Scope and data controller
First, confirm which interactions this policy covers and who determines how data is processed.
This policy applies to the public soarmac.com website, the SoarMac management console, account registration and verification, order and billing communications, machine delivery, support tickets, email exchanges, and the operational and security records required when users access Cloud Mac services.
SoarMac's operating entity determines the purposes and methods for processing personal information and service data in these situations. When an enterprise customer orders services for a team, it may also determine how member details, project materials, and workloads are processed. In that case, SoarMac processes the content only as needed to provide the agreed services.
This policy does not change the rights users hold in their source code, uploaded files, build artifacts, key materials, or business data.
Types of data collected
Data comes from information users submit, service operations, and necessary security checks.
Account and contact information
This may include a name or display name, work email, account verification status, organization name, language preference, and contact details users voluntarily provide during pre-sales inquiries or support conversations.
Order and billing records
This may include the selected machine model, rental term, node, storage add-ons, Thunderbolt 5 linked configuration, order status, amount, payment status, transaction references, and necessary accounting records.
Device and security logs
This may include login times, source network information, session results, device identifiers, failed access attempts, permission changes, instance lifecycle events, and technical logs used to investigate unusual activity.
Support content
This may include ticket subjects, issue descriptions, order numbers, nodes, occurrence times, reproduction steps, sanitized logs submitted by users, and replies and status timelines during resolution.
Website usage data
This may include pages visited, referral sources, browser and device categories, page interactions, and basic performance data. We use it to understand page availability, identify faults, and improve content structure.
Cloud Mac operational information
This may include physical node assignments, machine configuration, delivery status, rental start and end dates, connection status, and resource anomaly signals. We do not proactively inspect users' work content unless necessary for support, security, or meeting obligations.
Purposes and legal bases
Each processing activity must serve a clear purpose rather than involve indefinite collection.
- Account management Create and verify accounts, maintain sign-in sessions, identify account ownership, process password changes, and provide account security notifications.
- Machine delivery Assign a physical node based on the order configuration, prepare access credentials, record delivery results, and manage renewals, configuration changes, and service status during the rental term.
- Identity and security verification Detect unusual logins, unauthorized access, malicious requests, and resource abuse, while protecting accounts, physical nodes, and other users' normal use.
- Billing Confirm order amounts, process payment status, create transaction records, handle refunds or disputes, and meet necessary financial recordkeeping obligations.
- Support response Locate connection, system, configuration, storage, or billing issues, reproduce faults, record the resolution timeline, and verify whether the issue has been resolved.
- Compliance and service improvement Meet applicable obligations, respond to valid requests, audit critical actions, and use aggregated data to improve the website, console, delivery process, and guide content.
Processing may be based on fulfilling user orders and service agreements, complying with applicable obligations, protecting the legitimate security interests of the platform and users, or obtaining consent when a specific feature requires it. Withdrawing consent does not affect processing lawfully completed before withdrawal.
Billing data
Orders are priced in USD, and payment data is handled separately according to the selected method.
Information required for on-chain settlement
Processing may include the order amount, receiving address, transaction hash, confirmation status, and time records associated with the order. This information is used to verify payment, identify duplicate or incorrect payments, and complete accounting records.
Visa / Mastercard / Amex
Card payments are processed through Stripe. SoarMac receives the payment status, amount, card type, partially masked identifier, and transaction references needed to complete the order and accounting. Users are not asked to send full card numbers or security codes through support channels.
The payment gateway actually available is shown in real time at checkout. Users should not submit full card details, wallet private keys, seed phrases, or other credentials that can directly control funds in tickets, emails, logs, or screenshots.
User data on Cloud Macs
The physical node is the user's work environment, and the project content remains under the user's control.
Users decide what to upload, create, sync, or process, including source code, build caches, signing materials, test data, media assets, model files, build artifacts, and team documents. Users must ensure they have the right to process this content and set appropriate permissions and access scopes for their workloads.
Control access and credentials
Use least-privilege accounts, limit team-member access, protect session credentials, and update authorization promptly when personnel or tasks change.
Check synchronization and backups
Confirm that source code, build artifacts, checkpoints, and business files have been synchronized to storage controlled by the user, and verify that backups can be read.
Complete migration and cleanup
Move out data that must be retained, revoke temporary credentials, stop sensitive tasks, and remove unneeded caches, tokens, and project copies.
When users request technical support, SoarMac accesses logs, screenshots, or reproduction materials only to the extent needed to diagnose the issue. Remove passwords, private keys, access tokens, and unrelated personal information before submitting them.
Retention, security, and incident response
Different records are retained separately according to their purpose; we do not keep everything permanently by default.
- Account information
- Retained while the account is active; after closure, we retain only what is needed to process outstanding orders, security investigations, disputes, or applicable obligations.
- Order and billing records
- Retained as needed for accounting reconciliation, transaction disputes, and applicable recordkeeping obligations. Payment credentials are not routinely retained through tickets or ordinary email.
- Device and security logs
- Retained for the period needed for diagnostics, security monitoring, and anomaly investigations; afterward, they are deleted, aggregated, or de-identified unless the related incident remains active.
- Support records
- Retained during issue resolution and only as needed for subsequent quality checks. Sensitive attachments unrelated to the issue should not be submitted; if found, access will be restricted as needed.
Access controls
SoarMac reduces the risk of unauthorized access through segregation of duties, least privilege, authentication, critical-action logging, transfer safeguards, anomaly monitoring, and regular permission reviews. Only personnel responsible for delivery, security, billing, or support may access relevant records within the scope required for their tasks.
Security incident response
When an incident that may affect personal information or service data is identified, SoarMac first contains the impact, preserves necessary evidence, assesses the data categories and users involved, and takes corrective action. When notification is required, we will use the account email, console notifications, or another appropriate method to explain confirmed impacts and recommended actions.
User rights and policy updates
Users may request access, correction, or deletion, or object to specific processing.
To the extent permitted by applicable rules, users may request access to account-related information, correction of inaccurate content, deletion of data no longer needed, copies of available records, restriction of specific processing, or object to processing based on legitimate interests.
-
1
Submit a request
Sign in tothe console to submit a ticket, or email support@soarmac.com, specifying the request type and associated account.
-
2
Complete required verification
To prevent impersonation, SoarMac may ask you to verify control of the account, order-related information, or your authority to make the request, but will never ask you to send a password or private key.
-
3
Review and respond
SoarMac will process the request based on its scope, the status of the records, the rights of others, and applicable obligations. If it cannot be fulfilled in full, we will explain why and describe available alternatives.
Policy updates and dispute handling
This policy may be updated as services, data flows, or applicable requirements change. We will provide clear notice of material changes through the website, console, or account email, and update the version information on this page.
The laws of the jurisdiction where the platform's operating entity is based govern the interpretation of and disputes related to this policy. The parties should first try to resolve matters through support channels; if they cannot, the matter may be submitted to a court with jurisdiction in that jurisdiction. For more service rules, see theTerms of Service.