DATA PRIVACY

How Data Enters, Stays With, and Leaves MacWorker

This policy explains what data MacWorker processes to provide Cloud Mac services, why it processes it, how long it retains it, and how you can request access, correction, deletion, or restricted processing.

Website & Portal Orders & Payments Dedicated Physical Nodes
Processing Boundaries Purpose-Based Controls
Access & Ordering Account, device, order, and payment status
Node Delivery Configuration, status, connection, and activity logs
Retention & Deletion Tiered by order, account, and security needs
01

Scope

Which Service Activities This Policy Covers

This policy applies when you visit the MacWorker website, use the portal, create or manage orders, make payments, receive a dedicated physical Mac node, request technical support, or release a node. Whether you use a node through a browser interface or SSH, records used to deliver, protect, or manage the service fall within this policy.

Website & Portal

This includes page visits, account sign-ins, language and interface preferences, session security, browsing by model and region, order configuration, and actions performed in the portal.

Orders & Support

This includes order IDs, selected models, rental terms, node regions, payment status, billing records, and support content submitted by email or through a console ticket.

Node Management

This includes physical node configuration, delivery status, operating status, connection events, resource anomalies, security events, release time, and audit records related to service operations.

This policy does not change control of project files, source code, build artifacts, or user-deployed data. MacWorker processes related information only as necessary to deliver the service, investigate security issues, troubleshoot failures, or fulfill an explicit user request.
02

Data We Collect

Data Categories and Where They Come From

MacWorker collects necessary data at each service stage. You do not need to submit project credentials, private keys, passwords, payment credentials, or source code for a standard inquiry. The categories below explain where data originates and which service action it supports.

Data Category Typical Content Source or Context Primary Use
Account Information Email address, account ID, verification status, interface language, and account security settings Registration, sign-in, identity verification, and account management Identify accounts, protect sessions, and send service information
Order Information Order ID; Forge M4, Studio M4, or Atlas M4 Pro model selection; region; term; storage; and parallel-use options Configuring orders, delivering nodes, renewing, or releasing services Confirm service scope, deliver delivery, and generate billing records
Payment Status USD amount, payment method category, transaction status, processing time, and transaction reference ID USDT-TRC20 or card payment processed by Stripe Confirm orders, reconcile transactions, and handle payment-related requests
Device & Access Logs IP address, browser and device type, access time, session ID, authentication result, and key portal actions Visiting the website, signing in to the portal, initiating a connection, or changing service configuration Security protection, anomaly detection, troubleshooting, and auditing
Support Records Ticket category, node ID, incident time, error summary, reproduction steps, email correspondence, and attachments Sending email or submitting a console ticket Troubleshoot issues, track resolution, and preserve service context
User-Submitted Content Purchase requirements, team size, workload, diagnostic output, privacy requests, and identity-verification materials Pre-sales evaluation, technical support, billing inquiries, or rights requests Respond to requests and verify the requester’s relationship with the account

Keep diagnostic materials to the minimum needed to resolve the issue. Before submitting logs, remove project keys, passwords, complete source code, personal communications, and unrelated data.

03

Processing Purposes and Grounds

Every Processing Activity Has a Defined Purpose

MacWorker processes data to perform its service contract, protect security, comply with applicable legal obligations, act on user consent, or pursue legitimate operational interests. The applicable ground depends on the data category, the rules applicable where the user is located, and the processing context; no blanket purpose covers every activity.

Service Delivery

Create Orders and Prepare Physical Nodes

We use account, order, region, term, and configuration data to assign a dedicated physical machine, provide connection details, display node status, and carry out configuration actions initiated in the portal.

Security

Protect Accounts, Portals, and Nodes

We use authentication results, device information, access logs, and activity records to identify suspicious sign-ins, unauthorized actions, malicious requests, and security events that may affect other systems.

Order Processing

Confirm Payment Status and Service Terms

We record transaction status, USD amounts, processing times, and order-linked information to activate services, reconcile transactions, resolve billing issues, and maintain necessary order records.

