PRIVACY & DATA PROTECTION

Chính sách bảo mật của Venroy

This policy explains in clear language what data Venroys processes, why it is needed, and the choices and rights available to you.

Last updated: August 10, 2026Effective August 10, 2026Venroys OÜ · 17427636 · EE102991020
In short

Venroys OÜ is established in Estonia and is subject to the GDPR. Depending on the service, Venroys, an independent seller and a service provider may each have a separate role.

No raw card data

Card and payment details are processed securely by Stripe. Venroys does not store full card numbers or CVC codes.

Seller storefronts

A seller is responsible for its products, customer service and its own legal obligations. Venroys operates the technical infrastructure.

Choice and control

You can exercise privacy rights, stop marketing and manage non-essential cookies.

01

1. Ai chịu trách nhiệm xử lý?

Venroys OÜ (Công ty trách nhiệm hữu hạn tư nhân của Estonia)
Ngày đăng ký: 2 tháng 2 năm 2026 (Estonia)
Mã đăng ký: 17427636
Địa chỉ: Tornimäe tn 5, 10145 Tallinn, Estonia
Trang web: venroys.com
Ban quản lý: Constantino Aemilius Darshan Changoe
Hoạt động chính (EMTAK): 47711 - Bán lẻ quần áo tại các cửa hàng chuyên doanh
Email: info@venroys.com
Đối với các câu hỏi, yêu cầu hoặc khiếu nại liên quan đến quyền riêng tư, vui lòng liên hệ với chúng tôi qua địa chỉ email ở trên. Nếu chúng tôi chỉ định Cán bộ Bảo vệ Dữ liệu (DPO) khi cần thiết, thông tin liên hệ sẽ được công bố tại đây.

Founders: Constantino Aemilius Darshan Changoe and Muhammet Fatih Koçyigit

02

2. Dữ liệu cá nhân mà chúng tôi xử lý

Tùy thuộc vào cách bạn sử dụng Venroys (mua sắm, tạo tài khoản, liên hệ với chúng tôi hoặc bán hàng trên nền tảng), chúng tôi có thể xử lý các loại dữ liệu cá nhân sau:

LoạiVí dụ
Thông tin nhận dạng và liên hệTên, địa chỉ thanh toán/giao hàng, địa chỉ email, số điện thoại, ID tài khoản
Dữ liệu thanh toán và lập hóa đơnMã thông báo của nhà cung cấp thanh toán, ID giao dịch, chi tiết hóa đơn, chi tiết thanh toán (dành cho người bán)
Dữ liệu đơn đặt hàng và thực hiện đơn hàngCác mặt hàng đã đặt, số lượng, phương thức vận chuyển, trạng thái giao hàng, thông tin trả hàng/hoàn tiền.
Thông tin tài khoản và đăng nhậpTên người dùng/email, mật khẩu đã mã hóa, tùy chọn tài khoản, dấu thời gian đăng nhập
Dữ liệu liên lạc và đồng ýThông báo hỗ trợ, trạng thái đăng ký nhận bản tin, lựa chọn chấp thuận cookie
Thông số kỹ thuật và thiết bịĐịa chỉ IP, loại trình duyệt, thông tin thiết bị, nhật ký phiên, sự kiện bảo mật
Dữ liệu sử dụng và hành viSố trang đã xem, truy vấn tìm kiếm, số lần nhấp chuột, hành vi cuộn trang, số sản phẩm đã xem
Seller and verification dataBusiness details, representatives, date of birth, tax details, verification status and Stripe Connect account references
Storefront and content dataBrand name, domain, website content, product media, theme settings and published pages
Derived risk and trust signalsDelivery outcomes, refund and chargeback rates, policy status, suspicious activity and marketplace progress

Chúng tôi không cố ý thu thập các loại dữ liệu cá nhân đặc biệt (ví dụ: dữ liệu sức khỏe). Vui lòng không bao gồm thông tin cá nhân nhạy cảm trong phần ghi chú đơn hàng, tin nhắn hỗ trợ hoặc các trường văn bản tự do khác trừ khi thực sự cần thiết.

