Privacy Policy — VGCPayment
Last updated: September 2, 2026 · Cập nhật lần cuối: 02/09/2026
1. Who we are / Chúng tôi là ai
VGCPayment and viewmoney.us are operated by Apex Meridian Group LLC, a California
limited liability company (Entity No. B20260338449), with its principal office at 555 Capitol Mall,
Suite 220, Sacramento, CA 95814, United States (“Apex”, “we”, “us”). VGCPayment is a store-management console that lets merchants monitor revenue, orders,
transactions and storefront analytics for their own online stores. The VGCPayment mobile
app is a read-only companion for merchants, used to view revenue reports, cash flow and
orders for their own store. Anyone may create an account from the app. It does not sell goods or services, does not process
purchases inside the app, and is not a banking, investment or financial-advice service.
VGCPayment và viewmoney.us do Apex Meridian Group LLC, công ty trách nhiệm hữu hạn
đăng ký tại California (Entity No. B20260338449), địa chỉ chính 555 Capitol Mall, Suite 220, Sacramento,
CA 95814, Hoa Kỳ, vận hành. VGCPayment là bảng điều khiển giúp theo dõi doanh thu, đơn hàng,
giao dịch và số liệu truy cập của chính cửa hàng của họ. Ứng dụng di động là công cụ chỉ-đọc dành cho chủ cửa hàng,
để xem báo cáo doanh thu, dòng tiền và đơn hàng của cửa hàng mình. Ai cũng có thể tự đăng ký trong app.
App không mua bán hàng hóa/dịch vụ,
không nhận thanh toán trong app và không cung cấp dịch vụ ngân hàng, đầu tư hay tư vấn tài chính.
2. Data we collect / Dữ liệu thu thập
(a) Account data: name, email address and role, provided at sign-up or created by an administrator.
(b) Business and customer data your organisation controls: store identifiers, orders, transaction and
payment references, amounts, fees, product/order details, customer contact and delivery information made
available by connected stores, and storefront analytics. (c) Device and technical data: platform,
app/device label, authentication-token hash, IP/network request logs, and a push-notification token
(Firebase Cloud Messaging) when notifications are enabled. Storefront analytics visible to authorised
users may include a shopper's IP address, browser/user-agent summary, country/city, page path/title,
activity time, cart activity and online/bot status. This storefront data is collected by the company's
connected store systems, not from the app user's iPhone sensors. (d) Legal-consent evidence: user ID,
policy version, acceptance time, IP address and browser user-agent when a web user accepts the policies.
(e) Configuration and credential data: payment-provider credentials, WooCommerce REST API keys,
mailbox credentials, analytics keys, webhook identifiers and connected-service URLs configured by
authorised staff. Mail headers, bodies and attachments are retrieved from the configured mailbox on demand
and are not saved to the application database by the Mail view. Recoverable third-party payment-provider,
WooCommerce, mailbox and analytics credentials are encrypted at rest. Per-store HMAC keys and operational
configuration secrets remain server-side and are access-controlled; account passwords and login tokens are
stored as one-way hashes. The Get Code tool processes a Microsoft email
address, OAuth refresh token, client ID and recent message previews, or a pasted TOTP secret, only for the
requested operation. Those pasted values and previews are not saved to the application database by that
tool. The Service does not store full payment-card numbers or card security codes. We do not collect the
app user's GPS location, contacts, photos, microphone, camera or advertising identifiers.
(a) Dữ liệu tài khoản: tên, email, vai trò — do bạn cung cấp khi đăng ký hoặc do quản trị viên tạo.
(b) Dữ liệu kinh doanh và khách hàng do tổ chức của bạn kiểm soát: mã cửa hàng, đơn hàng, tham chiếu giao dịch,
số tiền, phí, sản phẩm, thông tin liên hệ/giao hàng của khách và số liệu phân tích cửa hàng. (c) Dữ liệu kỹ thuật:
nền tảng, nhãn thiết bị/app, mã băm token đăng nhập, nhật ký IP/yêu cầu mạng và token thông báo đẩy (Firebase).
Dữ liệu Live có thể gồm IP, trình duyệt, quốc gia/thành phố, đường dẫn/tiêu đề trang, thời gian hoạt động,
thao tác giỏ hàng và trạng thái online/bot của khách truy cập cửa hàng. Dữ liệu storefront này đến từ hệ thống
cửa hàng kết nối, không lấy từ cảm biến iPhone của người dùng app. App không truy cập vị trí GPS, danh bạ,
hình ảnh, micro, camera hoặc mã định danh quảng cáo. (d) Bằng chứng đồng ý chính sách gồm ID người dùng,
phiên bản chính sách, thời điểm đồng ý, IP và user-agent của trình duyệt. (e) Dữ liệu cấu hình/thông tin
xác thực gồm khóa cổng thanh toán, WooCommerce REST API, mailbox, analytics, webhook và URL dịch vụ kết nối.
