ThueMi.com

隐私与个人数据政策

Privacy & Personal Data Policy

AnPuPu 在你使用 ThueMi 时如何收集、使用、共享、存储和保护你的个人数据,以及你如何行使自己的权利。

更新于 2026年10月3日草案
本页面为英文版本 · 中文版正在准备中。如英文版与越南语原版有出入,以越南语版本为准。
草案待律师审阅。正式发布前内容可能会有变动。
目录

1. Data controller and processor

Công ty TNHH Công nghệ AnPuPu ("AnPuPu", "we"), operator of ThueMi (thuemi.com), is the controller and processor of your personal data under this Policy.

  • Tax code: to be updated
  • Address: to be updated
  • Legal representative: to be updated
  • Data protection contact: Personal Data Protection Team, email to be updated, hotline 0969 866 669

This Policy is based on the Law on Personal Data Protection (effective 1 January 2026) and its implementing regulations, Decree 13/2023/ND-CP to the extent still applicable, the Law on Cybersecurity, the 2023 Law on Protection of Consumer Rights and the applicable e-commerce regulations. It applies together with the Terms of Use.

2. Data we collect

2.1 Basic personal data

2.2 Sensitive personal data

Some of the data below is sensitive personal data under the law. We process it only with your separate consent or where the law otherwise permits, and apply enhanced safeguards.

We do not track your location in the background and do not show a Companion's exact location to others; profiles show only the area (district, city).

2.3 Data we do not collect

We do not ask for data about sexual orientation, religion, political views, health or personal financial status. Please do not post such information in your profile or messages.

3. Purposes of processing

  1. Creating and managing accounts, authenticating sign-in via OTP.
  2. Verifying the identity and age of Companions (and Customers when required).
  3. Displaying profiles, Packages, Looking-to-hire and Available-for-hire posts; search and recommendations.
  4. Creating Bookings, processing payments, Escrow, refunds, Companion payouts and receipts.
  5. Providing in-app chat; masking phone numbers and links before a Booking is completed to prevent fraud and off-platform dealings.
  6. Safety: SOS, location sharing, in-meeting check-ins, handling reports, blocking, suspension.
  7. Content moderation (automated and manual) to detect violating content, solicitation and scams.
  8. Resolving complaints and disputes.
  9. Sending notifications about Bookings, payments and safety; sending promotions if you have agreed.
  10. Fraud prevention, system security, and aggregated operational statistics.
  11. Meeting legal obligations (accounting, tax, providing information to competent authorities).

We do not sell your personal data and do not use sensitive data for advertising.

  • Consent: at sign-up, you accept the Terms of Use and Privacy Policy (version 2026-10-01); Companions also accept the Companion Agreement. Processing of sensitive data (identity verification, facial data, location) and marketing messages requires separate consent at the time you use the feature. Every consent is logged with time, IP and device.
  • Performance of a contract: processing needed to provide the Platform and carry out Bookings.
  • Legal obligation: keeping accounting and tax records, responding to lawful requests.
  • Emergencies: processing needed to protect the life or health of you or others (e.g. SOS).
  • Withdrawing consent: you may withdraw consent at any time (see section 9). Withdrawal does not affect the lawfulness of prior processing. If you withdraw consent required for a feature (e.g. Companion identity verification), you will not be able to use that feature.

When we update this Policy in a way that changes the purposes or scope of processing, you must accept the new version.

5. Sharing data

5.1 With other users

  • A Companion's public profile: display name, age, approved photos, video and voice sample, bio, boundaries, Packages, reviews, area.
  • Within a Booking, both sides see display names, chat content and the information needed to meet. The exact address in a Looking-to-hire post is shown only to the Companion whose Offer is selected.
  • ID documents and facial data are never shown to other users.

5.2 With processors acting for us

These parties may process data only on our instructions, under contracts with confidentiality terms, and may not use it for their own purposes.

5.3 With authorities and in emergencies

  • We provide data to competent state authorities upon a lawful written request in accordance with the law.
  • Where there are signs of a crime (e.g. prostitution, human trafficking, abuse of minors, threats to life), we preserve evidence and proactively notify the authorities.
  • When you press SOS, your location and Booking details are sent to ThueMi's safety team; if enabled, your emergency contacts receive a link to view your location.

5.4 Business transfers

In a merger, demerger or transfer, data may pass to the successor, provided the successor continues to protect it under this Policy; we will notify you beforehand.

6. Cross-border transfer

Files you upload (photos, videos, voice samples, chat images, ID images) are stored on Cloudflare R2 and delivered via the Cloudflare network; data may be stored or processed on servers outside Vietnam. Push notifications pass through Google and Apple infrastructure. By accepting this Policy, you consent to these transfers abroad.

Safeguards:

  • We prepare and keep a cross-border personal data transfer impact assessment and complete the required procedures with the competent authority.
  • We contract with providers that commit to confidentiality and data protection.
  • Encryption in transit (TLS); ID documents and verification data are encrypted at rest and accessible only to authorised staff.
  • Private files (chat images, files pending review, ID documents) have no public URL and require authenticated access.

