Data handling rules

Privacy Policy

This policy explains how ZoneMini collects, uses, retains, shares, and protects information when providing its website, Cloud Mac order management, and support services. We limit data collection to each processing purpose and provide clear channels for access, correction, deletion, and restriction requests.

Applies to
Website visitors, account holders, order contacts, and support request submitters
Current version
Initial site version
Contact channel
support@zonemini.com or a console support ticket
01

Policy scope

First, confirm which points of contact are covered by this policy.

This policy applies to information processing when you visit zonemini.com, create or manage Cloud Mac orders through the ordering and management console, or contact ZoneMini through the support email or a console support ticket.

Information handled through the public website is primarily used to deliver pages, secure access, troubleshoot faults, and improve the service. The console handles accounts, configuration choices, node selections, orders, payment status, instance associations, and support records. Support communications cover problem descriptions, order numbers, reproduction steps, and redacted diagnostic content submitted by users.

When submitting information on behalf of a team or business, you must have authority to provide the relevant contact details, project requirements, and device information. Submissions must be limited to what is necessary for selection, ordering, connection, or troubleshooting.

Public website Page requests, basic access records, security-event indicators, and preference settings
Order management Accounts, three configuration tiers, five node choices, orders, and transaction status
Support communications Ticket subjects, reproduction steps, redacted logs, handling records, and replies
02

Information We Collect

Different actions involve different data sets; we do not collect every item in a single visit.

Account and contact details

This may include the account email address, contact name, verification records, team or organization name, and contact information you voluntarily provide to receive order and service notifications.

Order and device information

This may include the selected ZoneMini M4 Core, ZoneMini M4 Plus, or ZoneMini M4 Pro, billing cycle, optional additional storage or Thunderbolt 5 parallel-connection options, node selection, order number, service status, and necessary device identifiers associated with the instance.

Access and security logs

This may include request time, IP address, browser and device type, pages visited, session security events, authentication results, and records of unusual requests. We use this data to prevent unauthorized access, troubleshoot service errors, and audit critical actions.

Support tickets and diagnostic materials

This may include issue category, time of occurrence, node, model, reproduction steps, expected result, communications, and command output, build logs, or network diagnostics that you voluntarily submit after redaction.

03

Purposes of Use

Each type of information must serve a defined service or security task.

  1. Service delivery

    Provide and manage Cloud Mac Hosts

    Establish account and order relationships, record model, node, cycle, and add-on selections, deliver instances, manage status, process renewals, and send service notifications.

  2. Identity security

    Verify identity and protect critical actions

    Send verification codes, verify login status, identify unusual authentication activity, audit account and order actions, and apply access protections when risks are detected.

  3. Transaction processing

    Create orders and verify payment status

    Calculate the amount due for the selected configuration, link transaction results, create billing records, and handle payment-status inquiries.

  4. Issue resolution

    Troubleshoot connection, environment, and hardware issues

    Use the node, model, occurrence time, reproduction steps, and redacted logs to determine the scope of an issue, document the handling process, and report the outcome.

  5. Required notifications

    Send service and security information

    Send information directly related to the existing service, including order status, account security, service changes, ticket replies, and material policy updates.

  6. Legal obligations

    Retain necessary records and respond to lawful requests

    Under the laws of the jurisdiction where the platform operator is based, retain records needed for transactions, security, and dispute handling, and respond to requests made through valid legal procedures.

04

Payment Data Processing

Payment information is processed only to the extent needed to complete transactions, verify status, and meet recordkeeping obligations.

All orders are settled in USD. The only supported payment methods are USDT-TRC20 and Visa / Mastercard / Amex (via Stripe); actual gateway availability is determined by the result returned by the console.

USDT-TRC20

On-chain transaction verification

We process the order amount, receiving identifier, transaction hash, confirmation status, and necessary reconciliation records to link the payment result to the relevant order.

Visa / Mastercard / Amex

Card payment processing

Card payments are processed through Stripe. ZoneMini receives only the limited transaction information needed to complete orders, confirm transaction results, handle billing inquiries, and perform security checks.

Payment records are linked to the order number, amount, currency, transaction status, and processing time. Access is limited to personnel or processors who need it to process transactions, handle billing inquiries, conduct security audits, or meet legal obligations.

05

Sharing and Processor Handling

Service providers may process information only for agreed purposes and within the necessary scope.

ZoneMini may use service providers for hosting infrastructure, operational monitoring, customer support, transaction processing, and legal requirements where necessary. Information is divided by task; no single service function receives access to all account, order, or support materials.

