Chính sách quyền riêng tư
Cập nhật: 03/10/2026 · English version
Scaleon là phần mềm quản lý doanh nghiệp trên nền web, dùng cho các doanh nghiệp tại Việt Nam do CÔNG TY TNHH XUẤT NHẬP KHẨU QUYỀN MINH VŨ phát triển và vận hành. Doanh nghiệp dùng Scaleon để trả lời khách trên Facebook Messenger, lên đơn, nhận đơn sàn TikTok Shop, quản lý sản phẩm và tồn kho, gửi hàng qua hãng vận chuyển, đối soát tiền và xem báo cáo. Chính sách này nói rõ Scaleon xử lý dữ liệu gì, để làm gì, lưu bao lâu, chia sẻ với ai và cách yêu cầu xoá.
1. Ai chịu trách nhiệm
- Với hội thoại, hồ sơ khách và đơn hàng mà doanh nghiệp quản lý trong Scaleon: doanh nghiệp là bên kiểm soát dữ liệu (quyết định thu thập gì, để làm gì); chúng tôi là bên xử lý, chỉ xử lý theo yêu cầu của doanh nghiệp và chỉ để cung cấp Scaleon.
- Với tài khoản của người đăng nhập Scaleon (Tài khoản Scaleon) và thông tin người xem gửi qua biểu mẫu liên hệ trên website: chúng tôi là bên kiểm soát.
- Chúng tôi xử lý dữ liệu cá nhân theo Luật Bảo vệ dữ liệu cá nhân (Luật số 91/2025/QH15) và các văn bản hướng dẫn. Đầu mối về bảo vệ dữ liệu: lienhe@scaleon.vn.
2. Cách kết nối từng loại tài khoản
- Trang Facebook kết nối qua màn cấp quyền chính thức của Facebook (Facebook Login); quản trị viên tự chọn Trang. Scaleon không bao giờ hỏi mật khẩu Facebook.
- Gian hàng TikTok Shop kết nối qua màn uỷ quyền chính thức của TikTok Shop; người bán tự chọn gian hàng và thu hồi uỷ quyền được bất cứ lúc nào trong TikTok Shop Seller Center; trong Scaleon quản trị viên tắt được gian hàng để ngừng nhận đơn.
- Shopee (đang chờ Shopee duyệt), Lazada (đang phát triển) và Zalo OA (thử nghiệm): qua màn cấp quyền của chính nền tảng khi tính năng sẵn sàng.
- Tài khoản quảng cáo Meta và Conversions API: quản trị viên nhập mã truy cập của người dùng hệ thống trong tài khoản Meta Business của chính doanh nghiệp (để đọc báo cáo quảng cáo), và nếu bật Conversions API thì nhập ID pixel hoặc tập dữ liệu cùng mã truy cập của nó.
- Hãng vận chuyển và dịch vụ thanh toán: quản trị viên nhập khoá API, token hoặc tài khoản API (tên đăng nhập và mật khẩu cấp riêng cho API) mà hãng hay dịch vụ thanh toán cấp cho doanh nghiệp.
- Đăng nhập bằng Google: người dùng tự chọn tài khoản Google trên màn của Google (xem mục 4).
- Mọi mã truy cập, khoá API, mật khẩu API đều được mã hoá AES-256-GCM trước khi lưu.
3. Dữ liệu nhận từ nền tảng được kết nối
Trang Facebook và Messenger (Meta)
- Các Trang quản trị viên chọn (tên, ID) và mã truy cập của từng Trang; ID Facebook theo ứng dụng của người bấm nối (để xử lý yêu cầu xoá dữ liệu gửi qua Facebook). Không giữ mã truy cập cá nhân của người nối.
- Hội thoại Messenger giữa khách và Trang: nội dung, tệp đính kèm, thời gian; mã khách theo Trang (PSID), tên và ảnh đại diện do Meta cung cấp. Nhận qua webhook của Trang và Conversations API.
- Tin nhân viên gửi từ Scaleon, gồm tin trả lời gắn thẻ HUMAN_AGENT trong 7 ngày kể từ tin cuối của khách. Mọi tin loại này do người thật gõ; Scaleon không gửi tin tự động hay quảng cáo bằng thẻ này.
