01Scope & Definitions
This policy applies to the following two sites operated by OnceMini and all services offered through them:
- oncemini.com (including all language subdirectories): our product, plans, and documentation site;
- Console: our ordering, billing, instance management, and ticketing console.
Terms in this policy are used as follows:
- "User" / "You"
- The individual registering an account or accessing the sites above, or the organization they represent.
- "Platform Data"
- Data we collect and process to operate the service, such as account email, payment records, and access logs. This policy governs platform data only.
- "Instance Data"
- Anything you create, store, or process on the Mac mini you rent from us — source code, build artifacts, certificates, keys, all of it. Instance data is not platform data. We do not collect it, read it, or back it up, and its security and legality are entirely your responsibility.
- "Retention Period"
- The maximum length of time a given category of data stays in our systems, counted from creation or service termination, after which it's deleted or anonymized.
By accessing our sites or registering an account, you confirm you've read and agree to this policy. If you disagree with any part of it, please stop using the service; you may request deletion of your existing data under Section 7.
02Information We Collect
We collect only the four categories of platform data listed below. The "when collected" and "required" columns are exhaustive — anything not listed here, we don't collect.
| Category | Details | Collected When | Required? |
|---|---|---|---|
| Account information | Registered email, password hash (bcrypt, never stored in plaintext), preferred display language | At sign-up and account settings updates | Required — account creation fails without it |
| Payment records | Order ID, amount, payment method type, transaction ID returned by the payment processor; we never store full card numbers or wallet private keys | At every order and renewal | Required for billing and invoicing |
| SSH public key fingerprint | SHA256 fingerprint of the SSH public key you register in the console (used to pre-authorize access at provisioning); the key itself is removed from the provisioning queue within 24 hours of delivery | When you add a public key in the console | Optional — password-based delivery is also available |
| Access logs | IP address, timestamp, request path, and User-Agent for requests to oncemini.com and Console | Automatically, on every HTTP request | Required for security auditing and abuse prevention |
Explicitly never collected: any files, running processes, network traffic content, or screen output from the instance you rent. Once your instance is provisioned, only you hold the SSH key and VNC password — there's no operator-side login path. Out-of-band management is limited to power-level actions (power on, power off, restart) and never touches the OS layer. SSH login logs on the instance are written by macOS to your own disk, and they're wiped along with everything else in the cancellation process — none of it is ever sent back to us.
03How We Use It
Each category of data is used only for the purpose disclosed at the time of collection. We don't build profiles, we don't run ads, and we don't sell data to anyone:
- Provisioning. We use your registered email to send SSH/VNC credentials and expiration reminders, and your SSH key fingerprint to verify the pre-authorized key matches what you registered.
- Billing. We use payment records to generate orders, invoices, and receipts, and to process daily/weekly/monthly/quarterly renewals along with refunds requested within 24 hours of a first order.
- Troubleshooting. When you file a support ticket about a console or network issue, we use access logs from the relevant time window to diagnose the failure — limited strictly to records tied to that ticket.
- Abuse prevention. We use access logs to detect credential-stuffing, scraping, and payment fraud. If risk controls trigger, we may temporarily restrict account actions and notify you via your registered email with instructions on how to appeal.
If we ever need to process data for a purpose beyond those listed here — say, a new feature requiring a new data category — we'll update this policy first and give advance notice per the mechanism in Section 8; continued use of the service after that constitutes your consent.
04Data Retention Periods
Retention periods by data category are listed below. Deletion runs automatically on schedule — there's no manual exemption process:
| Category | Retention Period | Clock Starts | At Expiration |
|---|---|---|---|
| Billing records (orders, invoices, transaction IDs) | 7 years | Date transaction completes | Permanently deleted |
| Access logs | 90 days | Date log entry is written | Permanently deleted, no archiving |
| Cancelled instance data | 72 hours | Service expiration or cancellation | APFS encryption key destroyed + full-disk overwrite |
| Account information | For as long as the account is active | — | Deleted within 30 days of account closure (except billing records) |
| SSH public key fingerprint | For as long as the key is registered | — | Cleared instantly when you remove the key in the console |
On the 72-hour window for cancelled instances: during this time you can still renew to restore service or download a snapshot from the console. Once the window closes, wiping starts immediately — first the APFS encryption key is destroyed to render the data unreadable, then the entire disk is overwritten. This process is irreversible and can't be extended on request. Technical details of the wipe process are on our Security Commitments page.
Billing records are kept for 7 years to satisfy accounting and tax record-keeping obligations in the jurisdiction where our operating entity is based. Closing your account does not shorten this retention period.
07Your Data Rights
You can exercise the following rights over your own platform data, via the paths and response times listed below:
| Right | How to Request It | Response Time |
|---|---|---|
| Export your data | Log in to the console and file a ticket under category "Data Export"; we'll provide your account information and billing records in a machine-readable format (JSON/CSV) | Within 7 calendar days |
| Correct your data | Email, password, and SSH public key can be self-edited in console account settings and take effect immediately; other fields require a support ticket | Instant for self-service; 3 calendar days for tickets |
| Delete your account | After settling billing and releasing all instances, file an "Account Closure" ticket in the console, or email support@oncemini.com from your registered address | Completed within 30 days of identity verification |
| Restrict processing / object | Email support@oncemini.com from your registered address, describing the processing activity and your reason for objecting | Response within 14 calendar days |
Two boundaries worth noting: first, closing your account doesn't shorten the statutory 7-year retention of billing records described in Section 4; second, all rights requests must be submitted through your registered email or a logged-in console session — that's how we verify your identity. We don't act on requests made on behalf of a third party unless accompanied by valid proof of authorization. Deletion requests that qualify under applicable data protection law (including GDPR) are processed through this same single workflow — there's no separate track.
08Cross-Border Transfers, Policy Updates & Contact
Cross-Border Transfers
Platform data (account, billing, logs) is stored centrally on servers in the jurisdiction where our operating entity is based. Instance data, on the other hand, lives exclusively on the physical disk of whichever node you choose (e.g. Singapore, Tokyo, Seoul, Hong Kong and US West) — we never replicate or back it up across nodes. Whichever node you pick, your data stays within that node's jurisdiction until it's wiped at cancellation.
Policy Update Notices
This policy may change as our features and applicable regulations evolve. Our update process is fixed:
- The new version is published on this page, with an updated version number and effective date at the top;
- For material changes (new data categories, extended retention periods, new sharing recipients), we email a summary of the change to every registered address at least 14 days in advance;
- For non-material changes (wording clarifications, formatting), we simply update the date at the top of this page without a separate email;
- Continuing to use the service after a change takes effect counts as acceptance of the new version. If you don't accept it, you can close your account before the effective date per the process in Section 7.
Contact Us
For any questions about this policy, rights requests, or complaints, reach us through:
- Email: support@oncemini.com (please use your registered email so we can verify your identity);
- Console: log in to Console and file a ticket under category "Account & Privacy."
General inquiries get a response within 2 business days; rights requests follow the timelines listed in Section 7. If you believe our handling of your data falls short of applicable regulations, you have the right to lodge a complaint with the data protection authority in the relevant jurisdiction.
Related reading: service terms and billing rules are covered in our Terms of Service; the technical implementation of data isolation and wiping is covered in our Security Commitments; for anything else, check Support or visit Contact Us.