Chính sách bảo mật — Tablir

Áp dụng cho ứng dụng Tablir Chủ quán và Tablir Nhân viên

Cập nhật lần cuối: 02/10/2026 · Đơn vị cung cấp: CÔNG TY TNHH IR TECH ("chúng tôi").

Tablir là nền tảng quản lý quán ăn/nhà hàng gồm hai ứng dụng: Tablir Chủ quán (dành cho chủ/quản lý/nhân sự) và Tablir Nhân viên (dành cho nhân viên). Chính sách này giải thích chúng tôi thu thập dữ liệu gì, vì sao, chia sẻ với ai, và quyền của bạn.

1. Dữ liệu chúng tôi thu thập

Nhóm dữ liệuVí dụMục đích
Tài khoảnHọ tên, email, số điện thoại, mật khẩu (được băm). Tài khoản nhân viên có thể do bạn tự đăng ký, hoặc do chủ quán tạo khi thêm hồ sơ nhân viên (chủ quán nhập email/số điện thoại của bạn). Nếu bạn đăng ký hoặc đăng nhập bằng Google/Apple: mã định danh tài khoản Google/Apple của bạn, gắn với tài khoản Tablir. Bản ghi đồng ý: phiên bản Điều khoản sử dụng và Chính sách bảo mật bạn đã đồng ý (theo ngày “Cập nhật lần cuối”), thời điểm, kênh (đăng ký, đăng ký bằng Google/Apple, hoặc hộp hỏi đồng ý), địa chỉ IP và trình duyệt/ứng dụng (user agent)Đăng nhập, bảo mật tài khoản, khôi phục mật khẩu qua email; nhận ra bạn ở lần đăng nhập bằng Google/Apple sau; chứng minh bạn đã đồng ý Điều khoản sử dụng và Chính sách bảo mật
Hồ sơ nhân sự (do chủ quán nhập)Ngày sinh, giới tính, địa chỉ, số CCCD, chức vụ, lương, liên hệ khẩn cấpQuản lý nhân sự, chấm công, tính lương của quán
Chấm công & vị tríMốc vào/hết ca; vị trí thiết bị lúc vào ca (để xác minh có mặt tại quán) và địa chỉ IP của máy lúc vào ca; toạ độ quánXác nhận nhân viên có mặt tại quán khi vào ca; tính phí giao hàng theo khoảng cách
ẢnhẢnh món ăn, logo quán, ảnh banner sự kiện, và ảnh chân dung nhân viên do chủ quán/quản lý tải lên; ảnh món do nhân viên có quyền thực đơn tải lên; ảnh chụp màn hình chủ quán gửi cho đội hỗ trợHiển thị trong thực đơn và cấu hình quán; giúp đội hỗ trợ xử lý yêu cầu
Đơn hàngMón, số bàn, tên và số điện thoại khách (bắt buộc với đơn đặt từ xa/giao tận nơi qua mini app Zalo; đơn khác thì nếu nhập), vị trí GPS của máy khách (đơn đặt từ xa/giao tận nơi, chỉ khi khách đồng ý), mã định danh Zalo của khách, trạng thái, thanh toán; đánh giá của khách qua mini app (điểm, nhận xét tự do) gắn với nhân viên phục vụVận hành bán hàng, báo cáo, quy đơn về người phục vụ; giao hàng (nhân viên quán xem vị trí và mở bằng Google Maps); bảng hiệu suất nhân viên (từ đánh giá của khách); chuẩn bị cho việc báo trạng thái đơn cho khách qua Zalo — tính năng này chưa hoạt động: hiện chưa gửi gì cho Zalo, mã định danh Zalo chỉ được thu và lưu kèm đơn để chuẩn bị
Cộng tác viên giới thiệuThông tin nhận tiền (ngân hàng, số tài khoản, chủ tài khoản); số giấy tờ tuỳ thân hoặc mã số thuế khi pháp luật yêu cầuChi trả hoa hồng giới thiệu và thực hiện nghĩa vụ thuế
Thiết bị & thông báoMã đẩy thông báo (FCM token), loại thiết bịGửi thông báo: đơn mới, đơn quá hạn, xin nghỉ và kết quả duyệt nghỉ, kết quả duyệt chấm công, ca bị từ chối, phiếu lương sẵn sàng, đánh giá được công bố, phiếu yêu cầu (tạo/duyệt), trả lời của đội hỗ trợ, nhắc hạn gói

