SS SiteminderStore

Legal · Personal data

Privacy Policy

Chính sách bảo mật · Aligned to Decree 13/2023/ND-CP · Version 5.4

This Privacy Policy explains how SiteminderStore Vietnam Company Limited collects, uses, discloses, and safeguards personal data. It is written to satisfy the requirements of Decree 13/2023/ND-CP on Personal Data Protection (Nghị định 13/2023/NĐ-CP về bảo vệ dữ liệu cá nhân) and reflects the guidance issued by the Ministry of Public Security through the Department of Cybersecurity and High-Tech Crime Prevention (Cục An ninh mạng và phòng, chống tội phạm sử dụng công nghệ cao, A05). If you have a question that this policy does not answer, please write to dpo@siteminderstore.org.

§ 01Who we are and our role under Decree 13

The controller of the personal data described in this policy is SiteminderStore Vietnam Company Limited (Công ty TNHH SiteminderStore Việt Nam), Business Registration Certificate No. 0316854921, registered office at 235 Nguyễn Văn Cừ, Phường Nguyễn Cư Trinh, Quận 1, TP. Hồ Chí Minh. In the vocabulary of Decree 13, we are the Bên Kiểm soát dữ liệu cá nhân for the personal data of our own customers, visitors, and prospects. When a hotel Customer connects a marketplace Module to its SiteMinder Workspace and instructs the Module to process the personal data of its own guests, we act as processor (Bên Xử lý dữ liệu cá nhân) on behalf of that hotel. The relationship between controller and processor is governed by the Data Processing Agreement.

§ 02Categories of personal data we process

We process the following categories of personal data:

CategoryExamplesSource
Customer contact informationFull name, business e-mail, business phone, job title, name of the hotel entityProvided by the account owner at registration
Billing informationTax code, invoice address, bank-transfer reference numbers, MoMo or VNPay masked identifiersProvided at checkout or generated by the payment provider
Guest data flowing through a ModuleGuest name, e-mail, phone, reservation reference, arrival and departure dates, room type, special requestsRetrieved from your SiteMinder Workspace under your authorisation
Device and technical dataIP address, browser user agent, session identifier, coarse geolocation derived from IPAutomatically collected when you use the Marketplace
Support correspondenceTicket content, screenshots you attach, chat transcriptsProvided when you contact support

We do not knowingly process special-category data (health, biometric, religious, or political data) other than what a Customer may voluntarily embed in a support ticket. If we discover that a Module or a Customer instruction requires us to process special-category data, we apply the additional safeguards described in the Vietnam Personal Data Protection page.

§ 03Why we process personal data — purposes

We process personal data to perform the contract we have with a Customer (opening and operating the account, delivering the Modules, issuing electronic invoices, handling refunds); to comply with our legal obligations (tax law, e-invoicing rules, obligations under Decree 13 and under the Law on Cybersecurity 2018, obligations under the Law on Consumer Protection 2023); to secure the Marketplace against fraud and abuse; to communicate with Customers about service changes, incidents, and policy updates; to improve the Marketplace on the basis of aggregated, de-identified usage patterns; and, where a Customer has explicitly opted in, to send commercial e-mails about new Modules or promotions.

§ 04Legal bases we rely on

Article 11 of Decree 13 recognises consent as the principal ground for processing but also allows processing that is necessary for the performance of a contract, for compliance with a legal obligation, for the protection of the vital interests of the data subject, for the performance of a task in the public interest, or for the legitimate interests of the controller balanced against the rights of the data subject. In practice we rely on:

§ 05Data-subject rights and how to exercise them

Under Decree 13 you have the right to be informed, the right of access, the right to correct inaccurate data, the right to delete data whose processing is no longer necessary, the right to restrict processing in specified cases, the right to object, the right to data portability where technically feasible, the right to withdraw consent at any time, and the right to lodge a complaint with the competent authority. Requests can be sent to dpo@siteminderstore.org from the e-mail address associated with the account. We reply within seventy-two hours to acknowledge receipt and within thirty days to complete the request. Where a request is complex or where we receive a large volume of related requests we may extend that window by a further thirty days and will notify you of the extension and the reasons for it.

If you are dissatisfied with the way we have handled your request, you may lodge a complaint with the Department of Cybersecurity and High-Tech Crime Prevention (A05) of the Ministry of Public Security (Bộ Công an), whose contact details are published on the Ministry's website. Consumers may also refer to the Competition and Consumer Protection Committee of the Ministry of Industry and Trade under the Law on Consumer Protection 2023.

