プライバシー・個人情報保護方針
Privacy & Personal Data Policy
ThueMi のご利用時に AnPuPu が個人情報を収集・利用・共有・保管・保護する方法と、ご自身の権利を行使する方法を説明します。
目次
1. Data controller and processor
Công ty TNHH Công nghệ AnPuPu ("AnPuPu", "we"), operator of ThueMi (thuemi.com), is the controller and processor of your personal data under this Policy.
- Tax code: 0111619934
- Address: Tầng 5, Tòa IC, Số 82 Phố Duy Tân, Phường Cầu Giấy, TP Hà Nội, Việt Nam
- Legal representative: Trần Văn Long
- Data protection contact: Personal Data Protection Team, email to be updated, hotline 0969 866 669
This Policy is based on the Law on Personal Data Protection (effective 1 January 2026) and its implementing regulations, Decree 13/2023/ND-CP to the extent still applicable, the Law on Cybersecurity, the 2023 Law on Protection of Consumer Rights and the applicable e-commerce regulations. It applies together with the Terms of Use.
2. Data we collect
2.1 Basic personal data
| Category | Data | Source |
|---|---|---|
| Account | Phone number, display name, profile photo, gender, date or year of birth, city | You |
| Linked sign-in | Name, email, Google or Apple account identifier | Google, Apple, if you choose |
| Companion profile | Photos, intro video, voice sample, height, bio, interests, boundaries, Packages and prices, availability, service area | You |
| Transactions | Bookings, Looking-to-hire posts, Offers, Available-for-hire posts, amounts, payment method (full card numbers are not stored), transaction IDs, refund history, Companion payout account | You, payment gateways |
| Communications | Chat messages, images sent in chat | Created by your use |
| Reviews, reports | Reviews, violation reports, attached evidence, complaints | You, other users |
| Emergency contacts | Name, phone number, relationship (up to 3 people) | You |
| Technical | IP address, device type, operating system, browser, push token, sign-in logs, error logs | Automatic |
| Consent log | Document version you accepted, time, IP, device information | Automatic when you consent |
2.2 Sensitive personal data
Some of the data below is sensitive personal data under the law. We process it only with your separate consent or where the law otherwise permits, and apply enhanced safeguards.
| Data | When collected | Purpose |
|---|---|---|
| Images of your ID document (citizen ID card, old ID card or passport), ID number, name and date of birth on the document | Mandatory for Companions; for Customers when verification is required | Verifying identity and age, preventing impersonation, preventing one person from holding multiple accounts |
| Portrait photo and facial data used for matching (biometrics) | During identity verification | Matching your face against the document and profile photos, liveness checks |
| Location | Only when you press SOS, turn on location sharing, or check in/out of an in-person Booking | Emergency assistance, confirming attendance, evidence in disputes |
We do not track your location in the background and do not show a Companion's exact location to others; profiles show only the area (district, city).
2.3 Data we do not collect
We do not ask for data about sexual orientation, religion, political views, health or personal financial status. Please do not post such information in your profile or messages.
3. Purposes of processing
- Creating and managing accounts, authenticating sign-in via OTP.
- Verifying the identity and age of Companions (and Customers when required).
- Displaying profiles, Packages, Looking-to-hire and Available-for-hire posts; search and recommendations.
- Creating Bookings, processing payments, Escrow, refunds, Companion payouts and receipts.
- Providing in-app chat; masking phone numbers and links before a Booking is completed to prevent fraud and off-platform dealings.
- Safety: SOS, location sharing, in-meeting check-ins, handling reports, blocking, suspension.
- Content moderation (automated and manual) to detect violating content, solicitation and scams.
- Resolving complaints and disputes.
- Sending notifications about Bookings, payments and safety; sending promotions if you have agreed.
- Fraud prevention, system security, and aggregated operational statistics.
- Meeting legal obligations (accounting, tax, providing information to competent authorities).
We do not sell your personal data and do not use sensitive data for advertising.
4. Legal bases and consent
- Consent: at sign-up, you accept the Terms of Use and Privacy Policy (version 2026-10-01); Companions also accept the Companion Agreement. Processing of sensitive data (identity verification, facial data, location) and marketing messages requires separate consent at the time you use the feature. Every consent is logged with time, IP and device.
- Performance of a contract: processing needed to provide the Platform and carry out Bookings.
- Legal obligation: keeping accounting and tax records, responding to lawful requests.
- Emergencies: processing needed to protect the life or health of you or others (e.g. SOS).
- Withdrawing consent: you may withdraw consent at any time (see section 9). Withdrawal does not affect the lawfulness of prior processing. If you withdraw consent required for a feature (e.g. Companion identity verification), you will not be able to use that feature.
