Privacy Policy
1. Introduction and scope
This Privacy and Personal Data Protection Policy (“Policy”) explains how Thanh Tam collects, records, stores, uses, analyses, shares, protects and deletes personal data.
This Policy applies to:
- The Vietnamese website at https://nhathuocthanhtam.com/;
- The English-language website at https://nhathuocthanhtam.com/en/;
- The order tracking and management system at https://donhang.nhathuocthanhtam.com/;
- Customer accounts, shopping carts, forms, comments and ratings;
- Order-management, customer-care, inventory and related internal systems operated by Thanh Tam;
- Email, web push and other communication channels selected by users.
The personal data controller is:
Hộ Kinh Doanh Cửa Hàng Dược Liệu Thanh Tâm English-facing name: Thanh Tam Herbs Business registration/Tax identification number: 41E8 037068 Address: 119 Trieu Quang Phuc Street, Cho Lon Ward, Ho Chi Minh City, Vietnam Email: hi@hotro.nhathuocthanhtam.com Contact page: https://nhathuocthanhtam.com/en/contact-us/
In this Policy, “Thanh Tam”, “Thanh Tam Herbs”, “we”, “us” and “our” refer to Hộ Kinh Doanh Cửa Hàng Dược Liệu Thanh Tâm.
2. Personal data processing principles
We process personal data according to the following principles:
- We collect data that is relevant and reasonably necessary for an identified purpose;
- We do not use data for an incompatible purpose unless there is a lawful basis or additional consent;
- We provide information about the data, purposes, relevant processors and user rights;
- We apply security measures appropriate to the nature and sensitivity of the data;
- We restrict access to personnel and providers whose work requires it;
- We do not buy or sell personal data;
- Silence, failure to respond or merely visiting the website is not treated as consent where affirmative consent is required;
- Consent for marketing, web push, repurchase reminders and sensitive health-related processing is separated where appropriate.
Placing an order means that you request us to process the information necessary to confirm, prepare, deliver and support the order. Placing an order does not by itself mean that you consent to advertising.
3. Personal data we may collect
3.1. Identity and contact information
We may collect:
- Full name;
- Telephone number;
- Email address;
- Account name and customer identifier;
- Preferred language;
- Delivery and billing addresses;
- Country, province or city, ward or commune, and street address;
- Recipient name;
- Company name, tax identification number and invoicing address where requested;
- Information submitted through forms, email, comments, reviews or other communications.
Passwords are not stored in directly readable form. WordPress and related authentication systems use password hashing or access-code protection.
3.2. Order and transaction information
When you purchase a product or use order tracking, we may process:
- Order number;
- Order-tracking code or token;
- Product name, unit, quantity and unit price;
- Line totals and total payment amount;
- Payment method and payment status;
- Delivery method;
- Carrier;
- Tracking number and carrier-tracking URL;
- Current status and order-status history;
- Order creation, update and completion dates;
- Notes required to prepare or deliver the order;
- Return, support, feedback and complaint history.
We do not intentionally store complete payment-card numbers, card security codes or online banking passwords. Authentication credentials may be processed directly by the applicable bank, wallet or payment provider.
3.3. Health-related and product-use information
Because Thanh Tam supplies herbs, traditional medicines and products related to traditional medicine, information voluntarily provided by customers may reveal or enable inferences about health, including:
- The name of a prescription or traditional remedy;
- Products, medicines or herbs purchased;
- Symptoms or intended use;
- Consultation or preparation notes;
- The expected date on which medicine or a product may run out;
- The number of days before a repurchase reminder;
- Feedback about the use of a product.
This information may constitute sensitive personal data. We process it only to the extent necessary to respond to a request, fulfil an order, provide support, administer a requested reminder or meet a legal obligation.
Users should not submit unnecessary health information through a public comment, general order-notes field or an unsuitable communication channel.
Website content and behavioural data are not used to make an automated medical diagnosis, prescribe treatment or replace examination or advice from an appropriately qualified practitioner.