Processor scenarios and data boundaries
Processing scenario Information that may be involved Limited purpose
Hosting and infrastructure Account-linked identifiers, instance and node records, and operational logs Deliver services, keep systems running, and perform backup and recovery measures
Operational monitoring and security Request records, error information, authentication events, and indicators of unusual behavior Detect faults, prevent unauthorized access, and audit critical events
Customer support Ticket content, order numbers, redacted logs, and communication records Troubleshoot issues, coordinate handling, and record resolutions
Transaction processing Order amount, currency, transaction status, and necessary verification information Complete payments, reconcile records, process refunds, and verify transaction security
Legal requirements Records specifically required by valid procedures and relevant to the matter Meet legal obligations, protect legitimate rights, and handle disputes

When selecting or managing processors, we define the processing purpose, access scope, security requirements, and information-handling responsibilities. After the task ends, relevant information is returned, deleted, or retained under continued restrictions according to the contract, business-record requirements, and applicable law.

06

Retention, Security, and Cross-Border Processing

Retention periods, access controls, and data locations are managed separately by record type.

Retention periods

Account information is retained while the account relationship continues, with necessary records kept afterward for the periods required for security, accounting, dispute handling, and legal obligations. Order and transaction records are retained for accounting and legal obligations; access logs are retained for the period needed for security investigations and operational analysis; support tickets are retained as needed for issue tracking, service improvement, and dispute handling.

When information no longer serves a defined purpose and there is no legal or security need to retain it, we delete it, anonymize it, or dissociate it from identifiable accounts. Remaining copies in backups are gradually removed through backup rotation and recovery processes and remain subject to access restrictions.

Security measures

Access controls

Permissions are assigned by role and task, with least-privilege access applied to accounts, orders, transactions, and support records.

Log auditing

We record authentication, permission changes, and critical administrative actions to detect unusual behavior and reconstruct handling activities.

Transmission protection

The website, console, and service interfaces use encrypted connections during transmission to reduce the risk of information being read or altered in transit.

Support-material isolation

Tickets and diagnostic materials are handled within the scope of each request to prevent unrelated project information from spreading to other processing flows.

Node selection and data location

ZoneMini offers five available nodes: Singapore, Japan (Tokyo), South Korea (Seoul), Hong Kong, and the US East Coast. After you select a node, instance operation, local storage, and related technical logs may be processed in the region where that node is located. Records required by account, order, transaction, and support systems may also be processed by processors responsible for those functions.

When cross-region processing occurs, we limit the data scope to the processing purpose, apply access controls, transmission protection, and processor restrictions, and implement applicable requirements under the laws of the jurisdiction where the platform operator is based. Choose a node based on repository location, team access arrangements, project data requirements, and internal compliance rules.

07

User Rights and Policy Updates

Requests enter the handling process after identity and scope verification are complete.

To the extent provided by applicable law, you may request access to account-related information, correction of inaccurate data, deletion of information no longer needed, restriction of specific processing, or information about the purpose of processing and categories of recipients for a given type of information.

Step 1

Choose a submission channel

Email support@zonemini.com or log in to the console to submit a support ticket. For requests concerning existing orders, use a ticket where possible so the request can be linked to account and order records.

Step 2

Specify the request scope

State the account email address, request type, relevant order number or date range, and the specific information you want to access, correct, delete, or restrict.

Step 3

Complete required verification

We use necessary information linked to the account or order to verify the requester’s identity and prevent unauthorized access to, modification of, or deletion of information.

Step 4

Receive the outcome

After verification, we explain the actions taken, the categories of records that must still be retained and why, and respond through the original request channel.

If a request concerns another person’s information, transaction security, an unresolved dispute, or records that must be retained by law, we will narrow the scope and explain what can be completed. If you dispute the outcome, you may provide additional materials through support@zonemini.com or a console support ticket; matters requiring judicial handling will be handled by a court with jurisdiction in the relevant jurisdiction.

Policy updates

When there are material changes to data categories, processing purposes, service processes, processor arrangements, or user-rights mechanisms, we update this page and explain the key changes through the website, console, or a notification method appropriate to the service relationship. The updated policy applies from the version status shown on the page.

Privacy requests

Include your account, request type, and record scope before submitting

Do not send passwords, SSH private keys, repository tokens, signing certificates, or complete payment credentials. Existing orders can be linked through a console support ticket.