SFTPMAC is committed to protecting your personal data to the highest standards. This policy details how we collect, use, store, and protect your information, as well as your legal rights.
Important Notice:Please read this Privacy Policy carefully before using SFTPMAC services. Your account registration, access to the platform, or use of any services constitutes your full understanding and unconditional acceptance of all terms. If you disagree with any part of this policy, please stop using the services immediately.
SFTPMAC (hereinafter referred to as "the platform," "we," or "SFTPMAC") understands the importance of privacy to every user. This Privacy Policy (hereinafter referred to as "this policy") is formulated and published by SFTPMAC Global and its affiliated entities (collectively, "the SFTPMAC Group") and applies to all natural persons, legal entities, and other organizations (collectively, "users" or "you") accessing or using the cloud Mac compute rental and associated services (collectively, "services") provided through the SFTPMAC website, mobile applications, API interfaces, management console, and related digital products (collectively, "the platform").
This policy is formulated in accordance with the EU General Data Protection Regulation (GDPR), the Singapore Personal Data Protection Act (PDPA), and data protection regulations in other applicable jurisdictions. We commit to processing your personal information in a lawful and compliant manner, while reserving the right to maximize the utility of platform operational data and protect service operations and commercial interests within the extent permitted by law.
This policy applies to: (a) visitors to the SFTPMAC official website and all subdomains; (b) users registered with an SFTPMAC account; (c) customers purchasing or using any SFTPMAC paid services; (d) developers accessing the platform via API or programmatic interfaces; (e) end users using platform services indirectly through distributors or agents. This policy does not apply to third-party websites, applications, or services, even if accessed through links on the platform, for which SFTPMAC assumes no responsibility.
To provide you with secure, stable, and high-quality cloud Mac rental services and to fulfill our legal compliance obligations, SFTPMAC collects relevant information in various scenarios. The categories of data collected and their sources are listed in detail below.
| Data Category | Details | Collection Scenario |
|---|---|---|
| Account Registration Information | Email address, username, login password (encrypted), registration timestamp, registration IP | Upon account creation |
| Identity Verification Information | Real name, nationality, ID or passport number, photos of both sides of ID (for corporate customer KYC) | During high-value orders or compliance reviews |
| Contact Information | Phone number, correspondence address (for invoice and contract mailing), company name, Unified Social Credit Code | During profile completion or invoice issuance |
| Payment Information | Payment methods, last four digits of bank cards (full card numbers are processed by licensed payment institutions; SFTPMAC does not store them), transaction history, recharge and consumption records. | When purchasing services |
| Technical Preferences | SSH public keys, IP whitelist configurations, VNC access settings, custom scripts, and environment variables. | When configuring instances |
| Customer Support Communication | Support ticket content, live chat history, email correspondence, and call records (if applicable). | When contacting customer support |
When you access the platform or use the services, our system automatically collects the following technical information:
Under the premise of legality and compliance, we may obtain information about you from the following third-party sources:
SFTPMAC processes your personal information strictly in accordance with the principles of legality, fairness, and necessity, ensuring that every processing activity has a clear legal basis.
You can opt-out of non-essential marketing communications at any time through account settings or the unsubscribe link at the bottom of emails. Transactional notifications directly related to service operations (e.g., billing, security alerts, policy updates) are not affected by opt-out requests.
SFTPMAC does not sell, rent, or commercially trade your personal information. However, in the following circumstances, we may share your specific information with appropriate third parties:
We entrust strictly audited data processors to handle specific data under written instructions from SFTPMAC, requiring them to sign Data Processing Agreements (DPA) that comply with applicable laws:
Affiliated companies within the SFTPMAC Group may share necessary user information for legitimate business purposes such as unified account management, financial consolidation, and centralized risk control. All internal sharing is subject to this policy and implements data protection measures equivalent to those of external processors.
In the following circumstances, SFTPMAC will cooperate in accordance with the law to disclose relevant information to authorized authorities, exempt from the confidentiality commitments of this policy:
4.3 Legally Mandatory Disclosure
In the event of a merger, division, acquisition, reorganization, or transfer of partial assets involving SFTPMAC, your personal information may be transferred to the counterparty as part of business assets. In such cases, we will notify affected users in advance and ensure that the recipient adheres to data protection obligations at a standard equivalent to this policy. If the recipient cannot meet these requirements, we will request your re-authorization or deletion of the relevant data.
