← Back to Stepo

Privacy Policy

Last updated: June 4, 2026 · Effective: June 4, 2026

This Privacy Policy ("Policy") describes how Chau Apps Company Limited ("Chau Apps", "we", "us", or "our") collects, uses, shares, stores, and protects your personal data when you use the Stepo mobile application and related services (together, the "Service"). It also explains your rights and how to exercise them.

Please read this Policy carefully. By creating an account or using the Service, you confirm that you have read and understood it. Where required by law, we will ask for your consent before processing your personal data, and you may withdraw that consent at any time.

1. Who We Are (Data Controller)

The Service is operated by Chau Apps Company Limited, a limited liability company organized under the laws of Vietnam, which is the controller responsible for your personal data.

  • Company: Chau Apps Company Limited (CÔNG TY TNHH CHAU APPS)
  • Enterprise / Tax code: 0318597324
  • Registered office: A61 Nguyễn Thần Hiến, Ward 18, District 4, Ho Chi Minh City, Vietnam
  • Legal representative: Cao Minh Châu (Director)
  • Privacy contact: chaucao@chauapps.com

2. Scope & Governing Framework

Stepo is launching in Vietnam first. We process personal data in accordance with the laws of Vietnam, including the Law on Personal Data Protection No. 91/2025/QH15 (the "PDPL") and Decree No. 356/2025/ND-CP, each effective from 1 January 2026, together with other applicable regulations. Where users are located in other jurisdictions, additional local rights may apply, as described in Section 12.

3. Personal Data We Collect

3.1 Data you provide to us

  • Account data — name, username, email address, and password (stored in hashed form).
  • Profile data — profile photo, bio, and other details you choose to add.
  • User content — photos, videos, captions, comments, likes, follows, and other content you create, upload, or interact with.
  • Support & communications — information you provide when you contact us, report content, or give feedback.

3.2 Data collected automatically

  • Usage data — features used, screens viewed, actions taken, and interaction patterns within the app.
  • Device & technical data — device model, operating system and version, app version, language, time zone, and IP address.
  • Identifiers — app-generated identifiers, push notification tokens, and analytics identifiers (such as Firebase installation IDs).
  • Diagnostic & crash data — error reports, crash logs, stack traces, and performance metrics used to keep the Service stable.

We do not collect precise (GPS-level) location data, and we do not knowingly collect sensitive personal data unless you choose to include it in content you post.

4. Analytics, Crash Reporting & Similar Technologies

We use the following tools to understand usage and improve reliability. These tools use device identifiers and may process data on our behalf:

  • Google Firebase Analytics — aggregated, event-level usage analytics to understand how features are used and improve the Service.
  • Google Firebase Crashlytics — crash and stability reporting, including device state and diagnostic data at the time of a crash.
  • Push notification services — Apple Push Notification service (APNs) and Firebase Cloud Messaging (FCM) to deliver notifications.

These services are provided by Google LLC and Apple Inc. and are governed by their own privacy policies (see Firebase / Google Privacy and Apple Privacy). Where required, we rely on your consent for analytics and crash reporting, and you can limit some collection through your device settings.

4.1 Advertising

The Service does not currently display third-party advertising. We may introduce advertising in the future. If we do, we will update this Policy beforehand and, where required, obtain your consent. At that time we will disclose our advertising partners and the data they process (which may include device and advertising identifiers). On iOS, we will request your permission through Apple's App Tracking Transparency prompt before any cross-app tracking, and you will be able to control advertising identifiers in your device settings. We will not serve personalized or targeted advertising to users we know to be under the applicable age, and any ads will be subject to the consent requirements of the PDPL for users in Vietnam.

5. How We Use Your Personal Data

  • To provide, operate, maintain, and improve the Service.
  • To create and manage your account and authenticate you.
  • To store, process, and deliver the content you upload.
  • To enable social features such as following, commenting, and sharing.
  • To send service-related and activity notifications (including push notifications), which you can control in your device settings.
  • To analyze usage and diagnose and fix crashes and performance issues.
  • To respond to your requests and provide customer support.
  • To detect, prevent, and address fraud, abuse, security, and safety issues.
  • To comply with legal obligations and enforce our Terms of Service.

