Bỏ qua tới nội dung

Privacy Policy

Last updated: 2026-09-26 · Bản tiếng Việt

Scaleon ("we", "us") is web-based sales management software for businesses in Vietnam, developed and operated by QUYEN MINH VU IMPORT EXPORT COMPANY LIMITED. Businesses use Scaleon to answer their customers on Facebook Messenger, take orders, manage products and stock, ship through delivery carriers, reconcile payments and read sales reports. This policy explains what data Scaleon processes, why, how long it is kept and how to have it deleted.

Who is responsible

For the conversations, customer records and orders a business manages in Scaleon, that business decides what is collected and why; we process this data on its behalf and only to provide Scaleon to it. For the accounts of people who sign in to Scaleon, we are responsible.

How accounts are connected

  • Facebook Pages are connected through Facebook's official authorization screen (Facebook Login); the administrator chooses the Pages. Scaleon never asks for a Facebook password.
  • Meta ad accounts and Conversions API: the administrator enters an access token of a system user in the business's own Meta Business account (used to read ad reports), and, if the business turns on the Conversions API, its pixel or dataset ID and access token.
  • Delivery carriers and payment services: the administrator enters the API key, token or API account (user name and password issued for API use) that the carrier or payment service gives the business.
  • Zalo OA (in testing), TikTok Shop and Shopee (in development): through each platform's own authorization screen once available.
  • Every token, API key and API password is encrypted with AES-256-GCM before it is stored.

Data we receive from connected platforms

Facebook Pages and Messenger (Meta)

  • The Pages the administrator selects (name, ID) and each Page's access token.
  • Messenger conversations between customers and those Pages: message text, attachments and time; the customer's Page-scoped ID (PSID), name and profile picture as provided by Meta. Received through Page webhooks and the Conversations API.
  • Messages the business's staff send from Scaleon, including replies with the HUMAN_AGENT tag within 7 days of the customer's last message. Every such reply is typed by a person; Scaleon sends no automated or promotional messages with this tag.

Meta advertising

  • For ad accounts the business assigns to a project: account, campaign, ad set and ad names, spend and results (read-only, to calculate advertising cost per order). Scaleon does not create or edit ads.

Meta Conversions API (only if the business turns it on)

  • Events sent to the business's own pixel or dataset: Purchase (an order is confirmed, with its value), LeadSubmitted (a customer left a phone number in a Messenger conversation) and LeadQualified (staff confirmed the customer by phone).
  • Each event may include SHA-256 hashes of the customer's phone number (also used as external ID), first and last name, country and city or province; and, unhashed as Meta requires, the Page ID and the customer's PSID, plus the fbc/fbp click identifiers, IP address and browser user agent when the customer came from the business's landing page.

Zalo Official Account (in testing)

  • The Official Account (OA) ID and name; access and refresh tokens.
  • Messages between users and the OA (text, attachments, time); the user's Zalo ID for that OA, display name and avatar as provided by Zalo.

Instagram (in development)

  • Only if a business connects an Instagram professional account once available: the account ID and username, direct messages with that account (text, attachments, time), and the sender's Instagram-scoped ID, username and profile picture as provided by Meta.

TikTok Shop and Shopee (in development)

  • Only after a seller authorizes its shop once available: shop ID and name; access tokens; orders (order ID, items, quantities, prices, fees, status) with the buyer's name, phone number and delivery address as provided by the marketplace for fulfilment; products and stock levels; settlement amounts.
  • Used only to sync the seller's orders and stock, arrange delivery and produce the seller's reports, never to contact the marketplace's buyers for other purposes.

Delivery carriers and payment services

  • Carriers the business connects (such as GHN, GHTK, Viettel Post, J&T Express, Ahamove): we send the recipient's name, phone number, address, parcel details and COD amount of the orders the business ships, and receive tracking statuses and COD reconciliation data.
  • VietQR codes are generated from the business's own bank account. If the business connects SePay or payOS, we receive incoming transfer notifications (amount, transfer content, time, transaction reference) to match payments to orders.