Quảng cáo Meta
- Với tài khoản quảng cáo doanh nghiệp gán cho dự án: tên tài khoản, chiến dịch, nhóm quảng cáo, quảng cáo, chi tiêu và kết quả (chỉ đọc, để tính chi phí quảng cáo trên mỗi đơn). Scaleon không tạo hay sửa quảng cáo.
Meta Conversions API (chỉ khi doanh nghiệp bật)
- Sự kiện gửi tới pixel hoặc tập dữ liệu của chính doanh nghiệp: Purchase (đơn được xác nhận, kèm giá trị), LeadSubmitted (khách để lại số điện thoại trong hội thoại Messenger) và LeadQualified (nhân viên đã xác nhận khách qua điện thoại).
- Mỗi sự kiện có thể kèm mã băm SHA-256 của số điện thoại (cũng dùng làm mã khách bên ngoài), họ, tên, quốc gia, tỉnh/thành của khách; và, để nguyên theo yêu cầu của Meta, ID Trang và PSID của khách, cùng mã nhấp fbc/fbp, địa chỉ IP, thông tin trình duyệt khi khách đến từ landing của doanh nghiệp.
TikTok Shop
- Sau khi người bán uỷ quyền gian hàng: ID, tên và khu vực của gian hàng; mã truy cập và mã làm mới (mã hoá); đơn hàng (mã đơn, sản phẩm, số lượng, giá, phí, trạng thái, thông tin vận chuyển, đổi trả) kèm tên, số điện thoại, địa chỉ người mua đúng như TikTok trả về — TikTok có thể che một phần các thông tin này; thông tin sản phẩm; số tiền quyết toán.
- Chỉ dùng để đưa đơn của gian hàng vào Scaleon, giao hàng, trừ tồn kho và làm báo cáo cho người bán; không dùng để liên hệ người mua của TikTok vì mục đích khác, không dùng cho quảng cáo, không chia sẻ cho bên khác.
Shopee (đang chờ Shopee duyệt) và Lazada (đang phát triển)
- Khi tính năng mở và người bán uỷ quyền gian hàng: các loại dữ liệu đơn, sản phẩm, quyết toán như TikTok Shop ở trên, dùng đúng các mục đích như trên.
Zalo Official Account (thử nghiệm)
- ID và tên Official Account (OA); mã truy cập và mã làm mới.
- Tin nhắn giữa người dùng và OA (nội dung, tệp đính kèm, thời gian); mã người dùng Zalo theo OA, tên hiển thị và ảnh đại diện do Zalo cung cấp.
Instagram (đang phát triển)
- Chỉ khi doanh nghiệp kết nối tài khoản Instagram chuyên nghiệp lúc tính năng sẵn sàng: ID và tên người dùng của tài khoản, tin nhắn trực tiếp với tài khoản đó, mã người gửi theo Instagram, tên người dùng và ảnh đại diện do Meta cung cấp.
Hãng vận chuyển và dịch vụ thanh toán
- Hãng doanh nghiệp kết nối (SPX Express, GHN, GHTK, Viettel Post, J&T Express, Ahamove, BEST Express, VNPost): chúng tôi gửi tên, số điện thoại, địa chỉ người nhận, thông tin kiện hàng và tiền thu hộ của đơn doanh nghiệp gửi; nhận lại trạng thái giao và số liệu đối soát COD.
- Mã VietQR tạo từ tài khoản ngân hàng của chính doanh nghiệp. Nếu doanh nghiệp nối SePay hoặc payOS, chúng tôi nhận thông báo tiền về (số tiền, nội dung chuyển khoản, thời gian, mã giao dịch) để khớp với đơn.
4. Dữ liệu người dùng Google (Đăng nhập bằng Google)
- Khi bạn bấm "Đăng nhập bằng Google", Scaleon chỉ xin các quyền cơ bản openid, email, profile. Chúng tôi nhận từ Google: mã định danh tài khoản Google, địa chỉ email và việc Google đã xác minh email đó hay chưa, tên hiển thị. Scaleon không lưu ảnh đại diện Google, không giữ mã truy cập Google sau khi đăng nhập xong, không xin quyền đọc Gmail, Drive, Danh bạ hay bất kỳ dữ liệu Google nào khác.