2. Quyền trên thiết bị & lý do

3. Chia sẻ dữ liệu

Chúng tôi không bán dữ liệu cá nhân. Dữ liệu được xử lý bởi các nhà cung cấp hạ tầng để vận hành dịch vụ:

Trong một quán, dữ liệu nhân sự chỉ hiển thị cho chủ quán/quản lý/nhân sự có quyền tương ứng; nhân viên chỉ thấy dữ liệu của chính mình và công việc được giao.

🔴 Chuyển thông tin giao hàng cho người giao hàng. Với đơn giao tận nơi, nhân viên của quán có thể chủ động bấm nút gửi để chuyển cho người giao hàng: mã đơn, tên khách, số điện thoại khách và một liên kết bản đồ tới địa chỉ giao. Tin nhắn đi qua khay chia sẻ của hệ điều hành, nên bên nhận do quán chọn — một ứng dụng nhắn tin bất kỳ. Chúng tôi không kiểm soát ứng dụng đó, và không kiểm soát điều gì xảy ra sau khi tin nhắn rời khỏi máy của nhân viên. Mở liên kết bản đồ cũng có nghĩa Google nhận địa chỉ giao hàng của đơn đó.
Không có bộ phân tích của bên thứ ba. Ứng dụng không tích hợp Google Analytics for Firebase hay bất kỳ bộ phân tích nào khác, và không xin định danh quảng cáo (Advertising ID). Chúng tôi không theo dõi bạn giữa các ứng dụng, và không dựng hồ sơ quảng cáo.

⚠️ Nhưng điều đó không có nghĩa là không dữ liệu nào rời thiết bị. Năm điều cụ thể, nói rõ vì chúng dễ bị hiểu nhẹ: Xem bảng ở mục 1 và danh sách ở trên để biết chính xác thứ gì đi đâu.
Và về chính trang web này. Các trang công khai của chúng tôi — kể cả trang bạn đang đọc — tải phông chữ Be Vietnam Pro từ Google Fonts. Nghĩa là khi bạn mở trang này, trình duyệt của bạn gửi địa chỉ IP, loại trình duyệt và tên miền của trang đang mở (irtech.vn — không phải đường dẫn trang cụ thể) sang máy chủ của Google. Chúng tôi nói ra vì đây là điều xảy ra trước khi bạn kịp đọc hết chính sách. Bản điện thoại của hai ứng dụng thì không như vậy: chúng đóng gói phông sẵn trong máy và không gọi ra máy chủ phông nào. Bản web của hai ứng dụng (owner.tablir.irtech.vn, staff.tablir.irtech.vn) thì có gọi ra Google: khi mở, trình duyệt tải thành phần hiển thị (CanvasKit) và thư viện Firebase từ máy chủ của Google (gstatic.com), nên địa chỉ IP của bạn đi tới Google.

4. Lưu trữ & xoá

Nơi lưu trữ dữ liệu

Máy chủ và cơ sở dữ liệu chính của chúng tôi — nơi giữ dữ liệu quán, nhân sự và đơn hàng — do một nhà cung cấp hạ tầng tại Việt Nam vận hành.

Sao lưu. Bản sao lưu cơ sở dữ liệu được tạo tự động mỗi ngày và ghi ra đĩa của chính máy chủ đó; chúng tôi giữ 10 bản gần nhất. Hiện không có bản sao nào được đẩy ra ngoài máy chủ. Vì vậy dữ liệu đã xoá khỏi hệ thống đang chạy vẫn còn trong các bản sao lưu này tối đa khoảng 10 ngày, rồi bị ghi đè.

