Privacy practices

Where your data comes from, how we use it, and when we delete it

This notice covers mangovm.com, emails generated through the contact page, support communications, and data processing related to console orders and service management. We explain data categories, purposes, sharing limits, and your choices by scenario.

Current version 2026.08 Effective date August 24, 2026 Contact support@mangovm.com
01

Scope

First, confirm which interactions this notice covers, so node data is not confused with website operations data.

This notice applies to visits to mangovm.com, browsing products and pricing, preparing inquiry emails through the contact page, communicating via support@mangovm.com, and personal data created when you order, manage services, or submit tickets in the console.

When a website button takes you to the console, page visits, account authentication, order linking, and support may form one continuous process. We use necessary identifiers to confirm the relevant account or order, but a normal page visit does not automatically read project files, source code, or work products on a dedicated physical node.

Website browsing Page requests, device and browser type, necessary security logs, and preferences.
Contact communications Content entered on the contact page and confirmed by you, your email address, and subsequent correspondence.
Order linking Account ID, order ID, selected configuration, rental term, node region, and billing status.
Support handling Ticket content, incident timeframe, redacted logs, handling steps, and outcome records.

Data you create, import, or process on a dedicated physical node is generally under your control. The platform processes it only as necessary to provide the service, respond to authorized support requests, handle security incidents, or meet applicable legal requirements.

02

Information we collect

Data comes from what you provide, what service workflows generate automatically, and technical records required for secure operation.

Account and contact information

Email addresses used for login or contact, account display information, language preferences, identity-verification records, and necessary authorization information provided when acting for a team.

Order identifiers

Order number, subscription status, model, rental term, node region, add-ons, amounts due and paid, and transaction result identifiers. Full card numbers are not stored in ordinary support records.

Device and technical logs

IP address, request time, browser and device type, session identifier, login result, security events, API errors, and necessary performance information.

Support records

Email and ticket content, issue category, node region, occurrence time, error summary, attachments, handling history, internal status, and final response.

Content you submit

Workload details, concurrency scale, toolchain versions, log excerpts, screenshots, and other information you choose to provide. Remove irrelevant personal data and sensitive material before submitting.

The contact page does not submit payment information directly on the website

The contact page organizes inquiry details and opens your system email client. Content enters the email process only after you confirm sending. Console orders and payment steps are handled separately.

03

Purposes of use

Each information type must serve a clear task; collecting data does not expand it to unrelated purposes.

  1. Provide and manage services Link accounts, process orders, show service status, deliver connection details, manage rental terms and add-ons, and record necessary billing results.
  2. Verify access and authorization Identify login attempts and verify that requests come from the account holder or an authorized user, reducing the risk of unauthorized account use.
  3. Process order-linking requests Use the order identifier to verify the model, term, region, payment result, and service status, preventing one account’s information from being disclosed to another.
  4. Protect website and service security Detect abnormal requests, abuse, malicious-code distribution, and unauthorized access, while retaining enough technical records to investigate incidents and restore service.
  5. Respond to support and improve processes Reproduce issues, record completed steps, coordinate node and billing investigations, and improve documentation and product workflows based on recurring faults.
  6. Meet legal obligations Retain necessary transaction and compliance records, respond to legally authorized requests, and handle claims related to the service relationship.

If we plan to use existing information for a purpose materially different from the original context, we first assess compatibility, necessity, and impact. Where separate consent is required, we provide a clear choice rather than bundling consent with non-essential features.

04

Legal bases and choices

Different scenarios may rely on contract performance, legitimate interests, legal obligations, or your consent.

Processing scenarios, legal bases, and user choices
Processing scenario Primary basis Necessity and choice
Account authentication, order processing, node delivery, and service management Performance of a contract or steps necessary before ordering Core fields are required to complete ordering and delivery; without them, we may be unable to link an order or verify a service request.
Login security, abnormal-request detection, and incident investigation Legitimate interests in protecting the platform, customers, and services Only necessary risk-related records are retained. You may object, and we will assess the balance against applicable rules.
Transaction records, compliance checks, and rights claims Compliance with applicable legal obligations or establishment, exercise, or defense of legal claims Information required by law or dispute handling may not be deleted immediately on request, but its use and access will be restricted.
Optional analytics, non-essential preferences, or specific communications Consent obtained where applicable You may refuse or withdraw consent. This does not affect processing already carried out or core features that do not rely on that consent.

How required and optional fields differ

Required fields support account verification, order linking, billing checks, security controls, or support diagnosis. Optional fields usually add workload context, preferences, or reproduction details. Labels, descriptions, or workflow placement indicate the difference; you may submit the minimum first and let support confirm what else is needed.

Withdrawing consent, declining optional analytics, or leaving optional fields blank does not change a confirmed order’s configuration or rental term. Requests involving account ownership or order records still require enough information for identity verification.

05

Sharing and processors

Information is processed by service providers only in the categories and scope needed for a specific task.

Infrastructure and hosting

Technical infrastructure needed to host the website, account services, databases, backups, and node management. Access is role-limited and necessary audit records are retained.

Communications and support

Services used to send verification messages, receive support email, maintain tickets, and deliver service notices. Only addresses, subjects, content, and status information needed for communication are processed.

Payment and billing

Used to confirm payment results, amounts, currency, and transaction status. We receive result identifiers needed for order reconciliation and do not require full payment credentials in ordinary support communications.

