CAMBOX Application Privacy Policy
Last updated: August 13, 2026
1. Purpose of this Policy
CAMBOX is a service for recording the order-packing process, storing that video, and retrieving it when a complaint needs to be checked. This Policy explains what data the CAMBOX mobile application and the browser version collect, what it is used for, which parties it is transferred to, how long it is kept, and what users can request.
This Policy covers the CAMBOX software and service. If you purchase hardware on the cambox.vn website, your purchase information is governed by the Customer Information Privacy Policy published alongside this one.
The responsible entity is EVOS Vietnam Technology Joint Stock Company. Contact details are in the final section.
2. Data collected
Account information
Provided by the user at registration and when updating their profile:
- Full name.
- Phone number.
- Email address.
- Password, stored hashed and not reversible.
- Avatar image, if the user chooses to upload one.
- Date of birth and gender, if the user chooses to provide them.
- Address, if the user chooses to provide it.
- Store name and business details, including the tax code where an invoice is required.
Order-packing video
This is the primary data the service produces:
- Video of the packing process, recorded when the user actively starts a recording.
- A thumbnail extracted from the video for display in lists.
- The order code read from the shipping label, the recording time, duration, file size, and related technical details of the video file.
- Classification labels defined by the store and attached to the video.
Ambient audio
We list this separately because it is a distinct category of data from imagery. It also differs between the two ways of using CAMBOX:
- The mobile application records ambient sound throughout the recording, and that audio forms part of the video file. The purpose is to preserve the integrity of the evidence, since a muted video is much harder to rely on when a dispute arises.
- The application does not record audio outside of an active recording, does not listen in the background, and does not analyse the content of speech.
- The browser version does not record audio. Videos recorded in the browser are silent.
Device information
- Device model and operating-system version.
- IP address and network-connection information.
- The device identifier used to deliver push notifications, issued by Firebase Cloud Messaging. Only the mobile application has such an identifier.
- Application logs used for troubleshooting.
Feature-usage figures
This section applies to the mobile application only. The browser version sends no usage figures and no crash logs. The application records the actions below as events, together with the device identifier, so we can tell which features work well and where users run into trouble:
- Sign-in success or failure, and sign-out.
- Successful order scans and detection of duplicate orders.
- Recording started, recording completed, recording cancelled.
- Video upload succeeded or failed.
- Opening a video for playback, attaching and removing labels.
- Permission dialogs shown and the choice the user made.
- Progress through the initial onboarding steps.
Crash logs
- When the application hits an error and stops unexpectedly, a technical record of that error together with device information is sent for diagnosis. This record contains no video content.
Location
A store may enable embedding the address into the evidence video. The feature is off by default and each store decides whether to turn it on. It works the same way in the mobile application and in the browser version:
- While the feature is on, the coordinates captured at recording time are stored with that video’s record. When the store generates an evidence link to send to a customer, those coordinates are turned into a place name and printed onto the exported copy. The video never displays the coordinates themselves.
- Turning coordinates into a place name goes through the mapping service named in section 6. Before they are sent, the coordinates are reduced to roughly one-hundred-metre precision, just enough to look up the ward name, so exact coordinates never leave the CAMBOX system. The stored coordinates are deleted together with the video.
- While the feature is off, the system does not save any coordinates that arrive, even if a device sends them. That check sits on the server and re-reads the setting at the moment a video arrives, so turning the feature off also covers videos recorded earlier that have not been uploaded yet.
- The mobile application requests location permission only once the store has enabled this feature, and only at the while-in-use level. It does not take location in the background. The browser version asks for location through the browser itself. Declining still allows recording and storing the video; it simply has no address line.
- While an upload is pending, the mobile application keeps the coordinates in the application’s own private storage alongside the upload queue, so a video recorded out of signal does not lose its address when it is uploaded later. That temporary copy is kept until the video finishes uploading, or until the user drops that item from the queue. If the queue file is damaged, the application keeps the damaged copy rather than deleting it, so that videos which were recorded but never uploaded can still be traced; that copy also sits in the application’s own private storage and goes when the user uninstalls the application. The coordinates are not written to technical logs, not sent with analytics, and not embedded in the video file.
3. Buyers’ personal data appearing in the video
A packing video usually captures the shipping label, which carries the recipient’s name, phone number, and address. That means the video contains personal data of the buyer, someone who never installed or used the CAMBOX application. We set out the allocation of responsibility here.
- The store is the controller of the buyer information appearing in the video. The store decides to record, decides what enters the frame, sets the retention period, and decides when to delete. The store is responsible for informing and dealing with its own customers as the law requires.
- CAMBOX is the processor, acting on the store’s behalf. We store the video and serve it back at the store’s request, and do not use it for any other purpose of our own.
- Processing is limited to keeping evidence for reconciling order complaints. We do not use video content for advertising, do not sell it, and do not transfer it to any third party other than the infrastructure providers named in section 6.
- The retention periods and deletion mechanism in section 7 apply to this data as well. When a video is deleted, the buyer information inside it goes with it.
