Chính sách này mô tả cách 2FA Pro ("chúng tôi") xử lý dữ liệu cá nhân khi bạn sử dụng website, tiện ích trình duyệt và các dịch vụ liên quan tại sync2fa.com.
Chúng tôi xử lý dữ liệu để tạo và xác thực tài khoản; mã hóa, lưu trữ và đồng bộ kho; quản lý phiên; phát hiện gian lận; kích hoạt gói Pro; hỗ trợ người dùng; duy trì an toàn, hiệu năng và tuân thủ nghĩa vụ pháp luật. Việc xử lý dựa trên yêu cầu cung cấp dịch vụ của bạn, sự đồng ý khi pháp luật yêu cầu, lợi ích hợp pháp về an toàn hệ thống và nghĩa vụ pháp lý áp dụng.
Khóa bí mật trong kho được mã hóa bằng cơ chế mật mã phía máy khách. Master Password không được gửi lên dưới dạng rõ. Dữ liệu đã giải mã vẫn tồn tại tạm thời trong bộ nhớ của thiết bị khi kho đang mở; mã độc, tiện ích độc hại, XSS, thiết bị bị chiếm quyền hoặc việc để lộ Master Password có thể làm lộ dữ liệu. Nếu mất Master Password và mã khôi phục, chúng tôi có thể không thể khôi phục kho.
Chúng tôi có thể chuyển dữ liệu cần thiết cho các đơn vị xử lý phục vụ dịch vụ, gồm Google/Firebase (đăng nhập và cơ sở dữ liệu), Cloudflare (DNS, bảo vệ, phân phối nội dung và Worker), SePay và ngân hàng/VietQR (đối soát thanh toán), cùng các CDN hoặc nhà cung cấp kỹ thuật được tích hợp. Dữ liệu cũng có thể được cung cấp khi pháp luật yêu cầu, để bảo vệ quyền hợp pháp hoặc trong giao dịch tổ chức lại doanh nghiệp.
Chúng tôi không bán khóa bí mật OTP/TOTP hoặc dữ liệu cá nhân cho mục đích quảng cáo hành vi.
Dịch vụ sử dụng cookie, IndexedDB, Local Storage và Session Storage để duy trì đăng nhập, khóa phiên, tùy chọn và đồng bộ. Nhà cung cấp có thể xử lý dữ liệu tại máy chủ ngoài Việt Nam; khi đó chúng tôi áp dụng biện pháp hợp lý và nghĩa vụ pháp luật liên quan đến chuyển dữ liệu xuyên biên giới.
Dữ liệu tài khoản và kho được giữ trong thời gian tài khoản hoạt động. Khi bạn xóa tài khoản, dữ liệu trong hệ thống đang hoạt động sẽ được xóa hoặc vô hiệu hóa theo khả năng kỹ thuật; bản sao lưu, nhật ký chống gian lận, dữ liệu giao dịch hoặc dữ liệu phải lưu theo pháp luật có thể được giữ thêm trong thời hạn cần thiết rồi xóa hoặc ẩn danh.
Tùy pháp luật áp dụng, bạn có quyền được biết, đồng ý hoặc rút lại sự đồng ý, truy cập, chỉnh sửa, hạn chế hoặc phản đối xử lý, yêu cầu xóa, cung cấp dữ liệu và khiếu nại. Rút lại sự đồng ý không làm mất tính hợp pháp của việc xử lý trước đó và có thể khiến một số tính năng không thể tiếp tục cung cấp. Chúng tôi có thể yêu cầu xác minh danh tính trước khi giải quyết yêu cầu.
Bạn phải bảo vệ thiết bị, Master Password và mã khôi phục; không chia sẻ tài khoản; cập nhật phần mềm; và chỉ nhập dữ liệu mà bạn có quyền xử lý. Dịch vụ không chủ đích dành cho trẻ em chưa đủ độ tuổi tự mình đồng ý theo pháp luật; người đại diện hợp pháp phải chấp thuận khi được yêu cầu.
Chúng tôi áp dụng biện pháp hợp lý để phòng ngừa và xử lý sự cố, nhưng không hệ thống nào an toàn tuyệt đối. Khi có sự cố thuộc trường hợp phải thông báo, chúng tôi sẽ thực hiện theo pháp luật. Chính sách có thể được cập nhật; thay đổi quan trọng sẽ được thông báo phù hợp trước hoặc khi có hiệu lực.
Yêu cầu về dữ liệu cá nhân: support@sync2fa.com
Website: https://sync2fa.com/
Xem thêm Chính sách bảo mật và Điều khoản sử dụng, thanh toán và hoàn tiền.
This Policy describes how 2FA Pro ("we", "us") processes personal data when you use the website, browser extension, and related services at sync2fa.com.
We process data to create and authenticate accounts; encrypt, store, and synchronize vaults; manage sessions; detect fraud; activate Pro plans; support users; maintain security and performance; and comply with applicable law. Processing is based on providing the service you request, consent where required, legitimate security interests, and applicable legal obligations.
Vault secrets are protected using client-side cryptography. The Master Password is not transmitted in plaintext. Decrypted data temporarily exists in device memory while the vault is unlocked; malware, malicious extensions, XSS, a compromised device, or disclosure of the Master Password may expose it. We may be unable to recover a vault if both the Master Password and recovery code are lost.
We may provide necessary data to processors supporting the service, including Google/Firebase, Cloudflare, SePay, banks/VietQR, CDNs, and integrated technical providers. Data may also be disclosed when required by law, to protect legal rights, or as part of a business reorganization.
We do not sell OTP/TOTP secrets or personal data for behavioral advertising.
The service uses cookies, IndexedDB, Local Storage, and Session Storage for authentication, session locking, preferences, and synchronization. Providers may process data on servers outside Vietnam; where applicable, we use reasonable safeguards and follow legal requirements for cross-border transfers.
Account and vault data is retained while the account remains active. After account deletion, active-system data is deleted or disabled where technically possible. Backups, anti-fraud logs, transactions, or records required by law may be retained for the necessary period and then deleted or anonymized.
Subject to applicable law, you may have rights to be informed, consent or withdraw consent, access, correct, restrict or object to processing, request deletion or data delivery, and complain. Withdrawal does not affect prior lawful processing and may prevent certain features from operating. We may verify identity before completing a request.
You must protect your device, Master Password, and recovery codes; avoid sharing accounts; keep software updated; and only submit data you are entitled to process. The service is not intentionally directed to children who cannot independently consent under applicable law.
We use reasonable safeguards, but no system is completely secure. We will provide legally required incident notices when applicable. We may update this Policy and will give appropriate notice of material changes.
Privacy requests: support@sync2fa.com
Website: https://sync2fa.com/
See also the Security Policy and Terms of Use, Payment and Refund Policy.