← Back to homeTECHBUY PRIVACY · DATA TRANSPARENCY

Personal data protection policy

Data categories, purposes, recipients, retention, customer rights and security measures.

DRAFTUpdated 6 Sept 2026
01

1. Controller and scope

The controller or controller-processor is [CẦN BỔ SUNG: tên pháp lý của doanh nghiệp/hộ kinh doanh], number [CẦN BỔ SUNG: mã số doanh nghiệp/mã số thuế], at [CẦN BỔ SUNG: địa chỉ trụ sở đăng ký]. Privacy contact: cskh@techbuy.vn, 0981112112.

This policy covers visitors, buyers, account holders, reviewers, support/chat users, warranty recipients and other contacts.

02

2. Data categories

TECHBUY does not store card numbers, CVV, bank OTPs or online-banking passwords. OnePay and banks process those credentials.

  • Identity and contact details;
  • Hashed passwords, verification challenges, sessions, device and minimized security logs;
  • Cart, wishlist, viewed items, orders, payment status, delivery, returns and warranty;
  • Invoice and tax-verification details;
  • Reviews, support messages, uploads and case history;
  • Push tokens and notification choices;
  • Browser, error, security, search and product-usage events needed to operate or improve the service.
03

3. Sources and collection

Data comes from customer input and use, device storage, staff/stores, carriers, OnePay/banks, manufacturers/service centers, verification providers and competent authorities.

TECHBUY minimizes collection, gives timely notice and records consent where required. Refusing optional data must not block a contract that does not need it.

04

4. Purposes

  • Create and secure accounts and sync customer features;
  • Process orders, payments, delivery, invoices and records;
  • Provide returns, warranty, support, chat and complaints handling;
  • Prevent fraud, secure systems and meet legal duties;
  • Improve search, recommendations, content and customer experience where permitted;
  • Send marketing only on a lawful basis with an easy opt-out.
05

5. Consent and lawful grounds

TECHBUY relies on consent or another case in which applicable law permits processing without consent, including necessary transaction steps and legal duties.

Consent must be voluntary, specific, clear and verifiable and may be withdrawn. Withdrawal does not invalidate earlier processing or override statutory retention.

06

6. Recipients and transfers

Recipients receive only necessary data and must meet appropriate safeguards. Cross-border processing requires the applicable impact assessment, records and protective measures.

  • Authorized TECHBUY staff;
  • Infrastructure, storage, email, security and technical providers;
  • Carriers, OnePay, banks and payment providers;
  • Firebase/OTP/push providers, Cloudflare Turnstile, Zalo or another customer-selected support channel;
  • Manufacturers, distributors, service centers and tax lookup providers as needed;
  • Authorities or other parties under law, rights protection or valid consent.
07

7. Retention

  • Cookies and browser identifiers for the periods in the Cookie Policy;
  • Orders, payments, invoices, warranty and complaint records as needed for transactions, tax/accounting, rights and limitation periods;
  • Accounts until deletion is requested or they are no longer needed, subject to legal retention;
  • Support content, uploads, logs and backups under an approved, necessity-based schedule;
  • Marketing data until consent is withdrawn or the purpose ends.
08

8. Individual rights

Send a request to cskh@techbuy.vn or 0981112112 with contact, scope and reasonable verification. TECHBUY responds within the legal period and explains any lawful limitation.

  • Be informed and consent or decline; withdraw consent;
  • Request access, provision, correction, deletion or restriction;
  • Object, complain, report, sue and seek compensation as permitted by law;
  • Exercise other rights and protect personal data.
09

9. Security and incidents

TECHBUY applies access controls, suitable encryption/hashing, session protection, logging, backups, provider review and incident response.

A qualifying breach is reported to the specialized authority and affected individuals within the time and form required by law.

10

10. Children and third-party data

Anyone providing a child’s or another person’s data must have authority and protect that person’s interests. Child-data consent and verification rules apply.

Do not post identity documents, health, financial or other sensitive data in public reviews or support unless lawfully requested through an appropriate channel.

11

11. Changes

Material changes show an update date and receive advance notice where required. A new processing purpose requires new consent unless another lawful ground applies.

This draft is not effective and does not replace feature-specific notices or consent.

Personal data protection policy | TECHBUY