Privacy Policy
This policy describes how vne.email collects, uses, stores, and protects your personal data, in accordance with the Law on Personal Data Protection No. 91/2025/QH15 (effective Jan 1, 2026), Decree No. 356/2025/ND-CP implementing the Law on Personal Data Protection, and Decree No. 53/2022/ND-CP on domestic data storage.
Last updated: Jul 9, 2026
The entity responsible for processing personal data (the Data Controller) is CÔNG TY TNHH THƯƠNG MẠI VÀ DỊCH VỤ TRIPLES (Tax ID 0316579552), the operator of vne.email — address 201 Nguyễn Văn Lượng, Gò Vấp Ward, Ho Chi Minh City.
1. Data we collect
1.1. Data you provide when registering
- Full name
- Contact email
- Phone number
- Business name, tax ID (if a VAT invoice is needed)
- The domain to be used for your mailbox
When you register, you sign in with a Google account or an OTP code — the account does not use a password to sign in. To connect a third-party mail app via IMAP/SMTP (Outlook, Thunderbird, Mail on iPhone…), you create an “app password” in the portal: the system generates a random string, shown exactly once, which you can revoke individually. We only store a SHA-256 hash of this string — we never store the raw password.
1.2. Data generated while using the service
- Mail content (subject, body, attachments, labels) — stored on infrastructure located in Vietnam; transmitted over TLS; off-site backups are encrypted (restic + Age).
- Send/receive metadata: timestamp, sender/recipient, size.
- Technical access logs: sign-in IP, User-Agent, timestamp — retained 90 days for incident investigation.
- Mail server logs (Postfix, Dovecot, Rspamd) — retained 30 days locally + 90 days in encrypted backup.
1.3. Attendance & biometric data
This section only applies when your organization's administrator enables the Attendance feature and requires a photo at check-in/check-out. If your organization does not enable it, we do not collect the data described below.
- Facial photo (biometric data): when required by the attendance policy, each time you check in/out a selfie is captured as evidence for that specific attendance record — this is its sole purpose.
- Legal basis for processing: your consent. Before the first capture, you are explicitly asked to consent, and you may withdraw it at any time directly on the Attendance page; upon withdrawal, all of your stored photos are deleted immediately. If you do not consent, you can still check in/out by submitting an exception (without a photo) for administrator approval.
- Retention period: photos are kept for up to the duration configured by your organization (7 to 365 days), then automatically deleted; photos are also deleted immediately upon withdrawing consent, or when you leave the organization / your account is deleted.
- Who can access it: only you and your organization's workspace administrators. We do not use the photos for any other purpose and do not share them with third parties.
- Location coordinates: if required by policy, GPS coordinates are captured only at the moment you tap to check in/out (no background location tracking), to verify you are within the permitted area; the network IP address at the time of check-in/out may also be recorded.
2. Purposes of use
- Providing and operating the email service under your domain.
- Automatically filtering spam, malware, and phishing (via our in-house Rspamd — no third party ever sees mail content).
- Issuing payment receipts and managing your service plan.
- Sending operational notifications (renewals, incidents, updates) by email and in-app notification.
- Improving service quality through anonymized, aggregate statistics (not traceable back to an individual).
3. Data storage location
All mail content, metadata, and primary backups are stored in Vietnam — servers are located at an FPT data center. Secondary (disaster-recovery) backups are stored encrypted outside Vietnam at Backblaze B2 (United States), under a separate Age encryption key managed by vne.email.
This arrangement complies with Decree No. 53/2022/ND-CP: the primary data of Vietnamese users is stored domestically.
4. Data sharing
We do not sell or rent your data. Data is only shared in the following cases:
- Support partners: Casso.vn/Sepay (only bank-transfer reference information, for payment reconciliation). These partners see only transfer details, never your mail content.
- Legal requests: when a competent government authority requests it in writing, following proper legal process. We will notify you unless prohibited by law.
5. Security
- Passwordless sign-in (Google or OTP). App passwords for IMAP/SMTP are stored as a SHA-256 hash of a 120-bit random string; passwords protecting shared file links are stored as Argon2id — both irreversible.
- TLS 1.2+ is enforced on every protocol (IMAP, SMTP, HTTPS).
- DKIM + DMARC sign every outbound message to prevent spoofing.
- Backups are block-level encrypted (via restic + Age).
- Application-layer brute-force protection: rate limiting, temporary lockout after repeated failed sign-ins, and risk-based proof-of-work captcha.
- The operations team only accesses data when investigating an incident, and every access is recorded in a tamper-proof audit log.
