Data Processing Overview

Privacy Policy

This policy explains what information BookaMac processes during website visits, dedicated physical Mac mini orders and support, and how you can access, correct, delete or restrict that processing.

Effective date Covered servicesWebsite, console, orders and support
01

Scope

This policy applies to the bookamac.com website, the BookaMac console, and information processing carried out directly to create, deliver, renew and manage cloud Mac orders. It also covers presales inquiries, technical investigations, security reports, privacy requests and other communications directly related to support.

BookaMac provides dedicated physical Mac mini instances assigned by order. We limit the information we process to what is needed to deliver the physical node, verify access, record order status and resolve service issues. Code, build artifacts, certificates, logs and business data stored by users on a node are organized and managed by the users themselves. BookaMac does not collect this content as routine support material unless a user voluntarily submits it to the support team.

Covered by this policy

Website interactions, account and contact details, order records, payment status, console activity, operational logs required for connections and support communications.

Explained independently by other parties

Code repositories, automation platforms, development tools and other third-party services connected by users are governed by their own data-processing rules.

02

What Information We Collect

We do not expand our collection for unspecified future uses. The fields collected depend on the feature you access, the order you create and whether you request support.

Account and contact information

This may include your name or preferred form of address, email address, account identifier, login verification records and any team or organization details you choose to provide.

Order and configuration information

This may include the order ID, selected model, chip, memory, storage add-ons, rental period, node region, delivery status and renewal status.

Payment and billing status

This may include the amount due, USD settlement records, payment method type, transaction status, reconciliation identifiers and information needed to process refunds or disputes.

Device and access logs

This may include access times, IP addresses, browser or client type, login results, unusual requests, session records and security event records.

Support communications

This may include ticket subjects, issue descriptions, order IDs, when an issue occurred, region, troubleshooting steps and redacted logs you voluntarily submit.

Content you submit voluntarily

This may include presales requirements, security reports, partnership inquiries and privacy requests. Do not send private keys, complete connection credentials or unrelated data in emails or tickets.

Redact information before submitting support materials

Keep error codes, timestamps and necessary context, but remove keys, access tokens, complete credentials, private repository content and personal information unrelated to the issue.

03

How We Use Information

Each processing activity must serve a clear purpose. We may process information to fulfill orders, respond to requests, protect the service, comply with legal obligations or, where appropriate, with your consent.

  1. Service delivery

    Create and manage cloud Mac orders

    Confirm the model, node region, rental period and add-ons, then complete delivery, renewals, expiration handling and service-status communications.

  2. Access verification

    Protect accounts and console activity

    Perform login verification, manage sessions, identify unusual access and conduct necessary identity checks to reduce the risk of unauthorized activity.

  3. Support handling

    Troubleshoot connection, configuration and order issues

    Use the order ID, region, timestamps and redacted logs to reproduce issues, record progress and respond to the requester.

  4. Security protection

    Detect and limit abuse or attacks

    Analyze unusual requests, failed logins and security events to protect normal use of the website, console, physical nodes and other users.

  5. Operational improvement

    Improve workflows and page usability

    Use aggregated or de-identified information to understand page performance, common support topics and bottlenecks in delivery workflows, without creating user profiles unrelated to the service.

  6. Legal obligations

    Maintain records, support audits and respond to lawful requests

    Where required, retain necessary billing, security and dispute records and respond appropriately to requests with a valid legal basis.

04

How Payment Information Is Handled

All orders are settled in USD. BookaMac supports only USDT-TRC20 and Visa / Mastercard / Amex via Stripe. Actual gateway availability is determined by the checkout flow.

On-chain payments

USDT-TRC20

To confirm and reconcile payments, we may process the payment address, transaction hash, amount, time and confirmation status. On-chain transaction records may be publicly retained by the relevant network, and BookaMac cannot delete records maintained independently by that network.

Card payments

Visa / Mastercard / Amex

Card payments are processed through Stripe. BookaMac receives only the status, amount, payment method type and transaction identifiers needed to complete orders, reconcile payments, process refunds and handle disputes. Users are not asked to send complete card details by email or ticket.

Payment-related information is used only to complete transactions, match orders, process refunds or disputes, identify fraud risks and meet billing obligations. Retention periods are affected by transaction records, dispute handling and applicable legal requirements.

05

Sharing and Processors

We do not sell personal information. We provide limited information to processors responsible for the corresponding task only when necessary to deliver services, process payments, send essential communications, protect security or comply with legal obligations.