6. Legal Bases for Processing

We process your personal data on one or more of the following bases:

  • Consent — which you may withdraw at any time (for example, for analytics and notifications).
  • Performance of a contract — to provide the Service you request under our Terms.
  • Legitimate interests — such as securing the Service and preventing abuse, balanced against your rights.
  • Legal obligation — where processing is required by applicable law.

7. How We Share Personal Data

We do not sell your personal data. We share it only as described below:

  • Other users — content and profile details you choose to make visible are shared according to your settings.
  • Service providers (processors) — trusted third parties who process data on our behalf under contract, including:
    • Render — application hosting
    • Neon — database hosting
    • Bunny.net — media storage and content delivery (CDN)
    • Upstash — caching
    • Axiom — diagnostic logging
    • Google (Firebase Analytics, Crashlytics, Cloud Messaging) — analytics, crash reporting, and push delivery
    • Apple (APNs) — push notification delivery
  • Legal & safety — when required by law, legal process, or government request, or to protect the rights, property, safety, and security of our users, the public, or Chau Apps.
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.

8. International & Cross-Border Data Transfers

Some of our service providers are located outside Vietnam, which means your personal data may be transferred to and processed in other countries. Where we transfer personal data of users in Vietnam abroad, we conduct a Transfer Impact Assessment (TIA) and maintain the required dossier in accordance with the PDPL and Decree 356/2025/ND-CP. We take steps to ensure your data continues to be protected to the standard described in this Policy wherever it is processed.

9. Data Retention

We retain personal data for as long as your account is active or as needed to provide the Service. When you delete your account, we delete or anonymize your personal data within a reasonable period, except where we are required or permitted to retain it for legal, accounting, dispute-resolution, or legitimate business purposes. Diagnostic and analytics data is retained for limited periods consistent with the providers' settings.

10. Security

We apply reasonable technical and organizational measures to protect personal data, including encryption in transit, hashed passwords, access controls, and signed media URLs. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a personal data breach occurs, we will notify the competent authority and affected users as required by law, including within the timelines set out in Section 11.

11. Your Rights Under Vietnamese Law (PDPL)

Subject to the PDPL and its guiding decrees, you have the right to:

  • Be informed about the processing of your personal data.
  • Give or withhold consent, and to withdraw consent at any time.
  • Access and obtain a copy of your personal data.
  • Correct inaccurate or incomplete personal data.
  • Delete your personal data ("right to be forgotten"), subject to legal exceptions.
  • Restrict or object to certain processing.
  • Data portability — receive your data in a usable format.
  • Complain, denounce, or initiate legal action, and to claim compensation for damage caused by a violation.

To exercise these rights, contact us at chaucao@chauapps.com. We will respond within the timeframes required by law. You also have the right to lodge a complaint with the competent Vietnamese authority — the Department of Cybersecurity and High-Tech Crime Prevention (A05), Ministry of Public Security.

Breach notification: If we become aware of a personal data breach, we will notify the competent authority within 72 hours of detection, and notify affected data subjects where required.

12. Rights in Other Regions

If you are located in the European Economic Area or the United Kingdom, you may have rights under the GDPR/UK GDPR (including access, rectification, erasure, restriction, portability, and objection, and the right to complain to a supervisory authority). If you are a California resident, you may have rights under the CCPA/CPRA (including to know, delete, correct, and opt out of "sale"/"sharing"; we do not sell personal data). To exercise any of these rights, contact chaucao@chauapps.com.

13. Children's Privacy

The Service is not directed to children under 13, and we do not knowingly collect their personal data. For users in Vietnam, where a user is a child under 16, we require consent from a parent or legal guardian; for children aged 7 and older, consent of both the child and the parent or guardian is required where mandated by law. If you believe a child has provided us personal data without the required consent, contact us and we will delete it.

14. Changes to This Policy

We may update this Policy from time to time. We will revise the "Last updated" date above and, where changes are material, provide additional notice within the Service. Your continued use after the changes take effect constitutes acceptance, except where consent is required by law.

15. Contact Us

For any questions, requests, or complaints regarding this Policy or your personal data, contact us at chaucao@chauapps.com, or by mail at:

Chau Apps Company Limited
A61 Nguyễn Thần Hiến, Ward 18, District 4
Ho Chi Minh City, Vietnam