VGCPaymentLegal Center
Công ty Quyền riêng tư Điều khoản Bảo mật Sử dụng Xóa dữ liệu Hỗ trợ
VGCPayment

Security Policy — VGCPayment

Updated: September 2, 2026 · Cập nhật: 02/09/2026

VGCPayment and viewmoney.us are operated by Apex Meridian Group LLC, California Entity No. B20260338449. VGCPayment is a finance and operations system for merchants. Accounts are created by public sign-up in the mobile app or issued by an administrator; it is not a public shopping or payment service.
VGCPayment là hệ thống quản lý tài chính và vận hành dành cho chủ cửa hàng. Tài khoản được tạo bằng cách tự đăng ký trong ứng dụng, hoặc do quản trị viên cấp; đây không phải dịch vụ mua sắm hay thanh toán công khai.

1. Access protection / Bảo vệ truy cập

Accounts are created by public sign-up or provisioned by administrators. The Service uses authenticated sessions, role- and store-based permissions, user-enabled or administrator-required TOTP two-factor authentication, CSRF protection for web actions, bearer tokens for mobile access and token revocation on logout, password/2FA changes and account deletion. Repeated access must remain within the permissions assigned by the company.
Tài khoản do người dùng tự đăng ký hoặc quản trị viên cấp. Hệ thống dùng phiên đăng nhập, phân quyền theo vai trò/cửa hàng, 2FA TOTP do người dùng bật hoặc quản trị viên bắt buộc, chống CSRF, bearer token cho app và thu hồi token khi đăng xuất, đổi mật khẩu/2FA hoặc xóa tài khoản.

2. Data and credential protection / Bảo vệ dữ liệu

Traffic uses HTTPS/TLS. Passwords and authentication tokens are stored as one-way hashes. Recoverable third-party payment-provider, WooCommerce, mailbox and analytics credentials are encrypted at rest and remain server-side. Per-store HMAC keys and operational configuration secrets are protected by server-side access controls. Mobile responses are scoped to the signed-in user and exclude provider secrets and unfiltered raw transaction payloads.
Kết nối dùng HTTPS/TLS. Mật khẩu và token được lưu dạng băm một chiều. Thông tin xác thực có thể khôi phục của cổng thanh toán, WooCommerce, mailbox và analytics bên thứ ba được mã hóa khi lưu và giữ tại server. Khóa HMAC của từng cửa hàng cùng secret cấu hình vận hành được bảo vệ bằng kiểm soát truy cập phía server. App chỉ trả dữ liệu theo quyền người dùng và không trả secret của nhà cung cấp hoặc raw transaction chưa lọc.

3. Monitoring and minimisation / Giám sát và tối thiểu hóa

Authentication, policy acceptance and security-relevant actions may be logged with time, account, IP address and user-agent. Access should be limited to data needed for the employee's role. Customer, order, transaction and storefront analytics data must not be exported or shared without company authorisation.
Hoạt động đăng nhập, đồng ý chính sách và hành động liên quan bảo mật có thể được ghi cùng thời gian, tài khoản, IP và user-agent. Chỉ truy cập dữ liệu cần cho công việc; không xuất/chia sẻ dữ liệu khi chưa được phép.

4. User responsibilities / Trách nhiệm người dùng

  • Use a unique password and enable 2FA when available.
  • Never share passwords, TOTP codes, session tokens or payment/store secrets.
  • Keep devices updated, locked and under your control; sign out from shared devices.
  • Do not copy customer or financial data to personal accounts or unapproved services.
  • Report lost devices, suspicious access or accidental disclosure immediately.

Dùng mật khẩu riêng và 2FA; không chia sẻ thông tin xác thực; bảo vệ thiết bị; không sao chép dữ liệu sang tài khoản/dịch vụ cá nhân; báo ngay khi mất thiết bị hoặc nghi ngờ sự cố.

5. Security reports / Báo cáo bảo mật

Report suspected vulnerabilities or incidents to App@imc-marketing.com with subject “SECURITY — VGCPayment”. Do not include passwords, verification codes, full card data or active secrets. We will investigate, contain access, revoke credentials and notify affected parties or authorities when required.
Gửi báo cáo với tiêu đề “SECURITY — VGCPayment”; không gửi mật khẩu, mã xác minh, đầy đủ dữ liệu thẻ hoặc secret đang hoạt động. Chúng tôi sẽ điều tra, giới hạn truy cập, thu hồi thông tin xác thực và thông báo khi cần.

6. No absolute guarantee / Không bảo đảm tuyệt đối

No internet-connected system can guarantee absolute security. We maintain reasonable safeguards, review material incidents and improve controls as the Service changes.
Không hệ thống kết nối Internet nào an toàn tuyệt đối. Chúng tôi duy trì biện pháp hợp lý, xem xét sự cố và cải thiện kiểm soát khi hệ thống thay đổi.

← Legal & Support Center