Support Response

Troubleshoot Node and Connection Issues

We combine node IDs, incident times, connection methods, error summaries, and necessary logs to reproduce issues and help subsequent support staff understand the troubleshooting already completed.

Legal Obligations

Retain Necessary Records and Respond to Valid Requests

Where required by applicable rules, we retain records of orders, payment status, security events, and rights requests, and verify and process requests with a valid basis.

Product Improvement

Analyze Failure Patterns and Usage Flows

We prioritize aggregated or de-identified data to identify page errors, node-delivery bottlenecks, and frequent support issues. When raw records are no longer needed, they enter deletion or de-identification workflows.

If a new processing purpose is incompatible with the original purpose, MacWorker will first assess whether additional notice, consent, or a choice is required before beginning that processing.
04

Payment Data Boundaries

Payment Processing and Order Records Are Managed Separately

MacWorker supports only USDT-TRC20 and Visa / Mastercard / Amex (via Stripe), with all transactions settled in USD. The gateways available at checkout are determined by the result returned by the backend interface.

Card Payments

Processed by Stripe

Card payment information is processed by Stripe during checkout. MacWorker retains only the status and records needed to complete orders, confirm transactions, and handle billing inquiries, such as the order ID, USD amount, payment result, processing time, and transaction reference ID.

Crypto Asset Payments

USDT-TRC20

Crypto asset payments use USDT-TRC20. Order records may include payment-address association status, transaction reference ID, confirmation status, USD settlement amount, and processing time to verify whether an order qualifies for delivery.

Payment Information MacWorker Retains

  • 01The relationship between order IDs and transaction reference IDs
  • 02Billing amounts in USD, payment status, and processing time
  • 03Correspondence needed to process refunds, disputes, reconciliations, or billing support
  • 04Order and transaction status records required by applicable rules
05

Node & User Content

Users Manage Projects on Dedicated Physical Machines

Each MacWorker node is a dedicated physical machine assigned to a single order, not a virtual machine. Users decide which projects, dependencies, build caches, credentials, and data to deploy, and are responsible for managing team access, project backups, and cleanup when leaving.

Receiving a Node

Establish Access Boundaries First

Verify the node ID and connection details, configure separate SSH keys for different purposes, limit credential sharing, and record which members have access.

During Use

Control What Enters the Node

Upload only the code, models, assets, and certificate files needed for the task. Keep separate backups of critical projects, and regularly review disk usage, sign-in records, and automation permissions.

Before Release

Export, Revoke, and Clean Up

Export build artifacts and necessary logs, migrate project data, revoke team access, delete credentials, caches, and temporary files, and confirm that no task still depends on the node.

Support Troubleshooting Principle:Start by submitting the node ID, incident time, connection method, error summary, and reproducible steps. Provide additional diagnostic materials only when these details are insufficient and support staff explicitly request them, and then share the minimum necessary scope.
Do Not Submit:Private keys, passwords, payment credentials, complete project repositories, unrelated user data, or configuration content that could directly access production systems.
06

Retention & Deletion

Different Records Have Different Exit Conditions

Data does not automatically share the same retention period simply because it belongs to one account. MacWorker determines retention based on whether the service is ongoing, whether order and payment records remain necessary, whether security risks have ended, whether support requests are closed, and whether applicable rules require continued retention.

Account

Retain Necessary Information While the Account Exists

Account IDs, email addresses, verification status, and security settings are generally used while the account is active. After receiving an account-closure request, we check for incomplete orders, billing matters, security events, and open tickets before deleting or isolating account information no longer needed.

Orders

Retain as Required for Transactions and Records

Order IDs, models, regions, terms, add-ons, USD amounts, and payment status may be retained after service ends to support reconciliation, transaction inquiries, dispute handling, and applicable recordkeeping obligations. They are deleted or de-identified after the retention period ends.

Logs

Retain as Needed for Security and Troubleshooting

Access, authentication, node-status, and key activity logs are retained and access-controlled according to risk. Records related to an ongoing security investigation may be isolated; once the investigation is complete and the records are no longer needed, they enter deletion or de-identification workflows.