03

3. Mục đích và cơ sở pháp lý

Mục đíchCơ sở pháp lý (GDPR)Chi tiết
Tạo và xác thực tài khoảnThực hiện hợp đồng (Điều 6(1)(b))Để tạo tài khoản, cho phép bạn đăng nhập an toàn và duy trì tài khoản của bạn.
Xử lý đơn hàng, thanh toán và giao hàngThực hiện hợp đồng (Điều 6(1)(b))Để xử lý các giao dịch mua bán, xác nhận đơn hàng, sắp xếp vận chuyển và quản lý việc trả lại hàng hoặc hoàn tiền.
Hỗ trợ khách hàng và giao tiếp dịch vụLợi ích hợp pháp (Điều 6(1)(f))Để giải đáp thắc mắc, điều tra vấn đề và nâng cao chất lượng hỗ trợ.
Truyền thông tiếp thị và các chương trình khuyến mãiSự đồng ý (Điều 6(1)(a))Chỉ khi luật pháp yêu cầu và sau khi bạn đồng ý. Bạn có thể hủy đăng ký hoặc rút lại sự đồng ý bất cứ lúc nào.
Bảo mật, phòng chống gian lận và tính toàn vẹn của nền tảngLợi ích hợp pháp (Điều 6(1)(f)) và nghĩa vụ pháp lý (Điều 6(1)(c))Nhằm phát hiện hành vi lạm dụng, bảo mật tài khoản, ngăn chặn gian lận và tuân thủ các nghĩa vụ liên quan đến bảo mật.
Tuân thủ pháp luật, thuế và kế toánNghĩa vụ pháp lý (Điều 6(1)(c))Để đáp ứng các yêu cầu về kế toán, thuế, báo cáo và các quy định pháp luật khác.
Seller verification and payoutsContract, legal obligation and legitimate interestsTo onboard sellers, verify identity and business details, enable payouts and limit financial fraud.
Marketplace trust and policy administrationLegitimate interests and contractTo monitor seller performance, review marketplace applications and protect customers and the platform.
04

4. Platform, seller and storefront roles

  • Venroys is a controller for Venroys accounts, platform security, marketplace administration, platform fees, tax records and operation of our services.
  • For an independent seller storefront, the seller may be a separate controller for customer relationships, product information, fulfillment, returns and support. The seller's identity should be available in the relevant storefront or order information.
  • Where Venroys handles data only on a seller's instructions, we act as a processor under the applicable agreement. For certain services, including payments and legally required identity checks, Stripe may act as an independent controller.
05

5. Sources of personal data

  • Directly from you through registration, checkout, support, uploads or settings.
  • From sellers when they manage an order, return or customer request.
  • From payment, fulfillment, shipping, verification and fraud-prevention providers.
  • Automatically from devices, logs, cookies and security signals, depending on your choices.
06

4. Cookie và các công nghệ tương tự

Chúng tôi sử dụng cookie và các công nghệ tương tự để vận hành trang web, ghi nhớ tùy chọn của bạn, cải thiện hiệu suất và đo lường mức độ sử dụng. Chúng tôi yêu cầu sự chấp thuận đối với các cookie không thiết yếu khi luật pháp yêu cầu. Để biết thêm thông tin, vui lòng xem Chính sách Cookie của chúng tôi.
07

5. Chia sẻ với bên thứ ba

Chúng tôi chỉ chia sẻ dữ liệu cá nhân khi cần thiết, ví dụ như với:

  • Các nhà cung cấp dịch vụ thanh toán xử lý các khoản thanh toán, hoàn tiền và kiểm tra giao dịch liên quan.
  • Các đối tác vận chuyển và hậu cần để giao hàng và xử lý việc trả hàng.
  • Các nhà cung cấp dịch vụ lưu trữ, cơ sở hạ tầng, email và dịch vụ kỹ thuật hỗ trợ nền tảng này.
  • Các đối tác phân tích và tiếp thị (chỉ khi được phép và, nếu cần thiết, với sự đồng ý của bạn).
  • Các cơ quan công quyền, cơ quan quản lý hoặc cơ quan thực thi pháp luật mà chúng tôi có nghĩa vụ pháp lý phải tiết lộ thông tin.

Trong trường hợp bên thứ ba xử lý dữ liệu thay mặt chúng tôi, chúng tôi sử dụng các thỏa thuận xử lý dữ liệu khi cần thiết và hướng dẫn họ chỉ xử lý dữ liệu cá nhân cho các mục đích đã thỏa thuận.

08

8. Key service providers

ServiceRole and dataMore information
StripePayments, direct charges, seller verification, fraud prevention and payouts. Stripe receives data directly through secure payment and onboarding components.Stripe Privacy
PrintfulOptional product, fulfillment, shipping, tracking and return services. Name, address, contact and order data may be shared for fulfillment.Printful Privacy
Hosting and databaseCloud hosting, secure storage, backups, network delivery and operational logging.Contractually restricted providers
Email and communicationsTransactional messages, verification, order updates, support and consented marketing.Necessary contact and message data only

Specific vendors and subprocessors may change as our infrastructure changes. We assess providers before they process personal data.

09

9. International transfers

Some providers or their subprocessors are located outside the European Economic Area. Where the GDPR requires it, we rely on an adequacy decision, European Commission Standard Contractual Clauses or another valid safeguard. We assess supplementary organizational and technical measures where appropriate.