Tiêu đề, nội dung và tệp đính kèm email được lấy theo yêu cầu từ mailbox đã cấu hình; màn hình Mail không lưu
các nội dung này vào cơ sở dữ liệu ứng dụng. Thông tin xác thực có thể khôi phục của cổng thanh toán,
WooCommerce, mailbox và analytics bên thứ ba được mã hóa khi lưu. Khóa HMAC của từng cửa hàng và secret cấu
hình vận hành được giữ tại server, có kiểm soát truy cập; mật khẩu tài khoản và token đăng nhập được băm một chiều. Get Code
chỉ xử lý tạm thời email Microsoft, OAuth refresh token, client ID, phần xem trước email hoặc TOTP secret
cho yêu cầu hiện tại và không ghi các giá trị dán này vào cơ sở dữ liệu. Hệ thống không lưu đầy đủ số thẻ
hoặc mã bảo mật thẻ.
3. How data is used / Cách sử dụng
Data is used only for internal authentication, role-based access, financial and operational dashboards,
order/transaction review, reporting, security, support and optional order notifications. We do not sell,
rent or share personal data with third parties for advertising or marketing, and we do not use it to
commercialise the app or make automated credit, investment or employment decisions.
Transport is encrypted (HTTPS/TLS); access requires authentication and is scoped per user.
Dữ liệu chỉ dùng nội bộ cho xác thực, phân quyền, bảng tài chính–vận hành, xem đơn/giao dịch,
báo cáo, bảo mật, hỗ trợ và thông báo đơn hàng tùy chọn.
Chúng tôi không bán, cho thuê hay chia sẻ dữ liệu cá nhân cho bên thứ ba vì mục đích quảng cáo.
Kết nối được mã hóa (HTTPS/TLS); truy cập yêu cầu đăng nhập và giới hạn theo từng người dùng.
4. Third-party services / Dịch vụ bên thứ ba
The Service connects to PayPal and Stripe for store payment operations; WooCommerce and the company's
connected analytics endpoints for orders, customer details and storefront activity; Google Sheets for
configured product-cost data; Microsoft Graph when an authorised user invokes Get Code; configured email
providers through IMAP/SMTP for reading and sending company mail; and Google Firebase Cloud Messaging for
push delivery. Data sent to each provider is limited to what is needed for that connection, but the
provider processes it under its own terms and privacy policy. The 2FA setup QR is generated in the user's
browser with a self-hosted script; the TOTP provisioning URI is not sent to an external QR service. Remote
images in email are blocked by default. If an authorised user chooses to display them, the browser may
contact the image host and reveal normal request data such as IP address and user-agent. We do not use
third-party advertising or cross-app tracking.
Hệ thống kết nối PayPal/Stripe cho vận hành thanh toán cửa hàng; WooCommerce và endpoint
analytics của công ty cho dữ liệu đơn, khách và lượt truy cập; Google Sheets cho giá cost; Microsoft Graph
khi người được cấp quyền dùng Get Code; nhà cung cấp email qua IMAP/SMTP; và Firebase Cloud Messaging để gửi
thông báo. Chỉ dữ liệu cần cho từng kết nối được truyền đi và mỗi nhà cung cấp áp dụng điều khoản/chính sách
riêng. QR thiết lập 2FA được tạo ngay trong trình duyệt bằng script tự lưu trữ; URI chứa TOTP secret không
được gửi tới dịch vụ QR bên ngoài. Ảnh từ xa trong email bị chặn mặc định; nếu người dùng được cấp quyền chọn
hiển thị, trình duyệt có thể liên hệ máy chủ ảnh và gửi dữ liệu yêu cầu thông thường như IP và user-agent.
Chúng tôi không dùng quảng cáo hoặc theo dõi chéo ứng dụng.
5. Retention & deletion / Lưu trữ & xóa
Push tokens are deleted when the app explicitly unregisters the device, the account is deleted, or the
push provider reports the token as invalid. In-app account deletion immediately blocks access and revokes
mobile login and push tokens. It soft-deletes the account: the user row and relevant audit/legal-consent
records may remain for recovery, security and compliance, while the account can no longer sign in or
receive push notifications. Contact your administrator or email us for a verified personal-data deletion
request; valid requests are handled within 30 days except where retention is required for legal, security
or fraud-prevention purposes. You can also withdraw from optional push notifications in device settings.
