Sổ Chấm CôngPrivacy Policy
Data security & transparency

Privacy Policy

The Sổ Chấm Công app respects your privacy. This page explains exactly what data is collected, why, and how you stay in control of it.

Effective date: Jul 12, 2026Last updated: Sep 17, 2026Applies to version: 2.6.0

1Introduction

Sổ Chấm Công ("Attendance Notebook") is a personal work-log app that helps you record work days, work types, hours and allowances to track your monthly income. This policy covers the Sổ Chấm Công mobile app (Android/iOS) and any backend service used to sync your data when you choose to sign in.

By downloading or using the app, you agree to the collection and use of information as described in this policy.

2Two usage modes

On first launch you choose one of two modes. How much of your data ever leaves your device depends entirely on this choice:

Personal (default)

Fully offline. All data stays in a local SQLite database on your device and is never transmitted anywhere unless you actively sign in to enable sync.

Organization

Requires signing in and requires a network connection. Work-log data is stored on our server and shared with other people in the organisation you belong to — the owner, managers and accountants can see your logged days according to their role. If you are the owner, you also enter and store data about your own staff; see section 5.

Personal-mode users can enable sign-in later from Settings to switch to online sync, and can return to offline mode at any time.

3Information we collect

3.1 Account information (only if you sign in / register)

DataPurpose
Username, emailAccount creation & authentication
Phone number (optional)Contact, account recovery
PasswordHashed before storage — we never store plain-text passwords
Device-verification OTPEmailed when signing in from an unrecognized device

3.2 Work-log data (synced only if you're signed in)

  • Work types you create: name, coefficient, unit rate, color
  • Logged entries: date, work type, hours, any note you type in
  • Recurring allowances you set up: name, amount, frequency
  • Advances & deductions you record: date, type (advance or deduction), amount, note — used to work out your net pay for the period
  • Days off you record: the date and the kind of leave (annual, sick, public holiday, other)
  • Workplaces you name yourself: label, colour, and a per-workplace unit rate if you set one. In Personal mode these are just labels you type — no address and no coordinates
  • App preferences: currency, monthly goal, theme, reminder time
In Personal mode, everything in section 3.2 exists only on your device — we never see it and hold no server-side copy.

3.3 Data specific to Organization mode

The data below only exists in Organization mode, and only when the owner turns the matching feature on:

  • Staff entered by the owner: display name, phone number and notes. Some people on that list have not installed the app and have no account — the owner logs attendance on their behalf
  • Role and dates for each staff member: role, start date, end date, and which team or site they belong to
  • Pay, allowances, advances, deductions and net pay for each staff member. Only the owner, the accountant and the person themselves can see this — managers cannot
  • Workplace coordinates entered by the owner, together with the radius within which attendance may be logged
  • Your location at the moment you log attendance, if that shift has location checking enabled: taken once, at that moment, with its accuracy, then stored alongside the logged day so whoever approves it can check. Your location is also read once when someone opens the attendance QR code screen, purely to check whether the device showing the code is at the workplace — that reading is not stored. Outside those two moments, your location is not read
  • A device identifier, if the organisation enables device binding — so one person cannot log attendance from another person's phone
  • An activity log: who created, edited or deleted which logged day, when, and the reason they typed. Anyone whose logged day was edited can read the entries about themselves
The camera is used when you scan a QR code to log attendance. No image is stored and nothing is sent anywhere — the camera only reads the code.

4What we do NOT collect

Sổ Chấm Công does not integrate any advertising, behavioral-analytics, or third-party tracking library. Specifically, we do not collect:

Your location when you are neither logging attendance nor showing the attendance QR code

Contacts, photo library, microphone

Advertising identifiers

Third-party behavioral analytics or ad SDKs

The four items above hold in both modes. As for location and the camera: Personal mode never uses them; Organization mode does, but only at the moment you log attendance or open the QR code screen, and only when your organisation enables it — see section 3.3. We do not track where you travel.

5Staff data & who is responsible for what

In Organization mode the owner enters and stores data about other people — their staff. Responsibility therefore splits in two, and you should know which half belongs to whom:

The owner decides

The owner decides what is collected and why: who goes on the list, their name and phone number, whether location checking, QR scanning or device binding is switched on, and how long the data is kept. The owner is responsible for informing their staff and for having a lawful basis to do so under applicable employment and data-protection law.

What we do

We only process this data on the owner's instructions in order to provide the service: storing it, calculating with it, and showing it according to role. We do not use an organisation's staff data for our own purposes, do not sell it, do not use it for advertising, and do not use it to train any system.

If you are a member of staff

  • Your data may have been entered by someone else. Even if you never install the app, the owner can hold your name and phone number on their list in order to log attendance for you.
  • Ask the owner first. For attendance and pay data inside an organisation, the owner is the one who decides — so send requests to see, correct or delete it to them first. We help them carry it out.
  • You can always see your own part inside the app: your logged days, your pay, your pay slip, and the activity-log entries that are about you.
If you cannot reach the owner, or you believe data about you is being misused, write to us at the address in the last section. We will reply and work with the organisation concerned.

