Legal · Personal data
Privacy Policy
Chính sách bảo mật · Aligned to Decree 13/2023/ND-CP · Version 5.4This Privacy Policy explains how SiteminderStore Vietnam Company Limited collects, uses, discloses, and safeguards personal data. It is written to satisfy the requirements of Decree 13/2023/ND-CP on Personal Data Protection (Nghị định 13/2023/NĐ-CP về bảo vệ dữ liệu cá nhân) and reflects the guidance issued by the Ministry of Public Security through the Department of Cybersecurity and High-Tech Crime Prevention (Cục An ninh mạng và phòng, chống tội phạm sử dụng công nghệ cao, A05). If you have a question that this policy does not answer, please write to dpo@siteminderstore.org.
§ 01Who we are and our role under Decree 13
The controller of the personal data described in this policy is SiteminderStore Vietnam Company Limited (Công ty TNHH SiteminderStore Việt Nam), Business Registration Certificate No. 0316854921, registered office at 235 Nguyễn Văn Cừ, Phường Nguyễn Cư Trinh, Quận 1, TP. Hồ Chí Minh. In the vocabulary of Decree 13, we are the Bên Kiểm soát dữ liệu cá nhân for the personal data of our own customers, visitors, and prospects. When a hotel Customer connects a marketplace Module to its SiteMinder Workspace and instructs the Module to process the personal data of its own guests, we act as processor (Bên Xử lý dữ liệu cá nhân) on behalf of that hotel. The relationship between controller and processor is governed by the Data Processing Agreement.
§ 02Categories of personal data we process
We process the following categories of personal data:
| Category | Examples | Source |
|---|---|---|
| Customer contact information | Full name, business e-mail, business phone, job title, name of the hotel entity | Provided by the account owner at registration |
| Billing information | Tax code, invoice address, bank-transfer reference numbers, MoMo or VNPay masked identifiers | Provided at checkout or generated by the payment provider |
| Guest data flowing through a Module | Guest name, e-mail, phone, reservation reference, arrival and departure dates, room type, special requests | Retrieved from your SiteMinder Workspace under your authorisation |
| Device and technical data | IP address, browser user agent, session identifier, coarse geolocation derived from IP | Automatically collected when you use the Marketplace |
| Support correspondence | Ticket content, screenshots you attach, chat transcripts | Provided when you contact support |
We do not knowingly process special-category data (health, biometric, religious, or political data) other than what a Customer may voluntarily embed in a support ticket. If we discover that a Module or a Customer instruction requires us to process special-category data, we apply the additional safeguards described in the Vietnam Personal Data Protection page.
§ 03Why we process personal data — purposes
We process personal data to perform the contract we have with a Customer (opening and operating the account, delivering the Modules, issuing electronic invoices, handling refunds); to comply with our legal obligations (tax law, e-invoicing rules, obligations under Decree 13 and under the Law on Cybersecurity 2018, obligations under the Law on Consumer Protection 2023); to secure the Marketplace against fraud and abuse; to communicate with Customers about service changes, incidents, and policy updates; to improve the Marketplace on the basis of aggregated, de-identified usage patterns; and, where a Customer has explicitly opted in, to send commercial e-mails about new Modules or promotions.
§ 04Legal bases we rely on
Article 11 of Decree 13 recognises consent as the principal ground for processing but also allows processing that is necessary for the performance of a contract, for compliance with a legal obligation, for the protection of the vital interests of the data subject, for the performance of a task in the public interest, or for the legitimate interests of the controller balanced against the rights of the data subject. In practice we rely on:
- Consent for marketing communications, for analytics cookies, and for any transfer of personal data to a country outside Vietnam that requires it.
- Contract for the delivery of the Modules and the maintenance of the account.
- Legal obligation for e-invoicing, tax reporting, and any obligation to disclose data to A05 or to a competent Vietnamese court.
- Legitimate interest for security monitoring, fraud prevention, and internal reporting, always balanced against the data subject's fundamental rights.
§ 05Data-subject rights and how to exercise them
Under Decree 13 you have the right to be informed, the right of access, the right to correct inaccurate data, the right to delete data whose processing is no longer necessary, the right to restrict processing in specified cases, the right to object, the right to data portability where technically feasible, the right to withdraw consent at any time, and the right to lodge a complaint with the competent authority. Requests can be sent to dpo@siteminderstore.org from the e-mail address associated with the account. We reply within seventy-two hours to acknowledge receipt and within thirty days to complete the request. Where a request is complex or where we receive a large volume of related requests we may extend that window by a further thirty days and will notify you of the extension and the reasons for it.
If you are dissatisfied with the way we have handled your request, you may lodge a complaint with the Department of Cybersecurity and High-Tech Crime Prevention (A05) of the Ministry of Public Security (Bộ Công an), whose contact details are published on the Ministry's website. Consumers may also refer to the Competition and Consumer Protection Committee of the Ministry of Industry and Trade under the Law on Consumer Protection 2023.