Token thông báo bị xóa khi app chủ động hủy đăng ký thiết bị, tài khoản bị xóa hoặc nhà cung
cấp báo token không còn hợp lệ. Dữ liệu tài khoản được lưu trong thời gian tài khoản tồn tại. Bạn có thể tắt
thông báo đẩy tùy chọn trong cài đặt thiết bị.
Để yêu cầu xóa tài khoản và dữ liệu cá nhân liên quan, liên hệ quản trị viên hoặc email cho chúng tôi;
yêu cầu hợp lệ được xử lý trong vòng 30 ngày, trừ dữ liệu phải giữ vì pháp luật, bảo mật hoặc chống gian lận.
Khi người dùng chọn xóa tài khoản trong app, quyền truy cập bị khóa ngay và token đăng nhập mobile/token thông báo bị thu hồi. Đây là xóa mềm: bản ghi người dùng cùng nhật ký và hồ sơ đồng ý pháp lý liên quan có thể được giữ để khôi phục, bảo mật và tuân thủ; tài khoản không thể đăng nhập hoặc nhận thông báo. Yêu cầu xóa dữ liệu cá nhân đã xác minh được xử lý trong 30 ngày, trừ phần phải lưu vì pháp luật, bảo mật hoặc chống gian lận.
Legal-consent records are retained while the account is active and afterwards where reasonably necessary
to demonstrate compliance, resolve disputes and protect the Service.
Hồ sơ đồng ý chính sách được lưu khi tài khoản hoạt động và sau đó trong thời gian hợp lý
để chứng minh tuân thủ, giải quyết tranh chấp và bảo vệ hệ thống.
6. Security / Bảo mật
We use role-based access, HTTPS/TLS, hashed passwords and authentication tokens, encrypted storage for
supported third-party credentials, server-side access controls for operational secrets, user-enabled or
administrator-required two-factor authentication and access logging. No system is completely secure; please
report suspected compromise promptly and do not send passwords or verification codes by email.
Chúng tôi dùng phân quyền, HTTPS/TLS, mật khẩu và token được băm, mã hóa các credential
bên thứ ba được hỗ trợ, kiểm soát truy cập phía server cho secret vận hành, xác thực hai bước (do người dùng
bật hoặc quản trị viên yêu cầu) và nhật ký truy cập. Không hệ thống nào an toàn tuyệt đối; hãy báo ngay khi nghi ngờ sự cố.
7. International processing / Xử lý quốc tế
The Service and its providers may process data in countries other than yours. Where required, we use
appropriate contractual or legal safeguards for international transfers.
Dịch vụ và nhà cung cấp có thể xử lý dữ liệu tại quốc gia khác nơi bạn sinh sống.
Khi pháp luật yêu cầu, chúng tôi áp dụng biện pháp hợp đồng hoặc pháp lý phù hợp cho việc chuyển dữ liệu.
8. Your privacy rights / Quyền của bạn
Subject to applicable law, you may request access, correction, deletion, restriction or a copy of your
personal data, or object to certain processing. Your organisation may be the controller of business and
customer data shown in the Service, so some requests must be handled by its administrator. We verify
requests before acting and you may complain to your local data-protection authority.
Tùy pháp luật áp dụng, bạn có thể yêu cầu truy cập, sửa, xóa, hạn chế, nhận bản sao hoặc phản đối
một số hoạt động xử lý. Tổ chức của bạn có thể là bên kiểm soát dữ liệu kinh doanh/khách hàng nên một số yêu cầu
cần gửi cho quản trị viên. Chúng tôi xác minh danh tính trước khi xử lý.
9. Children / Trẻ em
The Service is a business tool and is not directed to children. We do not knowingly create accounts for
children or collect their personal data through the mobile app.
Dịch vụ là công cụ kinh doanh, không hướng đến trẻ em. Chúng tôi không chủ ý tạo tài khoản
cho trẻ em hoặc thu thập dữ liệu cá nhân của trẻ qua ứng dụng.
10. Policy changes / Thay đổi chính sách
We may update this Policy when the Service or legal requirements change. We will post the revised date
here and provide additional notice when a material change requires it.
Chúng tôi có thể cập nhật Chính sách khi Dịch vụ hoặc yêu cầu pháp luật thay đổi và sẽ ghi
ngày sửa đổi tại đây; thay đổi quan trọng sẽ được thông báo thêm khi cần.
11. Contact / Liên hệ
Apex Meridian Group LLC
555 Capitol Mall, Suite 220, Sacramento, CA 95814, United States
For privacy questions or deletion requests, email
App@imc-marketing.com.
Nếu có câu hỏi về quyền riêng tư hoặc muốn yêu cầu xóa dữ liệu, vui lòng gửi email đến địa chỉ trên.