7. Retention

After the retention period, data is deleted or irreversibly anonymised. The post-deletion retention periods above are based on current law: Decree 13/2023/ND-CP (Article 16) and the 2025 Law on Personal Data Protection allow us to keep data that other laws require us to retain.

7.1 When you delete your account

You can delete your account yourself in the app or on the web (Account → Delete account). Deletion takes effect immediately, with no waiting period, and cannot be undone; you are logged out on every device.

Deleted or anonymised right away:

  • Display name (changed to “Deleted account”), profile photo, phone number, email, date of birth, age, gender, city.
  • All login methods (phone, Google, Apple), OTP codes and sessions.
  • Companion profile: hidden from the Platform; bio, photos, video, voice, height, area and boundaries are removed; packages are archived, open availability posts and requests are closed, and pending offers are withdrawn.
  • Emergency contacts, location shares, likes and block lists, in-app notifications.
  • Profile photo, video and voice files (except files that are evidence in a dispute).

Kept as required by law (used only for accounting, tax, safety and dispute obligations, never shown to other users): Bookings, transactions, refunds, payouts and payout bank account (10 years); ID records (5 years; hash and last 4 digits 10 years); reports, SOS alerts, disputes and evidence (3 years); messages in the other person's conversations (up to 3 years); consent and deletion logs (5 years), as in the table above.

You can't delete your account while you have an unfinished Booking (including a finished Booking waiting to be paid out), a dispute in progress, a refund ThueMi hasn't sent you yet, or an unpaid earnings wallet balance. The Delete account screen lists each item to finish, with a link to handle it.

After deleting, you can still sign up again with the same phone number or Google, but it will be a brand-new account with no link to your old data. The ID record of a self-deleted account does not stop you from verifying again, unless the old account was suspended at the time of deletion.

8. Security

  • All connections use HTTPS/TLS; short-lived sign-in tokens, with remote sign-out.
  • Sensitive data (ID documents, verification data, payout accounts) is encrypted at rest, access is role-based and every access is logged.
  • Uploaded images have EXIF and GPS metadata removed; videos and audio are transcoded and stripped of metadata.
  • Phone and ID numbers are masked in admin screens and logs.
  • Rate limiting, OTP brute-force protection, regular backups.
  • In the event of a personal data breach, we notify the competent authority and affected users within the time limits required by law, together with remedial measures.

No system is completely secure. Keep your OTP codes secret, do not share signed-in devices, and tell us immediately if you suspect your account has been compromised.

9. Your rights

Under personal data protection law, you have the right to:

  1. Be informed about the processing of your data.
  2. Give or refuse consent, and withdraw consent.
  3. Access, view and obtain a copy of your data.
  4. Correct inaccurate data.
  5. Delete data or request restriction of processing, except where the law requires retention.
  6. Object to processing for marketing.
  7. Complain, denounce, sue and claim compensation as provided by law.

How to exercise your rights

  • In the app or on the web: Account (edit profile, turn off marketing notifications; download your data once the feature is available). Delete account: Account → Delete account (bottom of the page), type XOA to confirm; the account is deleted immediately, no phone call or email needed (see section 7.1).
  • If you can't delete in the app (e.g. you lost access to your account): call 0969 866 669 or email to be updated and we will help you delete it after verifying your identity.
  • Email to be updated from your linked email address, or call 0969 866 669, stating your request.
  • We may need to verify your identity (e.g. an OTP to the account's phone number) before acting.
  • We acknowledge requests within 72 hours and handle them within the time limits set by law. If we cannot fulfil a request (e.g. transaction data we must keep by law), we explain why.

If you are not satisfied with how we handle your data, you may complain to the specialised personal data protection authority (the Department of Cybersecurity and High-Tech Crime Prevention, Ministry of Public Security) or another competent authority.

10. Persons under 18

ThueMi is for people aged 18 and over. We do not knowingly collect data from anyone under 18. If we find an account belonging to a minor, we lock it and delete the data, except data we need to keep to report to the authorities or protect children. If you know someone under 18 is using ThueMi, please report it in the app or email to be updated.

11. Data about third parties

When you add emergency contacts or submit information about other people (e.g. in a report), you confirm that you have informed them and obtained their consent. Emergency contacts receive messages only when you turn on location sharing or press SOS. They can ask us to delete their information via to be updated.

12. Cookies and similar technologies

The website uses cookies and browser storage for:

  • Essential: keeping you signed in (secure httpOnly cookie), preventing request forgery, remembering your language.
  • Functional: remembering interface choices and recent filters.
  • Analytics (if used): aggregated visit statistics; enabled only with your consent.

We do not use third-party advertising cookies. You can delete or block cookies in your browser; if you block essential cookies, you will not be able to sign in.

13. Changes to this Policy

The current version is 2026-10-01. When we make changes, we update the date on this page, notify you in the app and ask you to accept again where the change affects the purposes, scope of processing or your rights.

14. Contact

Personal Data Protection Team – Công ty TNHH Công nghệ AnPuPu

  • Email: to be updated
  • Hotline: 0969 866 669
  • Address: to be updated

其他文件