3.4. Comments, ratings and feedback
When you submit a comment, rate an article or review an order, we may collect:
- Display name;
- Email address;
- Comment or review content;
- Article rating;
- Product, seller or carrier rating;
- IP address;
- Browser user-agent string;
- A hashed account or browser identifier;
- Submission time and moderation status;
- Your choice concerning whether a review may be shared or redirected to Google.
Your display name, comment and rating may be publicly displayed after moderation. Your email address, IP address and technical identifiers are not publicly displayed unless disclosure is legally required.
3.5. Technical and website-use information
When you access our websites, browsers, servers and technical tools may automatically record:
- IP address;
- Browser type and version;
- Operating system;
- Device type or category;
- User-agent string;
- Browser language;
- Time zone;
- Date and time of access;
- Pages viewed;
- Entry and exit pages;
- Links clicked;
- Referring page or domain;
- Landing-page path;
- UTM source, medium and campaign parameters;
- Session identifier, session hash, visitor ID or browser token;
- Page-view, product-view, add-to-cart, form-submission, order and rating events;
- Error, security and unusual-activity logs.
Some systems may store an IP address directly, including server logs, WordPress comments and tracked-link statistics. Other systems store only an IP hash, user-agent hash or session hash to reduce direct identifiability.
3.6. Email information
Emails sent through our systems may generate records including:
- Recipient email address;
- Email subject and content;
- Message identifier or tracking token;
- Queued, sent or failed status;
- Provider message identifier;
- Sent time;
- First and most recent open times;
- Open count;
- Link-click time;
- Hashed IP address;
- User-agent string;
- Classification of whether an open is likely to have been generated by a person or by an email-security system.
We use this information to operate transactional email, investigate delivery failures, support customers and measure communication performance.
3.7. Web push information
When web push functionality is loaded, OneSignal and the browser may process:
- Notification-permission status;
- OneSignal ID;
- Subscription ID;
- Push token and web-push subscription keys;
- Browser, operating system and device category;
- Language and time zone;
- Country or region inferred from IP;
- First and most recent session times;
- Session count;
- Notification sending, display and click history.
Displaying a permission prompt does not mean that a user has subscribed. Web push is enabled only after the user selects “Allow” in the browser permission dialog.
4. When information is collected
Information may be collected when you:
- Access a website covered by this Policy;
- Change the website language;
- Create or sign in to an account;
- View an article or product;
- Add a product to the cart;
- Place an order or request an invoice;
- Track an order;
- Submit a comment, rating or review;
- Contact us;
- Subscribe to web push;
- Open an email or select a link in an email;
- Request a repurchase reminder;
- Consent to marketing;
- Select a link configured for measurement;
- Trigger an error, failed login, unusual event or potential fraud alert.
Information may also be synchronised from WooCommerce to our order, CRM, customer-care or internal management systems for the same transaction.
5. Cookies and similar technologies
Cookies are small files stored on a user’s device. Our websites may also use Local Storage, Session Storage, IndexedDB, tracking pixels, service workers and similar identifiers.
5.1. Strictly necessary cookies
Necessary cookies may be used to:
- Test whether the browser accepts cookies;
- Maintain authentication;
- Protect accounts and sessions;
- Remember comment information where selected;
- Remember the Vietnamese or English language;
- Maintain the shopping cart and purchase session;
- Remember recently viewed products;
- Record that a store notice has been dismissed.
WooCommerce may use cookies including:
woocommerce_cart_hash;woocommerce_items_in_cart;wp_woocommerce_session_*;woocommerce_recently_viewed;- Store-notice cookies.
Polylang may use the pll_language cookie to remember the language selected by a user.
Cart cookies commonly last for a browser session. The WooCommerce session cookie may last for approximately two days under its default configuration.
Blocking necessary cookies may prevent login, the cart, checkout, commenting or language selection from working correctly.