6. Your rights
Under the Law on Personal Data Protection No. 91/2025/QH15 and Decree No. 356/2025/ND-CP, you have the following rights over your personal data:
- Right to access: view all the data we hold about you.
- Right to rectification: update your personal information via the portal.
- Right to erasure: delete your own account and all your data directly in the app or on the web, without contacting support — specific steps are in Section 7.
- Right to restrict processing: request that we not use your data for a specific purpose, except for processing necessary to operate the mailbox you're using and data that must be retained by law (e.g., invoices).
- Right to data portability: export your own data at any time — Drive: use Drive → Download all (one click, ZIP download); Email: connect a mail app via IMAP using an app password to download all mail as standard .eml/.mbox files, importable into any provider. We provide the tools for you to obtain your own data; we do not transfer data to a third party on your behalf.
- Right to lodge a complaint: file a complaint with the regulatory authority.
To exercise these rights, send a request to privacy@vne.email. We respond within 72 business hours.
7. Account & data deletion
This section applies to every way you use the service, including the vne.email — Email & Workspace mobile app (package name email.vne.app) on Google Play and the App Store, published by CÔNG TY TNHH THƯƠNG MẠI VÀ DỊCH VỤ TRIPLES — the operator of vne.email named at the top of this page. You can delete your own account directly within the product, without contacting support.
7.1. Steps to delete your own account
- Sign in and open Settings: in the app, select Settings; on the web, go to app.vne.email/account/settings — this also works if you've already uninstalled the app.
- Scroll down to the Delete account section and tap the Delete account button.
- Enter a reason if you'd like (optional), type the confirmation phrase delete account, then tap Delete my account.
The request takes effect immediately: all sign-in sessions are revoked and you lose access. The only case requiring an extra step: you are the owner of an organization that still has other members — in that case, the system requires you to transfer ownership to another member (done on the same Settings page) before deleting your own account. If you're unable to do this yourself, send a request from your email address to privacy@vne.email — we respond within 72 business hours.
7.2. What data is deleted, what is retained
- You are a member of an organization with other members: your account and access are deleted immediately; shared work data (Drive files, customer records, reports…) is handed over to an organization manager rather than deleted, since it belongs to the organization. The organization and its other members are unaffected.
- You are the sole member, and the organization has never had a billed invoice: all data — mailbox and mail content, Drive files, messages, contacts, calendar, domain configuration, account profile — is permanently deleted immediately, and cannot be recovered.
- You are the sole member, and the organization has had invoices: access is revoked and every mailbox stops working immediately; however, invoices and payment records must be retained for 10 years under Vietnamese accounting law, so they are kept in a locked state, and final deletion completes once that retention obligation ends.
In all cases: backup copies containing deleted data automatically expire within 90 days at most; technical logs are retained per the periods in Section 8; and we keep a minimal record of the deletion request itself (timestamp, requesting email, outcome) as evidence the obligation was fulfilled. To delete only part of your data (mail, files, messages…) without deleting your account: delete it directly in the app, or send a request to privacy@vne.email. Before deleting your account, be sure to download any data you need — see “Right to data portability” in Section 6.
8. Data retention periods
- Mailbox data: for the duration of the service + 30 days after the plan is terminated (recovery period). When you proactively delete your account, Section 7 applies instead — deleted immediately, no recovery period.
- Access logs: 90 days.
- Operational audit logs: 24 months.
- Invoices and payment records: 10 years under Vietnamese accounting law, even after account deletion.
- Off-site backups: 90 days from the last backup.
9. Cookies & tracking
The vne.email marketing site uses Google Analytics 4 (GA4) to measure traffic and how visitors use the site (page views, pages viewed, traffic source, device/browser type). Its sole purpose is to improve the site's content and experience. We enable IP anonymization and do not use this data to identify you personally; we do not sell or share this data for advertising purposes. GA4 sets a few analytics cookies in your browser — you can block them via your browser settings or a tracking-blocker extension without affecting your ability to use the service.
The portal, webmail and the mobile apps (iOS/Android) do not use GA4 or any third-party analytics service, and contain no analytics or advertising cookies — these surfaces use only a session cookie with the HttpOnly + Secure + SameSite=Lax flags, solely for sign-in purposes. The Terms page and this Privacy page also load no GA4. We do not track users: we do not link collected data with third-party data for advertising purposes, and we do not share data with data brokers.
10. Children
The vne.email service is not directed at individuals under 16 years old, and we do not knowingly collect personal data from children.
11. Changes to this policy
For material changes, we will send an email notice at least 30 days before they take effect. The current version is always available at vne.email/quyen-rieng-tu.
12. Contact
For any questions about this policy, please contact privacy@vne.email.