Privacy Policy

What we collect, how we use it, and where it goes when you cancel — spelled out plainly

No legal jargon piled on top of jargon: we've written out exactly what data we collect, where the boundary sits on your machine, and how the full wipe works — so before you host your code, certificates, and project files with us, you know precisely what we touch and what we don't.

Effective: Jul 21, 2026 Current version: v2.1

1. Policy overview

The one-line version: we only collect the three categories of data required to run the service — account information, billing information, and access logs. Everything stored on the Mac mini you rent — every file, every line of code, every credential — we never read, scan, or back up. When you cancel, we destroy the disk encryption keys and run a full wipe.

HireVPS Cloud Mac ("the Platform," "we," "us") provides dedicated Apple Silicon dedicated hardware rental. That business model comes with a simple fact: once a machine is handed over to you, everything on it is yours. Our operations only need to know "who rented which machine, for how long, and how much they paid." This policy covers the Platform's website, the management console , and every machine instance you rent from us.

What we don't collect matters just as much: no contacts, no location data, no device fingerprinting, no indexing of your on-machine file system, and no logging of the commands you run or the software you use on your rented machine.

2. What information we collect

These three categories cover our entire scope of collection. Each is labeled with its purpose and retention period — anything not on this list, we simply don't collect.

2.1 Account information

  • Registration email and login credentials (passwords are stored as one-way hashes — we can never see the plaintext): used to log into the console, issue SSH/VNC credentials, and send service notifications.
  • Optional display name and team name: used only for console UI display and to address you in support tickets.
  • Two-factor authentication key (if enabled): used only for login verification, stored encrypted.

Retention: kept for the life of your account; permanently deleted within 30 days of account closure.

2.2 Billing information

  • Order records: machine model rented, region, billing cycle, amount, and timestamps — used for billing, invoicing, and dispute resolution.
  • Payment reference identifiers: charges are processed through a payment provider, and we only retain the transaction ID and payment status — we never store your card number, card expiry, or payment account password. That information is handled entirely within the payment provider's own systems and never touches our servers.
  • Invoice billing details (if you request an invoice): used solely to issue the corresponding invoice.

Retention: transaction records are kept as required by financial compliance rules; invoice details are archived together with the related order once issued.

2.3 Access logs

  • Console activity logs: login time, source IP, and administrative actions performed (e.g., OS reinstall, region migration) — used for account security auditing. If you ever suspect your account has been compromised, this log is what we use to investigate.
  • Website access logs: standard server request records (timestamp, path, and anonymized IP) — used for troubleshooting and abuse prevention.

Retention: console activity logs are kept for 180 days; website access logs are kept for 90 days, then automatically purged on a rolling basis.

Data collection scope at a glance
Data categoryTypical contentPurposeRetention
Account informationEmail, password hash, 2FA keyLogin & credential issuanceDeleted within 30 days of closure
Billing informationOrders, transaction IDs, invoice detailsBilling & invoicingKept per financial compliance rules
Access logsLogin IP, admin actions, request recordsSecurity audit & troubleshootingRolling deletion after 90–180 days
On-machine dataEverything on your machineNot collectedFully wiped on cancellation

3. Machine data boundary & wipe on cancellation

This is the most important section in this policy. You're renting a dedicated hardware machine, not a slice of a shared VM — which lets us draw a very clean boundary:

  • We don't read it. Once your machine is provisioned, we hold no login credentials for it. The initial password generated at first setup is deleted from our systems the moment it's handed to you, and once you change it, we have no way of knowing it at all.
  • We don't back it up. We take no snapshots or images of your disk, in any form. Any snapshot you create yourself in the console belongs to you, is accessible only to you, and is wiped along with the machine on cancellation.
  • We don't monitor content. We monitor hardware health — temperature, disk SMART status, network port status — to keep the service running 365 days a year, but we do not monitor the processes, files, or traffic content inside your machine.

