Chính sách quyền riêng tư

Ứng dụng HyOperly · Cập nhật lần cuối: 22/08/2026

HyOperly là phần mềm nghiệp vụ dành cho các doanh nghiệp vận tải và giao nhận, phục vụ công tác điều hành giao nhận và ký duyệt chứng từ. Mỗi doanh nghiệp khách hàng có không gian dữ liệu riêng; tài khoản do quản trị viên của doanh nghiệp cấp cho nhân sự.

Ai cung cấp phần mềm này. HyOperly do Võ Vũ Hy — nhà phát triển độc lập — xây dựng, vận hành và cung cấp cho doanh nghiệp theo mô hình phần mềm dịch vụ (SaaS). Trong chính sách này, “chúng tôi” là nhà phát triển nói trên. Liên hệ: vovuhy@icloud.com.

Vai trò xử lý dữ liệu. Với dữ liệu nhân sự và dữ liệu nghiệp vụ phát sinh khi doanh nghiệp khách hàng sử dụng phần mềm, doanh nghiệp khách hàng là bên kiểm soát dữ liệu: họ quyết định thu thập gì, của ai và dùng vào việc gì. Chúng tôi là bên xử lý dữ liệu thay mặt doanh nghiệp đó, chỉ xử lý trong phạm vi nêu ở chính sách này và theo yêu cầu hợp lệ của doanh nghiệp. Nếu bạn là nhân sự của doanh nghiệp khách hàng, hãy gửi yêu cầu về dữ liệu cá nhân tới doanh nghiệp bạn trước; chúng tôi hỗ trợ doanh nghiệp thực hiện.

1. Dữ liệu chúng tôi thu thập và cách thu thập

1.1 Thông tin đăng nhập

Khi bạn đăng nhập, ứng dụng gửi mã công ty, tên đăng nhập và mật khẩu tới máy chủ của chúng tôi để xác thực. Ứng dụng không tự lưu mật khẩu xuống thiết bị; mật khẩu chỉ tồn tại trong bộ nhớ tạm của màn hình đăng nhập.

Lưu ý rằng hệ điều hành của thiết bị có cơ chế bộ nhớ đệm bàn phím và trình quản lý mật khẩu riêng, nằm ngoài phạm vi kiểm soát của ứng dụng.

1.2 Thông tin tài khoản

Sau khi xác thực thành công, máy chủ cấp một phiếu truy cập có hiệu lực 15 ngày, chứa: mã tài khoản, tên đăng nhập, họ tên, chức vụ, địa chỉ email, toàn bộ bản đồ phân quyền của bạn theo từng công ty (không chỉ công ty bạn đang đăng nhập), mã phiên làm việc, mã bản ghi phiên đăng nhập, cờ yêu cầu đổi mật khẩu và thời điểm hết hạn.

Khi bạn dùng chức năng đặt lại mật khẩu hoặc thiết lập xác thực hai bước, hệ thống gửi qua email các mã ngắn hạn riêng phục vụ đúng việc đó.

1.3 Thông tin kỹ thuật thu thập tự động

Mỗi lần bạn đăng nhập, máy chủ ghi lại địa chỉ IP, chuỗi nhận dạng trình duyệt hoặc ứng dụng (User-Agent), nền tảng, và tên thiết bị vào bản ghi phiên đăng nhập. Các thông tin này phục vụ bảo mật tài khoản và cho phép bạn hoặc quản trị viên rà soát các phiên đang hoạt động.

1.4 Nhật ký hoạt động

Trong quá trình sử dụng, hệ thống ghi nhận:

1.5 Thiết bị và thông báo đẩy

Nếu bạn bật thông báo, dữ liệu được gửi tới hai nơi:

Nội dung thông báo có thể chứa dữ liệu nghiệp vụ như mã phiếu, tên hàng hoá và loại hành động. Nội dung này đi qua dịch vụ của Expo rồi tới dịch vụ đẩy của Apple hoặc Google trước khi hiển thị trên thiết bị bạn.

Ngoài ra, mỗi lần mở ứng dụng, ứng dụng kiểm tra bản cập nhật từ máy chủ của Expo và gửi kèm một mã định danh bản cài đặt cùng thông tin nền tảng và phiên bản. Việc này diễn ra trước cả khi bạn đăng nhập.

1.6 Ảnh và tài liệu do bạn cung cấp

Ứng dụng truy cập camera chỉ để quét mã vạch trên kiện hàng; ứng dụng di động không có chức năng chụp ảnh. Ứng dụng truy cập thư viện ảnh chỉ khi bạn chủ động chọn chức năng đính kèm: chọn ảnh bằng chứng giao nhận, đính kèm ảnh và tệp vào phiếu đề xuất, quyết toán, hồ sơ vận hành và thảo luận. Ứng dụng không tự động quét hay tải lên nội dung nào trong thư viện của bạn.