- Mục đích duy nhất: đăng nhập, tạo và nhận diện Tài khoản Scaleon của bạn, và bảo vệ tài khoản (ví dụ báo qua email khi cách đăng nhập của tài khoản thay đổi). Không dùng cho quảng cáo, không bán, không chuyển cho bên thứ ba, không dùng để huấn luyện mô hình AI.
- Việc Scaleon sử dụng và chuyển giao thông tin nhận được từ API của Google tuân thủ Chính sách dữ liệu người dùng của Dịch vụ API Google (Google API Services User Data Policy), bao gồm các yêu cầu Sử dụng có giới hạn (Limited Use).
- Gỡ liên kết: Tài khoản → Bảo mật tài khoản → bỏ nối Google, hoặc thu hồi quyền của Scaleon tại trang Quyền truy cập của tài khoản Google (myaccount.google.com/permissions). Mã định danh Google bị xoá khỏi Scaleon ngay khi gỡ liên kết hoặc khi Tài khoản Scaleon bị xoá.
5. Biểu mẫu liên hệ trên website và yêu cầu xoá dữ liệu gửi qua Meta
- Biểu mẫu liên hệ: họ tên, số điện thoại và/hoặc email, tên công ty, nhu cầu và nội dung bạn tự gõ. Chỉ dùng để liên hệ lại và tư vấn cho bạn; không lưu địa chỉ IP vào yêu cầu (địa chỉ IP chỉ dùng tạm để chặn gửi tràn). Xoá khi bạn yêu cầu.
- Khi bạn yêu cầu xoá dữ liệu của Scaleon trong cài đặt Facebook, Meta gửi cho chúng tôi mã người dùng theo ứng dụng; chúng tôi lưu mã đó kèm một mã xác nhận để bạn tra trạng thái ở trang Hướng dẫn xoá dữ liệu.
6. Dữ liệu nhập vào Scaleon
- Dữ liệu doanh nghiệp do nhân viên nhập hoặc nhập từ tệp: khách hàng (tên, số điện thoại, địa chỉ, ghi chú), đơn hàng, sản phẩm, tồn kho, giá vốn, thu chi.
- Tài khoản: tên, tên đăng nhập, email, số điện thoại (bạn khai khi đăng ký hoặc trong hồ sơ, dùng để liên hệ và tìm lại tài khoản — mã đặt lại mật khẩu vẫn chỉ gửi về email), vai trò, mật khẩu đã băm (bcrypt), cài đặt xác thực hai lớp và khoá truy cập (passkey), lịch sử đăng nhập (thời gian, địa chỉ IP, thiết bị) và nhật ký bảo mật.
- Landing của chính doanh nghiệp (tuỳ chọn): biểu mẫu khách gửi (tên, số điện thoại, địa chỉ, sản phẩm, số lượng, giá trị đơn) cùng dữ liệu theo dõi trang gửi kèm (fbclid, fbc, fbp, tham số UTM, ID chiến dịch, nhóm quảng cáo, quảng cáo, địa chỉ IP, thông tin trình duyệt); lượt xem trang chỉ có mã khách truy cập ngẫu nhiên và tham số chiến dịch, không có tên, số điện thoại hay IP. Doanh nghiệp tự thông báo cho người xem website của mình.
7. Mục đích sử dụng
- Chỉ để cung cấp Scaleon cho doanh nghiệp: hiện hội thoại cho nhân viên và gửi tin trả lời, lên đơn và gửi hàng, đối soát tiền, làm báo cáo, bảo vệ tài khoản.
- Nhân viên chỉ thấy dự án (cửa hàng) mình được phân công; mỗi Trang, gian hàng được kết nối thuộc một dự án.
- Chúng tôi không bán dữ liệu, không chia sẻ cho bên thứ ba vì mục đích riêng của họ, không dùng cho quảng cáo của chúng tôi và không dùng để huấn luyện mô hình AI.