SFTPMAC uses cookies and similar tracking technologies (including Web Beacons, pixel tags, LocalStorage, SessionStorage, etc.) to ensure the platform functions properly, improve user experience, and support data analysis.
| Category | Description of Use | Can be Disabled |
|---|---|---|
| Strictly Necessary Cookies | Maintaining login sessions, CSRF protection tokens, and load balancing routing tags. Disabling these will prevent core platform functions from working properly. | Cannot be disabled |
| Functional Cookies | Remembering your language preferences, theme settings, console layout configurations, and other personalized settings to avoid repetitive configuration. | Optional |
| Analytical Cookies | Collecting anonymized page visit statistics, including traffic volume, bounce rates, and user flow paths, to improve the product experience (third-party analysis tools). | Optional |
| Security Auditing Cookies | Recording device fingerprint hashes and risk score data used to identify abnormal logins and protect account security. | Cannot be disabled |
| Marketing Cookies | Tracking ad source channels and assessing marketing performance (e.g., Google Ads conversion tracking). Does not track your browsing behavior across other websites. | Optional |
You can manage the activation status of optional cookies through the "Account Settings → Privacy Preferences" page on the platform. Additionally, you may restrict or delete cookies in your browser settings; however, please note that disabling strictly necessary cookies will prevent you from logging in or using platform services normally. SFTPMAC does not respond to browser-sent Do-Not-Track (DNT) signals, but respects the explicit preference settings made via the platform interface.
Our platform may integrate third-party analytical tools such as Google Analytics (with IP anonymization enabled) and Cloudflare Web Analytics, which set independent cookies on your device. For cookies set by these third-party tools, please refer to the respective third-party privacy policies. SFTPMAC assumes no independent responsibility for the cookie behaviors of third-party tools.
Your personal information is primarily stored in SFTPMAC data centers located in Singapore, Japan, Hong Kong, and the United States.
| Data Category | Default Retention Period | 6.2 Data Retention Period |
|---|---|---|
| Account Registration Information | 5 years after account cancellation | Extended in cases of outstanding disputes, legal investigations, or regulatory requirements |
| Payment methods, last four digits of bank cards (full card numbers are processed by licensed payment institutions; SFTPMAC does not store them), transaction history, recharge and consumption records. | 7 years after transaction completion (per tax regulations) | Retained indefinitely during formal litigation |
| Access Logs: | 180 days (per applicable laws) | Extended to 3 years |
| Resource Consumption Data: | 24 months after lease termination | Retained until final resolution during billing disputes |
| Support ticket content, live chat history, email correspondence, and call records (if applicable). | 3 years | Extended during complaints or disputes |
| Anonymized Statistical Data | Indefinitely (once no longer personal information) | —— |
Data exceeding the retention periods mentioned above will be deleted or thoroughly anonymized through secure wiping or physical destruction. Your request to cancel an account will be executed according to the periods described in this section, rather than immediate deletion of all data.
SFTPMAC has established a multi-layered security protection system covering the entire data lifecycle:
In the event of a data breach or security incident that may affect the security of your personal information, SFTPMAC will: (a) report to relevant regulatory authorities within 72 hours of incident confirmation (where applicable); (b) issue notifications to affected users via email or platform announcements when required by law or deemed necessary; (c) initiate incident response protocols and take necessary containment and remedial measures. However, inherent risks in internet transmission and data storage cannot be completely eliminated; SFTPMAC cannot provide absolute guarantees for any security measures, and users must acknowledge and assume a certain degree of residual security risk (see Section 11 for details).
In accordance with applicable data protection laws, you enjoy the following rights regarding your personal information. SFTPMAC is committed to responding to your reasonable requests within the timeframe prescribed by law (usually 30 business days after receipt of the request), while reserving the right to review the reasonableness of the request and verify your identity in accordance with the law.
