anyone who would. Every email you receive from us is transactional or security-related — credentials, invoices, expiry reminders, incident notices. No promotional content, ever.
04Third-Party Processors
We keep third-party processors to an absolute minimum. Currently there are three, each with a clearly scoped range of data access:
| Processor category | Data accessed | Purpose | Data never accessed |
|---|---|---|---|
| Payment gateway (Stripe) | Card details, billing email, transaction amount | Processing Visa / Mastercard / Amex charges and refunds | Your machine credentials & ticket content |
| Transactional email provider | Recipient email, message body (credentials delivered as encrypted attachments) | Delivering credentials, invoices, and security notices | Order payment information |
| Self-hosted basic analytics | Page paths, anonymized visitor address | Docs and page view statistics | Account identity, orders, anything outside its cookie scope |
USDT-TRC20 payments settle directly on the blockchain network, so there's no traditional third-party payment processor involved — the public nature of on-chain transaction records is a function of the blockchain protocol itself, not our choice. We've signed data processing agreements with each processor listed above, restricting them to processing data strictly per our instructions, with no secondary use permitted. Beyond the processors listed here, and except where legally compelled, we do not share your data with anyone.
05Retention & Deletion
Retention periods are set per data category and clean up automatically on expiry — there's no "kept forever" bucket:
5.1 How the wipe actually happens
Once a machine is reclaimed, we destroy the SSD's encryption keys, perform a full-disk overwrite, and then reinstall a clean macOS image. You can check "request wipe confirmation" when closing your account, and within 7 days of completion we'll email you a written record covering the machine's serial number, the wipe method used, and the completion timestamp. Retired disks never enter the secondhand market — they're physically destroyed.
5.2 What we don't back up
We do not back up any data on your machine — this is both a privacy commitment and a reminder that backing up your own data is on you. The 72-hour-before-expiry email reminder will flag this again; please move your data off with rsync or another tool of your choice before the service ends.
06Your Rights
You can exercise the following four rights over the data we hold about you. Here's how and how fast:
| Right | What it covers | How to exercise it | Response time |
|---|---|---|---|
| Access | Get a full list of every category and piece of data we hold about you | Submit a dashboard ticket under "Privacy Matters" | Within 7 business days |
| Correction | Fix inaccurate account details | Self-service edit in the dashboard; submit a ticket if you can't self-serve | Within 3 business days |
| Export | Export account details, orders, and ticket history as JSON | Email support@armmini.com with "Data Export" in the subject line | Within 14 business days |
| Deletion | Close your account and delete all associated data | Initiate closure in the dashboard, confirm via email verification code | Completed within 7 days of confirmation |
Two boundaries worth noting: first, order and billing records can't be deleted early during the 24-month retention window due to financial obligations — a deletion request will simply queue up and execute automatically once that window closes. Second, rights requests must come from your registered email or a logged-in dashboard session, which is how we verify the requester's identity — we don't accept requests submitted by third parties on your behalf. Exercising any of these rights is always free.
07Cross-Border Transfers
ArmMini runs five physical nodes — in Singapore, Tokyo, Seoul, Hong Kong, and Silicon Valley. Data placement follows a strict "data stays put" principle:
- On-machine data: the full-disk data on the Mac mini you're renting stays physically at the facility where that machine is located — never copied across nodes or backed up elsewhere. Pick the Tokyo node, and your data physically stays in Tokyo.
- Account & order data: stored in our primary platform database, synced to each node over an encrypted channel only for the minimal metadata required for troubleshooting (machine ID, network configuration).
- Payment data: card information is processed by Stripe entirely within its own infrastructure — storage location follows Stripe's own disclosures. We only retain non-sensitive fields like the transaction ID on our end.
Safeguards in place: all administrative traffic between nodes and between nodes and the platform runs over encrypted WireGuard tunnels; every facility undergoes physical access control audits with individually locked racks; cross-node migrations only happen when you actively request one, and the source machine is wiped per Chapter 5 immediately after migration completes.
08Changes & Contact
8.1 How we notify you of policy changes
When this policy is updated, we'll email a summary of the changes to every active account's registered address at least 14 days before the changes take effect, and update the version number and effective date at the top of this page. Material changes — expanded data collection scope, or changes to our third-party processors — will be itemized point by point in that email. Wording clarifications alone only trigger a version bump. Continuing to use the service after a change takes effect means you accept the updated policy; if you don't, you're welcome to close your account before the effective date following the process in Chapter 6.
8.2 Privacy contact
Questions, requests, or complaints about privacy go through either of these two channels:
- Email: support@armmini.com, with "Privacy Matters" in the subject line — we reply within 7 business days;
- Dashboard ticket: log in and submit one under "Privacy Matters" — first response time matches our standard ticket SLA.
The interpretation and enforcement of this policy, and any disputes arising from it, are governed by the laws of the jurisdiction where our operating entity is established; unresolved disputes are subject to the courts with jurisdiction there. Together with our Terms of Service, this policy forms the complete agreement between you and ArmMini — where the two conflict on matters of personal data handling, this policy governs.