5.2. Article-rating Local Storage
The article-rating function may store:
nttt_ar_visitor_token;- A rating-status identifier for each rated article.
The token is randomly generated and is hashed before being associated with a rating in the database. An IP address may be used temporarily for request rate-limiting.
Local Storage may remain until the user clears the website data in the browser.
5.3. Google Analytics, Google Tag Manager and Google Ads
Our website uses Google Site Kit, Google Analytics 4, Google Tag Manager and Google Ads to measure:
- Page views and sessions;
- Traffic sources;
- Pages and products viewed;
- Interaction events;
- Add-to-cart activity;
- Submitted forms;
- Orders and conversions;
- Content and advertising performance.
Google Analytics may receive an IP address during collection to determine approximate location, route data, detect spam and provide basic service functionality. Google Analytics 4 does not provide raw IP addresses to Thanh Tam in Analytics reports, and Google states that raw IP addresses are discarded after use.
Where Google Analytics is linked to Google Ads, encrypted information may be processed in accordance with the Google Ads configuration.
Google Tag Manager manages website tags. The data actually collected depends on the tags configured within the Google Tag Manager container.
5.4. Enhanced conversions
Google for WooCommerce may use Google Ads enhanced conversions to support advertising-conversion measurement.
When a purchase conversion occurs, customer-provided information such as an email address, telephone number, name or address may be:
- Normalised;
- Hashed using the one-way SHA-256 algorithm;
- Sent to Google in hashed form;
- Matched against signed-in Google Accounts to support advertising-conversion measurement.
Google does not receive this information in plain text through enhanced conversions where the implementation operates correctly. Hashed data nevertheless remains information that must be protected and may be used only for the disclosed measurement purpose.
Symptoms, prescription information, health notes and detailed order notes must not intentionally be sent as Google Analytics or enhanced-conversion parameters.
5.5. BetterLinks and tracked links
When you select a link configured for tracking through BetterLinks, the system may record:
- IP address;
- Click time;
- URL, host and path;
- Referring page;
- Browser, operating system and device;
- Language;
- Visitor ID;
- Query parameters;
- Bot-detection information.
Not every link on our websites is a tracked link.
5.6. OneSignal and web push
The OneSignal Web SDK may use:
- IndexedDB named
ONE_SIGNAL_SDK_DB; - Local Storage identifiers such as
os_pageViews,isOptedOutandisPushNotificationsEnabled; - Session Storage identifiers such as
onesignal-pageview-countandONESIGNAL_HTTP_PROMPT_SHOWN; - A service worker;
- Push tokens and Subscription IDs.
These technologies manage permission prompts, subscription state and notification delivery.
You may revoke web push permission through your browser settings. Clearing all website data may also remove the web push subscription.
5.7. Email pixels and tracked links
Transactional or customer-care emails may contain:
- A transparent 1 x 1 pixel that records an email open;
- Redirect links that record a click;
- A token associated with the message.
You may restrict tracking pixels by disabling automatic image loading in your email application. Selecting a tracked link may still be recorded.
5.8. Caching
WP Super Cache creates temporary HTML copies to improve website speed and reduce server load. The current maximum cache time is approximately 30 minutes.
Caching is not intended to create a separate advertising profile. A request that creates or receives a cached page may nevertheless appear in server or security logs.
Account, cart, checkout and personalised pages should be excluded from public caching where appropriate.
6. Purposes of processing
We may process personal data to:
- Operate and maintain our websites;
- Create and administer accounts;
- Remember language selection;
- Maintain the cart and purchase session;
- Receive, confirm and fulfil orders;
- Prepare, package and deliver products;
- Confirm payment;
- Provide order tracking;
- Send order-status notifications;
- Handle returns, feedback and complaints;
- Send a requested repurchase reminder;
- Send web push or marketing where appropriate consent exists;
- Record comments and ratings;
- Prevent spam, repeated ratings and fraud;
- Measure traffic, events and conversions;
- Evaluate content and advertising performance;
- Segment contacts within the CRM;
- Send transactional and customer-care email;
- Measure email opens and link clicks;
- Detect errors, unauthorised access and unusual activity;
- Back up and restore systems;
- Create invoices, records and reports;
- Comply with tax, accounting, e-commerce and consumer-protection obligations;
- Resolve disputes;
- Respond to lawful requests from competent authorities.