8. Chia sẻ dữ liệu và bên xử lý phụ
Dữ liệu chỉ rời Scaleon để làm theo yêu cầu của doanh nghiệp hoặc để vận hành dịch vụ, tới các bên sau; mỗi bên xử lý dữ liệu nhận được theo điều khoản của chính họ:
- Nhà cung cấp máy chủ tại Việt Nam nơi Scaleon được đặt (lưu trữ thay chúng tôi).
- Meta (Messenger Platform, Conversions API), TikTok Shop, Shopee, Lazada, Zalo — khi doanh nghiệp kết nối.
- Hãng vận chuyển và dịch vụ thanh toán (SePay, payOS) mà doanh nghiệp kết nối.
- Google — khi người dùng chọn Đăng nhập bằng Google.
- Nhà cung cấp hộp thư của tên miền (hiện là Zoho Mail) — để gửi mã xác minh, thư hệ thống và trả lời liên hệ.
- Cơ quan nhà nước có thẩm quyền — khi pháp luật Việt Nam yêu cầu.
Máy chủ của Scaleon đặt tại Việt Nam. Khi doanh nghiệp dùng tính năng của Meta, Google, TikTok, Shopee hay Lazada, dữ liệu gửi tới các nền tảng này có thể được họ xử lý trên máy chủ ở ngoài Việt Nam theo chính sách của họ.
9. Nơi lưu trữ và bảo mật
Mỗi công ty có cơ sở dữ liệu riêng trên máy chủ đặt tại Việt Nam do chúng tôi thuê và quản lý; dữ liệu truyền qua HTTPS. Mã truy cập, khoá API, mật khẩu API được mã hoá AES-256-GCM; mật khẩu được băm. Scaleon hỗ trợ xác thực hai lớp và khoá truy cập, quản trị viên có thể bắt buộc cho nhân viên; phân quyền theo vai trò và có nhật ký đăng nhập. Chi tiết ở trang Bảo mật. Khi xảy ra sự cố làm lộ dữ liệu cá nhân, chúng tôi thông báo cho doanh nghiệp bị ảnh hưởng và cơ quan chuyên trách theo thời hạn pháp luật quy định.
10. Cookie
Scaleon chỉ dùng cookie cần để hoạt động: giữ phiên đăng nhập, các bước xác thực hai lớp, khoá truy cập và xác minh lại, công ty và dự án đang chọn, cookie ngắn hạn khi đang kết nối Trang Facebook hoặc đăng nhập Google, và lựa chọn giao diện. Không dùng cookie quảng cáo hay cookie phân tích. Các trang công khai của website này không đặt cookie nào.
11. Thời hạn lưu
- Mã truy cập của Trang Facebook bị xoá ngay khi quản trị viên bấm "Gỡ" Trang.
- Các khoá khác (mã tài khoản quảng cáo, mã Conversions API, khoá hãng vận chuyển, thanh toán, sàn): tắt kết nối là ngừng dùng nhưng vẫn giữ khoá đã mã hoá, để bật lại được và vẫn theo dõi được kiện hàng đang đi. Các khoá này bị xoá trong 7 ngày kể từ khi có yêu cầu, và trong 30 ngày sau khi doanh nghiệp ngừng dùng Scaleon.
- Hội thoại, hồ sơ khách, đơn hàng, khách tiềm năng từ landing và dữ liệu người mua từ sàn lưu khi doanh nghiệp còn dùng Scaleon; xoá trong 7 ngày kể từ khi yêu cầu xoá được xác minh, và trong 30 ngày sau khi doanh nghiệp ngừng dùng Scaleon, trừ khi pháp luật Việt Nam buộc lưu lâu hơn (ví dụ chứng từ kế toán doanh nghiệp phải giữ).
- Khi ngừng dùng Scaleon: trước khi dữ liệu bị xoá, doanh nghiệp có thể tự tải các danh sách ra tệp hoặc yêu cầu chúng tôi xuất dữ liệu.
- Lịch sử đăng nhập (thời gian, địa chỉ IP, thiết bị): trong dữ liệu của từng công ty, tự xoá sau 180 ngày; nhật ký đăng nhập của Tài khoản Scaleon chỉ được ghi thêm (không sửa được) và chỉ được phép xoá khi đã quá 180 ngày.
- Nhật ký bảo mật và phân quyền chỉ được ghi thêm: không sửa, không xoá được từ phần mềm, và được giữ khi tài khoản doanh nghiệp còn tồn tại để bảo vệ tài khoản.