Về dữ liệu vị trí nhúng trong ảnh. Ứng dụng không sử dụng dịch vụ định vị của thiết bị và không hỏi quyền truy cập vị trí. Ảnh chụp bằng điện thoại thường mang sẵn siêu dữ liệu EXIF, trong đó có thể có toạ độ GPS, độ cao, thời điểm và kiểu máy chụp.

Khi bạn tải ảnh lên, máy chủ của chúng tôi dựng lại ảnh từ dữ liệu điểm ảnh và chuyển sang định dạng WebP trước khi lưu. Quá trình này loại bỏ toàn bộ siêu dữ liệu EXIF, bao gồm mọi toạ độ GPS. Ảnh được lưu trữ và hiển thị về sau không còn chứa thông tin vị trí. Điều này áp dụng cho cả ảnh bằng chứng giao nhận lẫn ảnh đính kèm thông thường.

1.7 Dữ liệu nghiệp vụ bạn nhập vào

Nội dung đơn hàng, kiện hàng, phiếu đề xuất, phiếu quyết toán, ghi chú và thảo luận bạn tạo trong quá trình làm việc. Trong đó bao gồm thông tin tài chính: số tài khoản ngân hàng, tên chủ tài khoản, tên người thụ hưởng, số tiền và nội dung chuyển khoản trên các phiếu thanh toán.

1.8 Dữ liệu về người thứ ba

Khi thực hiện nghiệp vụ giao hàng, hệ thống ghi nhận tên, địa chỉ và thông tin liên hệ của người nhận hàng, ảnh chụp hiện trường giao hàng và ảnh chữ ký của người nhận. Riêng ảnh hiện trường và ảnh chữ ký hiện chỉ thu thập qua giao diện web, ứng dụng di động chưa có chức năng này. Đây là dữ liệu của người thứ ba do bạn — với tư cách nhân viên — nhập vào để làm bằng chứng giao nhận. Doanh nghiệp sử dụng ứng dụng chịu trách nhiệm bảo đảm việc thu thập này phù hợp với thỏa thuận với khách hàng và pháp luật hiện hành.

1.9 Dữ liệu nhân sự hiển thị trong ứng dụng

Ứng dụng hiển thị dữ liệu chấm công và số dư ngày phép của chính bạn. Dữ liệu này do hệ thống chấm công của doanh nghiệp tạo ra và được truyền từ máy chủ xuống thiết bị; ứng dụng không tự thu thập.

1.10 Bảng nhớ tạm của hệ thống

Khi bạn bấm nút sao chép, ứng dụng ghi số điện thoại người nhận hoặc ảnh mã QR chuyển khoản vào bảng nhớ tạm của hệ điều hành. Bảng nhớ tạm là vùng dùng chung mà ứng dụng khác có thể đọc, và trên thiết bị Apple có thể đồng bộ sang các thiết bị khác cùng tài khoản.

Khi bạn in tem dán kiện, ứng dụng dựng tệp PDF chứa tên người nhận rồi chuyển sang bảng chia sẻ của hệ điều hành hoặc dịch vụ in (AirPrint). Dữ liệu khi đó rời khỏi ứng dụng sang ứng dụng hoặc máy in bạn chọn.

2. Dữ liệu chúng tôi KHÔNG thu thập

3. Mục đích sử dụng

Toàn bộ dữ liệu nêu trên chỉ dùng để vận hành chính ứng dụng: xác thực và phân quyền; hiển thị và xử lý chứng từ, đơn hàng, kiện hàng; lưu bằng chứng giao nhận; gửi thông báo về công việc liên quan tới bạn; bảo vệ an toàn tài khoản; và phục vụ đối soát, kiểm toán nội bộ của doanh nghiệp. Chúng tôi không bán dữ liệu và không dùng dữ liệu cho mục đích tiếp thị.

4. Lưu trữ trên thiết bị

Dữ liệuNơi lưuMã hoá
Phiếu truy cập phiên đăng nhậpKho bảo mật của hệ điều hành (Keychain trên iOS, Keystore trên Android)Có
Hồ sơ người dùng: mã tài khoản, tên đăng nhập, họ tên, email, chức vụ và toàn bộ cây phân quyềnBộ nhớ ứng dụng thông thườngKhông
Mã công ty, vai trò đang dùng, ngôn ngữ, tuỳ chọn thông báo, bản sao mã thông báo đẩy và mã thiết bịBộ nhớ ứng dụng thông thườngKhông

Khi bạn đăng xuất, ứng dụng xoá dữ liệu cục bộ nêu trên, riêng lựa chọn ngôn ngữ được giữ lại để lần mở sau vẫn đúng ngôn ngữ bạn chọn. Trên Android, ứng dụng hiện cho phép hệ điều hành sao lưu dữ liệu ứng dụng theo cơ chế sao lưu mặc định của hệ thống.

