Data Processing Overview

A Privacy Policy You Can Understand and Use

This policy explains what data RunnerVM needs across its public website, console, dedicated physical Mac node orders, and support interactions, why it needs it, how long it retains it, and how you can submit a data request.

Current version Applies to current service processes
Scope Website, console, orders, and support
Contact options Email or console ticket
01

Scope and Roles

First, understand what this policy covers and who determines how different types of data are processed.

This policy applies to the public pages on runnervm.com, structured fields used to generate contact emails, the RunnerVM console, and order, billing, security, and support data associated with dedicated physical Mac nodes. It covers the relevant processes when you browse plans, create an account, configure an order, use a node, or submit a ticket.

For account details, order metadata, access logs, and support records, RunnerVM determines the purposes and methods of processing as needed to provide services, protect accounts, and meet applicable obligations. For project files, build scripts, and artifacts stored by users on rented nodes, users determine the content and purposes of use. RunnerVM does not read this content for product analytics or advertising.

The public contact page does not submit your entries directly to a separate message backend. If you use the email template feature, the fields are assembled locally and sent through the email client you choose; once delivered, the message becomes part of the support record and is handled under this policy. Existing users who need to link an order or node should use the console to submit a ticket whenever possible.

Public pages

We process page access, security logs, language preferences, and contact content sent voluntarily by users.

Console and orders

We process the data needed for account verification, configuration choices, billing status, node association, and service requests.

Support collaboration

We process ticket content, incident timelines, redacted logs, and materials needed to reproduce an issue.

02

What Data We Collect

The data we collect is triggered by account, order, and troubleshooting activity; we do not require information unrelated to the service.

Account and contact information

Email address, account verification status, interface language, and the name and contact details users provide in emails or tickets.

Order metadata

Order ID, Runner M4 configuration, rental period, selected region, add-ons, amount, currency, payment method category, and status changes.

Device and browser information

Browser type, operating system category, screen and language settings, session identifiers, and technical parameters needed for page compatibility and account security.

Access and security logs

Access time, IP address, request path, login result, session events, error codes, and signals of unusual activity, used for protection, auditing, and troubleshooting.

Support records

Ticket subject, issue description, linked order, node region, incident time, handling timeline, redacted logs, attachment names, and reply history.

Content submitted voluntarily

Project context, reproduction steps, screenshots, and redacted output that users voluntarily provide for plan selection, billing checks, security reports, or technical troubleshooting.

03

How We Use Data

Each processing activity supports a specific service action rather than an open-ended range of uses.

A

Provide dedicated physical node services

Create and verify accounts, record selected configurations, link orders with nodes, display service status, and provide the console features users need.

B

Process orders and reconcile billing

Create order records, confirm payment results, resolve billing discrepancies, retain necessary transaction evidence, and prevent duplicate charges or incorrect associations.

C

Protect account and network security

Identify unusual logins, automated abuse, unauthorized access attempts, and activity that may affect node or network stability, while retaining audit trails.

D

Respond to support and security requests

Reproduce issues, verify timelines, assess impact, advance ticket handling, and provide submitters with actionable troubleshooting or remediation results.

E

Meet applicable obligations

Retain necessary billing and compliance records, respond to requests with a valid legal basis, and maintain records that explain orders, access, and processing activities.

F

Improve products and reliability

Aggregate page errors, feature usage, and support issue types to fix compatibility problems, improve documentation, and reduce recurring incidents. This analysis prioritizes aggregated or de-identified data.

04

Data Sharing and Processors

We share only the data necessary to complete infrastructure, payment, security, and compliance tasks.

RunnerVM does not sell account details, order records, or support content, and does not provide this data to third parties for their independent advertising profiles. Processors access only the data relevant to their task when it is required in the service chain.

Processor Categories, Required Data, and Use Limits
Processor category Data that may be involved Limited purpose Controls
Infrastructure and hosting Network identifiers, system logs, service configuration, backup metadata Deliver website, console, and physical node services Access tiers, least privilege, and service agreements
Payment processing Order number, amount, USD currency, payment method category, and processing status Complete payments, refunds, reconciliation, and risk assessment Only transaction-required fields are transmitted; payment credentials are handled by the relevant process
Security protection IP address, request characteristics, login events, and anomaly signals Prevent attacks, account takeover, and network abuse Access auditing, purpose limits, and retention-period management
Professional and compliance support Necessary order, billing, security, or dispute materials Audits, compliance responses, and rights requests Confidentiality duties, authorization limits, and data minimization

Processors are bound by contractual or equivalent arrangements that impose purpose, confidentiality, security, and deletion requirements. If the business structure changes, data transfers must still follow the purposes described in this policy and applicable legal requirements, with necessary notice and safeguards.

For requests from public authorities that have a valid legal basis and clearly defined scope, RunnerVM verifies the requester, authority, data scope, and procedural requirements, provides only the data legally required, and retains necessary processing records.

05

Retention, Archiving, and Deletion

Retention periods are determined by data purpose; we do not keep every record indefinitely in one system.