12. Quyền của bạn và xoá dữ liệu
Bạn có quyền được biết, truy cập, chỉnh sửa, xoá, hạn chế xử lý, rút lại sự đồng ý đối với dữ liệu cá nhân của mình và khiếu nại theo Luật Bảo vệ dữ liệu cá nhân. Doanh nghiệp có thể tự gỡ Trang Facebook, tắt gian hàng TikTok Shop trong Scaleon bất cứ lúc nào. Mọi yêu cầu khác do nhân viên của chúng tôi xử lý: gửi email tới lienhe@scaleon.vn hoặc qua biểu mẫu liên hệ, chúng tôi xác minh, thực hiện trong 7 ngày và báo lại. Người đã nhắn tin cho doanh nghiệp qua Trang được kết nối có thể yêu cầu doanh nghiệp đó, hoặc chúng tôi, cho xem, sửa hoặc xoá dữ liệu của mình. Các bước cụ thể ở Hướng dẫn xoá dữ liệu.
13. Trẻ em
Scaleon là công cụ cho doanh nghiệp, không dành cho trẻ em.
14. Thay đổi chính sách
Khi chính sách thay đổi, chúng tôi cập nhật trang này và ngày ở trên; thay đổi quan trọng được thông báo cho quản trị viên ngay trong Scaleon.
15. Liên hệ
CÔNG TY TNHH XUẤT NHẬP KHẨU QUYỀN MINH VŨ, 15 Lý Nam Đế, Phường Hoàn Kiếm, Thành phố Hà Nội, Việt Nam. Email: lienhe@scaleon.vn · Điện thoại: 0342946386.
Privacy Policy
Last updated: 2026-10-03 · Bản tiếng Việt
Scaleon ("we", "us") is web-based business management software for businesses in Vietnam, developed and operated by QUYEN MINH VU IMPORT EXPORT COMPANY LIMITED. Businesses use Scaleon to answer their customers on Facebook Messenger, take orders, receive TikTok Shop orders, manage products and stock, ship through delivery carriers, reconcile payments and read reports. This policy explains what data Scaleon processes, why, how long it is kept, who it is shared with and how to have it deleted.
1. Who is responsible
- For the conversations, customer records and orders a business manages in Scaleon, that business is the controller; we are the processor and process this data only on its instructions and only to provide Scaleon.
- For the accounts of people who sign in to Scaleon and for messages sent through our website contact form, we are the controller.
- We process personal data under Vietnam's Personal Data Protection Law (Law No. 91/2025/QH15) and its implementing regulations. Data protection contact: lienhe@scaleon.vn.
2. How accounts are connected
- Facebook Pages are connected through Facebook's official authorization screen (Facebook Login); the administrator chooses the Pages. Scaleon never asks for a Facebook password.
- TikTok Shop shops are connected through TikTok Shop's official authorization screen; the seller can revoke authorization at any time in TikTok Shop Seller Center; in Scaleon an administrator can turn the shop off to stop receiving orders.
- Shopee (awaiting Shopee's approval), Lazada (in development) and Zalo OA (in testing): through each platform's own authorization screen once available.
- Meta ad accounts and Conversions API: the administrator enters an access token of a system user in the business's own Meta Business account (used to read ad reports), and, if the business turns on the Conversions API, its pixel or dataset ID and access token.
- Delivery carriers and payment services: the administrator enters the API key, token or API account that the carrier or payment service gives the business.
- Sign in with Google: the user picks their Google account on Google's own screen (see section 4).
- Every token, API key and API password is encrypted with AES-256-GCM before it is stored.
3. Data we receive from connected platforms
Facebook Pages and Messenger (Meta)
- The Pages the administrator selects (name, ID) and each Page's access token; the app-scoped Facebook ID of the person who connected them (to handle deletion requests sent through Facebook). The connecting person's own access token is not kept.
- Messenger conversations between customers and those Pages: message text, attachments and time; the customer's Page-scoped ID (PSID), name and profile picture as provided by Meta. Received through Page webhooks and the Conversations API.
