Privacy Policy
Version 2.1 · Effective: 4 October 2026
This version replaces all earlier versions of this policy.
This policy is published in Vietnamese and English. The Vietnamese text governs; the English text is a translation.
1. Who we are and how to contact us
This policy explains how Thaodien (thaodien.app) ("Thaodien", "we") processes personal data on Sai Gon (sai-gon.app), our related websites and apps, and the software we provide to restaurants, cafés and bars ("venues").
Send any request, question or complaint about personal data to: [email protected]
The details of the operating entity will be published here once its registration in Vietnam is complete.
2. Thaodien and venues
Each venue decides how the data of its own customers is used: orders, bookings, membership and the messages you send it. For that data the venue is the personal data controller and Thaodien is its processor, acting only on the venue's instructions. Thaodien is the controller of platform accounts, search and discovery, analytics on our websites and the messages we send you. You can send a request about venue data to us and we will pass it to the venue.
3. Personal data we collect and why
- Account details (name, phone number, email, and date of birth if you give it): to sign you in and manage your account, loyalty points and prepaid wallet.
- Orders, bookings and payments (items, amounts, notes, delivery address, ratings, e-invoice details): to prepare, deliver and charge for your order and to issue invoices.
- Messages you send a venue through website chat, Zalo, Messenger, Instagram, SMS or email: to answer you and take orders.
- Your device location, only if you allow it: to show places near you. It stays on your device.
- Technical data (IP address, device and browser type, error reports): to run the service securely and fix faults.
- Details of venue owners and staff, and the employment records a venue keeps in our software (such as identity documents, attendance and payroll): to provide the service to the venue.
- Public information about venues, including reviewer names that are already public: to show venue listings. Email us to have content about you removed.
We process this data to perform our contract with you or the venue, to meet legal obligations such as accounting and tax, or with your consent, which we ask for separately for marketing and analytics. We do not sell personal data.
4. Sensitive personal data
An allergy or health detail you write in an order note is sensitive personal data. Giving it is optional. The venue uses it only to prepare your order, and the health wording is removed 90 days after the order is completed.
A venue may save allergy details to your customer profile only with your explicit consent, which you can withdraw at any time. Identity document images of venue staff are also sensitive personal data.
6. Who receives personal data and transfers outside Vietnam
Staff of the venue you deal with see the data their role needs. Our staff access it only for technical support or security, and competent authorities receive it where the law requires. Service providers process data for us under contracts that limit how they use it:
- hosting, database and backups: Singapore;
- AI processing: Singapore, with health details removed first;
- error monitoring, SMS and email delivery: United States;
- content delivery and security, Google and Apple sign-in, and the messaging apps you choose: global networks;
- payment, e-invoice and delivery partners: only for the orders they handle.
7. Automated processing and AI
We use automated tools, including AI, for search, for drafting replies and, where a venue turns it on, for an ordering assistant that answers messages. Health details are removed before data reaches the AI service, and no tool makes decisions with legal effect on you. You can always ask for a person, and you can ask us to correct or delete information these tools produce about you.
8. How long we keep personal data
We keep personal data only as long as needed for the purpose it was collected for, then delete or anonymise it. Accounting and tax records, including order and invoice records, are kept for 10 years as the law requires. Allergy and health wording in order notes is removed 90 days after the order is completed. When you ask us to delete your account, we delete or anonymise your account data, except the records we must keep for accounting.
9. Your rights
You have the right to be informed about how your personal data is processed; to give or withdraw consent; to access, correct and receive a copy of your data; to have it deleted; to restrict or object to its processing, including for marketing; and to complain, bring a claim or seek compensation under the law.
To exercise these rights, email [email protected]. We may verify your identity first. We reply within 2 working days and act within the legal time limits. You can also delete your account yourself under Account, then Profile.
10. Children's data
Our services are not intended for children; where a child's data is processed, a parent or guardian exercises the child's rights and can ask us to delete it.
11. Security and breaches
We protect personal data with encrypted connections, role-based access and regular backups. If a breach could harm you, we notify the personal data protection authority within 72 hours of discovering it, inform the venue concerned, and tell you where the law requires it or where you need to act to protect yourself.
12. Changes to this policy
When our processing changes, we update this policy, show the new version and effective date at the top of this page, and announce significant changes on the website before they take effect.