⚠️ Nhưng không phải mọi dữ liệu đều nằm trong Việt Nam. Những dịch vụ nêu ở mục 3 là dịch vụ nước ngoài — Google (ảnh, thông báo đẩy, đăng nhập), Apple (đăng nhập), Open-Meteo (thời tiết) — nên phần dữ liệu gửi cho họ được xử lý ngoài Việt Nam. PayOS và Zalo là doanh nghiệp Việt Nam. Chúng tôi cố ý không chép lại danh sách ấy ở đây: mục 3 là bản có hiệu lực, và hai bản danh sách thì sẽ có ngày lệch nhau.

Giữ bao lâu, và xoá thế nào

Dữ liệu được giữ trong thời gian tài khoản/quán còn hoạt động. Bạn có thể tự yêu cầu xoá bất cứ lúc nào — các bước cụ thể, kể cả khi bạn đã gỡ ứng dụng, nằm ở trang Hướng dẫn xoá tài khoản & dữ liệu.

Trường hợpChuyện gì xảy ra
Chủ quán xoá quán Xoá luôn cả quán: đóng băng 60 ngày (khôi phục được bằng nút Khôi phục quán trong ứng dụng), sau đó quán và dữ liệu của quán bị xoá vĩnh viễn: đơn hàng, thanh toán, phiếu lương, hồ sơ nhân sự, hợp đồng, và chỗ làm của mọi nhân viên tại quán (chỗ làm bị xoá cùng quán khi hết thời gian đóng băng). Vẫn còn sau khi quán bị xoá: thông báo giao dịch PayOS (mục 3); bản ghi các yêu cầu kết thúc chỗ làm (tên nhân viên, lý do, ghi chú của chủ quán); nếu quán đến qua cộng tác viên — hồ sơ giới thiệu (tên quán, email và số điện thoại chủ quán, địa chỉ IP và trình duyệt lúc đăng ký) và sổ hoa hồng; hội thoại với đội hỗ trợ (phiên đã đóng bị xoá 7 ngày sau khi đóng, phiên chưa đóng thì còn); và nhật ký thao tác của đội nền tảng IR Tech (ai làm gì, trên quán/người nào, kèm tên). Việc này không xoá tài khoản Tablir (email, mật khẩu) của chủ quán hay của nhân viên. ⚠️ Chủ quán hãy tự lưu một bản chứng từ của quán (in, chụp màn hình…) trước khi xoá quán. Ảnh trong kho của Google có thể vẫn còn — xem mục 3.
Nhân viên gửi yêu cầu và chủ quán duyệt Chỗ làm tại quán bị khoá ngay khi duyệt, rồi xoá hẳn sau 90 ngày. Việc này không xoá tài khoản Tablir của bạn — email và mật khẩu vẫn còn, và bạn vẫn đăng nhập được bằng email và mật khẩu, hoặc bằng Google/Apple nếu tài khoản ấy dùng cùng email (Quên mật khẩu có thể chưa dùng được khi bạn không còn chỗ làm ở quán nào — hãy giữ mật khẩu). ⚠️ Từ lúc bị khoá bạn không mở lại phiếu lương trong ứng dụng được nữa — hãy lưu phiếu lương TRƯỚC khi gửi yêu cầu. Bản ghi yêu cầu của bạn (tên, lý do bạn gõ, ghi chú của chủ quán, kết quả) được giữ làm vết kiểm toán và không bị xoá — kể cả sau khi chỗ làm, quán hoặc tài khoản Tablir của bạn bị xoá.
