1. Scope
This policy applies to the lemonvm.com website, the LemonVM console, support communications sent to support@lemonvm.com, and cloud Mac services configured and delivered by LemonVM for orders. Services run on dedicated Mac mini physical nodes: dedicated physical machines rather than virtual machines.
Browsing the website, creating an account, ordering a plan, processing billing, delivering a node, sending connection details, troubleshooting issues, and managing services may involve different categories of data. We process data only as needed for each action and do not automatically expand its use merely because you visit a particular page.
Code, materials, build artifacts, and tool configurations that users create, upload, or run on a physical node are generally user-managed work data. Except where necessary to deliver the service, respond to an explicit support request, address a security issue, or meet a legal obligation, we do not use this content for unrelated purposes.
2. Data We Collect
Account data includes the email address, login verification records, account status, and necessary identity-linking information that users provide. We do not require private keys, seed phrases, complete access tokens, or unredacted signing materials for ordinary pre-sales inquiries.
Order data includes the selected Lemon M4 or Lemon M4 Pro, rental term, node, SSD or Thunderbolt 5 add-ons, billing amount, payment status, order ID, and service status. Device and browsing logs may include access times, browser type, device category, network address, security events, and page interaction records.
Support records include issue descriptions, node details, occurrence times, reproduction steps, screenshots, and redacted logs submitted by users in email or console tickets. Submitted content may contain project names or environment details, so remove unrelated credentials, customer information, and other sensitive content before submitting.
3. Processing Purposes
Account data is used to create and maintain accounts, complete login verification, identify service ownership, send necessary order- or security-related notices, and handle account requests. Order data is used to confirm configurations, fulfill orders, generate invoices, deliver connection details, and manage service periods.
Device, browsing, and security logs help identify unusual access, prevent unauthorized actions, diagnose page or API issues, verify the source of service requests, and maintain system stability. Support records are used to reproduce issues, assess their impact, provide troubleshooting steps, and confirm resolution.
We may also use aggregated or de-identified operational information to improve service workflows, node-selection guidance, and help documentation. Where accounting, tax, compliance, or other legal obligations apply, we process necessary records only to the extent required by those obligations.
4. Payment Data
LemonVM supports USDT-TRC20 and card payments by Visa, Mastercard, or Amex processed through Stripe. All orders are settled in USD. The payment gateways actually available in the console are determined by the backend’s real-time response.
For USDT-TRC20, we may process the order amount, linked receiving address, transaction ID, on-chain confirmation status, and records needed for reconciliation. For card payments processed through Stripe, we process order associations, payment results, amount, currency, failure categories, and records needed for refunds or dispute handling.
Sensitive card details are collected and transmitted through the applicable payment process. LemonVM retains only payment results and related records needed to fulfill orders, reconcile transactions, handle disputes, and meet legal obligations. Do not send complete card details by email, ticket, or node session.
5. Node & Work Data
Users are responsible for managing code, media assets, keys, environment variables, caches, database copies, and build artifacts uploaded to a physical node. Before starting work, confirm that each item truly needs to be uploaded, and keep separate backups of important repositories, key copies, and final artifacts.
When submitting a support request, provide reproducible steps, the error time, the selected node, and redacted logs whenever possible. Do not paste private keys, seed phrases, complete access tokens, or unredacted signing materials. If screenshots contain paths, customer names, repository URLs, or credential fragments, redact unrelated content first.
When a user explicitly asks us to help with a node issue, we may inspect system status, resource usage, connection records, or user-specified logs only to the minimum extent needed to investigate the issue. After the investigation, related support materials are managed according to support-record retention principles and are not automatically used for other purposes.
6. Sharing & Cross-Border Processing
To provide payment processing, infrastructure operations, email delivery, security protection, and technical support, we may share necessary data with service providers performing these functions. Sharing is limited to the task at hand, with access restrictions, contractual requirements, and internal authorization controls used to reduce unnecessary exposure.
LemonVM offers five available node locations: Singapore, Tokyo, Seoul, Hong Kong, and the western United States. When users select a node, connect to one from their location, or request cross-region support, account data, order data, connection metadata, or user-submitted support materials may be transferred between the relevant processing regions.
When cross-border processing occurs, we apply necessary safeguards based on the data type, processing purpose, and applicable requirements. These may include limiting recipients’ use, controlling access, reducing transferred fields, and retaining necessary operational records. Choose a node that fits your project requirements and avoid uploading sensitive data unrelated to the task.
7. Retention & Deletion
Account data is generally retained while an account is active, with necessary records kept after closure for the periods required for security, dispute handling, and legal obligations. Order, billing, and payment-related records are retained as required for transaction reconciliation, financial records, and applicable legal obligations.
Support records are retained based on issue complexity, the need for follow-up review, and security impact. Security logs are retained only as needed to identify anomalies, investigate incidents, protect accounts and services, and meet necessary audit requirements; they are not kept as a long-term source for unrelated user profiling.
Users may submit deletion requests by emailing support@lemonvm.com or logging in to the console. We will verify the requester’s relationship to the account or order and explain which items can be deleted, corrected, or de-identified, and which must be temporarily retained for legal obligations, security investigations, or dispute handling.
8. Security Measures
We manage account and service data through tiered access controls, least-privilege permissions, login verification, credential protection, operational logs, and necessary network restrictions. Employees and service providers access relevant information only when performing authorized tasks and must follow confidentiality and purpose limitations.
Log audits help detect unusual logins, unauthorized configuration changes, suspicious requests, and events affecting service delivery. If an event may affect user data or service use, we assess its scope, limit further impact, preserve necessary evidence, and take corrective action.
Security is a shared responsibility between the platform and its users. Use separate credentials, promptly replace initial credentials, limit key permissions, lock unattended sessions, and avoid forwarding connection details through public channels. No technical measure eliminates all risk, so we continuously adjust controls as risks and services change.
9. User Rights & Contact
To the extent permitted by applicable rules, users may request access to account-related data, correction of inaccurate information, deletion of data no longer needed, or restriction of specific processing. You may also ask about a data item’s source, purpose, sharing scope, and retention principles. Some requests may require verification of account or order ownership.
Privacy questions can be sent to support@lemonvm.com, or you can log in to the console to submit a ticket. Include your account email, relevant order ID, request type, and the data scope you want us to address, but do not include passwords, private keys, seed phrases, or complete access tokens.
This policy is interpreted and applied under the laws of the jurisdiction where the platform operator is established. Disputes arising from this policy that cannot be resolved through communication may be submitted to a court with jurisdiction in that jurisdiction. After updates, we will make the effective version available through the website or console.