§ 06How long we keep personal data

CategoryRetentionTrigger to delete
Customer account dataDuration of the account plus 24 monthsAccount closure request or 24-month inactivity
Billing and e-invoicing records10 yearsStatutory obligation under the Law on Accounting and tax regulations
Guest data processed on behalf of a CustomerAs instructed by the Customer, default 12 monthsCustomer instruction or termination of the Module
Server logs and security telemetry13 monthsRolling deletion
Support tickets36 monthsRolling deletion
Marketing consent recordsUntil withdrawn plus 24 months as proof of consentWithdrawal of consent

§ 07Cross-border transfers

The personal data of Vietnamese data subjects is stored in Vietnam in the Viettel IDC datacentres in Hồ Chí Minh City and Hà Nội, in compliance with the localisation obligation of Article 26 of the Law on Cybersecurity 2018. A limited category of aggregated, de-identified operational data (Module version counters, anonymised latency measurements, feature-usage histograms) is replicated to a Singapore region operated by Amazon Web Services for the purposes of regional latency optimisation and disaster recovery. Before that replication began we completed a Cross-Border Transfer Impact Assessment as required by Article 25 of Decree 13; the assessment is on file with our DPO and available on request to Customers subject to a confidentiality undertaking.

Personal data of Vietnamese guests never leaves Vietnamese soil. Only aggregated, de-identified operational metrics cross the border, and only after an Article-25 impact assessment.

§ 08Subprocessors

We rely on a small number of vetted subprocessors, each of which is bound by a written data-processing agreement compatible with Decree 13:

SubprocessorPurposeLocation
Viettel IDCPrimary infrastructure hostingHồ Chí Minh City and Hà Nội, Vietnam
Amazon Web Services SingaporeKey management (AWS KMS) and disaster-recovery replication of anonymised operational dataSingapore
MoMoPayment processing for e-wallet transactionsVietnam
VNPayPayment processing for domestic cardsVietnam
VietcombankBank-transfer settlement and refundsVietnam
PostmarkTransactional e-mail deliveryUnited States (only marketing lists that Customers explicitly opt in to)

§ 09Cookies and analytics

The Marketplace sets a small number of first-party cookies for session management, cart persistence, and consent recording. By default we do not run any third-party analytics. Customers may opt in, on a per-property basis, to Google Analytics 4 or to Meta Pixel; when they do so, the opt-in is captured in an audit log and the corresponding data-processing terms of the third-party provider apply. The full inventory of cookies is published in the Cookie Policy.

§ 10Minors

The Marketplace is not directed at children under the age of sixteen. Under Article 20 of Decree 13, the processing of personal data of a child under seven requires the consent of the parent or legal guardian; between the ages of seven and fifteen, both the child's own consent and that of the parent or legal guardian must be obtained. Because the Marketplace addresses hotel operators and not consumers, we do not knowingly collect data of minors on our own account. Where a Module handles guest data that includes minors, the Customer is responsible for ensuring that the appropriate consents have been obtained.

§ 11Security measures

We apply the security measures described in Annex 2 of our DPA: encryption in transit with TLS 1.3, encryption at rest with AES-256, key management with AWS KMS in Singapore for our own control-plane secrets, multi-factor authentication for every administrator account, quarterly penetration testing by an independent Vietnamese firm accredited by A05, an incident-response run-book tested twice per year, and continuous monitoring by an in-house security-operations team. Employee access to production data follows a least-privilege model with mandatory periodic re-attestation.

§ 12Data-protection officer

We have appointed a Data Protection Officer as required by Article 28 of Decree 13. The DPO is independent from the commercial teams, reports directly to the director Nguyễn Minh Đức, and can be reached at dpo@siteminderstore.org or by post at 235 Nguyễn Văn Cừ, Phường Nguyễn Cư Trinh, Quận 1, TP. Hồ Chí Minh, marked for the attention of the Data Protection Officer. The DPO is available to receive data-subject requests, complaints, and questions from Customers about the way we handle personal data.

§ 13Complaints to A05

Data subjects who consider that we have breached Decree 13 may lodge a complaint with the Department of Cybersecurity and High-Tech Crime Prevention of the Ministry of Public Security. The Department operates a hotline and an online form for complaints; the current contact details are published on the Ministry of Public Security's website. We commit to cooperating in full with any inquiry the Department opens and to providing, within the deadlines set by the Department, any documentation it considers relevant.

§ 14Changes to this policy

We review this Privacy Policy at least once per year and whenever we introduce a Module or a subprocessor that materially changes the way we process personal data. Material changes will be notified to account owners by e-mail at least thirty days before they take effect and will be published on this page with a version number and an effective date. Non-material changes (typographical corrections, clarifications) may be published without prior notice.

§ 15Contact

For any question concerning this Privacy Policy or the processing of your personal data please write to dpo@siteminderstore.org, or call +84 28 3925 6800 and ask for the Data Protection Officer. For general support please use support@siteminderstore.org. We reply to every e-mail within one Vietnamese business day.