3.1 The full-wipe process after cancellation

Once your rental period ends or you cancel, the machine goes through this fixed process, with every step logged by the system:

  1. Shutdown & credential recall

    A machine that isn't renewed by its due date is immediately shut down and disconnected from the network, entering a 72-hour grace period — renew within this window and everything is restored exactly as it was, with no data affected.

  2. Destroy the disk encryption key

    Once the grace period expires, the machine's FileVault full-disk encryption key is destroyed first. The instant that key is gone, the data on disk becomes cryptographically unrecoverable.

  3. Full erase & reset

    The disk is then fully erased using Apple's official recovery mechanism, the APFS container is rebuilt, and a clean copy of macOS is reinstalled — leaving no trace of the previous tenant.

  4. Wipe record generated

    A timestamped processing record is generated once the wipe is complete. Business customers can contact us to request the wipe certificate for a specific machine for internal compliance records.

Reminder: the full wipe is irreversible. Back up any code, certificates, or project files you want to keep before cancellation — once the 72-hour grace period is over, there's nothing we can do to get it back, no matter how much we'd like to help.

4. How data is used and shared

The data we collect serves exactly two purposes: getting the numbers right (billing, invoicing, fraud prevention) and solving your problems (support tickets, security audits, service notifications). We don't build user profiles, don't run ad targeting, and don't use your data for any analysis unrelated to the service.

On sharing, there's exactly one principle: we never sell, rent, or trade your personal data to any third party. Data leaves our systems only in these limited cases:

  • Payment processing: the minimum order information required to complete a charge is passed to our payment provider.
  • Legal requirements: when we receive a formal, properly issued request from a competent law enforcement or judicial authority, we verify its legitimacy and provide the minimum information required, notifying you where the law permits.
  • Business transfer: in the event of a merger or asset transfer, data would be transferred under equivalent protection obligations, with advance email notice to you and an option to close your account.

5. Cookies & access analytics

Cookies and local storage on our website are kept deliberately minimal:

  • Essential: the console login session cookie. Without it you can't stay logged in, and it cannot be disabled.
  • Preferences: remembers your chosen language and billing cycle display preference, stored locally in your browser and never uploaded to our servers.
  • Analytics: we use an open-source analytics tool self-hosted on our own domain, with IP addresses anonymized and no cross-site tracking. This data is never shared with any external ad network or analytics platform. If your browser sends a Do Not Track signal, our analytics script honors it.

We don't use third-party advertising cookies, and we don't embed any script that reports your browsing behavior back to an external platform.

6. Your rights and how to exercise them

Most of the following can be handled directly in the console, with no manual review required:

  • Access and correction: log into Order now and go to "Account Settings" to view and update your email, display name, and invoice billing details at any time.
  • Data export: from "Account Settings → Data Export" in the console, download every piece of data we hold about you — account details, order history, activity logs — in one click, packaged as machine-readable JSON.
  • Account closure: initiate closure directly in the console, or email support@hirevps.com to request it. Outstanding balances must be settled and all machines canceled first; we delete your account data within 30 days of closure (except transaction records required by financial compliance rules).
  • Withdrawing consent and complaints: if you have concerns about how your data is processed, reach us through the channels in Section 7 — we'll respond in writing with our findings within 15 business days.

7. Policy updates & contact channels

This policy may be updated as the service evolves. Here's how updates work:

  • Any revision updates the effective date and version number at the top of this page, and we keep a changelog of key updates that you can request from us.
  • Material changes (such as an expanded scope of data collection or new sharing scenarios) will be communicated to you by email at least 14 days before taking effect. If you don't agree with a change, you can cancel and close your account before it takes effect, with any unused prepaid balance refunded per the rules in our Terms of Service.
  • This policy is governed by the laws of the jurisdiction in which the Platform's operating entity is established, and any related disputes fall under the jurisdiction of the competent courts there.

For any privacy-related question, request, or complaint, write to us:

Dedicated privacy inbox

support@hirevps.com (put "Privacy" in the subject line; we reply within 12 business hours)

For more ways to reach us, see Contact Us; for common questions, check our FAQ hub first.