When we update this Policy in a way that changes the purposes or scope of processing, you must accept the new version.
5. Sharing data
5.1 With other users
- A Companion's public profile: display name, age, approved photos, video and voice sample, bio, boundaries, Packages, reviews, area.
- Within a Booking, both sides see display names, chat content and the information needed to meet. The exact address in a Looking-to-hire post is shown only to the Companion whose Offer is selected.
- ID documents and facial data are never shown to other users.
5.2 With processors acting for us
| Recipient | Data | Purpose |
|---|---|---|
| Payment gateways and banks (e.g. MoMo, ZaloPay, VNPay, card schemes, VietQR via SePay) | Amount, transaction ID, information needed for payment, refund and payout | Payments, refunds, payouts |
| Zalo (ZNS messages from a Zalo Official Account), SMS providers | Phone number, OTP or notification content | Sending OTP codes and important notices |
| Google, Apple | Push tokens; sign-in data when you use linked sign-in | Push notifications, sign-in |
| Infrastructure providers (VPS servers, Cloudflare R2 file storage, Cloudflare CDN) | Files you upload, data in transit | Storage, content delivery, attack protection |
| Electronic identity verification providers (if used) | ID images, portrait | Reading documents, face matching |
These parties may process data only on our instructions, under contracts with confidentiality terms, and may not use it for their own purposes.
5.3 With authorities and in emergencies
- We provide data to competent state authorities upon a lawful written request in accordance with the law.
- Where there are signs of a crime (e.g. prostitution, human trafficking, abuse of minors, threats to life), we preserve evidence and proactively notify the authorities.
- When you press SOS, your location and Booking details are sent to ThueMi's safety team; if enabled, your emergency contacts receive a link to view your location.
5.4 Business transfers
In a merger, demerger or transfer, data may pass to the successor, provided the successor continues to protect it under this Policy; we will notify you beforehand.
6. Cross-border transfer
Files you upload (photos, videos, voice samples, chat images, ID images) are stored on Cloudflare R2 and delivered via the Cloudflare network; data may be stored or processed on servers outside Vietnam. Push notifications pass through Google and Apple infrastructure. By accepting this Policy, you consent to these transfers abroad.
Safeguards:
- We prepare and keep a cross-border personal data transfer impact assessment and complete the required procedures with the competent authority.
- We contract with providers that commit to confidentiality and data protection.
- Encryption in transit (TLS); ID documents and verification data are encrypted at rest and accessible only to authorised staff.
- Private files (chat images, files pending review, ID documents) have no public URL and require authenticated access.
7. Retention
| Data | Retention period |
|---|---|
| Account and profile information | While the account is active; deleted or anonymised as soon as you delete your account (section 7.1), except as required by the rows below |
| ID documents, facial data | While the account is active. After account deletion: ID images, selfie, and the full name and date of birth on the ID are kept for 5 years; the hash of the ID number and its last 4 digits are kept for 10 years (fraud prevention and stopping new accounts created to get around a suspension – with reference to the 2022 Law on Anti-Money Laundering). The ID number (or its hash) of permanently banned accounts is kept on a blocklist to prevent re-registration |
| Chat and chat images | 12 months from the last message; longer if linked to a complaint, report or request from a competent authority. When you delete your account, messages you sent stay in the other person's conversation (your name shows as “Deleted account”) for up to 3 years from deletion |
| Location (SOS, location sharing, check-in) | Location share links expire after 6 hours or 1 hour after the Booking ends (whichever is later) and stop showing coordinates; location data is kept for up to 90 days, longer if linked to a safety incident or dispute |
| Bookings, transactions, payment records, refunds, payouts, payout bank account | 10 years from the end of the financial year of the transaction (Accounting Law 2015 Article 41, Decree 174/2016/ND-CP Article 12, Tax Administration Law 2019) |
| Violation reports, SOS alerts (with location), safety check-ins, disputes and evidence | 3 years from when the case is closed or from account deletion (whichever is later), longer if legal proceedings are pending (limitation period under Civil Code 2015 Article 429) |
| Consent log, account deletion log | While the account is active and 5 years thereafter |
| Reviews you wrote | Text and rating are kept to compute the Companion's score; the author's name and photo are replaced with “Deleted account”, so they are no longer linked to you |
| Technical and security logs | Up to 12 months |
After the retention period, data is deleted or irreversibly anonymised. The post-deletion retention periods above are based on current law: Decree 13/2023/ND-CP (Article 16) and the 2025 Law on Personal Data Protection allow us to keep data that other laws require us to retain.
7.1 When you delete your account
You can delete your account yourself in the app or on the web (Account → Delete account). Deletion takes effect immediately, with no waiting period, and cannot be undone; you are logged out on every device.