5. Bên thứ ba có thể tiếp cận dữ liệu

Chúng tôi yêu cầu và xác nhận rằng mọi bên thứ ba nêu dưới đây áp dụng mức bảo vệ dữ liệu người dùng tương đương với chính sách này.

Ngoài các bên trên, dữ liệu được lưu trên máy chủ do chúng tôi vận hành. Chúng tôi không chia sẻ dữ liệu cho bên nào khác, trừ khi pháp luật yêu cầu.

6. Thời gian lưu trữ và cách xoá dữ liệu

Tài khoản trong HyOperly do doanh nghiệp cấp và quản lý. Ứng dụng không có chức năng tự đăng ký, do đó cũng không có nút tự xoá tài khoản trong ứng dụng — việc mở, khoá hoặc xoá tài khoản do quản trị viên của doanh nghiệp thực hiện.

Lưu ý về thông báo đẩy khi đăng xuất. Khi bạn đăng xuất, mã thông báo đẩy của thiết bị được đánh dấu ngừng hoạt động để thiết bị không nhận thông báo nữa, nhưng bản ghi tương ứng không bị xoá ngay. Bản ghi này còn lưu mã tài khoản, mã công ty, mã định danh thiết bị và mã thông báo đẩy.

Tương tự, bản ghi phiên đăng nhập và nhật ký kiểm toán (gồm địa chỉ IP và thông tin thiết bị) được giữ lại phục vụ bảo mật và đối soát, không bị xoá khi đăng xuất.

Dữ liệu nghiệp vụ (chứng từ, đơn hàng, bằng chứng giao nhận) được doanh nghiệp lưu giữ theo yêu cầu lưu trữ chứng từ và quy định kế toán hiện hành.

Nếu bạn muốn xoá các dữ liệu cá nhân nêu trên, hãy gửi yêu cầu theo mục 7. Chúng tôi phản hồi trong vòng 30 ngày.

7. Rút lại sự đồng ý và liên hệ

Bạn có thể rút lại quyền truy cập camera, ảnh hoặc thông báo bất cứ lúc nào trong phần Cài đặt của hệ điều hành. Việc này không xoá dữ liệu đã gửi trước đó; muốn xoá thì gửi yêu cầu theo địa chỉ dưới đây.

Email: vovuhy@icloud.com

8. Thay đổi chính sách

Khi có thay đổi, chúng tôi cập nhật nội dung trên trang này và sửa ngày ở đầu trang. Bạn nên xem lại định kỳ.

Privacy Policy

HyOperly app · Last updated: 22 August 2026

HyOperly is business software for logistics and delivery companies, covering delivery operations and document approval. Each customer company has its own separate data space, and accounts are provisioned by the company's administrator for its staff.

Who provides this software. HyOperly is built, operated and provided as software-as-a-service by Vo Vu Hy, an independent developer. In this policy, “we” refers to that developer. Contact: vovuhy@icloud.com.

Data protection roles. For the HR and business data that arises when a customer company uses the software, the customer company is the data controller: it decides what is collected, about whom, and for what purpose. We act as a data processor on that company's behalf, processing only within the scope set out in this policy and on the company's lawful instructions. If you are an employee of a customer company, please direct personal-data requests to your company first; we assist the company in fulfilling them.

1. Data we collect and how

1.1 Sign-in credentials

When you sign in, the app sends your company code, username and password to our server for authentication. The app does not itself store the password on the device; it exists only in the sign-in screen's temporary memory. Note that the operating system has its own keyboard cache and password manager, which are outside the app's control.

1.2 Account information

On successful authentication the server issues an access token valid for 15 days containing: your account identifier, username, full name, job title, email address, your complete permission map across every company (not only the one you signed in to), a session identifier, a sign-in session record identifier, a password-change flag and an expiry time. Password reset and two-factor setup use separate short-lived tokens delivered by email.

1.3 Technical information collected automatically

Each time you sign in, the server records your IP address, User-Agent string, platform and device name in the sign-in session record. This supports account security and lets you or an administrator review active sessions.