§ 06How long we keep personal data
| Category | Retention | Trigger to delete |
|---|---|---|
| Customer account data | Duration of the account plus 24 months | Account closure request or 24-month inactivity |
| Billing and e-invoicing records | 10 years | Statutory obligation under the Law on Accounting and tax regulations |
| Guest data processed on behalf of a Customer | As instructed by the Customer, default 12 months | Customer instruction or termination of the Module |
| Server logs and security telemetry | 13 months | Rolling deletion |
| Support tickets | 36 months | Rolling deletion |
| Marketing consent records | Until withdrawn plus 24 months as proof of consent | Withdrawal of consent |
§ 07Cross-border transfers
The personal data of Vietnamese data subjects is stored in Vietnam in the Viettel IDC datacentres in Hồ Chí Minh City and Hà Nội, in compliance with the localisation obligation of Article 26 of the Law on Cybersecurity 2018. A limited category of aggregated, de-identified operational data (Module version counters, anonymised latency measurements, feature-usage histograms) is replicated to a Singapore region operated by Amazon Web Services for the purposes of regional latency optimisation and disaster recovery. Before that replication began we completed a Cross-Border Transfer Impact Assessment as required by Article 25 of Decree 13; the assessment is on file with our DPO and available on request to Customers subject to a confidentiality undertaking.
Personal data of Vietnamese guests never leaves Vietnamese soil. Only aggregated, de-identified operational metrics cross the border, and only after an Article-25 impact assessment.
§ 08Subprocessors
We rely on a small number of vetted subprocessors, each of which is bound by a written data-processing agreement compatible with Decree 13:
| Subprocessor | Purpose | Location |
|---|---|---|
| Viettel IDC | Primary infrastructure hosting | Hồ Chí Minh City and Hà Nội, Vietnam |
| Amazon Web Services Singapore | Key management (AWS KMS) and disaster-recovery replication of anonymised operational data | Singapore |
| MoMo | Payment processing for e-wallet transactions | Vietnam |
| VNPay | Payment processing for domestic cards | Vietnam |
| Vietcombank | Bank-transfer settlement and refunds | Vietnam |
| Postmark | Transactional e-mail delivery | United States (only marketing lists that Customers explicitly opt in to) |
§ 09Cookies and analytics
The Marketplace sets a small number of first-party cookies for session management, cart persistence, and consent recording. By default we do not run any third-party analytics. Customers may opt in, on a per-property basis, to Google Analytics 4 or to Meta Pixel; when they do so, the opt-in is captured in an audit log and the corresponding data-processing terms of the third-party provider apply. The full inventory of cookies is published in the Cookie Policy.
§ 10Minors
The Marketplace is not directed at children under the age of sixteen. Under Article 20 of Decree 13, the processing of personal data of a child under seven requires the consent of the parent or legal guardian; between the ages of seven and fifteen, both the child's own consent and that of the parent or legal guardian must be obtained. Because the Marketplace addresses hotel operators and not consumers, we do not knowingly collect data of minors on our own account. Where a Module handles guest data that includes minors, the Customer is responsible for ensuring that the appropriate consents have been obtained.
§ 11Security measures
We apply the security measures described in Annex 2 of our DPA: encryption in transit with TLS 1.3, encryption at rest with AES-256, key management with AWS KMS in Singapore for our own control-plane secrets, multi-factor authentication for every administrator account, quarterly penetration testing by an independent Vietnamese firm accredited by A05, an incident-response run-book tested twice per year, and continuous monitoring by an in-house security-operations team. Employee access to production data follows a least-privilege model with mandatory periodic re-attestation.
§ 12Data-protection officer
We have appointed a Data Protection Officer as required by Article 28 of Decree 13. The DPO is independent from the commercial teams, reports directly to the director Nguyễn Minh Đức, and can be reached at dpo@siteminderstore.org or by post at 235 Nguyễn Văn Cừ, Phường Nguyễn Cư Trinh, Quận 1, TP. Hồ Chí Minh, marked for the attention of the Data Protection Officer. The DPO is available to receive data-subject requests, complaints, and questions from Customers about the way we handle personal data.
§ 13Complaints to A05
Data subjects who consider that we have breached Decree 13 may lodge a complaint with the Department of Cybersecurity and High-Tech Crime Prevention of the Ministry of Public Security. The Department operates a hotline and an online form for complaints; the current contact details are published on the Ministry of Public Security's website. We commit to cooperating in full with any inquiry the Department opens and to providing, within the deadlines set by the Department, any documentation it considers relevant.
§ 14Changes to this policy
We review this Privacy Policy at least once per year and whenever we introduce a Module or a subprocessor that materially changes the way we process personal data. Material changes will be notified to account owners by e-mail at least thirty days before they take effect and will be published on this page with a version number and an effective date. Non-material changes (typographical corrections, clarifications) may be published without prior notice.
§ 15Contact
For any question concerning this Privacy Policy or the processing of your personal data please write to dpo@siteminderstore.org, or call +84 28 3925 6800 and ask for the Data Protection Officer. For general support please use support@siteminderstore.org. We reply to every e-mail within one Vietnamese business day.