- Messages the business's staff send from Scaleon, including replies with the HUMAN_AGENT tag within 7 days of the customer's last message. Every such reply is typed by a person; Scaleon sends no automated or promotional messages with this tag.
Meta advertising
- For ad accounts the business assigns to a project: account, campaign, ad set and ad names, spend and results (read-only, to calculate advertising cost per order). Scaleon does not create or edit ads.
Meta Conversions API (only if the business turns it on)
- Events sent to the business's own pixel or dataset: Purchase (an order is confirmed, with its value), LeadSubmitted (a customer left a phone number in a Messenger conversation) and LeadQualified (staff confirmed the customer by phone).
- Each event may include SHA-256 hashes of the customer's phone number (also used as external ID), first and last name, country and city or province; and, unhashed as Meta requires, the Page ID and the customer's PSID, plus the fbc/fbp click identifiers, IP address and browser user agent when the customer came from the business's landing page.
TikTok Shop
- After a seller authorizes its shop: shop ID, name and region; access and refresh tokens (encrypted); orders (order ID, items, quantities, prices, fees, status, fulfilment and return information) with the buyer's name, phone number and delivery address exactly as TikTok returns them — TikTok may mask parts of this information; product information; settlement amounts.
- Used only to bring the shop's orders into Scaleon, ship them, deduct stock and produce the seller's reports; never to contact TikTok buyers for other purposes, never for advertising, never shared with anyone else.
Shopee (awaiting Shopee's approval) and Lazada (in development)
- Once available and authorized by the seller: the same kinds of order, product and settlement data as for TikTok Shop above, for the same purposes.
Zalo Official Account (in testing)
- The Official Account (OA) ID and name; access and refresh tokens.
- Messages between users and the OA (text, attachments, time); the user's Zalo ID for that OA, display name and avatar as provided by Zalo.
Instagram (in development)
- Only if a business connects an Instagram professional account once available: the account ID and username, direct messages with that account, and the sender's Instagram-scoped ID, username and profile picture as provided by Meta.
Delivery carriers and payment services
- Carriers the business connects (SPX Express, GHN, GHTK, Viettel Post, J&T Express, Ahamove, BEST Express, VNPost): we send the recipient's name, phone number, address, parcel details and COD amount of the orders the business ships, and receive tracking statuses and COD reconciliation data.
- VietQR codes are generated from the business's own bank account. If the business connects SePay or payOS, we receive incoming transfer notifications (amount, transfer content, time, transaction reference) to match payments to orders.
4. Google user data (Sign in with Google)
- When you choose "Sign in with Google", Scaleon requests only the basic scopes openid, email, profile. We receive from Google: your Google account identifier, your email address and whether Google has verified it, and your display name. Scaleon does not store your Google profile picture, does not keep Google access tokens after sign-in completes, and does not request access to Gmail, Drive, Contacts or any other Google data.
- The sole purpose is to sign you in, create and recognize your Scaleon account, and protect it (for example, emailing you when your sign-in methods change). It is not used for advertising, not sold, not transferred to third parties and not used to train AI models.
- Scaleon's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- To unlink: Account → Account security → disconnect Google, or remove Scaleon's access on your Google Account's third-party access page (myaccount.google.com/permissions). The Google identifier is deleted from Scaleon as soon as the link is removed or the Scaleon account is deleted.
5. Website contact form and deletion requests sent through Meta
- Contact form: name, phone number and/or email, company name, the request type and the message you type. Used only to get back to you; your IP address is not stored with the request (it is used only briefly to block flooding). Deleted on request.
- When you ask Facebook to delete your Scaleon data, Meta sends us your app-scoped user ID; we store it with a confirmation code so you can check the status on the Data Deletion Instructions page.
6. Data entered in Scaleon
- Business data entered or imported by staff: customers (name, phone number, address, notes), orders, products, stock, costs, income and expenses.
- Accounts: name, user name, email, phone number (entered at sign-up or in the profile, used to contact you and to find your account — password reset codes are still sent only to your email), role, password hash (bcrypt), two-factor settings and passkeys, sign-in history (time, IP address, device) and security logs.