The business's own landing pages (optional)

  • Form submissions: name, phone number, address, product, quantity and order value, plus the tracking data the page sends (fbclid, fbc, fbp, UTM parameters, campaign, ad set and ad IDs, IP address and browser user agent).
  • Page views: a random visitor ID, the page, campaign and ad IDs and UTM parameters, without name, phone number or IP address.
  • Used to create leads for the business's staff and to measure its conversion rate and ads. The business is responsible for informing visitors of its own website.

Data entered in Scaleon

  • Business data entered or imported by staff: customers (name, phone number, address, notes), orders, products, stock and costs.
  • Staff accounts: name, user name, role, password hash (bcrypt), two-factor settings and passkeys, sign-in history (time, IP address, device) and security logs.

How we use data

  • Only to provide Scaleon to the business: show conversations to its staff and send their replies, create and ship orders, reconcile payments, produce reports and keep accounts secure.
  • Staff see only the projects (stores) they are assigned to; each connected Page belongs to one project.
  • We do not sell data, do not share it with third parties for their own purposes, do not use it for our own advertising and do not use it to train AI models.

Sharing

Data leaves Scaleon only to carry out the business's instructions: to Meta when the business uses Meta features (replies through the Messenger Platform, Conversions API events), to the carriers and payment services it connects, to our hosting provider that stores it on our behalf, or to competent authorities when Vietnamese law requires it. Each platform processes what it receives under its own terms.

Where data is stored and how it is protected

Data is stored on servers located in Vietnam that we rent and manage, and travels over HTTPS. Tokens, API keys and API passwords are encrypted with AES-256-GCM; staff passwords are hashed. Two-factor sign-in is available and administrators can require it for their staff; access is role-based and sign-ins are logged.

Cookies

Scaleon uses only the cookies it needs to work: keeping a user signed in, the two-factor, passkey and re-verification steps, the selected project, a short-lived cookie while a Facebook Page is being connected, and interface preferences. We use no advertising or analytics cookies. The public pages of this website set no cookies.

Retention

  • Facebook Page access tokens are deleted immediately when an administrator removes the Page ("Gỡ").
  • Other keys (ad-account token, Conversions API token, carrier, payment and marketplace keys): turning a connection off stops its use but keeps the encrypted key, so it can be turned back on and parcels already on the way can still be tracked. They are deleted within 7 days of a request, and within 30 days after the business stops using Scaleon.
  • Conversations, customer records, orders, landing-page leads and marketplace buyer data are kept while the business uses Scaleon. They are deleted within 7 days of a verified deletion request, and within 30 days after the business stops using Scaleon, unless Vietnamese law requires a longer period (for example, accounting records the business must keep).
  • Sign-in history (time, IP address, device) is deleted after 180 days.
  • Security and permission audit logs are append-only: they cannot be edited or deleted from the application and are kept while the business's account exists, to protect it.

Your rights and data deletion

Businesses can remove a Facebook Page in Scaleon themselves at any time. Every other deletion request is handled by our staff: email lienhe@scaleon.vn, we verify the request, carry it out within 7 days and confirm by email. People who messaged a business through a connected Page can ask that business, or us, to access, correct or delete their data. Step-by-step instructions are in the Data Deletion Instructions.

Children

Scaleon is a tool for businesses and is not directed to children.

Changes

When this policy changes we update this page and the date above. Significant changes are announced to administrators inside Scaleon.

Contact

QUYEN MINH VU IMPORT EXPORT COMPANY LIMITED, 15 Lý Nam Đế, Phường Hàng Mã, Quận Hoàn Kiếm, Thành phố Hà Nội, Việt Nam. Email: lienhe@scaleon.vn · Phone: 0342946386.


Chính sách quyền riêng tư

Cập nhật: 26/09/2026

Scaleon là phần mềm quản lý bán hàng trên nền web cho doanh nghiệp tại Việt Nam do CÔNG TY TNHH XUẤT NHẬP KHẨU QUYỀN MINH VŨ phát triển và vận hành. Doanh nghiệp dùng Scaleon để trả lời khách trên Facebook Messenger, lên đơn, quản lý sản phẩm và tồn kho, gửi hàng qua hãng vận chuyển, đối soát tiền và xem báo cáo. Chính sách này nói rõ Scaleon xử lý dữ liệu gì, để làm gì, lưu bao lâu và cách yêu cầu xoá.