Account details

Retained during the account lifecycle for login, verification, and service management. After account closure, we retain only what is needed for unsettled orders, security incidents, disputes, or applicable obligations.

Trigger: account closure or completion of identity-link cleanup

Order and billing records

Retained for the period needed to fulfill orders, reconcile accounts, process refunds, maintain financial records, and handle disputes. Different fields may have different retention periods based on their purposes.

Trigger: order completion and completion of necessary reconciliation

Security and access logs

Retained while needed to detect anomalies, investigate security incidents, prevent repeated attacks, and support audits, with detail reduced as risk declines.

Trigger: risk window ends and no incident remains open

Support records

Retained until the issue is closed, recurrence risk is reduced, and necessary quality review is complete. Materials directly related to an order or security incident may be retained under the corresponding category.

Trigger: ticket closure and completion of necessary review

User data on nodes

Managed by the user during the rental period. After the order ends, RunnerVM revokes access credentials through the node recovery process and processes user data on the device. Users should export any needed files before expiration.

Trigger: order end and entry into the device recovery process

Rights request records

We retain the request, identity verification, processing scope, outcome, and necessary communications to demonstrate proper handling and prevent unauthorized disclosure.

Trigger: request completion and expiry of the period needed to demonstrate compliance

After the retention period ends, data is deleted, irreversibly anonymized according to its medium and purpose, or isolated where required by applicable law. Isolated data is not reused for marketing, product profiling, or analysis unrelated to the original retention purpose.

Deletion from backup systems may occur as backups are rotated. During this period, backup copies are access-restricted and not used for routine business processing. If a backup is restored, the deletion rules already in effect are reapplied.

06

International Processing and Security Measures

Regional nodes and support collaboration may involve international processing, with safeguards applying throughout the data flow.

RunnerVM operates on a regional basis. When users select a node, access the console, or submit a support request, account, order, network, and support data may be transferred to or processed outside their location. Processing locations are determined by node selection, infrastructure arrangements, payment workflows, security controls, and support needs.

When international processing occurs, RunnerVM assesses the data category, purpose, recipient access, and applicable requirements, reducing risk through contractual restrictions, data minimization, transfer safeguards, and access auditing. Selecting a node region does not mean that all account and billing data is processed only in that region.

Access controls

Access is granted by role and task, administrative permissions are restricted, and access is revoked when responsibilities change or collaboration ends.

Transfer protection

Encrypted connections are used for data transfers across the website, console, and support processes to reduce the risk of interception or alteration in transit.

Log auditing

Key login, permission, order, and support actions are recorded to detect anomalies and reconstruct necessary processing timelines.

Least privilege

Only the fields necessary for a processing task are made available, reducing the copying of complete orders, logs, or support materials between systems.

07

Your Rights and Contact Process

You may ask about how your data is processed and submit specific requests to the extent permitted by applicable law.

Access

Confirm whether we process data relating to you and obtain available information about its categories, purposes, and recipients.

Correction

Request correction of inaccurate or incomplete account, contact, or order-association information.

Deletion

Request deletion of eligible data when it is no longer needed and there is no basis for continued retention.

Restricted processing

Request temporary restriction of specific processing activities while accuracy, processing grounds, or a dispute is being verified.

Object

Explain your reasons for objecting to processing based on a specific lawful purpose; we will assess them alongside the request and service security needs.

Request an explanation

Ask about data sources, retention logic, security measures, and important processing activities that may affect you.

Provide four details with your request

The clearer your request, the less back-and-forth is needed and the less unrelated data is disclosed.

  1. 01
    Specify the request type

    State whether you are requesting access, correction, deletion, restricted processing, an objection, or help with another data matter.

  2. 02
    Define what it relates to

    Provide the account email, relevant order ID, or ticket ID. Do not submit passwords or access tokens.

  3. 03
    Limit the data involved

    Specify whether the request concerns account data, orders, logs, or support records, and include the necessary time range.

  4. 04
    Complete identity verification

    We use verification appropriate to the risk of the request to confirm the requester’s identity and prevent disclosure to an unauthorized person.

Existing users can log in tosubmit a ticket through the console, so the request can be securely linked to the account and order. You can also email support@runnervm.com. We first confirm the request scope and identity, then search relevant systems, assess applicable limits, and provide the outcome.

Some requests may not be completed immediately because of billing records, security investigations, rights protection, or other applicable obligations. If this happens, we will explain the affected data categories, the basis for continued retention, and actionable next steps, without using retained data for unrelated purposes.

This policy and related data processing activities are governed by the laws of the jurisdiction where the platform operator is based. Any dispute related to this policy that cannot be resolved through communication will be handled by a court with jurisdiction in that jurisdiction.

If our data processing practices change materially, we will update this page and notify users in a manner proportionate to the impact of the change. Before continuing to use the service, we recommend checking whether the policy scope, data categories, or contact process has changed.

Need to verify specific data?

Start with the relevant order, ticket, or account

Existing users can link records through a console ticket. If you cannot log in or do not yet have an account, submit your request by email to support.