Privacy Policy

Privacy Policy

This policy explains what data M4Rent collects, why we collect it, how long we keep it, how to delete it, and the clear line between the data on your host's disk and the data we hold on our platform.

Version v1.2 · Effective Jul 20, 2026 · About 8 min read

In short: we only collect the account, billing, and connection metadata needed to run the service. The data on the SSD of the dedicated Mac mini you rent is yours alone — M4Rent never reads, scans, or backs it up unless you explicitly turn on snapshots.

01What We Collect

M4Rent collects only the three categories of data listed below. Each is collected at the moment the corresponding action takes place — we don't gather anything beyond that.

Category Fields Collected When
Account information Email address, salted password hash, two-factor authentication status, interface language preference At sign-up and when account settings change
Billing information Order number, machine model and region, billing cycle, payment gateway receipt reference (never the full card number), invoice details (if requested) At checkout, renewal, or invoice request
Connection logs Source IP, timestamp, target port, protocol type, and session duration for Portal logins and SSH/VNC sessions Every time a connection is established

Connection logs record metadata only — never session content. We don't log the commands you run over SSH, don't capture VNC screen output, and don't inspect the payload of your host's inbound or outbound traffic. Sensitive payment details such as card numbers and CVVs are handled entirely by the payment gateway; M4Rent's servers never see or store them.

02Host Data Boundary

This is the single most important point in this policy. Every Mac mini you rent is dedicated hardware — there's no hypervisor layer, and therefore no technical path for the platform to transparently read your disk. Specifically:

  • Ownership: everything on your host's SSD during your rental term (code, certificates, keys, build artifacts) belongs to you. M4Rent claims no rights over it whatsoever.
  • No access: our ops team doesn't hold login credentials for your host. You replace the initial delivery password on first login, and the platform keeps no copy of it.
  • No backups: by default, the platform makes no copy of your disk in any form. The one exception is the daily snapshot feature you can opt into from the Portal — snapshot data is encrypted and stored in the same regional storage cluster as your host, and you can delete it anytime from the Portal; it's purged from the storage cluster within 24 hours.
  • Faulty hardware replacement: if replacing a faulty component requires physical access to the machine, we'll notify you by email in advance. If the SSD itself is replaced, the old drive is handled per the wipe process in Section 5.

03How We Use Data

Data we collect is used only for the three purposes below, each mapped to a specific data category:

  • Billing and fulfillment: order and billing data drives charges, invoicing, expiration reminders, and renewal settlement.
  • Abuse prevention and security: connection logs help us flag anomalies like credential-stuffing attempts or port scanning. When risk controls trigger, we analyze connection patterns (frequency, source, target port) — never session content.
  • Service notifications: we use your email to send delivery credentials, incident notices, and expiration/wipe countdown reminders. Marketing emails are off by default — you have to opt in from the Portal, and every message includes a one-click unsubscribe.

M4Rent never sells, rents, or trades your personal data to third parties. Data is shared externally only in two situations: the minimum necessary sharing to fulfill the service (payment gateways processing charges, email providers delivering notifications), or in response to a legally binding, properly issued order from an authority with jurisdiction over the entity operating this platform — in which case we provide only the minimum data set the order requires and notify you where the law permits.

04Cookies & Analytics

This site and the Portal use only strictly necessary cookies. We don't integrate any third-party ad tech or cross-site tracking scripts:

Cookie Purpose Lifetime
Session token Keeps you logged in to the Portal 7 days
Language preference Remembers your chosen interface language 365 days

Traffic analytics run on a self-hosted script served from this same domain: IP addresses are truncated and anonymized before being written to storage, no cross-site profile is built, and nothing is linked back to your account identity. This data is used solely to evaluate page performance and improve content. If your browser sends "Do Not Track" (DNT), the analytics script skips logging that visit entirely.

05Data Retention & Deletion

Wipe timeline after host expiration

Once your rental term ends, data is handled on the timeline below, with an email notification at every step:

At expiration: host goes offline

SSH/VNC access is closed and the host is disconnected from the network. Data stays intact on disk, and renewing restores access immediately.

72-hour grace period

Renew within 72 hours of expiration and your data comes back fully intact — no extra charges during this window.

Past the deadline: full wipe

Starting at hour 72, we run a full-disk overwrite wipe and reinstall the OS. The data is unrecoverable, and any associated snapshots are deleted at the same time.

Platform-side retention periods

  • Connection logs: kept for 180 days on a rolling basis, then automatically deleted — except for records tied to an open security investigation, which are deleted within 30 days of the investigation closing.
  • Billing records: retained for the minimum period required for financial records under the law applicable to the entity operating this platform, then deleted.
  • Account closure: once you submit a closure request in the Portal, your account information and connection logs are deleted within 30 days. Every host under your account goes through the wipe process above. Only billing records that must be legally retained are kept, for the period noted above, and are stored decoupled from your identity.

06Cross-Border Transfer & Data Location

M4Rent's dedicated hardware nodes are located across four regions: Singapore, Tokyo, Seoul, Hong Kong, and Silicon Valley. Data location follows two rules:

  • Host data never leaves its region: the data and snapshots on your Mac mini's disk always stay in the region you chose at checkout — the platform never migrates it to another jurisdiction. If you switch regions, you're responsible for migrating the data yourself.
  • Platform data is centrally stored: account and billing information is stored in a data center located in the jurisdiction where the entity operating this platform is based. No matter where you access the Portal from, all data in transit is encrypted end-to-end with TLS 1.3.

Choosing a region means you understand your host data will be stored in — and subject to the data regulations of — that region's jurisdiction. The exact storage location for each region is listed on the Portal's order page.

07Your Rights & How to Exercise Them

You can exercise the following rights over your personal data held by us at any time: access (export a copy of all account and log data we store), correction (fix inaccurate account or invoice information), deletion (close your account and delete associated data), and restriction (opt out of non-essential notification processing). Submit a request through any of these channels:

  • Email support@m4rent.com with "Data Rights Request" in the subject line;
  • Open a ticket in the Portal under the "Privacy & Data" category;
  • Submit the form on our Contact page with "Other" selected as the topic.

We confirm receipt within 3 business days and complete processing with an emailed outcome within 15 business days. To prevent impersonation, export and deletion requests must be verified through your registered email address.

08Policy Updates

This policy may be updated as the service and applicable regulations evolve. Updates are handled at two levels depending on impact:

  • Material changes (expanded data collection, new use cases, longer retention periods): all users are notified by email at least 14 days before the change takes effect, and this page will display an old-vs-new version comparison at the top. Continuing to use the service after the effective date counts as acceptance; if you disagree, you may close your account before that date.
  • Non-material changes (wording clarifications, updated contact channels): this page is updated directly, along with a refreshed version number and effective date.

This policy is governed by, and any disputes arising from it are subject to the exclusive jurisdiction of the competent courts in, the jurisdiction where the entity operating this platform is based. Previous versions are available on request by emailing support@m4rent.com. Current version v1.2, effective Jul 20, 2026.