TWOHEARTS · POLICIES
Twohearts Data Policy
Last Updated: 11 February 2026 | Ngày cập nhật: 11/02/2026
Governing Language
This Data Policy is provided in English and Vietnamese for convenience. If there is any inconsistency, the Vietnamese version (immediately following each section) shall prevail for users in Vietnam.
1. Introduction
This data policy explains how Twohearts Technologies processes data received from Meta platforms, including Facebook and Facebook Messenger.
This policy supplements our general Privacy Policy and is built to comply with Meta Platform Terms and Developer Data Use Policy from Meta.
We use Facebook Messenger as a channel for customers to place food orders and contact support. This policy specifically describes how we handle data arising from this interaction.
2. Data We Receive from Meta
When you interact with us through Facebook Messenger, we receive the following types of data via Meta Messenger Platform and Meta Platform API:
Profile data:
- Page-Scoped User ID (PSID): Your unique identifier within our Facebook page scope. PSID is different from your Facebook User ID and is only valid on our page
- Display name: Your Facebook user name
- Profile picture URL: Link to your Facebook profile picture
Message data:
- Message content: Text messages you send to our page via Messenger
- Attachments: Images, files, or media you send via Messenger (e.g., payment receipt photos)
- Timestamps: When messages are sent and received
3. How We Use Meta Data
Data from Meta is only used for the following purposes:
- Customer support: Answering questions, resolving order issues, and providing product information via Messenger
- Order processing: Receiving and processing orders sent through Messenger, including confirming menu items, delivery address, and payment method
- AI ordering assistant: Using AI assistant to understand ordering requests and suggest suitable dishes. AI processes message content to analyze requests, but data is minimized — only the context needed for the current conversation is sent to the AI service
- Order history: Linking PSID with customer profile to provide order history and personalized service
We do not use Meta data for advertising, third-party marketing, or any purpose beyond the scope stated above.
4. Meta Data Storage
Retention periods:
- PSID and profile data: Stored for the duration of your interaction with us and up to 1 year from your last interaction
- Messenger messages: 1 year from date received
- Attachments (images, media): 90 days after related order is completed
Storage location:
- Data is stored on secure cloud servers
- Images and attachments are stored on secure cloud storage
- Database uses encryption at rest
Security measures:
- TLS/SSL encryption for all data in transit
- Encryption at rest for database
- Role-based access control — only authorized personnel have access to customer data
- Access logs are monitored and periodically audited
5. Data Sharing
We do not sell data received from Meta to any third party.
Meta data is only shared with the following sub-processors, with data minimization principles:
| Sub-processor | Data | Purpose | Minimization |
|---|---|---|---|
| OpenRouter | Message content, order context | AI assistant for order processing | Only current conversation context is sent; PSID or identifying information is not sent |
| POS system provider | Name, phone number (when creating order) | Place order in POS system | PSID and Messenger data are not sent to the POS provider |
| Cloudflare R2 | Image attachments (payment receipts) | File storage | Only images are stored, without identifying metadata |
| Sentry | Technical error logs | System error monitoring | Automatic PII scrubbing — personal information is removed before sending |
| Pinecone | Menu item vectors (dish names, descriptions) | AI menu search and dish recommendations | Only menu catalog data is stored; no user messages, PSID, or identifying data is sent to Pinecone |
6. Data Deletion Requests
You have the right to request deletion of all data we have received from Meta about you.
How to submit a request
Send an email to chat@twohearts.vn with subject "Data Deletion Request" and include:
- Your Facebook name
- Phone number linked to your account (if any)
What happens next
- We will acknowledge your request and reach back to you within 24 hours
- We verify your identity by cross-referencing the request with the PSID, email, or phone number in our system
- Your data will be deleted within 30 days of receiving a valid request
Data that will be deleted
- PSID and Facebook profile data (display name, profile picture)
- All Messenger message history
- Attachments and images sent via Messenger
- Links between Facebook profile and customer profile in our system
Track your request
If you submitted your request through Facebook (by removing the app), you will receive a confirmation code and a link to check your deletion status online at any time. The status page is available at `/deletion-status/your-code`.
Completion
We will send you a confirmation email once the deletion is complete.
Data that may be retained
Under Vietnamese law, we may retain certain financial transaction data (not including Meta profile data) for up to 5 years as required by accounting law. This data is anonymized and not linked to your Facebook account.
7. User Rights
Regarding data received from Meta, you have the following rights:
- Right to access: Request to view all Meta data we store about you, including PSID, profile, and message history
- Right to deletion: Request deletion of all Meta data (see Section 6 above)
- Right to data portability: Receive a copy of your Meta-related data in JSON or CSV format
- Right to object: Object to Meta data processing for a specific purpose
- Right to restrict: Request restriction of Meta data processing while we review your complaint
To exercise any right, please send a request via email chat@twohearts.vn. We will respond within 15 business days.
8. Security
We apply the following technical and organizational security measures to protect Meta data:
- Encryption in transit: All communication with Meta API uses HTTPS/TLS 1.2+
- Encryption at rest: Data in database is encrypted at rest
- Role-based access control: Only authorized operations personnel have access to customer data
- PII Scrubbing: Personal information is automatically removed from error logs before being sent to monitoring systems
- Secure tokens: Meta API access tokens are stored securely in environment variables, never in source code
- Access auditing: All access to customer data is logged
9. Compliance
This data policy is built to comply with the following regulations:
Meta regulations:
- Meta Platform Terms
- Meta Developer Data Use Policy
- Messenger Platform Policy
Vietnamese law:
- Cybersecurity Law 2018 (Law No. 24/2018/QH14)
- E-Commerce Law
- Consumer Protection Law
- Personal Data Protection Decree (Decree 13/2023/ND-CP)
We are committed to updating this policy when there are changes in Meta regulations or Vietnamese law.
10. Contact
If you have any questions about how we handle data from Meta, or wish to exercise your data rights, please contact:
- Company: Twohearts Technologies
- Address: 212/2B1 Nguyen Trai, Cau Ong Lanh Ward, Ho Chi Minh City, Vietnam 700000
- Data contact email: chat@twohearts.vn
You can also refer to our Privacy Policy and Terms of Service for more details.