Chính sách bảo mật
Cập nhật lần cuối: 26/08/2026
TT01 cam kết bảo vệ dữ liệu cá nhân và workflow của bạn. Chính sách này mô tả chúng tôi thu thập, sử dụng và bảo vệ dữ liệu như thế nào.
1. Dữ liệu chúng tôi thu thập
1.1 Dữ liệu bạn cung cấp trực tiếp
- Đăng ký tài khoản: họ tên, email, mật khẩu (đã hash với bcrypt), tên công ty (tuỳ chọn).
- Test cases & workflows: JSON workflow bạn tạo qua builder.
- Test run logs: kết quả chạy test, nhật ký thực thi, screenshot (nếu bật).
- Thanh toán: giao dịch PayOS (số tiền, plan, thời gian). Chúng tôi KHÔNG lưu thông tin thẻ - PayOS xử lý trực tiếp.
1.2 Dữ liệu tự động thu thập
- Log truy cập: IP, User-Agent, timestamp các request - phục vụ debug, security audit, abuse detection.
- Cookies: session cookie (xác thực) + remember-me cookie (tuỳ chọn khi user check "Ghi nhớ").
- Telemetry tổng hợp: số test cases, số runs/tháng - để tính quota và stats. Dạng aggregate, không tracking hành vi cá nhân.
Chúng tôi KHÔNG dùng analytics bên thứ ba (Google Analytics, Facebook Pixel, v.v.) trên CMS sau khi đăng nhập.
2. Cách chúng tôi sử dụng dữ liệu
- Cung cấp dịch vụ: lưu trữ test case, chạy test qua API, hiển thị run history.
- Xác thực: kiểm tra email/mật khẩu khi đăng nhập, sinh remember-me token.
- Thanh toán: gửi giao dịch tới PayOS, kích hoạt plan sau khi thanh toán thành công.
- Hỗ trợ: trả lời email/ticket support khi bạn liên hệ.
- Bảo mật: phát hiện bất thường, chặn brute-force, audit log.
3. Chúng tôi KHÔNG làm
- KHÔNG bán dữ liệu của bạn cho bất kỳ bên thứ ba nào.
- KHÔNG đọc test case của user một cách tự động hoá - workspace cô lập.
- KHÔNG training AI trên test workflow / log của bạn.
- KHÔNG track hành vi cá nhân (mouse movements, click heatmaps) trên CMS.
- KHÔNG gửi email marketing nếu bạn không opt-in.
4. Chia sẻ với bên thứ ba
Chúng tôi chỉ chia sẻ dữ liệu trong các trường hợp sau:
- PayOS: orderCode, amount, email/tên người mua (chỉ khi thanh toán) - phục vụ thanh toán.
- Hostinger: hạ tầng lưu trữ - Hostinger là data processor, không truy cập dữ liệu ứng dụng.
- Theo yêu cầu pháp luật: khi có lệnh từ cơ quan có thẩm quyền tại Việt Nam.
5. Bảo mật kỹ thuật
- HTTPS mọi trang - TLS 1.3.
- Mật khẩu hash với bcrypt cost factor 10.
- Cookie httpOnly, secure, sameSite=lax.
- CSRF protection cho mọi form POST.
- Per-user isolation ở tầng query - admin nền tảng cũng không bypass.
- Backup DB hàng ngày, lưu 30 ngày.
- Audit log mọi truy cập admin tới DB (giới hạn nội bộ).
6. Cookies
TT01 dùng cookies tối thiểu:
autotest_tt01_session- session cookie xác thực user đang đăng nhập. Hết hạn khi đóng browser hoặc sau 120 phút.XSRF-TOKEN- chống CSRF.remember_*- chỉ set khi bạn check "Ghi nhớ đăng nhập". Hết hạn 5 năm.
Chúng tôi KHÔNG dùng cookies tracking bên thứ ba.
7. Quyền của bạn
Theo Nghị định 13/2023/NĐ-CP về bảo vệ dữ liệu cá nhân tại Việt Nam, bạn có quyền:
- Xem dữ liệu của mình - yêu cầu export.
- Sửa dữ liệu sai - qua trang Settings hoặc support.
- Xoá tài khoản - dữ liệu xoá vĩnh viễn sau 30 ngày grace period.
- Phản đối xử lý dữ liệu cho mục đích cụ thể.
- Khiếu nại với cơ quan bảo vệ dữ liệu.
