Data transparency
Privacy and data protection policy
SHOP respects customer privacy and takes reasonable measures to limit unnecessary data collection.
1. Principles of data collection
SHOP does not proactively request the collection of unnecessary information such as date of birth, avatar or other personal information if it does not serve the provision of services.
However, to operate the service, SHOP may process some necessary data, including:
- e-mail;
- account identifier;
- transaction code;
- payment amount and status;
- KEY or related identifier value in appropriate form;
- quota and usage history;
- model called;
- token or unit of use;
- request time;
- request status;
- IP address;
- browser/device information;
- login log;
- Technical data for fraud prevention and security.
SHOP only processes data to the extent necessary, in accordance with service purposes and legal regulations.
2. Prompt content and data sent to the AI model
For the AI model to process the request, the customer submission may have to be passed through the SHOP infrastructure and forwarded to the AI model provider or the corresponding upstream provider.
Therefore, customers should not send passwords, API KEYs, banking information, trade secrets, sensitive identification data or confidential information to the prompt, unless the customer clearly understands and accepts how the respective service handles such data.
SHOP applies a mechanism to limit the storage of unnecessary content. However, depending on the technical architecture, security systems, error logs, caches or upstream providers, some data may be processed or stored temporarily to the extent necessary.
SHOP does not claim that the service is an end-to-end encrypted system if the technical architecture does not meet that standard.
3. Purpose of data processing
The data can be used to:
- Log in and authenticate your account;
- providing services;
- calculate quota and costs;
- payment processing;
- Transaction reconciliation;
- detect abuse;
- prevent fraud;
- error investigation;
- account and server protection;
- customer support;
- fulfill legal obligations;
- Improve the technical stability of the service.
SHOP does not sell customers' personal data to third parties for advertising purposes.
4. Payment
Payments may be processed by PayOS, the bank or the relevant payment entity.
SHOP can receive necessary data to confirm transactions such as:
- transaction code;
- amount;
- time;
- transaction content;
- payment status;
- and other necessary information legally provided by the payment unit.
Information collected directly by the billing entity is also governed by that entity's own policies.
5. AI vendors and third parties
When using a third-party model, the data needed to fulfill the request can be passed to the respective provider.
Such providers may have their own data storage and processing policies.
SHOP is only responsible for data processing activities within the scope of SHOP's control and within the scope of law.
SHOP cannot provide absolute guarantees regarding systems under the independent control of third parties.
6. Security
SHOP applies reasonable technical and organizational measures to limit:
- unauthorized access;
- account hijacking;
- KEY leak;
- unauthorized data alteration;
- and system attacks.
Data transmitted over the network is protected by appropriate transmission security mechanisms when supported by the infrastructure.
No Internet system can be guaranteed to be absolutely secure. Therefore, SHOP does not make a commitment that all security risks can be eliminated 100%.
7. Share data
SHOP does not sell or provide customer data to third parties other than for the purpose of providing services, except in necessary cases such as:
- infrastructure providers;
- database;
- payment system;
- AI model provider;
- security services;
- necessary operational services;
- or a competent state agency when required by law.
Parties may only access data to the extent necessary for their respective functions and in accordance with applicable law.
8. Data security and abuse protection
SHOP may use IP, device technical identifiers, login logs and usage behavior to:
- detect fake accounts;
- prevent abuse of free plans;
- spam detection;
- avoid limits;
- and server protection.
SHOP does not use this data to track customers other than for its stated legitimate purposes.
9. Storage period
Data is saved for as long as necessary to:
- providing services;
- control;
- dispute handling;
- security;
- anti-fraud;
- and meet legal retention obligations.
When data is no longer needed and is not subject to continued storage, SHOP can delete, anonymize or process according to appropriate procedures.
10. Customer rights
To the extent applicable under applicable law, customers may request to exercise their rights regarding their personal data, including the right to know, access, request correction, deletion or exercise other rights in accordance with the law.
Some requests may be limited if SHOP needs to continue saving data to:
- fulfill legal obligations;
- dispute handling;
- anti-fraud;
- protect legal rights;
- or as permitted by law.
SHOP may require identity verification before processing requests related to account data.
11. Policy changes
SHOP may update the Privacy Policy when there are changes to:
- system;
- supplier;
- features;
- data processing methods;
- or legal regulations.
The current version and update date will be announced on SHOP.
Contact for privacy and support: Zalo 0352171405