Security Policy — VGCPayment
Updated: September 2, 2026 · Cập nhật: 02/09/2026
VGCPayment and viewmoney.us are operated by Apex Meridian Group LLC, California
Entity No. B20260338449. VGCPayment is a finance and operations system for merchants. Accounts are created by public
sign-up in the mobile app or issued by an administrator; it is not a public shopping or payment service.
VGCPayment là hệ thống quản lý tài chính và vận hành dành cho chủ cửa hàng. Tài khoản được tạo
bằng cách tự đăng ký trong ứng dụng, hoặc do quản trị viên cấp; đây không phải dịch vụ mua sắm hay thanh toán công khai.
1. Access protection / Bảo vệ truy cập
Accounts are created by public sign-up or provisioned by administrators. The Service uses authenticated sessions, role- and
store-based permissions, user-enabled or administrator-required TOTP two-factor authentication, CSRF protection
for web actions, bearer tokens for mobile access and token revocation on logout, password/2FA changes and account deletion.
Repeated access must remain within the permissions assigned by the company.
Tài khoản do người dùng tự đăng ký hoặc quản trị viên cấp. Hệ thống dùng phiên đăng nhập, phân quyền theo vai trò/cửa hàng,
2FA TOTP do người dùng bật hoặc quản trị viên bắt buộc, chống CSRF, bearer token cho app và thu hồi token khi đăng xuất,
đổi mật khẩu/2FA hoặc xóa tài khoản.
2. Data and credential protection / Bảo vệ dữ liệu
Traffic uses HTTPS/TLS. Passwords and authentication tokens are stored as one-way hashes.
Recoverable third-party payment-provider, WooCommerce, mailbox and analytics credentials are encrypted at rest
and remain server-side. Per-store HMAC keys and operational configuration secrets are protected by server-side
access controls. Mobile responses are scoped to the signed-in user and exclude provider secrets and unfiltered
raw transaction payloads.
Kết nối dùng HTTPS/TLS. Mật khẩu và token được lưu dạng băm một chiều. Thông tin xác thực có thể
khôi phục của cổng thanh toán, WooCommerce, mailbox và analytics bên thứ ba được mã hóa khi lưu và giữ tại server.
Khóa HMAC của từng cửa hàng cùng secret cấu hình vận hành được bảo vệ bằng kiểm soát truy cập phía server. App chỉ
trả dữ liệu theo quyền người dùng và không trả secret của nhà cung cấp hoặc raw transaction chưa lọc.
3. Monitoring and minimisation / Giám sát và tối thiểu hóa
Authentication, policy acceptance and security-relevant actions may be logged with time, account,
IP address and user-agent. Access should be limited to data needed for the employee's role. Customer, order,
transaction and storefront analytics data must not be exported or shared without company authorisation.
Hoạt động đăng nhập, đồng ý chính sách và hành động liên quan bảo mật có thể được ghi cùng thời gian,
tài khoản, IP và user-agent. Chỉ truy cập dữ liệu cần cho công việc; không xuất/chia sẻ dữ liệu khi chưa được phép.
4. User responsibilities / Trách nhiệm người dùng
- Use a unique password and enable 2FA when available.
- Never share passwords, TOTP codes, session tokens or payment/store secrets.
- Keep devices updated, locked and under your control; sign out from shared devices.
- Do not copy customer or financial data to personal accounts or unapproved services.
- Report lost devices, suspicious access or accidental disclosure immediately.
Dùng mật khẩu riêng và 2FA; không chia sẻ thông tin xác thực; bảo vệ thiết bị; không sao chép dữ liệu sang tài khoản/dịch vụ cá nhân; báo ngay khi mất thiết bị hoặc nghi ngờ sự cố.
5. Security reports / Báo cáo bảo mật
Report suspected vulnerabilities or incidents to
App@imc-marketing.com
with subject “SECURITY — VGCPayment”. Do not include passwords, verification codes, full card data or active secrets.
We will investigate, contain access, revoke credentials and notify affected parties or authorities when required.
Gửi báo cáo với tiêu đề “SECURITY — VGCPayment”; không gửi mật khẩu, mã xác minh, đầy đủ dữ liệu thẻ
hoặc secret đang hoạt động. Chúng tôi sẽ điều tra, giới hạn truy cập, thu hồi thông tin xác thực và thông báo khi cần.
6. No absolute guarantee / Không bảo đảm tuyệt đối
No internet-connected system can guarantee absolute security. We maintain reasonable safeguards,
review material incidents and improve controls as the Service changes.
Không hệ thống kết nối
Internet nào an toàn tuyệt đối. Chúng tôi duy trì biện pháp hợp lý, xem xét sự cố và cải thiện kiểm soát khi hệ thống thay đổi.