Bạn xoá tài khoản Tablir của chính mình Email và mật khẩu đăng nhập bị xoá ngay, và mọi chỗ làm của bạn khép lại cùng lúc. Liên kết với tài khoản Google/Apple (mã định danh) cũng bị xoá cùng lúc. Bản ghi đồng ý của bạn được giữ làm bằng chứng, nhưng địa chỉ IP và trình duyệt/ứng dụng (user agent) trong đó bị xoá ngay (dòng “Bản ghi đồng ý” bên dưới). Không ai duyệt và không hoàn tác được. Nhưng bản sao email, số điện thoại (cùng địa chỉ, ngày sinh, số giấy tờ…) trong hồ sơ nhân sự của từng quán vẫn còn cho tới khi quán đó bị xoá; nếu bạn là chủ quán đến qua cộng tác viên, hồ sơ giới thiệu vẫn giữ email và số điện thoại của bạn (dòng đầu). Chứng từ của quán vẫn giữ theo các dòng dưới đây. Nếu bạn là chủ duy nhất của một quán đang hoạt động, phải xoá quán trước. Quán đã đóng băng thì xoá tài khoản được ngay — nhưng khi ấy không còn ai bấm Khôi phục quán được nữa; muốn giữ đường lùi, hãy chờ hết thời gian đóng băng rồi mới xoá tài khoản.
Nhân viên nghỉ việc (không gửi yêu cầu) Chỗ làm tại quán bị khoá ngay khi chủ quán cho bạn nghỉ việc, và xoá hẳn sau 90 ngày. Tài khoản Tablir của bạn không bị xoá — email và mật khẩu vẫn còn, bạn vẫn đăng nhập được bằng email và mật khẩu (thành người chưa vào quán nào), hoặc bằng Google/Apple nếu tài khoản ấy dùng cùng email; Quên mật khẩu có thể chưa dùng được khi bạn không còn chỗ làm ở quán nào — hãy giữ mật khẩu. ⚠️ Từ lúc bị khoá bạn không mở lại phiếu lương của quán ấy trong ứng dụng được nữa — hãy lưu phiếu lương TRƯỚC khi nghỉ.
Chủ quán tạm khoá đăng nhập của bạn (bạn vẫn còn làm) Chủ quán có thể mở lại. Nếu chủ quán không mở lại trong 90 ngày, chỗ làm tại quán bị xoá hẳn như khi nghỉ việc (dòng trên).
Hồ sơ nhân sự (hợp đồng, CCCD, lương) Do quán quản lý, và bị xoá cùng quán (dòng đầu). Hệ thống không giữ riêng hồ sơ này sau khi quán bị xoá: nghĩa vụ lưu hồ sơ theo pháp luật lao động thuộc về chủ quán — hãy tự lưu một bản (in, chụp màn hình…) trước khi xoá quán.
Chứng từ kinh doanh (đơn hàng, phiếu lương, sổ hoa hồng cộng tác viên) Đơn hàng, thanh toán, phiếu lương: giữ trong khi quán còn hoạt động, với tên đã được chụp lại tại thời điểm giao dịch để bản ghi cũ vẫn đọc được, và bị xoá cùng quán (dòng đầu) — trừ thông báo giao dịch PayOS (mục 3). Nghĩa vụ lưu chứng từ kế toán, thuế của quán thuộc về chủ quán — hãy tự lưu một bản (in, chụp màn hình…) trước khi xoá quán. Sổ hoa hồng cộng tác viên là sổ của IR Tech (cấp nền tảng), không bị xoá cùng quán: giữ ít nhất 10 năm theo nghĩa vụ kế toán và thuế của IR Tech (hiện không có cơ chế xoá).
Bản ghi đồng ý (Điều khoản sử dụng, Chính sách bảo mật) Giữ làm bằng chứng bạn đã đồng ý, kể cả sau khi bạn xoá tài khoản Tablir. Khi bạn xoá tài khoản Tablir, địa chỉ IP và trình duyệt/ứng dụng (user agent) trong bản ghi bị xoá ngay; phần còn lại — phiên bản đã đồng ý, thời điểm, kênh — vẫn được giữ nhưng không còn gắn với tài khoản của bạn.

