Chính sách quyền riêng tư

Ứng dụng HyOperly · Cập nhật lần cuối: 10/08/2026

HyOperly là ứng dụng nghiệp vụ nội bộ dùng cho công tác vận hành giao nhận và ký duyệt chứng từ. Tài khoản do doanh nghiệp cấp cho nhân viên; ứng dụng không có chức năng tự đăng ký.

1. Dữ liệu chúng tôi thu thập và cách thu thập

1.1 Thông tin đăng nhập

Khi bạn đăng nhập, ứng dụng gửi mã công ty, tên đăng nhập và mật khẩu tới máy chủ của chúng tôi để xác thực. Ứng dụng không tự lưu mật khẩu xuống thiết bị; mật khẩu chỉ tồn tại trong bộ nhớ tạm của màn hình đăng nhập.

Lưu ý rằng hệ điều hành của thiết bị có cơ chế bộ nhớ đệm bàn phím và trình quản lý mật khẩu riêng, nằm ngoài phạm vi kiểm soát của ứng dụng.

1.2 Thông tin tài khoản

Sau khi xác thực thành công, máy chủ cấp một phiếu truy cập có hiệu lực 15 ngày, chứa: mã tài khoản, tên đăng nhập, họ tên, chức vụ, địa chỉ email, toàn bộ bản đồ phân quyền của bạn theo từng công ty (không chỉ công ty bạn đang đăng nhập), mã phiên làm việc, mã bản ghi phiên đăng nhập, cờ yêu cầu đổi mật khẩu và thời điểm hết hạn.

Khi bạn dùng chức năng đặt lại mật khẩu hoặc thiết lập xác thực hai bước, hệ thống gửi qua email các mã ngắn hạn riêng phục vụ đúng việc đó.

1.3 Thông tin kỹ thuật thu thập tự động

Mỗi lần bạn đăng nhập, máy chủ ghi lại địa chỉ IP, chuỗi nhận dạng trình duyệt hoặc ứng dụng (User-Agent), nền tảng, và tên thiết bị vào bản ghi phiên đăng nhập. Các thông tin này phục vụ bảo mật tài khoản và cho phép bạn hoặc quản trị viên rà soát các phiên đang hoạt động.

1.4 Nhật ký hoạt động

Trong quá trình sử dụng, hệ thống ghi nhận:

1.5 Thiết bị và thông báo đẩy

Nếu bạn bật thông báo, dữ liệu được gửi tới hai nơi:

Nội dung thông báo có thể chứa dữ liệu nghiệp vụ như mã phiếu, tên hàng hoá và loại hành động. Nội dung này đi qua dịch vụ của Expo rồi tới dịch vụ đẩy của Apple hoặc Google trước khi hiển thị trên thiết bị bạn.

Ngoài ra, mỗi lần mở ứng dụng, ứng dụng kiểm tra bản cập nhật từ máy chủ của Expo và gửi kèm một mã định danh bản cài đặt cùng thông tin nền tảng và phiên bản. Việc này diễn ra trước cả khi bạn đăng nhập.

1.6 Ảnh và tài liệu do bạn cung cấp

Ứng dụng truy cập camera và thư viện ảnh chỉ khi bạn chủ động chọn chức năng đính kèm: quét mã vạch kiện hàng, chụp hoặc chọn ảnh bằng chứng giao nhận, đính kèm ảnh và tệp vào phiếu đề xuất, quyết toán, hồ sơ vận hành và thảo luận. Ứng dụng không tự động quét hay tải lên nội dung nào trong thư viện của bạn.

Về dữ liệu vị trí nhúng trong ảnh. Ứng dụng không sử dụng dịch vụ định vị của thiết bị và không hỏi quyền truy cập vị trí. Ảnh chụp bằng điện thoại thường mang sẵn siêu dữ liệu EXIF, trong đó có thể có toạ độ GPS, độ cao, thời điểm và kiểu máy chụp.