Ai chịu trách nhiệm

Với hội thoại, hồ sơ khách và đơn hàng mà doanh nghiệp quản lý trong Scaleon, doanh nghiệp quyết định thu thập gì và để làm gì; chúng tôi xử lý thay cho doanh nghiệp và chỉ để cung cấp Scaleon. Với tài khoản của người đăng nhập Scaleon, chúng tôi chịu trách nhiệm.

Cách kết nối từng loại tài khoản

  • Trang Facebook kết nối qua màn cấp quyền chính thức của Facebook (Facebook Login); quản trị viên tự chọn Trang. Scaleon không bao giờ hỏi mật khẩu Facebook.
  • Tài khoản quảng cáo Meta và Conversions API: quản trị viên nhập mã truy cập của người dùng hệ thống trong tài khoản Meta Business của chính doanh nghiệp (để đọc báo cáo quảng cáo), và nếu bật Conversions API thì nhập ID pixel hoặc tập dữ liệu cùng mã truy cập của nó.
  • Hãng vận chuyển và dịch vụ thanh toán: quản trị viên nhập khoá API, token hoặc tài khoản API (tên đăng nhập và mật khẩu cấp riêng cho API) mà hãng hay dịch vụ thanh toán cấp cho doanh nghiệp.
  • Zalo OA (thử nghiệm), TikTok Shop và Shopee (đang phát triển): qua màn cấp quyền của chính nền tảng khi tính năng sẵn sàng.
  • Mọi mã truy cập, khoá API, mật khẩu API đều được mã hoá AES-256-GCM trước khi lưu.

Dữ liệu nhận từ nền tảng được kết nối

Trang Facebook và Messenger (Meta)

  • Các Trang quản trị viên chọn (tên, ID) và mã truy cập của từng Trang.
  • Hội thoại Messenger giữa khách và Trang: nội dung, tệp đính kèm, thời gian; mã khách theo Trang (PSID), tên và ảnh đại diện do Meta cung cấp. Nhận qua webhook của Trang và Conversations API.
  • Tin nhân viên gửi từ Scaleon, gồm tin trả lời gắn thẻ HUMAN_AGENT trong 7 ngày kể từ tin cuối của khách. Mọi tin loại này do người thật gõ; Scaleon không gửi tin tự động hay quảng cáo bằng thẻ này.

Quảng cáo Meta

  • Với tài khoản quảng cáo doanh nghiệp gán cho dự án: tên tài khoản, chiến dịch, nhóm quảng cáo, quảng cáo, chi tiêu và kết quả (chỉ đọc, để tính chi phí quảng cáo trên mỗi đơn). Scaleon không tạo hay sửa quảng cáo.

Meta Conversions API (chỉ khi doanh nghiệp bật)

  • Sự kiện gửi tới pixel hoặc tập dữ liệu của chính doanh nghiệp: Purchase (đơn được xác nhận, kèm giá trị), LeadSubmitted (khách để lại số điện thoại trong hội thoại Messenger) và LeadQualified (nhân viên đã xác nhận khách qua điện thoại).
  • Mỗi sự kiện có thể kèm mã băm SHA-256 của số điện thoại (cũng dùng làm mã khách bên ngoài), họ, tên, quốc gia, tỉnh/thành của khách; và, để nguyên theo yêu cầu của Meta, ID Trang và PSID của khách, cùng mã nhấp fbc/fbp, địa chỉ IP, thông tin trình duyệt khi khách đến từ landing của doanh nghiệp.

Zalo Official Account (thử nghiệm)

  • ID và tên Official Account (OA); mã truy cập và mã làm mới.
  • Tin nhắn giữa người dùng và OA (nội dung, tệp đính kèm, thời gian); mã người dùng Zalo theo OA, tên hiển thị và ảnh đại diện do Zalo cung cấp.