5. Bảo mật

Kết nối dùng HTTPS/WSS. Mật khẩu được băm (bcrypt), không lưu dạng chữ. Truy cập theo phân quyền theo chức năng.

6. Trẻ em

Tablir là công cụ vận hành doanh nghiệp, không dành cho trẻ em dưới 16 tuổi và không chủ đích thu thập dữ liệu của trẻ em.

7. Quyền của bạn

Bạn có quyền truy cập, chỉnh sửa hoặc yêu cầu xoá dữ liệu cá nhân của mình.

Để xoá tài khoản và dữ liệu, làm theo Hướng dẫn xoá tài khoản & dữ liệu. Trang đó tách rõ ba việc khác nhau: chủ quán xoá quán; nhân viên gửi yêu cầu kết thúc chỗ làm để chủ quán duyệt; và xoá hẳn tài khoản Tablir của chính bạn — việc cuối không ai duyệt và không hoàn tác được. Trang đó cũng có đường gửi email cho trường hợp bạn đã gỡ ứng dụng hoặc không đăng nhập được — và cho chủ quán muốn xoá tài khoản Tablir, vì ứng dụng Chủ quán chưa có nút làm việc này (ứng dụng Nhân viên có: Hồ sơ của tôi → Xoá tài khoản Tablir).

8. Liên hệ

Đơn vị cung cấp: CÔNG TY TNHH IR TECH
Email: contact.irteam@irtech.vn · Điện thoại: +84 968 534 201
Địa chỉ: 93 Đường Tô Hiến Thành, Phường Hải Ninh, Tỉnh Hà Tĩnh, Việt Nam


English version

Last updated: 2 October 2026 · Provided by CÔNG TY TNHH IR TECH ("we").

Privacy Policy — Tablir. Tablir is a restaurant-management platform with two apps: Tablir Owner (owners/managers/HR) and Tablir Staff (employees). This policy explains what data we collect, why, who we share it with, and what rights you have.

1. Data we collect

Data groupExamplesPurpose
AccountFull name, email, phone number, password (hashed). A staff account may be created by you, or by the owner when adding your staff record (the owner enters your email/phone number). If you sign up or sign in with Google/Apple: your Google/Apple account identifier, linked to your Tablir account. A consent record: the version of the Terms of Use and of the Privacy Policy you accepted (identified by their “Last updated” date), the time, the channel (sign-up, sign-up with Google/Apple, or a consent prompt), your IP address and your browser/app (user agent)Sign-in, account security, password recovery by email; recognising you the next time you sign in with Google/Apple; proving that you accepted the Terms of Use and the Privacy Policy
HR records (entered by the owner)Date of birth, gender, address, national ID number, position, salary, emergency contactThe store’s HR management, time tracking and payroll
Attendance & locationClock-in/clock-out times; device location at clock-in (to verify presence at the store) and the device’s IP address at clock-in; store coordinatesConfirming a staff member is at the store when clocking in; distance-based delivery pricing
PhotosMenu photos, store logo, event banners, and staff portrait photos uploaded by the owner or a manager; menu photos uploaded by staff with menu permission; screenshots the owner sends to our support teamDisplayed in the menu and store configuration; helping our support team handle a request
OrdersItems, table number, customer name and phone number (required for remote/delivery orders placed through the Zalo mini app; for other orders, if entered), the customer device’s GPS location (remote/delivery orders, only if the customer consents), the customer’s Zalo identifier, status, payment; customer ratings through the mini app (score, free-text comment) linked to the staff member who servedRunning sales, reporting, attributing orders to the staff who served them; delivery (store staff view the location and open it in Google Maps); the staff performance board (from customer ratings); preparing order-status updates to the customer through Zalo — a feature that is not active yet: nothing is sent to Zalo today, and the Zalo identifier is only collected and stored with the order in preparation
Referral partnersPayout details (bank, account number, account holder); identity document or tax number where the law requires itPaying referral commission and meeting tax obligations
Device & notificationsPush token (FCM), device typeSending notifications: new orders, overdue orders, leave requests and leave decisions, attendance approval results, rejected shifts, payslips ready, published reviews, request tickets (created/decided), support-team replies, plan renewal reminders

2. Device permissions & why

3. Data sharing

We do not sell personal data. Data is processed by these infrastructure providers in order to run the service:

Within a store, HR data is visible only to authorized owner/manager/HR; employees see only their own data and assigned work.

🔴 Forwarding delivery details to a courier. For delivery orders, store staff can deliberately tap a button to forward, to a courier, the order number, customer name, customer phone and a map link to the delivery address. It is sent through the operating system’s share sheet, so the recipient is chosen by the store — any messaging app. We do not control that app, and we do not control what happens once the message leaves the staff member’s device. Opening the map link also means Google receives that delivery address.