You may submit a rights request through the following methods: (a) log in to your account and access the "Privacy and Data" self-service page; (b) send an email to [email protected] with the subject line "Data Rights Request"; (c) submit via the platform support ticket system. To protect your account security, we will verify your identity before processing the request and may require you to provide additional identification documents.[email protected], with the email subject clearly marked as "Data Rights Request"; (c) submit via the platform support ticket system. To ensure your account security, we will verify your identity before processing your request and may require you to provide additional identity documentation.
Under the following circumstances, SFTPMAC may partially or fully refuse your rights request: (a) responding to the request would harm the legitimate rights and interests of other individuals; (b) responding to the request would impede ongoing law enforcement or regulatory investigations; (c) the request is technically infeasible; (d) the request falls under specific exceptions clearly defined by law. For refused requests, we will provide an explanation and inform you of available appeal channels.
As a globalized cloud Mac rental platform, SFTPMAC operates services in multiple data centers worldwide; therefore, your personal information may be transferred to jurisdictions outside of your country or region for processing and storage.
For users from the European Economic Area (EEA), SFTPMAC relies on the following lawful transfer mechanisms approved by the European Commission when conducting cross-border data transfers:
If your jurisdiction has mandatory data localization requirements, SFTPMAC will take corresponding compliance measures in accordance with the law. Specific arrangements can be consulted via [email protected].[email protected] for consultation.
Special Note:Please read this section carefully. This section applies to all users renting SFTPMAC physical Mac instances and contains important descriptions of your usage behavior. By using the rental services, you are deemed to have agreed to all content in this section.
To ensure the security and stability of platform infrastructure, SFTPMAC implements monitoring at the platform level for rented instances, specifically including:platform-level monitoring, which specifically includes:
When the platform detects the following abnormal conditions and has reasonable grounds to believe that a violation has occurred, SFTPMAC reserves the right to initiate Enhanced Security Auditing on the involved instance. Specific measures include, but are not limited to: (a) capturing instance network traffic for security analysis; (b) performing forensic examination of instance disk images; (c) reviewing system log files. Trigger conditions include:
By using the SFTPMAC rental services, you explicitly commit to:
SFTPMAC services are intended for adults with full capacity for civil conduct. We do not provide account registration or service purchases to minors under 18 years of age (or the legal age of majority in your jurisdiction).
If you are a minor, please use this service under the supervision of a parent or guardian and with their explicit consent. If we discover that we have collected personal information from a minor without parental or guardian consent, we will take steps to delete the relevant data as quickly as possible and may suspend or terminate the associated account.
If you are a parent or guardian of a minor and find that your ward has registered an SFTPMAC account without authorization, please contact [email protected] immediately. We will cooperate with you to process account cancellation and data deletion.[email protected], and we will cooperate with you to process account cancellation and data deletion.
Legal Notice:This section contains important limitations on SFTPMAC liability. Please read it carefully.
11.2 Data Content DisclaimerHowever, given the inherent characteristics of the internet and information technology, SFTPMAC cannot guarantee absolute data security.SFTPMAC shall not be held liable for compensation, or shall limit its liability to the maximum extent permitted by applicable law, for data security incidents occurring in the following circumstances:
SFTPMAC provides hardware compute rental services. We assume no responsibility for the data content stored, processed, or transmitted on your rented instance. You assume full legal responsibility for all data and activities on the rented instance. SFTPMAC shall not be liable for any direct, indirect, incidental, special, punitive, or consequential damages arising from your use of the instance for any activity, regardless of the nature of the claim (tort, contract, or otherwise) and whether or not SFTPMAC has been advised of the possibility of such damages.
In no event shall the total aggregate liability of SFTPMAC to you for any breach of this Privacy Policy exceed the total amount of service fees actually paid by you to SFTPMAC in the 3 months preceding the claim event, and in no case shall it exceed 10,000 RMB (or equivalent currency). This liability cap applies to legal claims of any form and shall not be invalidated by the failure of the essential purpose of any limited remedy. Some jurisdictions do not allow the limitation of liability for implied warranties or certain types of damages; in such jurisdictions, the aforementioned limitations may not apply to you, and you may possess additional legal rights.be limited to the total service fees actually paid by you to SFTPMAC in the 3 months preceding the claim event, and in no case shall it exceed 10,000 RMB (or equivalent currency). This liability cap applies to legal claims of any form and shall not be invalidated by the failure of the essential purpose of any limited remedy. Some jurisdictions do not allow the limitation of liability for implied warranties or certain types of damages; in such jurisdictions, the aforementioned limitations may not apply to you, and you may possess additional legal rights.