European Commission Standard Contractual Clauses
10

6. Lưu trữ dữ liệu

Danh mục dữ liệuThời gian lưu giữ
Hóa đơn và hồ sơ giao dịchAt least 7 years under applicable Estonian accounting and tax rules, calculated from the legally prescribed starting date
Dữ liệu tài khoản khách hàngTrong suốt thời gian tài khoản hoạt động và một khoảng thời gian giới hạn sau khi không hoạt động hoặc bị đóng.
hồ sơ về tùy chọn tiếp thị và sự đồng ýCho đến khi sự đồng ý bị thu hồi hoặc không còn cần thiết để chứng minh sự đồng ý nữa.
Dữ liệu bảo mật, nhật ký và phân tíchTrong một khoảng thời gian giới hạn phù hợp với mục đích bảo mật và phân tích.
Seller KYC and payout recordsWhile needed for the payment relationship and afterward as required for financial, anti-fraud and legal obligations; Stripe also applies its own retention periods
Order and fulfillment recordsAs needed for delivery, returns, disputes, warranties and applicable accounting and tax periods

After the applicable period, we delete or anonymize data unless it remains necessary for a legal claim, investigation, dispute or other legal obligation.

11

7. An ninh

Chúng tôi thực hiện các biện pháp kỹ thuật và tổ chức phù hợp để bảo vệ dữ liệu cá nhân, bao gồm:

  • Mã hóa trong quá trình truyền tải (HTTPS / TLS)
  • Mã hóa mật khẩu và kiểm soát xác thực an toàn
  • Kiểm soát truy cập và quyền hạn dựa trên vai trò
  • Các quy trình giám sát, sao lưu và bảo trì an ninh

No system is entirely risk-free. Protect your account with a unique password and two-factor authentication where available.

12

8. Quyền của bạn

Tùy thuộc vào địa điểm cư trú và luật pháp hiện hành, bạn có thể có quyền:

  • Yêu cầu quyền truy cập vào dữ liệu cá nhân mà chúng tôi đang lưu giữ về bạn.
  • Yêu cầu chỉnh sửa thông tin cá nhân không chính xác hoặc không đầy đủ.
  • Yêu cầu xóa dữ liệu cá nhân của bạn, nếu có thể.
  • Yêu cầu hạn chế xử lý dữ liệu hoặc phản đối một số hoạt động xử lý dữ liệu nhất định.
  • Bạn có thể rút lại sự đồng ý bất cứ lúc nào nếu việc xử lý dữ liệu dựa trên sự đồng ý của bạn.
  • Receive your data in a portable format where the right to data portability applies.
  • You may also complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or the supervisory authority where you usually live.

Send requests to info@venroys.com. We may request additional information to verify your identity. We normally respond within one month; the GDPR permits a reasoned extension for complex requests.

13

13. Fraud, trust and automated signals

Venroys uses security, fraud and performance indicators such as delivery outcomes, refunds, chargebacks, account age, policy incidents and verification status. These signals support risk management and marketplace review. Marketplace access is not automatically guaranteed by a score. Decisions with a material effect may be reviewed by a person, and you may contact us to request an explanation or review.

14

14. Security incidents

We investigate suspected personal-data breaches, limit their effects and notify the competent authority and affected people where legally required. Report suspected security issues to info@venroys.com without sending passwords or complete payment details.

15

15. Seller responsibilities

Sellers receiving personal data through Venroys must use it lawfully, securely and only for permitted business purposes. They may not use customer data for unsolicited marketing, sell it or disclose it outside necessary order and support processes. Sellers must provide their own privacy information where required and respond to data-subject requests for which they are responsible.

16

9. Người chưa thành niên

Venroys không dành cho trẻ em dưới độ tuổi được pháp luật hiện hành quy định phải tự nguyện đồng ý cho việc xử lý dữ liệu (ví dụ: 16 tuổi ở một số khu vực pháp lý). Chúng tôi không cố ý thu thập dữ liệu cá nhân từ trẻ em mà không có sự đồng ý cần thiết.

17

11. Những thay đổi đối với Chính sách Bảo mật này

Chúng tôi có thể cập nhật Chính sách Bảo mật này theo thời gian. Ngày "Cập nhật lần cuối" ở đầu trang cho biết thời điểm trang này được sửa đổi lần cuối. Nếu chúng tôi thực hiện những thay đổi quan trọng, chúng tôi có thể thông báo cho bạn thông qua trang web, email hoặc thông báo tài khoản nếu phù hợp.

18

12. Liên hệ

Nếu bạn có thắc mắc, lo ngại hoặc yêu cầu về Chính sách bảo mật này hoặc các hoạt động xử lý dữ liệu của chúng tôi, vui lòng liên hệ với chúng tôi theo địa chỉ:
Venroys OÜ
Tornimäe tn 5
10145 Tallinn
Estonia
Mã đăng ký: 17427636
Ban quản lý: Constantino Aemilius Darshan Changoe
Email: info@venroys.com
Trang web: venroys.com

Founders: Constantino Aemilius Darshan Changoe and Muhammet Fatih Koçyigit

info@venroys.com