No third-party analytics. The apps do not integrate Google Analytics for Firebase or any other analytics SDK, and do not request an advertising identifier (Advertising ID). We do not track you across apps and build no advertising profile. ⚠️ That does not mean no data leaves the device. Five specifics, spelled out because they are easy to understate:

  • A notification’s content carries people’s names, not just a device token. To deliver notifications your device push token (FCM) is sent to Google Firebase Cloud Messaging — and so is the notification’s content. That content may contain: a staff member’s full name and leave type (e.g. “A requested annual leave”); a shift’s date and the reason a manager gives for rejecting a shift or a leave request; and, in the other direction, a staff member’s full name with the shift name, its date and the reason they themselves gave for declining an assigned shift; a ticket’s author and title, plus the note a manager writes when approving or rejecting it; and the first 120 characters of a reply our Tablir support team sends to a store. These are examples, not a closed list.
  • Photos go straight from your device to Google, not through our servers.
  • A photo’s link is public. Each image gets an address with a read token; anyone holding that address can view the image, signed in or not. The link does not expire with time. Today an old image is removed from storage only when the store replaces a menu photo or its logo, or when the IR Tech platform team deletes a store outright. When an owner deletes their store (the normal route, once the freeze ends) — and for staff portraits, event banners and images sent to our support team — the image may remain in storage and still open from its old link. To have a specific image removed, contact us (section 8).
  • When a guest opens a menu containing photos, their browser or Zalo fetches them directly from Google, so the guest’s IP address goes to Google. Images are marked long-lived cacheable, so later views are usually served from the guest’s own device cache without contacting Google again; a new request happens on the first view of each image on each device, when the cache is cleared, or when the store replaces the image.
  • When a screen with a photo field appears — no tap and no upload needed — the app creates an anonymous identifier for that device at Google (anonymous Firebase Auth) — Google’s storage requires one before allowing a write. A device that has never opened a screen with a photo field creates no identifier. It does not carry your name, but the request carries an IP address.

See the table in section 1 and the list above for exactly what goes where.

And about this website. Our public pages — including the one you are reading — load the Be Vietnam Pro typeface from Google Fonts. That means opening this page sends your IP address, browser type and the site you are on (irtech.vn — not the specific page address) to Google’s servers. We say so because it happens before you have had a chance to read this policy. The phone versions of the two apps do not work this way: they bundle the typeface on the device and call no font server. The web versions of the two apps (owner.tablir.irtech.vn, staff.tablir.irtech.vn) do reach Google: when opened, your browser loads the rendering engine (CanvasKit) and the Firebase libraries from Google’s servers (gstatic.com), so your IP address goes to Google.

4. Retention & deletion

Where data is stored

Our primary server and database — which hold store, HR and order data — are operated by an infrastructure provider in Vietnam.

Backups. Database backups are created automatically every day and written to that same server’s disk; we keep the 10 most recent. No copy is currently pushed outside the server. So data deleted from the live system remains in these backups for up to about 10 days, after which it is overwritten.

⚠️ But not all data stays inside Vietnam. The services listed in section 3 are foreign services — Google (photos, push notifications, sign-in), Apple (sign-in), Open-Meteo (weather) — so the data sent to them is processed outside Vietnam. PayOS and Zalo are Vietnamese companies. We deliberately do not repeat that list here: section 3 is the one in force, and two copies of a list will drift apart.

How long we keep it, and how deletion works

Data is kept while the account and store are active. You can ask for deletion at any time — the exact steps, including if you have already uninstalled the app, are on the Delete your account & data page.