Khi bạn tải ảnh lên, máy chủ của chúng tôi dựng lại ảnh từ dữ liệu điểm ảnh và chuyển sang định dạng WebP trước khi lưu. Quá trình này loại bỏ toàn bộ siêu dữ liệu EXIF, bao gồm mọi toạ độ GPS. Ảnh được lưu trữ và hiển thị về sau không còn chứa thông tin vị trí. Điều này áp dụng cho cả ảnh bằng chứng giao nhận lẫn ảnh đính kèm thông thường.

1.7 Dữ liệu nghiệp vụ bạn nhập vào

Nội dung đơn hàng, kiện hàng, phiếu đề xuất, phiếu quyết toán, ghi chú và thảo luận bạn tạo trong quá trình làm việc. Trong đó bao gồm thông tin tài chính: số tài khoản ngân hàng, tên chủ tài khoản, tên người thụ hưởng, số tiền và nội dung chuyển khoản trên các phiếu thanh toán.

1.8 Dữ liệu về người thứ ba

Khi thực hiện nghiệp vụ giao hàng, ứng dụng ghi nhận tên, địa chỉ và thông tin liên hệ của người nhận hàng, ảnh chụp hiện trường giao hàng và ảnh chữ ký của người nhận. Đây là dữ liệu của người thứ ba do bạn — với tư cách nhân viên — nhập vào để làm bằng chứng giao nhận. Doanh nghiệp sử dụng ứng dụng chịu trách nhiệm bảo đảm việc thu thập này phù hợp với thỏa thuận với khách hàng và pháp luật hiện hành.

1.9 Dữ liệu nhân sự hiển thị trong ứng dụng

Ứng dụng hiển thị dữ liệu chấm công và số dư ngày phép của chính bạn. Dữ liệu này do hệ thống chấm công của doanh nghiệp tạo ra và được truyền từ máy chủ xuống thiết bị; ứng dụng không tự thu thập.

1.10 Bảng nhớ tạm của hệ thống

Khi bạn bấm nút sao chép, ứng dụng ghi số điện thoại người nhận hoặc ảnh mã QR chuyển khoản vào bảng nhớ tạm của hệ điều hành. Bảng nhớ tạm là vùng dùng chung mà ứng dụng khác có thể đọc, và trên thiết bị Apple có thể đồng bộ sang các thiết bị khác cùng tài khoản.

2. Dữ liệu chúng tôi KHÔNG thu thập

3. Mục đích sử dụng

Toàn bộ dữ liệu nêu trên chỉ dùng để vận hành chính ứng dụng: xác thực và phân quyền; hiển thị và xử lý chứng từ, đơn hàng, kiện hàng; lưu bằng chứng giao nhận; gửi thông báo về công việc liên quan tới bạn; bảo vệ an toàn tài khoản; và phục vụ đối soát, kiểm toán nội bộ của doanh nghiệp. Chúng tôi không bán dữ liệu và không dùng dữ liệu cho mục đích tiếp thị.

4. Lưu trữ trên thiết bị

Dữ liệuNơi lưuMã hoá
Phiếu truy cập phiên đăng nhậpKho bảo mật của hệ điều hành (Keychain trên iOS, Keystore trên Android)
Hồ sơ người dùng: mã tài khoản, tên đăng nhập, họ tên, email, chức vụ và toàn bộ cây phân quyềnBộ nhớ ứng dụng thông thườngKhông
Mã công ty, vai trò đang dùng, ngôn ngữ, tuỳ chọn thông báo, bản sao mã thông báo đẩy và mã thiết bịBộ nhớ ứng dụng thông thườngKhông

Khi bạn đăng xuất, ứng dụng xoá dữ liệu cục bộ nêu trên, riêng lựa chọn ngôn ngữ được giữ lại để lần mở sau vẫn đúng ngôn ngữ bạn chọn. Trên Android, ứng dụng hiện cho phép hệ điều hành sao lưu dữ liệu ứng dụng theo cơ chế sao lưu mặc định của hệ thống.

