ThueMi.com

Privacy & Personal Data Policy

How AnPuPu collects, uses, shares, stores and protects your personal data when you use ThueMi, and how you can exercise your rights.

Updated October 1, 2026Draft
Draft pending legal review before official use.
Contents

1. Data controller and processor

Công ty TNHH Công nghệ AnPuPu ("AnPuPu", "we"), operator of ThueMi (thuemi.com), is the controller and processor of your personal data under this Policy.

  • Tax code: to be updated
  • Address: to be updated
  • Legal representative: to be updated
  • Data protection contact: Personal Data Protection Team, email to be updated, hotline 0969 866 669

This Policy is based on the Law on Personal Data Protection (effective 1 January 2026) and its implementing regulations, Decree 13/2023/ND-CP to the extent still applicable, the Law on Cybersecurity, the 2023 Law on Protection of Consumer Rights and the applicable e-commerce regulations. It applies together with the Terms of Use.

2. Data we collect

2.1 Basic personal data

2.2 Sensitive personal data

Some of the data below is sensitive personal data under the law. We process it only with your separate consent or where the law otherwise permits, and apply enhanced safeguards.

We do not track your location in the background and do not show a Companion's exact location to others; profiles show only the area (district, city).

2.3 Data we do not collect

We do not ask for data about sexual orientation, religion, political views, health or personal financial status. Please do not post such information in your profile or messages.

3. Purposes of processing

  1. Creating and managing accounts, authenticating sign-in via OTP.
  2. Verifying the identity and age of Companions (and Customers when required).
  3. Displaying profiles, Packages, Looking-to-hire and Available-for-hire posts; search and recommendations.
  4. Creating Bookings, processing payments, Escrow, refunds, Companion payouts and receipts.
  5. Providing in-app chat; masking phone numbers and links before a Booking is completed to prevent fraud and off-platform dealings.
  6. Safety: SOS, location sharing, in-meeting check-ins, handling reports, blocking, suspension.
  7. Content moderation (automated and manual) to detect violating content, solicitation and scams.
  8. Resolving complaints and disputes.
  9. Sending notifications about Bookings, payments and safety; sending promotions if you have agreed.
  10. Fraud prevention, system security, and aggregated operational statistics.
  11. Meeting legal obligations (accounting, tax, providing information to competent authorities).

We do not sell your personal data and do not use sensitive data for advertising.

  • Consent: at sign-up, you accept the Terms of Use and Privacy Policy (version 2026-10-01); Companions also accept the Companion Agreement. Processing of sensitive data (identity verification, facial data, location) and marketing messages requires separate consent at the time you use the feature. Every consent is logged with time, IP and device.
  • Performance of a contract: processing needed to provide the Platform and carry out Bookings.
  • Legal obligation: keeping accounting and tax records, responding to lawful requests.
  • Emergencies: processing needed to protect the life or health of you or others (e.g. SOS).
  • Withdrawing consent: you may withdraw consent at any time (see section 9). Withdrawal does not affect the lawfulness of prior processing. If you withdraw consent required for a feature (e.g. Companion identity verification), you will not be able to use that feature.

When we update this Policy in a way that changes the purposes or scope of processing, you must accept the new version.

5. Sharing data

5.1 With other users

  • A Companion's public profile: display name, age, approved photos, video and voice sample, bio, boundaries, Packages, reviews, area.
  • Within a Booking, both sides see display names, chat content and the information needed to meet. The exact address in a Looking-to-hire post is shown only to the Companion whose Offer is selected.
  • ID documents and facial data are never shown to other users.

5.2 With processors acting for us

These parties may process data only on our instructions, under contracts with confidentiality terms, and may not use it for their own purposes.

5.3 With authorities and in emergencies

  • We provide data to competent state authorities upon a lawful written request in accordance with the law.
  • Where there are signs of a crime (e.g. prostitution, human trafficking, abuse of minors, threats to life), we preserve evidence and proactively notify the authorities.
  • When you press SOS, your location and Booking details are sent to ThueMi's safety team; if enabled, your emergency contacts receive a link to view your location.