12.1 Right to Amend Policy
You agree to fully indemnify and hold SFTPMAC, its affiliates, directors, employees, and agents harmless from any claims, losses, liabilities, damages, costs, and expenses (including reasonable attorney fees) arising from: (a) your violation of this Privacy Policy or the Terms of Service; (b) illegal or infringing activities on your rented instance; (c) damages suffered by SFTPMAC due to false information provided by you; (d) losses caused to SFTPMAC or third parties due to unauthorized access to your account resulting from your negligence.
SFTPMAC reserves the full right to modify, update, or replace this Privacy Policy at any time without your prior consent. The revised policy shall become effective upon its publication. We may amend this policy for reasons including: adapting to changes in laws and regulations, adding or adjusting service features, responding to regulatory requirements, improving data protection practices, or optimizing clarity of expression.We may amend this policy for reasons including: adapting to changes in laws and regulations, adding or adjusting service features, responding to regulatory requirements, improving data protection practices, or optimizing clarity of expression.
For material changes (such as substantially changing the purpose of data processing or introducing new categories of data sharing), we will notify you through one or more of the following methods:
For non-material changes (such as typo corrections, expression optimization, or updated legal references), SFTPMAC may not provide separate active notifications and will only update the "Last Updated" date at the top of the page.
Regardless of whether SFTPMAC has notified you of policy changes, your continued access to or use of any platform services after the policy update constitutes your full knowledge and unconditional acceptance of all contents of the revised policy. If you do not accept the revised policy, your sole remedy is to immediately stop using all platform services and cancel your account. To cancel your account, please send a request to [email protected].If you do not accept the revised policy, your sole remedy is to immediately stop using all platform services and cancel your account. To cancel your account, please send a request to [email protected] for graphical interfaces.
13.4 Right to Complain to Regulatory Authorities
The interpretation, validity, and dispute resolution of this policy shall be governed by the laws of Singapore (the place of registration of SFTPMAC Global).
For any dispute arising out of or in connection with this policy, both parties shall first attempt to resolve it through amicable negotiation. You may initiate the negotiation process by sending a written complaint to [email protected]. SFTPMAC commits to providing a substantive response within 15 business days of receiving the complaint.[email protected]. SFTPMAC commits to providing a substantive response within 15 business days of receiving the complaint.
If the dispute cannot be resolved within 30 days through amicable negotiation, both parties agree to submit the dispute to the Singapore International Arbitration Centre (SIAC) for final resolution by arbitration in accordance with the SIAC Rules then in effect. The seat of arbitration shall be Singapore, the language of arbitration shall be English, and the arbitral award shall be final and binding on both parties. However, the following matters are not subject to this arbitration clause: (a) emergency injunctive relief applications by SFTPMAC to protect its intellectual property or platform security; (b) complaints filed by you with data protection regulatory authorities as provided by law.
The arbitration clause of this policy does not affect your right to file a complaint with the competent data protection regulatory authority according to the law. EU users may complain to the Data Protection Authority (DPA) of their respective member state; Singapore users may complain to the Personal Data Protection Commission (PDPC); users in other regions may complain to their local competent data protection authority.
If you have any questions, comments regarding this Privacy Policy, or need to exercise your data rights, please contact us through the following channels. Our data protection team will carefully handle every request within the timeframes prescribed by law.
Please indicate "Privacy Policy" or "Data Rights Request" in the email subject line to ensure prioritized processing.
Complex requests (e.g., large-scale data export, cross-departmental coordination) may take up to 30 days, in which case we will notify you in advance.
Submit a ticket via the management console after logging in to synchronously track processing progress.
Applicable to GDPR data rights requests and privacy compliance matters.