5. Bên thứ ba có thể tiếp cận dữ liệu

Chúng tôi yêu cầu và xác nhận rằng mọi bên thứ ba nêu dưới đây áp dụng mức bảo vệ dữ liệu người dùng tương đương với chính sách này.

Ngoài các bên trên, dữ liệu được lưu trên máy chủ do chúng tôi vận hành. Chúng tôi không chia sẻ dữ liệu cho bên nào khác, trừ khi pháp luật yêu cầu.

6. Thời gian lưu trữ và cách xoá dữ liệu

Tài khoản trong HyOperly do doanh nghiệp cấp và quản lý. Ứng dụng không có chức năng tự đăng ký, do đó cũng không có nút tự xoá tài khoản trong ứng dụng — việc mở, khoá hoặc xoá tài khoản do quản trị viên của doanh nghiệp thực hiện.

Lưu ý về thông báo đẩy khi đăng xuất. Khi bạn đăng xuất, mã thông báo đẩy của thiết bị được đánh dấu ngừng hoạt động để thiết bị không nhận thông báo nữa, nhưng bản ghi tương ứng không bị xoá ngay. Bản ghi này còn lưu mã tài khoản, mã công ty, mã định danh thiết bị và mã thông báo đẩy.

Tương tự, bản ghi phiên đăng nhập và nhật ký kiểm toán (gồm địa chỉ IP và thông tin thiết bị) được giữ lại phục vụ bảo mật và đối soát, không bị xoá khi đăng xuất.

Dữ liệu nghiệp vụ (chứng từ, đơn hàng, bằng chứng giao nhận) được doanh nghiệp lưu giữ theo yêu cầu lưu trữ chứng từ và quy định kế toán hiện hành.

Nếu bạn muốn xoá các dữ liệu cá nhân nêu trên, hãy gửi yêu cầu theo mục 7. Chúng tôi phản hồi trong vòng 30 ngày.

7. Rút lại sự đồng ý và liên hệ

Bạn có thể rút lại quyền truy cập camera, ảnh hoặc thông báo bất cứ lúc nào trong phần Cài đặt của hệ điều hành. Việc này không xoá dữ liệu đã gửi trước đó; muốn xoá thì gửi yêu cầu theo địa chỉ dưới đây.

Email: vovuhy@icloud.com

8. Thay đổi chính sách

Khi có thay đổi, chúng tôi cập nhật nội dung trên trang này và sửa ngày ở đầu trang. Bạn nên xem lại định kỳ.

Privacy Policy

HyOperly app · Last updated: 10 August 2026

HyOperly is an internal business application used for delivery operations and document approval. Accounts are issued by the operating company to its employees; the app has no self-registration.

1. Data we collect and how

1.1 Sign-in credentials

When you sign in, the app sends your company code, username and password to our server for authentication. The app does not itself store the password on the device; it exists only in the sign-in screen's temporary memory. Note that the operating system has its own keyboard cache and password manager, which are outside the app's control.

1.2 Account information

On successful authentication the server issues an access token valid for 15 days containing: your account identifier, username, full name, job title, email address, your complete permission map across every company (not only the one you signed in to), a session identifier, a sign-in session record identifier, a password-change flag and an expiry time. Password reset and two-factor setup use separate short-lived tokens delivered by email.

1.3 Technical information collected automatically

Each time you sign in, the server records your IP address, User-Agent string, platform and device name in the sign-in session record. This supports account security and lets you or an administrator review active sessions.

1.4 Activity logs

During use, the system records the session's last-active timestamp on every call to our server; your IP address and device information alongside each operational action (delivery confirmation, label voiding, tracking updates, parcel creation); and your IP address, device information and the before/after content of every edit you make to business data. These form an audit trail for internal reconciliation.

1.5 Device and push notifications

If you enable notifications, data goes to two destinations. To Expo's servers (a third-party push provider): the operating-system push token, an Expo-generated installation identifier, the application identifier and project identifier. This repeats automatically when the operating system issues a new token and at least every seven days, without any action from you. To our servers: the Expo push token, device platform and a device identifier (identifierForVendor on iOS, Android ID on Android), stored against your account and company along with activation state and last-active time.