Gửi yêu cầu: privacy@goseedup.com
8. Thời gian lưu trữ
| Loại dữ liệu | Thời gian lưu |
|---|---|
| Tài khoản & workspace | Đến khi user xoá + 30 ngày grace |
| Test cases & workflow | Giữ song song với account |
| Run logs (Solo plan) | 90 ngày |
| Run logs (Team/Business) | 1 năm - không giới hạn |
| Subscription/payment records | Vĩnh viễn (yêu cầu kế toán) |
| Server access log | 30 ngày |
| Laravel error log | 7 ngày |
9. Trẻ em dưới 16 tuổi
TT01 không nhằm phục vụ trẻ em dưới 16 tuổi. Chúng tôi không cố ý thu thập dữ liệu của trẻ em. Nếu phụ huynh phát hiện con em mình đã đăng ký, vui lòng liên hệ chúng tôi để xoá account.
10. Thay đổi chính sách
Chính sách có thể được cập nhật. Thay đổi quan trọng (ảnh hưởng cách xử lý dữ liệu) sẽ được thông báo qua email ít nhất 14 ngày trước khi có hiệu lực.
11. Liên hệ
Câu hỏi về bảo mật: privacy@goseedup.com
Báo cáo lỗ hổng bảo mật: security@goseedup.com
TT01 is committed to protecting your personal data and workflows. This policy explains how we collect, use, and protect your information.
1. Data we collect
1.1 Data you provide directly
- Account registration: full name, email, password (hashed with bcrypt), and company name (optional).
- Test cases & workflows: JSON workflows you create with the builder.
- Test run logs: test results, execution logs, and screenshots (when enabled).
- Payments: PayOS transaction details (amount, plan, and time). We do not store card information; PayOS processes it directly.
1.2 Data collected automatically
- Access logs: IP address, User-Agent, and request timestamps for debugging, security audits, and abuse detection.
- Cookies: a session cookie (authentication) and an optional remember-me cookie.
- Aggregated telemetry: number of test cases and monthly runs to calculate quotas and statistics. This is aggregated and does not track individual behavior.
We do not use third-party analytics services (such as Google Analytics or Facebook Pixel) in the CMS after you sign in.
2. How we use data
- Provide the service: store test cases, run tests through the API, and show run history.
- Authenticate users: verify email and password at sign-in and issue remember-me tokens.
- Process payments: send transactions to PayOS and activate a plan after successful payment.
- Provide support: respond to support emails or tickets when you contact us.
- Maintain security: detect unusual activity, prevent brute-force attacks, and keep audit logs.
3. What we do not do
- We do not sell your data to any third party.
- We do not automatically read users' test cases; workspaces are isolated.
- We do not train AI on your test workflows or logs.
- We do not track individual behavior (such as mouse movements or click heatmaps) in the CMS.
- We do not send marketing emails unless you opt in.
4. Sharing with third parties
We share data only in the following circumstances:
- PayOS: order code, amount, and buyer email/name (only for payments) to process payment.
- Hostinger: hosting infrastructure. Hostinger acts as a data processor and does not access application data.
- Legal requirements: when required by an order from a competent authority in Vietnam.
5. Technical safeguards
- HTTPS on every page, using TLS 1.3.
- Passwords hashed with bcrypt, cost factor 10.
- Cookies configured as httpOnly, secure, and sameSite=lax.
- CSRF protection for every POST form.
- Per-user isolation at the query layer; even platform administrators cannot bypass it.
- Backups of the database daily, retained for 30 days.
- Audit logs for administrator access to the database (internally limited).
6. Cookies
TT01 uses only the following essential cookies:
autotest_tt01_session— authenticates the signed-in user. It expires when the browser closes or after 120 minutes.XSRF-TOKEN— protects against CSRF.remember_*— set only when you select “Remember me”; it expires after 5 years.
We do not use third-party tracking cookies.
7. Your rights
Under Vietnam's Decree 13/2023/ND-CP on personal data protection, you have the right to:
- Access your data by requesting an export.
- Correct inaccurate data through Settings or support.
- Delete your account; data is permanently deleted after a 30-day grace period.
- Object to processing of data for a particular purpose.
- Lodge a complaint with the data protection authority.
Send requests to privacy@goseedup.com.
8. Retention periods
| Data type | Retention period |
|---|---|
| Account & workspace | Until deletion by the user, plus a 30-day grace period |
| Test cases & workflows | Retained with the account |
| Run logs (Solo plan) | 90 days |
| Run logs (Team/Business) | 1 year — unlimited |
| Subscription/payment records | Indefinitely (accounting requirement) |
| Server access logs | 30 days |
| Laravel error logs | 7 days |
9. Children under 16
TT01 is not intended for children under 16. We do not knowingly collect children's data. If a parent discovers that their child has registered, please contact us so that we can delete the account.
10. Changes to this policy
We may update this policy. Material changes that affect how data is handled will be announced by email at least 14 days before they take effect.
11. Contact
Privacy questions: privacy@goseedup.com
Report a security vulnerability: security@goseedup.com