Legal · Data protection

PixVPS user data processing & privacy statement

This document explains how PixVPS collects, uses, stores, and protects personal information when you browse pixvps.com, register, rent dedicated Mac mini M4 remote hosts, or connect via the dashboard, VNC, and SSH—and the choices and rights available to you under law.

Effective date: July 20, 2026 Applies together with the Terms of Service

Policy overview & scope

PixVPS ("we") treats user privacy and data security as foundational to platform operations. This Privacy Policy ("Policy") applies to all services accessed, registered for, or used through pixvps.com and its subdomains (collectively, the "Services"), and describes how we handle personal information relating to you.

By accessing or using the Services, you have read, understood, and agree to this Policy. If you disagree with any term, stop using the Services. This Policy together with the Terms of Service forms the complete agreement between you and PixVPS; for personal data matters, this Policy prevails in case of conflict.

Business data you store, run, or transmit on rented devices (source code, build artifacts, databases, etc.) is primarily managed by you as data controller; this Policy focuses on account, transaction, and access information collected on the platform side.

What we process

To provide Mac mini M4 cloud rental and related services, we may collect the categories below. Some you provide voluntarily; some are recorded automatically during normal use.

Information you provide

Account data

Registration email, login password (stored as encrypted hash—we cannot read plaintext), and other information you voluntarily provide.

Orders and configuration

Selected data center region, rental period, SSD expansion or Thunderbolt 5 clustering add-ons, and order notes.

Payment records

Transaction amount, payment status, order ID, and redacted billing summary; full card numbers or on-chain wallet private keys are handled by Stripe, USDT payment channels, and other third parties—we do not store them.

Support communications

Issue descriptions, attachments, and correspondence submitted via tickets or email.

Information collected automatically

  • Access logs: IP address, request time, access path, browser type, operating system, and referrer
  • Client identifier: Device ID generated for security verification and anomaly detection (pixvps_ssaid, stored in browser local storage)
  • Usage behavior: Login times, dashboard actions, feature usage frequency, and resource consumption such as bandwidth
  • UI preferences: Settings such as language choice (stored via preferred_language in local storage)

How we use information

We use your personal information only as necessary for the purposes below and will not process beyond what is consistent with this Policy:

  • Service delivery & operations: Create accounts, allocate Mac mini M4 instances, process payments and renewals, provide SSH / VNC remote access
  • Identity verification & risk control: Verify logins, detect abnormal access, prevent fraud and abuse
  • Customer support: Respond to tickets and email inquiries, troubleshoot connectivity or billing issues
  • Essential notices: Send verification codes, billing reminders, expiry notices, maintenance announcements, and security alerts
  • Product improvement: Analyze access and performance data in aggregated or anonymized form to improve platform stability and UX
  • Marketing: Send product updates or offers we believe are relevant, unless you opt out
  • Legal compliance: Meet legal obligations, respond to lawful authority requests, protect platform and user rights

Sharing and transfers

We do not sell your personal information. We may share necessary information with third parties only in these limited cases:

Processors we engage

For normal service operations, we may engage the following types of partners to process minimal information:

  • Payment processors (Stripe card payments, USDT on-chain collection services)
  • Email delivery providers (verification codes and service notifications)
  • Self-hosted analytics (Matomo, data stored on infrastructure we control)
  • Data center and network infrastructure providers

We require these partners to process information only for the entrusted purpose and implement appropriate security measures.

Legal requirements and business changes

When required by law, court order, or competent authority, we may disclose necessary information. In mergers, acquisitions, asset transfers, or similar transactions, user information may transfer as business assets; we will notify you via website notice within a reasonable period, and the recipient must remain bound by equivalent policy terms.

With your explicit consent, we may share information with designated third parties for authorized purposes.

Retention and deletion

We retain your information only as long as necessary for the purposes in this Policy. Typical retention periods by data type:

Basic account information (email, preferences, etc.) While account is active; up to 12 months after closure
Transaction and billing records At least 7 years per financial and tax law
Access and security logs Typically 90 days
Tickets and support correspondence While account is active; 12 months after closure
User data on rented devices Secure wipe within 72 hours after service ends

Information requiring longer retention by law will be kept per legal obligation; after retention ends, we delete or anonymize relevant data.

Technical and organizational safeguards

We apply industry-standard technical and organizational measures to protect personal information from unauthorized access, disclosure, alteration, or destruction:

  • Transport encryption: Website and API traffic uses TLS encryption
  • Credential protection: Account passwords stored with strong hashing; plaintext passwords cannot be recovered
  • Access control: Internal staff access operational data on least-privilege basis with audit logging
  • Physical security: Data centers with 24×7 physical access control and redundant infrastructure
  • Device isolation: Your data resides on dedicated physical hardware during rental; secure wipe on return
  • Ongoing review: Regular security assessments and vulnerability checks

No internet transmission or electronic storage is absolutely secure. If a security incident may affect your rights, we will notify you promptly per applicable law with an overview, potential impact, and measures taken.

Cookies and local storage

We use cookies and browser local storage to keep services running and improve experience:

You can manage or clear cookies and local storage in browser settings, but login persistence and some features may be affected.

Your rights and preferences

Under applicable data protection law, you may have the rights below. Submit requests via ticket or email; we respond within a reasonable period (typically within 30 days for rights requests):

Access & copy

Request a copy of personal information we hold about you.

Correction & supplementation

Request correction of inaccurate or incomplete information; some details can be edited in the dashboard.

Deletion

Request deletion after account closure; transaction records required by law are excluded.

Opt out of marketing

Use email unsubscribe links to stop promotional messages; billing and security notices cannot be opted out.

Withdraw consent

Where processing is consent-based, you may withdraw anytime; withdrawal does not affect lawfulness of prior processing.

While your account is active with outstanding orders, some deletion requests may not execute immediately so we can fulfill the service contract and legal obligations.

Children

This service is not directed at anyone under 18. We do not knowingly collect minors' personal information. If you are a guardian and believe a minor provided information without consent, contact us via ticket or email—we will delete it after verification.

Cross-border transfers

PixVPS operates data centers in Singapore, Japan (Tokyo), South Korea (Seoul), Hong Kong, and US East. Your personal information may be stored or processed on servers outside your country or region, where data protection standards may differ.

We use data processing agreements, encrypted transmission, access controls, and other measures to protect cross-border information and comply with applicable transfer requirements.

External sites and services

Our site may link to third-party websites or services (payment redirects, documentation links, etc.). We are not responsible for their content, privacy practices, or security. Review their privacy policies before providing personal information.

Policy updates

We may revise this Policy from time to time. Updates will be posted on this page with a revised effective date at the top. For material changes (e.g., substantial changes to use purposes), we will notify you via registered email or in-platform notice.

Continued use after publication means you accept the revised Policy. If you disagree, stop using the Services and disable auto-renewal; purchased services not yet expired generally remain under the prior Policy unless law or we state otherwise.

Privacy contacts

For questions, complaints, or to exercise data rights regarding this Policy, contact us:

Privacy email:[email protected](please include "Privacy" in the subject)
Ticket system:Sign inConsoleSubmit a ticket (recommended for tracking)
Response time:General inquiries within 2 business days; data rights requests within 30 days