7. Consent and grounds for processing
Depending on the circumstances, processing may be based on:
- Your request to enter into or perform a transaction;
- An agreement between you and Thanh Tam;
- Your clear and verifiable consent;
- A legal obligation;
- System security, fraud prevention or the protection of lawful rights and interests;
- Another circumstance in which processing without consent is permitted by law.
The following choices are treated separately where applicable:
- Receiving order confirmation and status emails;
- Receiving advertising email;
- Receiving advertising messages;
- Receiving web push;
- Receiving repurchase or medicine-running-out reminders;
- Allowing a review to be redirected to or shared through Google;
- Permitting health-related processing beyond what is necessary for a specific request.
Providing an email address for an order does not by itself constitute consent to advertising email.
You are not required to consent to marketing or web push in order to place an order.
8. Recipients and service providers
Where necessary, data may be processed by or disclosed to:
- Authorised Thanh Tam personnel;
- Hosting, server, domain, backup and security providers;
- Google services, including Google Analytics, Google Tag Manager, Google Ads, Google Site Kit, Merchant Center and Google for WooCommerce;
- OneSignal;
- Email, SMTP and mail-infrastructure providers;
- Banks, digital wallets and payment providers;
- Carriers;
- Software and technical-support providers;
- Accountants, auditors or legal advisers;
- Competent authorities;
- A lawful transferee following a reorganisation or transfer of business activities.
Service providers may access data only to the extent required for the relevant service and are subject to applicable security and confidentiality obligations.
We do not sell personal data.
9. International personal data transfers
Google, OneSignal and certain infrastructure providers may process or store data on systems located outside Vietnam.
Transferred information may include:
- Analytics and advertising information;
- Cookies and online identifiers;
- IP or approximate-location information;
- Device and browser information;
- Push tokens and Subscription IDs;
- Hashed conversion information;
- Email or notification delivery logs.
Where an international transfer occurs, we apply measures and procedures required by Vietnamese law, which may include purpose limitation, recipient assessment, security controls and required documentation.
10. Data retention
Retention depends on the purpose, type of data and applicable legal obligations:
- Session cookies commonly expire when the browser session ends;
- The default WooCommerce session cookie may remain for approximately two days;
- The current HTML cache period is approximately 30 minutes;
- Article-rating Local Storage remains until the user clears website data;
- Order, invoice and transaction records are retained for the period required for accounting, tax, warranty, complaint and dispute purposes;
- Account information is retained while the account is active and for a reasonable period following closure;
- CRM and customer-care history is retained for as long as reasonably necessary to fulfil transactions, provide support or carry out a consented purpose;
- Repurchase-reminder data is retained until the reminder is completed, cancelled or no longer required;
- Marketing information is retained until consent is withdrawn, the user unsubscribes or the information is no longer used;
- OneSignal information is retained until the subscription is removed or in accordance with OneSignal’s retention practices;
- Analytics information is retained in accordance with the Google Analytics account configuration;
- Security logs, IP information, IP hashes, user-agent information and technical events are retained for as long as reasonably necessary to investigate errors, prevent fraud and protect systems;
- Backups may remain for an additional period before being overwritten under the backup cycle.
Where there is no remaining lawful basis, the data will be deleted, destroyed, de-identified or access-restricted, unless continued retention is required by law.
11. Data security
Security measures may include:
- HTTPS connections;
- Account access controls;
- Password hashing;
- Hashing of selected tokens, IP information or identifiers;
- Login limits;
- Administrative logs;
- Firewalls and unusual-access controls;
- Backups;
- WordPress, theme and plugin updates;
- Restrictions on access to customer information;
- Protection of secrets, tokens and integration keys;
- Vulnerability and incident review.