Deleted or anonymised right away:
- Display name (changed to “Deleted account”), profile photo, phone number, email, date of birth, age, gender, city.
- All login methods (phone, Google, Apple), OTP codes and sessions.
- Companion profile: hidden from the Platform; bio, photos, video, voice, height, area and boundaries are removed; packages are archived, open availability posts and requests are closed, and pending offers are withdrawn.
- Emergency contacts, location shares, likes and block lists, in-app notifications.
- Profile photo, video and voice files (except files that are evidence in a dispute).
Kept as required by law (used only for accounting, tax, safety and dispute obligations, never shown to other users): Bookings, transactions, refunds, payouts and payout bank account (10 years); ID records (5 years; hash and last 4 digits 10 years); reports, SOS alerts, disputes and evidence (3 years); messages in the other person's conversations (up to 3 years); consent and deletion logs (5 years), as in the table above.
You can't delete your account while you have an unfinished Booking (including a finished Booking waiting to be paid out), a dispute in progress, a refund ThueMi hasn't sent you yet, or an unpaid earnings wallet balance. The Delete account screen lists each item to finish, with a link to handle it.
After deleting, you can still sign up again with the same phone number or Google, but it will be a brand-new account with no link to your old data. The ID record of a self-deleted account does not stop you from verifying again, unless the old account was suspended at the time of deletion.
8. Security
- All connections use HTTPS/TLS; short-lived sign-in tokens, with remote sign-out.
- Sensitive data (ID documents, verification data, payout accounts) is encrypted at rest, access is role-based and every access is logged.
- Uploaded images have EXIF and GPS metadata removed; videos and audio are transcoded and stripped of metadata.
- Phone and ID numbers are masked in admin screens and logs.
- Rate limiting, OTP brute-force protection, regular backups.
- In the event of a personal data breach, we notify the competent authority and affected users within the time limits required by law, together with remedial measures.
No system is completely secure. Keep your OTP codes secret, do not share signed-in devices, and tell us immediately if you suspect your account has been compromised.
9. Your rights
Under personal data protection law, you have the right to:
- Be informed about the processing of your data.
- Give or refuse consent, and withdraw consent.
- Access, view and obtain a copy of your data.
- Correct inaccurate data.
- Delete data or request restriction of processing, except where the law requires retention.
- Object to processing for marketing.
- Complain, denounce, sue and claim compensation as provided by law.
How to exercise your rights
- In the app or on the web: Account (edit profile, turn off marketing notifications; download your data once the feature is available). Delete account: Account → Delete account (bottom of the page), type XOA to confirm; the account is deleted immediately, no phone call or email needed (see section 7.1).
- If you can't delete in the app (e.g. you lost access to your account): call 0969 866 669 or email to be updated and we will help you delete it after verifying your identity.
- Email to be updated from your linked email address, or call 0969 866 669, stating your request.
- We may need to verify your identity (e.g. an OTP to the account's phone number) before acting.
- We acknowledge requests within 72 hours and handle them within the time limits set by law. If we cannot fulfil a request (e.g. transaction data we must keep by law), we explain why.
If you are not satisfied with how we handle your data, you may complain to the specialised personal data protection authority (the Department of Cybersecurity and High-Tech Crime Prevention, Ministry of Public Security) or another competent authority.
10. Persons under 18
ThueMi is for people aged 18 and over. We do not knowingly collect data from anyone under 18. If we find an account belonging to a minor, we lock it and delete the data, except data we need to keep to report to the authorities or protect children. If you know someone under 18 is using ThueMi, please report it in the app or email to be updated.
11. Data about third parties
When you add emergency contacts or submit information about other people (e.g. in a report), you confirm that you have informed them and obtained their consent. Emergency contacts receive messages only when you turn on location sharing or press SOS. They can ask us to delete their information via to be updated.
12. Cookies and similar technologies
The website uses cookies and browser storage for:
- Essential: keeping you signed in (secure httpOnly cookie), preventing request forgery, remembering your language.
- Functional: remembering interface choices and recent filters.
- Analytics (if used): aggregated visit statistics; enabled only with your consent.
We do not use third-party advertising cookies. You can delete or block cookies in your browser; if you block essential cookies, you will not be able to sign in.
13. Changes to this Policy
The current version is 2026-10-01. When we make changes, we update the date on this page, notify you in the app and ask you to accept again where the change affects the purposes, scope of processing or your rights.
14. Contact
Personal Data Protection Team – Công ty TNHH Công nghệ AnPuPu
- Email: to be updated
- Hotline: 0969 866 669
- Address: Tầng 5, Tòa IC, Số 82 Phố Duy Tân, Phường Cầu Giấy, TP Hà Nội, Việt Nam