Processor category, necessary information and purpose limitations
Processor category Information that may be involved Limited purposes
Infrastructure and hosting Service identifiers, node regions, operational logs and necessary technical metadata Operate the website, console, order system and service infrastructure
Payment processing Amount, currency, transaction identifiers, payment status and fields needed for risk assessment Payment confirmation, reconciliation, refunds, disputes and fraud protection
Communications support Email address, ticket content, notification status and necessary attachments Send verification messages, order notifications and support replies
Security and protection IP addresses, request characteristics, login results and security event records Detect attacks, limit abuse and investigate unusual access
Professional advisers and competent authorities Necessary records directly related to audits, disputes or lawful requests Comply with legal obligations, protect lawful rights or respond to valid procedures

We require processors to handle information only for agreed purposes and to apply safeguards appropriate to their responsibilities. A processor may not use information for unrelated purposes merely because it has technical access.

06

Retention, Archiving and Deletion

We do not apply one retention period to all information. Retention depends on order fulfillment, security investigations, dispute handling, billing records, support continuity and legal obligations. Once the purpose is complete and there is no reasonable basis for further retention, information is deleted, aggregated or de-identified.

While an order is active

Keep records needed for delivery available

Retain account, configuration, region, payment-status and support records to enable delivery, renewal, troubleshooting and access verification.

After an order ends

Reduce the information retained to what is necessary

Stop routine processing that is no longer needed and retain only limited records required for billing, security, disputes or legal obligations.

When the retention period ends

Delete or de-identify

Remove identifiable information from active systems. Backup copies leave use through established rotation procedures and are not used for new business purposes.

Users must migrate node data themselves

Before an order ends, users should migrate code, build artifacts, logs and other work data and delete files they no longer need. A privacy request does not replace data migration before order expiration.

07

Your Choices and Rights

To the extent permitted by applicable rules, you may request access to, correction of, deletion of or restricted processing of information about you. You may also ask about processing purposes, information categories, retention grounds and sharing scope.

Access

Confirm whether we process information about you and obtain a reasonably available copy or summary of the records.

Correction

Update inaccurate or incomplete contact, account or order-linked information and identify the fields that need to be changed.

Deletion

Request deletion of information that is no longer needed and has no basis for continued retention. Billing, security or dispute records may be retained where required.

Restrict processing

Request temporary limits on nonessential use of specific information while accuracy, an objection or a dispute is being reviewed.

What to include in a request

  1. Specify the request type

    State whether you want access, correction, deletion or restricted processing, and identify the relevant website, order or support communication.

  2. Provide minimal identifying information

    Provide a contact email address, the necessary order ID and an approximate time range. Do not send private keys, complete credentials or unrelated files.

  3. Complete identity verification

    To prevent disclosure to unrelated people, we may ask you to verify through the original contact email, a console session or an order-linked record.

  4. Receive the outcome

    We will explain the actions taken, the information categories that must still be retained and any parts that cannot be completed because of legal obligations or others’ rights.

Privacy requests can be sent to support@bookamac.com or submitted through theconsole ticket system. These are the privacy contact channels BookaMac provides externally.

08

Regional Processing, Policy Updates and Disputes

BookaMac serves users in different regions. Website, order, payment, security and support activities may involve processing across regions. When this occurs, we apply contractual safeguards, access controls, data minimization and security measures based on the purpose, information category, recipient responsibilities and applicable requirements.

How we update this policy

We will update this page and its effective date when the service scope, data-processing practices or applicable requirements change materially. Significant changes will be announced through the website, console notifications or the contact email linked to an order.

How to raise a question

To ask about the processing basis, retention scope or status of a rights request for a particular type of information, email support@bookamac.com or log in to theconsole and submit a ticket.

This policy and related disputes are governed by the laws of the jurisdiction where the platform operator is based. Disputes that cannot be resolved through reasonable communication may be submitted to a court with jurisdiction in that jurisdiction. This provision does not affect user rights that apply and cannot be waived under applicable rules.

This policy should be read together with theTerms of Service. The Terms of Service explain order formation, permitted use, billing, liability and termination; this policy specifically explains arrangements related to processing personal information.

Privacy request portal

Need to access, correct or delete information?

State the request type, associated email address and necessary order ID. Do not send private keys, complete credentials or unrelated business data in emails or tickets.