Not every database field is separately encrypted. Operational information such as a customer’s name, email address, telephone number, address and order content may be stored in a form readable by authorised systems and is protected through access controls, server security and operational safeguards.
No system can be guaranteed to be completely secure. Where an incident may affect users, we will investigate, mitigate the impact and make notifications required by applicable law.
12. User rights
To the extent permitted by law, users may have the right to:
- Be informed about processing;
- Give or refuse consent;
- Withdraw consent;
- Request access;
- Request a copy of data;
- Request correction;
- Request deletion or destruction;
- Request restriction of processing;
- Object to marketing;
- Unsubscribe from email or web push;
- Submit a complaint or request assistance from a competent authority;
- Claim compensation for legally recognised loss;
- Protect their own lawful rights and interests.
Withdrawal does not affect the lawfulness of processing completed before the withdrawal.
A deletion or restriction request may not be fully granted where information must be retained to:
- Complete an order;
- Meet tax or accounting obligations;
- Resolve a dispute;
- Prevent fraud;
- Protect lawful rights and interests;
- Comply with a request from a competent authority.
13. Submitting a personal data request
Requests may be submitted to:
Email: hi@hotro.nhathuocthanhtam.com Address: 119 Trieu Quang Phuc Street, Cho Lon Ward, Ho Chi Minh City, Vietnam Contact page: https://nhathuocthanhtam.com/en/contact-us/
A request should state:
- Your full name;
- The email address or telephone number previously used;
- The relevant order number or account, where applicable;
- The type of request;
- The information to be accessed, corrected or deleted.
We may carry out reasonable verification to prevent unauthorised access or deletion.
14. Web push, email and marketing choices
Users may:
- Select an unsubscribe link in an email;
- Disable web push through browser settings;
- Revoke the website’s notification permission;
- Clear cookies and website data;
- Contact us to withdraw a marketing choice or repurchase reminder.
Opting out of marketing does not prevent messages required for orders, payment, delivery, security or support.
15. Order-tracking link security
An order-tracking URL may contain a token unique to the order. A person who obtains the URL or token may be able to view certain order-status information.
Users should:
- Not publish an order-tracking URL;
- Not send the URL to an unrelated person;
- Not place the URL in a public comment or social-media post;
- Contact Thanh Tam if they believe the URL has been disclosed.
16. Children’s personal data
Our purchasing and account functions are not designed for independent use by children under 16 without supervision by a parent or legal representative.
Where information concerning a child is provided, the representative is responsible for:
- Providing only necessary information;
- Ensuring appropriate authority and consent;
- Supervising the child’s use of the website;
- Avoiding public disclosure of the child’s health information or private life.
We may request verification of representative consent and delete data that we reasonably determine was collected improperly.
17. Third-party links and services
Our websites may contain links to carriers, payment services, social networks, maps, Google Reviews or other websites.
Those parties maintain their own privacy policies and collection practices. When you leave a Thanh Tam website and provide information directly to a third party, that party’s privacy policy applies.
18. Managing cookies and browser data
Users may manage browser data by:
- Blocking or deleting cookies;
- Blocking third-party cookies;
- Clearing Local Storage, Session Storage and IndexedDB;
- Disabling automatic image loading in email;
- Revoking web push permission;
- Using the website’s cookie-preference tool when provided.
Clearing website data may remove the cart, login status, language selection, saved rating status and web push subscription.
19. Changes to this Policy
We may update this Policy to reflect changes in law, features, plugins, providers or business activities.
The updated version will be published at:
Where a change introduces a new purpose requiring consent, an appropriate notice and consent request will be provided.
20. Language
This Policy is available in Vietnamese and English. The English version is provided for international users and for convenience.
In the event of a difference in interpretation, the Vietnamese version prevails to the extent permitted by law.
Updated on July 23, 2026.
This version is effective as of July 23, 2026.