Support

Retain Context and Outcomes

Email and ticket records support follow-up, handoffs, and identification of recurring issues. When attachments contain diagnostic data, retention is reduced according to the issue status and ongoing need; attachments no longer needed should be deleted first.

Node Release

Users Export First; the Platform Then Releases the Node

Before releasing a node, users should export and clean up projects, build artifacts, keys, and logs. Once the node enters the release process, related access ends, while service configuration and node-association records are handled separately according to operational, security, and recordkeeping needs.

A deletion request does not mean that every record is removed immediately. MacWorker first verifies the requester’s identity and distinguishes deletable information from information needed to complete ongoing services, records that must be retained under applicable rules, and evidence temporarily isolated to protect account security.
07

Sharing & International Processing

Data Is Shared Only as Needed for a Defined Task

MacWorker provides relevant data to service providers only as necessary for service delivery, security protection, payment processing, or responding to valid legal requests. Sharing must match the task and is subject to access controls, confidentiality, and security requirements.

Service Delivery

To prepare, connect, and manage physical nodes in the selected region, we process order configuration, node IDs, operating status, and necessary contact information.

Security Protection

To detect unusual access, block malicious traffic, and investigate security events, we process device, session, network, and key activity records.

Payment Processing

Card payments are processed by Stripe; USDT-TRC20 transactions are processed for transaction status and reference IDs needed to confirm orders.

Valid Requests

After verifying the source, authority, scope, and valid basis of a request, we provide only the data necessary to satisfy it and record the processing.

How International Processing Occurs

When users select nodes in Singapore, Japan (Tokyo), South Korea (Seoul), Hong Kong, or the Eastern United States, node-management and connection-related data may be processed where required to deliver the service. Support, payment, and security services may also involve controlled processing in different locations.

Controls We Apply

MacWorker limits fields by purpose, controls staff access, keeps necessary audit records, and applies contractual, security, and organizational measures as required. When submitting support materials, users should also avoid including data unrelated to the issue.

08

Your Rights & Contact

Submit a Request, Verify Identity, Receive the Result

Under rules applicable to you, you may request a copy of your personal information, correction of inaccurate data, deletion of data no longer needed, restriction of specific processing, object to processing, or additional information about data handling. What can be fulfilled depends on the request, account status, and necessary recordkeeping obligations.

ACCESS

Access & Explanation

Specify the account, order, or support records you want to review, and whether you need a data copy or an explanation of processing activities.

CORRECT

Correction & Supplementation

Identify the inaccurate field, its current value, and the proposed correction. Some account information can be updated directly in the portal.

DELETE

Deletion & Closure

Specify the data categories to delete and whether you also request account closure. Any incomplete orders must be addressed first.

RESTRICT

Restrict Processing

Describe the processing activity you want paused, your reason, and the relevant time period so we can assess whether the data can be isolated.

OBJECT

Object to Processing

Identify the specific processing purpose and the reasons relevant to your situation. MacWorker will assess whether there is a necessary basis to continue processing.

PORTABILITY

Structured Export

Where applicable and technically feasible, you may request relevant personal information you provided in a commonly used structured format.

Request Process

  1. 1
    Choose a Channel

    Email support@macworker.com or sign in to the console to submit a ticket. For existing orders or node-related requests, use a ticket whenever possible so the request can be securely linked to your account context.

  2. 2
    Describe the Scope

    Provide your account email, relevant order ID, request type, data scope, and desired outcome. Do not submit passwords, private keys, or payment credentials by email or ticket.

  3. 3
    Complete Identity Verification

    MacWorker will verify account control, order information, or other minimum necessary details based on the sensitivity of the request. Requests made by an agent also require verification of the agent’s authority.

  4. 4
    Receive the Result

    The result will explain completed actions, information still needed, parts that cannot be completed immediately, and the reasons. Complex requests may be completed in stages.

PRIVACY REQUEST

Prepare a Data Request

If you have an account or order, submit the request type and relevant order ID through a console ticket. For general privacy inquiries, email support@macworker.com.