Privacy Policy

Last updated: 07/09/2026

This policy explains how Haru — a software product at haru.com.vn operated by Hộ kinh doanh Nguyễn Đức Nam (business household, registration no. 8412496920-001) ("we") — collects, uses, shares and deletes personal data when you use our AI assistant for Facebook Page messages (Messenger) and Meta ads management. It applies to shop owners (Haru account holders) and to people who message a Page (the shop's customers). It follows Vietnam's Decree 13/2023/ND-CP on personal data protection and the Meta Platform Terms.

1. Data controller and contact

  • Entity: Hộ kinh doanh Nguyễn Đức Nam — representative Nguyễn Đức Nam.
  • Address: Cao Bat Lu Hamlet, Nam Cao Commune, Kien Xuong District, Thai Binh Province, Vietnam.
  • Privacy email: lienhe@haru.com.vn · Phone: +84966586185.

2. Data we collect

  • Haru account: email, display name, password (scrypt-hashed — never stored in plain text), role, creation time.
  • Data from Meta when you log in with Facebook: exactly what the permissions in section 3 grant, including the access token issued by Meta.
  • Page message data (when you enable a Page): messages customers send and replies sent (including AI-drafted ones), the sender's public name and profile picture, labels/notes you add; order details a customer voluntarily provides in the conversation (name, phone, address, products).
  • Data you enter: product catalog, AI context, message templates, automation rules; AI API keys if you connect your own.
  • Technical data: IP address, request time and type (server logs), login session cookie.
  • Contact form: name, phone, email, shop name and the message you send.

3. Meta permissions we request and why

Haru requests only the permissions below through the official Facebook Login for Business dialog. You can review, limit or revoke them at any time in Facebook Settings › Business Integrations.

PermissionData receivedSole purpose
public_profile, emailYour Facebook account's name, profile picture and emailShow who is connected; match your Haru account to your Facebook account
pages_show_listList of Pages you manageLet you choose which Pages to use with Haru
pages_manage_metadataSubscribe the Page to webhooks and read Page settingsReceive new messages in real time for Pages you enable
pages_messagingMessages sent to your Page; sender's public name and picture; sending repliesShow the inbox, let AI/staff reply, create orders on customer request
pages_read_engagementBasic Page info (name, picture, category)Display the correct Page in the connection list
pages_utility_messagingRegister and send utility message templatesSend order updates to customers after 24 hours using Meta-approved templates

If you enable the optional Meta Ads module, Haru additionally requests:

PermissionData receivedSole purpose
ads_read, ads_managementCampaign metrics and structure of the ad accounts you choose; pause/resume, budget, duplicate actionsReports and automation rules you configure
business_managementYour Business Manager list and assetsSelect the right ad account/Page under your business

4. How we use data

  • Show your Page inbox so you or the AI can reply; create and manage orders at the customer's request.
  • Send conversation content to your chosen AI provider solely to generate a reply for that conversation.
  • Send utility templates (order updates) after the 24-hour window when an order changes status.
  • Show ad reports and perform the actions you request on your own ad accounts.
  • Security, abuse prevention, troubleshooting; support when you ask for it.

We do not sell, rent, or use message data or data received from Meta for advertising, profiling, or training AI models.

5. Who we share data with

  • Meta Platforms: to read/send messages and ad metrics as you request, under the Meta Platform Terms.
  • The AI provider you choose (DeepSeek, OpenAI, Google, Anthropic, xAI, Moonshot, OpenRouter): receives conversation content and shop context to generate replies. These providers are located outside Vietnam and process data under their own policies.
  • Shipping carriers: only if you enable the integration, to deliver orders.
  • Authorities: when required by law.

As a Tech Provider under the Meta Platform Terms, we process Meta data only to serve the specific customer (shop owner) who connected it; each customer's data is stored separately and never used for another customer.

6. Where data is stored and international transfers

Haru servers are located in Singapore (Vultr). Transfers outside Vietnam (hosting and AI providers) follow the requirements of Decree 13/2023/ND-CP; data is encrypted in transit (HTTPS) and at rest.

7. Security

  • All connections over HTTPS (Let's Encrypt certificate, HSTS).
  • Data store (Page tokens, API keys, conversations) encrypted with AES-256-GCM at rest; passwords hashed with scrypt.
  • Login sessions use signed httpOnly, Secure cookies; failed logins are rate-limited.
  • Webhooks from Meta are processed only with a valid X-Hub-Signature-256 signature.
  • Tokens and API keys are used server-side only and never sent to the browser; each account's data is isolated.

8. Retention

  • Meta access tokens: until you disconnect, remove the app on Facebook, or the token expires.
  • Messages, orders, catalog, context: until you delete the Page/account or request deletion.
  • Sender profile pictures: not stored permanently; loaded from Facebook for display.
  • Technical logs: kept briefly for troubleshooting, then deleted.

9. Your rights

Under Decree 13/2023/ND-CP you have the rights to be informed, to consent, to access, to rectify, to withdraw consent, to erase, to restrict and object to processing, and to complain. How to exercise them:

  • Disconnect Facebook on the Connections page → the token is deleted immediately.
  • Remove Haru in your Facebook Settings → Meta sends a deletion request to our callback; related Facebook data is deleted automatically and you receive a confirmation code.
  • Email lienhe@haru.com.vn with the subject "Personal data request" — we respond and complete deletion within 72 hours of a valid request. See the Data Deletion Instructions.

10. People who message a Page (the shop's customers)

The shop owner decides the purposes of processing their customers' data; Haru processes it on the shop owner's behalf. If you messaged a Page that uses Haru and want your data deleted, contact that Page or email lienhe@haru.com.vn; we delete within 72 hours and notify the shop owner.

11. Cookies and browser storage

Haru uses only a login session cookie (strictly necessary) and browser storage for display preferences. No third-party advertising or tracking cookies.

12. Children

The service is for shop owners aged 18 or older. We do not knowingly collect children's data; if discovered, we delete it immediately.

13. Meta policy compliance

Our use of information received from Meta complies with the Meta Platform Terms and Developer Policies. We have registered a Data Deletion Callback with Meta and complete the annual Data Use Checkup.

14. Changes

Changes are posted on this page with a new date; material changes are announced in the app. Questions: lienhe@haru.com.vn.

Chính sách quyền riêng tư — Haru