6How we use information

  • Creating, authenticating and securing your account (including OTP device verification)
  • Syncing your work-log data across devices when you're signed in
  • Computing your work totals, income and monthly-goal progress locally on your device
  • Sending the daily check-in reminder you opt into (handled locally — no push-notification server involved)

We do not use your data for advertising purposes, and we never sell or rent it in any form.

7Storage & security

  • On-device: data lives in a local SQLite database inside the app's private sandbox, inaccessible to other apps.
  • In transit: every connection to our server uses HTTPS. Sessions use an HttpOnly cookie — no plain-text token is stored on device.
  • Passwords: one-way hashed server-side before storage; we cannot ever view your original password.
  • Backup/restore: CSV reports you export are saved and shared through your operating system's share sheet — we have no access to these files. Your data is only backed up to our servers when you sign in to sync.

8Third-party sharing

We do not share, sell, or rent your personal data to any third party for marketing or commercial purposes.

AI assistant — only when you choose to send a question: what you type, and the earlier messages in the same conversation, are sent through our servers to a third-party AI model provider located outside Vietnam (currently OpenAI, United States) to generate the answer. We do not send your attendance data, income, name, email or account ID with it, and we do not store the conversation — we only record the number of questions and usage to enforce limits. The provider processes this content under its own terms of service; if we add or change providers, this policy will be updated. Do not enter passwords, bank account numbers or other sensitive information into the assistant. If you don't use the assistant, nothing is sent.

Signing in with Google is live — section 9 sets out exactly what we receive from Google. Signing in with Zalo or Facebook is not active; if it is enabled, this policy will state what data is received before the feature opens to users.

Data may only be disclosed where required by law, or to protect the rights, property, or safety of users and ourselves.

9Signing in with Google / Zalo

If you choose to sign in with Google or Zalo, we receive the following from that provider and use it only to create or recognise your account: the provider’s identifier for you, your display name, your avatar, and your email (Google only — Zalo does not provide an email). We do not receive your password at that provider, and we do not post anything on your behalf.

On the website’s Sign in page, your browser loads a script provided by Google in order to show the account chooser. Google may therefore receive a request from your device when you open the Sign in page, even if you never click the Google button. This script is loaded only on the Sign in page, not on any other page. You can still sign in with your email and password as usual.

10Device permissions

PermissionWhy it's needed
NotificationsShow the daily check-in reminder (only if you enable it)
Storage / file accessSave CSV files when you export a report

Camera: used only to scan the attendance QR code in Organization mode, when the organisation turns that on — no photo is stored. Location: read once, at the moment you check in on shifts where the organisation requires location verification, or at the moment you open the attendance QR code screen; never tracked in the background. The app does not request contacts or microphone permissions.

11Your rights

  • Access & export: export a monthly CSV report at any time from Settings.
  • Delete local data: uninstalling the app or clearing app data in OS settings removes everything stored on your device.
  • Delete account & server data: request in-app (Settings → Delete account) or via our Request Account Deletion page — no app install required.
  • Opt out of sync: switch back to offline/Personal mode at any time in Settings to stop sending data to our server.

12How long we keep data

Local data stays on your device indefinitely until you delete it. If you belong to an organisation, you need to leave it — or have the owner end your employment — before you can request account deletion. When the deletion runs, your Personal-mode data (logged days, work types, allowances, advances, workplaces) is permanently removed from the server. What you recorded inside an organisation stays with that organisation: it is a shared attendance book, and the people still there need it to reconcile the periods you took part in; your name remains in the staff list under former members. When an organisation is deleted, its data is kept for a further 12 months and then permanently erased; during the first 30 days the owner can cancel the deletion, and we send a link to download all of the data before it goes.

13Children's privacy

Sổ Chấm Công is not directed at, and does not knowingly collect personal information from, children under 13. If you believe your child has provided us with personal information, please contact us so it can be removed.

14Changes to this policy

We may update this policy from time to time, particularly as new features ship (e.g. Google/Zalo sign-in). The "Last updated" date at the top of this page will change accordingly. We encourage you to review this page periodically.

15Email updates

If you enter your email into the Subscribe to updates box on the homepage, we store your email address, the language you were reading the site in, and the times you subscribed, confirmed, or unsubscribed. We do not store the IP address or browser details of that sign-up, and we do not add your address to this list when you create an account or send a contact message.

This list is used only to announce new features and important changes to the product. No advertising, no promotions, and the list is never sold or handed to anyone else.

After you enter your email we send one message asking you to confirm. Until you click confirm, that address receives no other email from us.

Messages are written and sent by the project owner using the project’s own email infrastructure (Gmail SMTP). No third-party newsletter service ever receives this list.

Every message carries an unsubscribe link: one click, no sign-in required. Unsubscribing keeps the record marked unsubscribed so we do not email you again by mistake; if you want the address removed entirely, contact us using the section below and we delete the record for real.

16Contact

If you have questions about this policy or want to exercise your rights (export, delete data/account), please contact:

Phạm Đình Thơ — Developer

We respond to privacy-related requests as promptly as possible.

support.attendance@gmail.com