Instagram (đang phát triển)

  • Chỉ khi doanh nghiệp kết nối tài khoản Instagram chuyên nghiệp lúc tính năng sẵn sàng: ID và tên người dùng của tài khoản, tin nhắn trực tiếp với tài khoản đó (nội dung, tệp đính kèm, thời gian), mã người gửi theo Instagram, tên người dùng và ảnh đại diện do Meta cung cấp.

TikTok Shop và Shopee (đang phát triển)

  • Chỉ sau khi người bán cấp quyền cho gian hàng lúc tính năng sẵn sàng: ID và tên gian hàng; mã truy cập; đơn hàng (mã đơn, sản phẩm, số lượng, giá, phí, trạng thái) kèm tên, số điện thoại, địa chỉ người mua do sàn cung cấp để giao hàng; sản phẩm và tồn kho; số tiền quyết toán.
  • Chỉ dùng để đồng bộ đơn và tồn kho, giao hàng và làm báo cáo cho người bán, không dùng để liên hệ người mua của sàn vì mục đích khác.

Hãng vận chuyển và dịch vụ thanh toán

  • Hãng doanh nghiệp kết nối (như GHN, GHTK, Viettel Post, J&T Express, Ahamove): chúng tôi gửi tên, số điện thoại, địa chỉ người nhận, thông tin kiện hàng và tiền thu hộ của đơn doanh nghiệp gửi; nhận lại trạng thái giao và số liệu đối soát COD.
  • Mã VietQR tạo từ tài khoản ngân hàng của chính doanh nghiệp. Nếu doanh nghiệp nối SePay hoặc payOS, chúng tôi nhận thông báo tiền về (số tiền, nội dung chuyển khoản, thời gian, mã giao dịch) để khớp với đơn.

Landing của chính doanh nghiệp (tuỳ chọn)

  • Biểu mẫu khách gửi: tên, số điện thoại, địa chỉ, sản phẩm, số lượng, giá trị đơn, cùng dữ liệu theo dõi trang gửi kèm (fbclid, fbc, fbp, tham số UTM, ID chiến dịch, nhóm quảng cáo, quảng cáo, địa chỉ IP và thông tin trình duyệt).
  • Lượt xem trang: mã khách truy cập ngẫu nhiên, trang được xem, ID chiến dịch, quảng cáo và tham số UTM; không có tên, số điện thoại hay địa chỉ IP.
  • Dùng để tạo khách tiềm năng cho nhân viên của doanh nghiệp và đo tỉ lệ chuyển đổi, hiệu quả quảng cáo. Doanh nghiệp tự thông báo cho người xem website của mình.

Dữ liệu nhập vào Scaleon

  • Dữ liệu doanh nghiệp do nhân viên nhập hoặc nhập từ tệp: khách hàng (tên, số điện thoại, địa chỉ, ghi chú), đơn hàng, sản phẩm, tồn kho, giá vốn.
  • Tài khoản nhân viên: tên, tên đăng nhập, vai trò, mật khẩu đã băm (bcrypt), cài đặt xác thực hai lớp và khoá đăng nhập, lịch sử đăng nhập (thời gian, địa chỉ IP, thiết bị) và nhật ký bảo mật.

Mục đích sử dụng

  • Chỉ để cung cấp Scaleon cho doanh nghiệp: hiện hội thoại cho nhân viên và gửi tin trả lời, lên đơn và gửi hàng, đối soát tiền, làm báo cáo, bảo vệ tài khoản.
  • Nhân viên chỉ thấy dự án (cửa hàng) mình được phân công; mỗi Trang được kết nối thuộc một dự án.
  • Chúng tôi không bán dữ liệu, không chia sẻ cho bên thứ ba vì mục đích riêng của họ, không dùng cho quảng cáo của chúng tôi và không dùng để huấn luyện mô hình AI.

Chia sẻ dữ liệu

Dữ liệu chỉ rời Scaleon để làm theo yêu cầu của doanh nghiệp: tới Meta khi doanh nghiệp dùng tính năng của Meta (trả lời qua Messenger Platform, sự kiện Conversions API), tới hãng vận chuyển và dịch vụ thanh toán doanh nghiệp đã kết nối, tới nhà cung cấp máy chủ lưu trữ thay chúng tôi, hoặc tới cơ quan có thẩm quyền khi pháp luật Việt Nam yêu cầu. Mỗi nền tảng xử lý dữ liệu nhận được theo điều khoản của chính họ.