SituationWhat happens
An owner deletes their store The store is deleted with it: frozen for 60 days (restorable in-app with the Restore store button), then the store and its data are permanently deleted: orders, payments, payslips, HR records, contracts, and every staff member’s job at the store (jobs are deleted together with the store when the freeze ends). Still kept after the store is deleted: PayOS transaction notices (section 3); records of requests to end a job (the staff member’s name, the reason, the owner’s note); if the store came through a referral partner — the referral record (store name, the owner’s email and phone number, IP address and browser at sign-up) and the commission ledger; conversations with our support team (closed sessions are deleted 7 days after closing; open ones remain); and the IR Tech platform team’s action log (who did what, to which store or person, with names). This does not delete the Tablir accounts (email, password) of the owner or the staff. ⚠️ Owners should save their own copy of the store’s records (print, screenshots…) before deleting the store. Photos in Google’s storage may remain — see section 3.
An employee submits a request and the owner approves it The job at that store is locked immediately on approval, then deleted after 90 days. This does not delete your Tablir account — your email and password remain, and you can still sign in with your email and password, or with Google/Apple if that account uses the same email (Forgot password may not work once you no longer have a job at any store — keep your password). ⚠️ From the moment it is locked you can no longer open your payslips in the app — save them BEFORE submitting the request. The record of your request (name, the reason you typed, the owner’s note, the outcome) is kept as an audit trail and is not deleted — even after the job, the store or your Tablir account is deleted.
You delete your own Tablir account Your sign-in email and password are deleted at once, and every job you hold ends with them. The link to your Google/Apple account (the identifier) is deleted at the same time. Your consent record is kept as evidence, but the IP address and browser/app (user agent) in it are deleted at once (see the “Consent record” row below). Nobody approves it and it cannot be undone. However, copies of your email and phone number (along with address, date of birth, ID number…) in each store’s HR records remain until that store is deleted; if you are an owner who came through a referral partner, the referral record still holds your email and phone number (first row). The store’s records are still kept under the rows below. If you are the sole owner of an active store, you must delete the store first. Once the store is frozen you can delete your account straight away — but then nobody is left to press Restore store; to keep a way back, wait until the freeze ends before deleting your account.
An employee leaves (no request submitted) Your job at that store is locked as soon as the owner ends your employment, and deleted after 90 days. Your Tablir account is not deleted — your email and password remain and you can still sign in with your email and password (as someone not yet at any store), or with Google/Apple if that account uses the same email; Forgot password may not work once you no longer have a job at any store — keep your password. ⚠️ From the moment it is locked you can no longer open that store’s payslips in the app — save them BEFORE you leave.
The owner suspends your sign-in (you still work there) The owner can lift the suspension. If the owner does not lift it within 90 days, your job at that store is deleted outright, just as when you leave (row above).
HR records (contracts, national ID, salary) Managed by the store, and deleted together with the store (first row). The system does not keep these records separately once the store is deleted: the duty to keep them under labour law lies with the owner — save your own copy (print, screenshots…) before deleting the store.
Business records (orders, payslips, affiliate commission ledger) Orders, payments, payslips: kept while the store is active, with names snapshotted at the time of the transaction so older records stay readable, and deleted together with the store (first row) — except PayOS transaction notices (section 3). The duty to keep the store’s accounting and tax records lies with the owner — save your own copy (print, screenshots…) before deleting the store. The affiliate commission ledger is IR Tech’s own ledger (platform level) and is not deleted with a store: it is kept for at least 10 years under IR Tech’s accounting and tax obligations (there is currently no mechanism to delete it).
Consent record (Terms of Use, Privacy Policy) Kept as evidence that you gave your consent, even after you delete your Tablir account. When you delete your Tablir account, the IP address and browser/app (user agent) in the record are deleted at once; the rest — the version you accepted, the time, the channel — is kept but no longer linked to your account.

5. Security

Connections use HTTPS/WSS. Passwords are hashed (bcrypt) and never stored in plain text. Access is controlled by function-level permissions.

6. Children

Tablir is a business operations tool. It is not intended for anyone under 16 and we do not knowingly collect children’s data.

7. Your rights

You may access, correct or request deletion of your personal data.

To delete your account and data, follow Delete your account & data. That page separates three different things: an owner deleting a store; an employee asking to end their job at a store, for the owner to approve; and deleting your own Tablir account outright — the last needs nobody’s approval and cannot be undone. That page also has an email route for anyone who has already uninstalled the app or cannot sign in — and for owners who want to delete their Tablir account, since the Owner app has no button for that yet (the Staff app does: My profile → Delete your Tablir account).

8. Contact

Provided by: CÔNG TY TNHH IR TECH
Email: contact.irteam@irtech.vn · Phone: +84 968 534 201
Address: 93 To Hien Thanh Street, Hai Ninh Ward, Ha Tinh Province, Vietnam