- The business's own landing pages (optional): form submissions (name, phone number, address, product, quantity, order value) plus tracking data the page sends (fbclid, fbc, fbp, UTM parameters, campaign, ad set and ad IDs, IP address, browser user agent); page views carry only a random visitor ID and campaign parameters, without name, phone number or IP address. The business is responsible for informing visitors of its own website.
7. How we use data
- Only to provide Scaleon to the business: show conversations to its staff and send their replies, create and ship orders, reconcile payments, produce reports and keep accounts secure.
- Staff see only the projects (stores) they are assigned to; each connected Page or shop belongs to one project.
- We do not sell data, do not share it with third parties for their own purposes, do not use it for our own advertising and do not use it to train AI models.
8. Sharing and sub-processors
Data leaves Scaleon only to carry out the business's instructions or to run the service, to the following; each processes what it receives under its own terms:
- Our hosting provider in Vietnam, which stores Scaleon on our behalf.
- Meta (Messenger Platform, Conversions API), TikTok Shop, Shopee, Lazada, Zalo — when the business connects them.
- The delivery carriers and payment services (SePay, payOS) the business connects.
- Google — when a user chooses Sign in with Google.
- Our domain's email provider (currently Zoho Mail) — to send verification codes, system emails and replies.
- Competent authorities — when Vietnamese law requires it.
Scaleon's servers are located in Vietnam. When a business uses features of Meta, Google, TikTok, Shopee or Lazada, data sent to those platforms may be processed on their servers outside Vietnam under their own policies.
9. Where data is stored and how it is protected
Each company has its own database on servers located in Vietnam that we rent and manage; data travels over HTTPS. Tokens, API keys and API passwords are encrypted with AES-256-GCM; passwords are hashed. Two-factor sign-in and passkeys are available and administrators can require them; access is role-based and sign-ins are logged. Details are on our Security page. If a breach exposes personal data, we notify the affected businesses and the competent authority within the time required by law.
10. Cookies
Scaleon uses only the cookies it needs to work: keeping a user signed in, the two-factor, passkey and re-verification steps, the selected company and project, short-lived cookies while a Facebook Page is being connected or a Google sign-in is in progress, and interface preferences. We use no advertising or analytics cookies. The public pages of this website set no cookies.
11. Retention
- Facebook Page access tokens are deleted immediately when an administrator removes the Page ("Gỡ").
- Other keys (ad-account token, Conversions API token, carrier, payment and marketplace keys): turning a connection off stops its use but keeps the encrypted key, so it can be turned back on and parcels already on the way can still be tracked. They are deleted within 7 days of a request, and within 30 days after the business stops using Scaleon.
- Conversations, customer records, orders, landing-page leads and marketplace buyer data are kept while the business uses Scaleon. They are deleted within 7 days of a verified deletion request, and within 30 days after the business stops using Scaleon, unless Vietnamese law requires a longer period (for example, accounting records the business must keep).
- When a business stops using Scaleon, it can download its lists as files or ask us to export its data before deletion.
- Sign-in history (time, IP address, device): within each company's data it is deleted automatically after 180 days; the sign-in log of Scaleon accounts is append-only and can only be deleted once older than 180 days.
- Security and permission audit logs are append-only: they cannot be edited or deleted from the application and are kept while the business's account exists, to protect it.
12. Your rights and data deletion
You have the right to be informed about, access, correct, delete and restrict the processing of your personal data, to withdraw consent and to complain, under Vietnam's Personal Data Protection Law. Businesses can remove a Facebook Page or turn off a TikTok Shop shop in Scaleon themselves at any time. Every other request is handled by our staff: email lienhe@scaleon.vn or use the contact form; we verify the request, carry it out within 7 days and confirm. People who messaged a business through a connected Page can ask that business, or us, to access, correct or delete their data. Step-by-step instructions are in the Data Deletion Instructions.
13. Children
Scaleon is a tool for businesses and is not directed to children.
14. Changes
When this policy changes we update this page and the date above. Significant changes are announced to administrators inside Scaleon.
15. Contact
QUYEN MINH VU IMPORT EXPORT COMPANY LIMITED, 15 Lý Nam Đế, Phường Hoàn Kiếm, Thành phố Hà Nội, Việt Nam. Email: lienhe@scaleon.vn · Phone: 0342946386.