Notification content may include business data such as document codes, goods names and action types. That content passes through Expo and then Apple's or Google's push services before reaching your device.

Additionally, each time you open the app it checks for updates from Expo's servers, sending an installation identifier along with platform and version information. This happens before you sign in.

1.6 Photos and documents you provide

Camera and photo library are accessed only when you actively choose an attachment action: scanning parcel barcodes, capturing or selecting delivery proof photos, and attaching images or files to proposals, settlements, operation records and discussions. The app never scans or uploads library content automatically.

About location data embedded in photos. The app does not use the device's location services and never requests location permission. Photos taken with a phone commonly carry EXIF metadata that can include GPS coordinates, altitude, timestamp and camera model.

When you upload a photo, our server rebuilds the image from its pixel data and converts it to WebP before storing it. This removes all EXIF metadata, including any GPS coordinates. The stored and subsequently displayed image no longer contains location information. This applies to both delivery proof photos and ordinary attachments.

1.7 Business data you enter

Orders, parcels, proposal and settlement documents, notes and discussion messages you create. This includes financial information: bank account numbers, account holder names, beneficiary names, amounts and transfer descriptions on payment documents.

1.8 Third-party data

During delivery workflows the app records the recipient's name, address and contact details, on-site delivery photos, and an image of the recipient's signature. This is third-party data entered by you as an employee to evidence delivery. The operating company is responsible for ensuring such collection complies with its customer agreements and applicable law.

1.9 HR data shown in the app

The app displays your own attendance records and leave balances. This data is produced by the company's attendance system and sent from our server to your device; the app does not collect it.

1.10 System clipboard

When you tap a copy button, the app writes the recipient's phone number or a bank transfer QR image to the system clipboard. The clipboard is a shared area readable by other apps, and on Apple devices it may sync to your other devices.

2. What we do NOT collect

3. How we use the data

All data listed above is used only to operate the app: authenticating and authorising users; displaying and processing documents, orders and parcels; storing delivery evidence; sending notifications about work assigned to you; protecting account security; and supporting the operating company's internal reconciliation and audit. We do not sell data and do not use it for marketing.

4. On-device storage

Session access tokens are stored in the operating system's secure storage (Keychain on iOS, Keystore on Android) and are encrypted. Everything else is stored in ordinary, unencrypted application storage: your user profile (account identifier, username, full name, email, job title and your complete permission tree), company code, active role, language, notification preferences, and a local copy of the push token and device identifier.

Signing out clears this local data except your language choice, which is kept so the app opens in the language you selected. On Android, the app currently permits the operating system's default application backup mechanism.

5. Third parties with access

We require and confirm that each third party below provides protection of user data equal to that stated in this policy.

Otherwise data resides on servers we operate. We do not share data with anyone else except where required by law.

6. Retention and deletion

Accounts are provisioned and managed by the operating company. Because the app has no self-registration, it also has no in-app account deletion; opening, disabling or deleting an account is performed by the company's administrator.

Note on sign-out. When you sign out, your device's push token is marked inactive so the device stops receiving notifications, but the corresponding record is not deleted immediately; it still holds the account identifier, company code, device identifier and push token. Likewise, sign-in session records and audit logs — including IP addresses and device information — are retained for security and reconciliation purposes and are not deleted at sign-out.

Business data (documents, orders, delivery evidence) is retained by the operating company in accordance with its record-keeping and accounting obligations.

To have any of the personal data above erased, send a request as described in section 7. We respond within 30 days.

7. Withdrawing consent and contact

You may revoke camera, photo or notification permissions at any time in your operating system settings. Doing so does not erase data already submitted; to request erasure, contact us at vovuhy@icloud.com.

8. Changes to this policy

When this policy changes we update this page and revise the date at the top. Please review it periodically.