5.4 Business transfers

In a merger, demerger or transfer, data may pass to the successor, provided the successor continues to protect it under this Policy; we will notify you beforehand.

6. Cross-border transfer

Files you upload (photos, videos, voice samples, chat images, ID images) are stored on Cloudflare R2 and delivered via the Cloudflare network; data may be stored or processed on servers outside Vietnam. Push notifications pass through Google and Apple infrastructure. By accepting this Policy, you consent to these transfers abroad.

Safeguards:

  • We prepare and keep a cross-border personal data transfer impact assessment and complete the required procedures with the competent authority.
  • We contract with providers that commit to confidentiality and data protection.
  • Encryption in transit (TLS); ID documents and verification data are encrypted at rest and accessible only to authorised staff.
  • Private files (chat images, files pending review, ID documents) have no public URL and require authenticated access.

7. Retention

After the retention period, data is deleted or irreversibly anonymised.

8. Security

  • All connections use HTTPS/TLS; short-lived sign-in tokens, with remote sign-out.
  • Sensitive data (ID documents, verification data, payout accounts) is encrypted at rest, access is role-based and every access is logged.
  • Uploaded images have EXIF and GPS metadata removed; videos and audio are transcoded and stripped of metadata.
  • Phone and ID numbers are masked in admin screens and logs.
  • Rate limiting, OTP brute-force protection, regular backups.
  • In the event of a personal data breach, we notify the competent authority and affected users within the time limits required by law, together with remedial measures.

No system is completely secure. Keep your OTP codes secret, do not share signed-in devices, and tell us immediately if you suspect your account has been compromised.

9. Your rights

Under personal data protection law, you have the right to:

  1. Be informed about the processing of your data.
  2. Give or refuse consent, and withdraw consent.
  3. Access, view and obtain a copy of your data.
  4. Correct inaccurate data.
  5. Delete data or request restriction of processing, except where the law requires retention.
  6. Object to processing for marketing.
  7. Complain, denounce, sue and claim compensation as provided by law.

How to exercise your rights

  • In the app: Account → Settings (edit profile, turn off marketing notifications, delete account; download your data once the feature is available).
  • Email to be updated from your linked email address, or call 0969 866 669, stating your request.
  • We may need to verify your identity (e.g. an OTP to the account's phone number) before acting.
  • We acknowledge requests within 72 hours and handle them within the time limits set by law. If we cannot fulfil a request (e.g. transaction data we must keep by law), we explain why.

If you are not satisfied with how we handle your data, you may complain to the specialised personal data protection authority (the Department of Cybersecurity and High-Tech Crime Prevention, Ministry of Public Security) or another competent authority.

10. Persons under 18

ThueMi is for people aged 18 and over. We do not knowingly collect data from anyone under 18. If we find an account belonging to a minor, we lock it and delete the data, except data we need to keep to report to the authorities or protect children. If you know someone under 18 is using ThueMi, please report it in the app or email to be updated.

11. Data about third parties

When you add emergency contacts or submit information about other people (e.g. in a report), you confirm that you have informed them and obtained their consent. Emergency contacts receive messages only when you turn on location sharing or press SOS. They can ask us to delete their information via to be updated.

12. Cookies and similar technologies

The website uses cookies and browser storage for:

  • Essential: keeping you signed in (secure httpOnly cookie), preventing request forgery, remembering your language.
  • Functional: remembering interface choices and recent filters.
  • Analytics (if used): aggregated visit statistics; enabled only with your consent.

We do not use third-party advertising cookies. You can delete or block cookies in your browser; if you block essential cookies, you will not be able to sign in.

13. Changes to this Policy

The current version is 2026-10-01. When we make changes, we update the date on this page, notify you in the app and ask you to accept again where the change affects the purposes, scope of processing or your rights.

14. Contact

Personal Data Protection Team – Công ty TNHH Công nghệ AnPuPu

  • Email: to be updated
  • Hotline: 0969 866 669
  • Address: to be updated

Other documents