Security and compliance support

Used to detect malicious requests, investigate incidents, complete audits, or respond to legally authorized requests. Disclosure is checked against purpose and necessity.

Processors must handle information according to agreed purposes, confidentiality requirements, and security measures, and may not use it independently for unrelated purposes. We assess access controls, incident response, and data-return or deletion arrangements based on the processing, risk, and available information.

If our business structure changes, relevant information is transferred only as necessary for transaction evaluation, service continuity, and legal obligations. Recipients must continue to meet applicable data-protection duties.

06

Cross-border and regional details

Node location, website processing location, and support-team access location are three different concepts.

MangoVM offers nodes in Singapore, Tokyo, Japan, Seoul, South Korea, and Hong Kong. Your selected node region determines where the dedicated physical node is provided, but does not mean account data, orders, email, tickets, or security logs remain permanently in that region.

To provide website, authentication, order management, communications, security monitoring, and support, information may move between regions or be accessed by processors in the relevant regions. We use measures such as contractual safeguards, access restrictions, transfer protections, log audits, and vendor assessments as required.

Node region Determines where the rented physical node is deployed.
Business records May be processed across regions for order, support, and compliance needs.
Access control Restricted by role, task necessity, and authorization scope.

If you require regional handling for specific information, email support@mangovm.com before ordering with the data category, business restriction, and target region. The team will confirm what is feasible; node availability is not a permanent regional commitment for all related information.

07

Retention and deletion

We do not apply one period to all data. Retention depends on the service relationship, risk, and legal requirements.

Retention criteria for key information categories
Information category Usually retained until Conditions for extended retention
Account and service relationship records The account’s active period and a reasonable period after closure, settlement, and necessary verification Unresolved orders, disputes, security incidents, or valid legal requirements
Order and billing records The period needed for transaction reconciliation, financial records, and applicable compliance obligations Refunds, payment disputes, audits, or rights claims remain unresolved
Support emails and tickets The period needed to resolve issues, review handling quality, and identify recurring faults The ticket concerns a security incident, ongoing fault, or unresolved dispute
Security and access logs The period needed to detect anomalies, investigate incidents, and validate control effectiveness The logs relate to a confirmed incident, unauthorized access, or investigation request
Optional analytics records A shorter period needed for trend analysis, followed by aggregation, deletion, or de-identification Continued retention remains justified and necessary

Once the retention purpose ends, information is deleted, de-identified, or placed in access-restricted archives until any mandatory retention period ends. Deletion may need to cover active systems and rotating backups; before backups are overwritten, the data is not returned to routine business use.

Before service expiry, migrate project files, logs, build artifacts, and other data you need to keep from the dedicated physical node. Deleting account records does not replace node-data migration or automatically cancel incomplete orders, disputes, or legal obligations.

08

Your rights and contact

Subject to applicable rules, you may request access, correction, deletion, restriction of processing, or exercise other applicable rights.

  1. 1

    Define the request scope

    State the right you wish to exercise, related account email, order identifier, information category, and approximate timeframe. Do not send passwords, private keys, or signing certificates by email.

  2. 2

    Complete identity verification

    To prevent others from obtaining or deleting your information, we use login status, control of the email address, order links, and request risk for necessary verification. We do not ask for unrelated information.

  3. 3

    Assess scope and exceptions

    We confirm whether the request can be fulfilled, whether it affects others’ rights, and whether retention is required for transaction records, security investigations, disputes, or applicable law.

  4. 4

    Receive the outcome

    The result is sent to the account-linked email or console ticket. If the request cannot be fully fulfilled, we explain the affected categories, reason for restriction, and available next steps.

You can submit a request by emailing support@mangovm.comor by logging in to theconsole and submitting a ticket. If the request concerns an active service, we recommend using a ticket first so the order and handling records can be linked securely.

Where applicable rules permit, you may object to specific processing based on legitimate interests, withdraw consent, request data in a portable format, or contact an authorized supervisory authority. The applicable scope depends on the request and the rules where you are located.

09

Cookies and technical logs

Necessary technical information supports security and sessions; optional analytics helps us understand page performance. They are not treated the same way.

Server technical logs

Even if your browser rejects optional Cookies, servers may record request time, IP address, request path, response status, browser type, and security decisions to deliver pages, detect faults, and block attacks. These logs are processed as necessary for security and operation and are not optional analytics preferences.

You can delete Cookies, block non-essential storage, or adjust site permissions in your browser. Deleting necessary session identifiers usually signs you out and requires access verification again. Browser settings do not automatically delete existing orders, tickets, or security-incident records.

10

Updates and effective date

Version changes include an effective date; material changes are communicated in a manner proportionate to their impact.

This version takes effect on August 24, 2026. The version number and effective date at the top of the page identify the rules you are reading.

If processing purposes, information categories, recipients, retention principles, or rights procedures materially change, we will update this page and, based on impact, notify you through the website, account-linked email, or console. New processing requiring consent will not treat continued browsing alone as consent.

You can request historical versions at support@mangovm.com. Put “Historical privacy notice” in the subject and state the approximate period you want. If an update affects existing orders, we will also explain its effective date and transition arrangements.

Applicable rules and dispute handling

This notice is interpreted under the laws of the jurisdiction where the platform operator is based. Disputes not resolved through discussion will be handled by a competent court in that jurisdiction under applicable procedures.

Privacy request access

Identify the information category first, then provide only what is necessary

For account or order matters, submitting a console ticket enables secure verification; general privacy questions can be sent to the sole support email.