Privacy Policy
Cách iSale thu thập, lưu trữ và xử lý dữ liệu của bạn.
Hiệu lực từ 2026-05-16 · phiên bản đầu (MVP)
iSale — Privacy Policy
Effective date: 2026-XX-XX (TBD pre-launch) Last updated: 2026-05-15 Status: Draft for legal review (Vietnamese counsel)
This is a draft template. Final version requires Vietnamese privacy lawyer review for PDP Law compliance + GDPR-equivalent posture.
1. Who we are
iSale (operated by [Company Legal Name], registered in Vietnam, registration #[XXX]) provides an AI-powered video creation platform for sellers and businesses.
Contact:
- General: support@isale.app
- Privacy: privacy@isale.app
- Data subject rights: dsar@isale.app
- Mail: [Company address, Vietnam]
2. What data we collect
2.1 Account data
- Email address (from Google or Apple Sign-In)
- Display name
- Profile picture URL (if provided by OAuth)
- Locale preference
- Workspace name(s)
2.2 Content data
- Product images you upload
- Product names, descriptions, categories you provide
- Scripts, captions, scene plans you create or AI generates
- Video renders and exports
- Brand kit assets (Pro tier)
2.3 Usage data
- Features used (anonymized analytics)
- AI generation history (provider, cost, latency)
- Quota usage
- Error reports (Sentry — IP truncated, no PII)
- Device info: OS version, app version, screen size
2.4 Payment data (Phase 2)
- Processed by Stripe directly. We store: subscription tier, status, period, last 4 digits.
- Full card data is never stored on iSale servers.
2.5 Communications
- Support tickets and replies
- Marketing email opt-in status
3. Why we use your data
| Purpose | Legal basis | Examples |
|---|---|---|
| Provide the service | Contract performance | Sign you in, generate clips, store products |
| AI processing | Consent (explicit, version-tracked) | Send images to AI providers for analysis |
| Service improvement | Legitimate interest | Anonymized aggregate analytics, A/B testing |
| Security | Legal obligation + legitimate interest | Fraud detection, abuse prevention, audit logs |
| Billing (Phase 2) | Contract performance | Process subscription |
| Customer support | Legitimate interest | Respond to your requests |
| Legal compliance | Legal obligation | Tax records, lawful disclosure if required |
4. Sharing data with third parties
4.1 AI providers (sub-processors)
We use external AI providers to deliver core functionality. See full list in AI Transparency document.
Summary: OpenAI, Anthropic, VBee, ElevenLabs, Kling AI, Google Vertex Veo, Runway, AWS Rekognition.
We send only the data required for the specific function (e.g., product image + prompt, never your email).
4.2 Infrastructure providers
- Amazon Web Services (Singapore region) — hosting, storage, database, compute
- Sentry — error tracking (PII-redacted)
- Expo — mobile push notifications
- Stripe — payment processing (Phase 2)
4.3 Legal disclosure
We may disclose data when required by Vietnamese law, court order, or to protect our rights, safety, or property.
4.4 What we never do
- We do not sell your data to third parties.
- We do not use your content to train our own AI models.
- We do not share your content across workspaces.
5. International data transfer
Your data may be processed in:
- Singapore (primary — AWS ap-southeast-1)
- United States (when using OpenAI, Anthropic, ElevenLabs, Veo, Runway)
- China (when using Kling AI — Pro tier AI Mode only)
- Vietnam (when using VBee TTS)
These transfers happen only when you use AI features, with your prior consent.
6. Data retention
| Data type | Retention |
|---|---|
| Account data | Until you delete account; then 30 days for legal/safety review, then deleted |
| Product images | 60 days hot storage, 180 days cold; permanent deletion on request |
| Render previews | 30 days, then auto-deleted |
| Final renders | 30 days hot, 180 days cold |
| Exports (MP4, etc.) | 60 days |
| Provider audit logs | 90 days hot, 7 years cold (compliance) |
| Generation jobs | 90 days hot, 1 year cold |
| Support tickets | 3 years |
| Billing records | 7 years (tax law) |
7. Your rights (Vietnam PDP Law + GDPR-equivalent)
You have the right to:
- Access — request a copy of your data
- Correct — fix incorrect data
- Delete — close your account and delete data
- Portability — receive your data in machine-readable format (CSV + JSON)
- Object — withdraw consent for AI processing (you keep your account, but AI features become unavailable)
- Restrict — limit processing in certain cases
- Lodge a complaint — with the Vietnamese Ministry of Public Security (Cục An ninh mạng và phòng, chống tội phạm sử dụng công nghệ cao — A05)
To exercise: email dsar@isale.app with your registered email and request type. We respond within 30 days.
8. Security measures
- TLS 1.2+ in transit
- KMS-encrypted at rest (AES-256) for database and storage
- IAM role-based access; no static passwords for service-to-service
- All admin actions logged and reviewed
- Annual third-party penetration testing
- 24/7 monitoring and incident response
- Employees access user data only when necessary (support, debugging) — all access logged
If a data breach occurs, we will notify affected users within 72 hours of discovery, per Vietnam PDP requirements.
9. Cookies and tracking
We use minimal cookies:
- Essential — session, authentication (cannot be disabled)
- Functional — remember language, UI preferences (opt-in via banner)
- Analytics — PostHog product analytics, anonymized (opt-in via banner)
We do not use advertising cookies or third-party trackers.
See Cookie Policy for details (TBD).
10. Children
iSale is not directed at users under 18. We do not knowingly collect data from minors. If we discover a minor's account, we delete it within 7 days.
11. Changes to this policy
We update this policy when:
- We add or remove a sub-processor
- We change data retention periods
- We add new data types
- Vietnam PDP Law or other applicable law changes
We notify users:
- In-app banner + email for material changes 30 days in advance
- Effective date updated at top of this document
- Previous versions archived at
/legal/privacy/archive
12. Governing law
This policy is governed by the laws of the Socialist Republic of Vietnam. Disputes are resolved by Vietnamese courts unless otherwise required by applicable law for cross-border users.
13. Contact
For any privacy question: privacy@isale.app
For data subject requests: dsar@isale.app
For security disclosure: security@isale.app
NOTE TO TEAM: This document is a working draft. Before launch:
- Vietnamese privacy counsel must review and adapt to current PDP regulations.
- Provide Vietnamese translation (legal binding version).
- Confirm legal entity name + registration number + address.
- Cross-check sub-processor list with all signed provider DPAs.
- Confirm "designated representative" required by PDP Law.