Nơi lưu trữ và bảo mật

Dữ liệu nằm trên máy chủ đặt tại Việt Nam do chúng tôi thuê và quản lý, truyền qua HTTPS. Mã truy cập, khoá API, mật khẩu API được mã hoá AES-256-GCM; mật khẩu nhân viên được băm. Scaleon hỗ trợ đăng nhập hai lớp và quản trị viên có thể bắt buộc cho nhân viên; phân quyền theo vai trò và có nhật ký đăng nhập.

Cookie

Scaleon chỉ dùng cookie cần để hoạt động: giữ phiên đăng nhập, các bước xác thực hai lớp, khoá đăng nhập và xác minh lại, dự án đang chọn, cookie ngắn hạn khi đang kết nối Trang Facebook, và lựa chọn giao diện. Không dùng cookie quảng cáo hay cookie phân tích. Các trang công khai của website này không đặt cookie nào.

Thời hạn lưu

  • Mã truy cập của Trang Facebook bị xoá ngay khi quản trị viên bấm "Gỡ" Trang.
  • Các khoá khác (mã tài khoản quảng cáo, mã Conversions API, khoá hãng vận chuyển, thanh toán, sàn): tắt kết nối là ngừng dùng nhưng vẫn giữ khoá đã mã hoá, để bật lại được và vẫn theo dõi được kiện hàng đang đi. Các khoá này bị xoá trong 7 ngày kể từ khi có yêu cầu, và trong 30 ngày sau khi doanh nghiệp ngừng dùng Scaleon.
  • Hội thoại, hồ sơ khách, đơn hàng, khách tiềm năng từ landing và dữ liệu người mua từ sàn lưu khi doanh nghiệp còn dùng Scaleon; xoá trong 7 ngày kể từ khi yêu cầu xoá được xác minh, và trong 30 ngày sau khi doanh nghiệp ngừng dùng Scaleon, trừ khi pháp luật Việt Nam buộc lưu lâu hơn (ví dụ chứng từ kế toán doanh nghiệp phải giữ).
  • Lịch sử đăng nhập (thời gian, địa chỉ IP, thiết bị) được xoá sau 180 ngày.
  • Nhật ký bảo mật và phân quyền chỉ được ghi thêm: không sửa, không xoá được từ phần mềm, và được giữ khi tài khoản doanh nghiệp còn tồn tại để bảo vệ tài khoản.

Quyền của bạn và xoá dữ liệu

Doanh nghiệp có thể tự gỡ Trang Facebook trong Scaleon bất cứ lúc nào. Mọi yêu cầu xoá khác do nhân viên của chúng tôi xử lý: gửi email tới lienhe@scaleon.vn, chúng tôi xác minh, thực hiện trong 7 ngày và báo lại qua email. Người đã nhắn tin cho doanh nghiệp qua Trang được kết nối có thể yêu cầu doanh nghiệp đó, hoặc chúng tôi, cho xem, sửa hoặc xoá dữ liệu của mình theo quy định của pháp luật Việt Nam về bảo vệ dữ liệu cá nhân. Các bước cụ thể ở Hướng dẫn xoá dữ liệu.

Trẻ em

Scaleon là công cụ cho doanh nghiệp, không dành cho trẻ em.

Thay đổi chính sách

Khi chính sách thay đổi, chúng tôi cập nhật trang này và ngày ở trên; thay đổi quan trọng được thông báo cho quản trị viên ngay trong Scaleon.

Liên hệ

CÔNG TY TNHH XUẤT NHẬP KHẨU QUYỀN MINH VŨ, 15 Lý Nam Đế, Phường Hàng Mã, Quận Hoàn Kiếm, Thành phố Hà Nội, Việt Nam. Email: lienhe@scaleon.vn · Điện thoại: 0342946386.