1.4 Activity logs

During use, the system records the session's last-active timestamp on every call to our server; your IP address and device information alongside each operational action (delivery confirmation, label voiding, tracking updates, parcel creation); and your IP address, device information and the before/after content of every edit you make to business data. These form an audit trail for internal reconciliation.

1.5 Device and push notifications

If you enable notifications, data goes to two destinations. To Expo's servers (a third-party push provider): the operating-system push token, an Expo-generated installation identifier, the application identifier and project identifier. This repeats automatically when the operating system issues a new token and at least every seven days, without any action from you. To our servers: the Expo push token, device platform and a device identifier (identifierForVendor on iOS, Android ID on Android), stored against your account and company along with activation state and last-active time.

Notification content may include business data such as document codes, goods names and action types. That content passes through Expo and then Apple's or Google's push services before reaching your device.

Additionally, each time you open the app it checks for updates from Expo's servers, sending an installation identifier along with platform and version information. This happens before you sign in.

1.6 Photos and documents you provide

The camera is used only to scan parcel barcodes; the mobile app has no photo-capture feature. The photo library is accessed only when you actively choose an attachment action: selecting delivery proof photos, and attaching images or files to proposals, settlements, operation records and discussions. The app never scans or uploads library content automatically.

About location data embedded in photos. The app does not use the device's location services and never requests location permission. Photos taken with a phone commonly carry EXIF metadata that can include GPS coordinates, altitude, timestamp and camera model.

When you upload a photo, our server rebuilds the image from its pixel data and converts it to WebP before storing it. This removes all EXIF metadata, including any GPS coordinates. The stored and subsequently displayed image no longer contains location information. This applies to both delivery proof photos and ordinary attachments.

1.7 Business data you enter

Orders, parcels, proposal and settlement documents, notes and discussion messages you create. This includes financial information: bank account numbers, account holder names, beneficiary names, amounts and transfer descriptions on payment documents.

1.8 Third-party data

During delivery workflows the system records the recipient's name, address and contact details, on-site delivery photos, and an image of the recipient's signature. On-site and signature photos are currently captured through the web interface only; the mobile app does not yet offer this feature. This is third-party data entered by you as an employee to evidence delivery. The operating company is responsible for ensuring such collection complies with its customer agreements and applicable law.

1.9 HR data shown in the app

The app displays your own attendance records and leave balances. This data is produced by the company's attendance system and sent from our server to your device; the app does not collect it.

1.10 System clipboard

When you tap a copy button, the app writes the recipient's phone number or a bank transfer QR image to the system clipboard. The clipboard is a shared area readable by other apps, and on Apple devices it may sync to your other devices.

When you print a parcel label, the app renders a PDF containing the recipient's name and hands it to the operating system's share sheet or print service (AirPrint). At that point the data leaves the app for the app or printer you choose.

2. What we do NOT collect

3. How we use the data

All data listed above is used only to operate the app: authenticating and authorising users; displaying and processing documents, orders and parcels; storing delivery evidence; sending notifications about work assigned to you; protecting account security; and supporting the operating company's internal reconciliation and audit. We do not sell data and do not use it for marketing.

4. On-device storage

Session access tokens are stored in the operating system's secure storage (Keychain on iOS, Keystore on Android) and are encrypted. Everything else is stored in ordinary, unencrypted application storage: your user profile (account identifier, username, full name, email, job title and your complete permission tree), company code, active role, language, notification preferences, and a local copy of the push token and device identifier.

Signing out clears this local data except your language choice, which is kept so the app opens in the language you selected. On Android, the app currently permits the operating system's default application backup mechanism.

5. Third parties with access

We require and confirm that each third party below provides protection of user data equal to that stated in this policy.

Otherwise data resides on servers we operate. We do not share data with anyone else except where required by law.

6. Retention and deletion

Accounts are provisioned and managed by the operating company. Because the app has no self-registration, it also has no in-app account deletion; opening, disabling or deleting an account is performed by the company's administrator.

Note on sign-out. When you sign out, your device's push token is marked inactive so the device stops receiving notifications, but the corresponding record is not deleted immediately; it still holds the account identifier, company code, device identifier and push token. Likewise, sign-in session records and audit logs — including IP addresses and device information — are retained for security and reconciliation purposes and are not deleted at sign-out.

Business data (documents, orders, delivery evidence) is retained by the operating company in accordance with its record-keeping and accounting obligations.

To have any of the personal data above erased, send a request as described in section 7. We respond within 30 days.

7. Withdrawing consent and contact

You may revoke camera, photo or notification permissions at any time in your operating system settings. Doing so does not erase data already submitted; to request erasure, contact us at vovuhy@icloud.com.

8. Changes to this policy

When this policy changes we update this page and revise the date at the top. Please review it periodically.