- CAMBOX personnel do not view a store’s videos, except where the store requests technical support or where there is a lawful request from a competent state authority.
If you are a buyer and want to know which videos contain your information, please contact the store that shipped your order first, as the store is the party that decides. You may also contact CAMBOX using the details in the final section, and we will work with the store to handle your request.
4. Permissions the application requests
This section concerns the mobile application. Each permission below serves only the function stated next to it. Users may decline, but the corresponding function will then not work.
- Camera, to record the packing video and scan the barcode on the shipping label.
- Microphone, to record ambient audio alongside the video as described in section 2.
- Location, to embed the address into the evidence video as described in section 2. It is requested only once the store has enabled that feature, and only at the while-in-use level.
- Notifications, to alert the user about activity relating to orders and the account.
- Writing to the photo library, to save a recorded video onto the device when the user actively chooses to download it.
The browser version requests permissions through the browser itself: camera access in order to record, and location access if the store has enabled address embedding. It does not request microphone access.
About choosing an avatar on Android
Behaviour differs by operating-system version:
- On Android 13 and above, the application uses the operating system’s built-in photo picker. The user picks exactly one image and the application receives only that image; no library-read permission is requested.
- On Android 12 and below, the application must request storage-read permission in order to open the photo library. That permission is used only for choosing an avatar.
5. Purposes of use
- Recording and storing packing evidence for reconciling order complaints.
- Authenticating users and applying per-store permissions.
- Sending notifications about activity relating to the account and orders.
- Detecting faults and improving the stability of the application.
- Supporting users on request.
- Calculating storage used and retention periods under the service plan.
- Protecting the system and detecting or preventing fraud and unauthorised access.
- Meeting obligations imposed by law.
CAMBOX does not sell users’ personal data and does not use video content for advertising.
6. Transfers to third parties
To operate the service we use the providers below. Each receives only the portion of data needed for its role and may not use it for anything else.
- Bizfly Simple Storage, operated by VCCorp Joint Stock Company, receives packing videos, thumbnails, and avatar images, for storage. The data is held on infrastructure located in Vietnam.
- The Bizfly email service receives email addresses and names, to send account-related mail such as password resets, store invitations, and plan-renewal reminders.
- Zalo ZNS, operated by VNG Corporation, receives phone numbers, to send the verification code at registration. This is CAMBOX’s only verification-code channel, so every account passes through it.
- Cloudflare receives the IP address when a user requests a verification code, to distinguish real people from automated programs.
- Firebase Cloud Messaging, operated by Google, receives the device identifier, to deliver push notifications to the correct device.
- Firebase Analytics, operated by Google, receives the usage events listed in section 2 together with the device identifier, to analyse feature usage.
- Firebase Crashlytics, operated by Google, receives crash logs and device information, to diagnose errors.
- Google Gemini receives a cropped photograph of the product label, only when the shop has itself switched on the serial-reading feature described in section 2, in order to read the digits printed on it. What is sent is the framed area around the label rather than the whole picture, and it carries no order code and no recipient details. One order may send several such photographs when the shop records several serials for it.
- The Goong mapping service receives coordinates reduced to roughly one-hundred-metre precision, only where a store has enabled the address-embedding feature described in section 2, to turn coordinates into a place name. Full-precision coordinates never leave the CAMBOX system.
- Google’s font service receives your browser’s IP address when you open CAMBOX web pages, because the fonts are loaded from Google’s servers. This happens in the browser only, not in the mobile application.
When a service plan is paid for in the browser version, the transaction is processed through the VNPAY payment gateway. VNPAY receives the order details, the amount, and the payer’s IP address. CAMBOX does not store bank-card details. See the Payment Policy published alongside this one for more.
Beyond the parties above, we disclose data only on a lawful request from a competent state authority, where necessary to protect legal rights and interests as provided by law, or with the user’s consent.
We do not sell or trade personal data to third parties for commercial purposes. Using infrastructure providers to run the service is a separate matter, and those providers are named individually in this section.
7. Retention periods
The video retention period is not a fixed number. Each store sets it, within the ceiling of the service plan it is on.
- Each store sets the number of days videos are kept for that store.
- The service plan sets the ceiling. A store may choose any number of days that does not exceed that ceiling.
- Once a video is past its retention period, the system deletes the video file and its thumbnail on a scheduled run. Deleted videos cannot be recovered. The video’s management record, covering the order code, label, and recording time, is kept so the store retains its log. That record holds no imagery, so the buyer information printed on the shipping label goes with the video file.
- If a store raises its ceiling, the new period applies to videos still held in the system as well.
For other categories of data:
- Account data is kept for as long as the service is used, and is handled under section 10 when the user requests account deletion.
- Transaction and payment data is kept for the periods required by accounting and tax law.
- Feature-usage figures and crash logs are kept under Firebase’s default retention settings.
8. Security
We apply the following measures:
- All data transmitted between the application and the servers is encrypted using HTTPS.
- Videos and thumbnails are held in a private store with no public access. Each playback goes through a temporary, time-limited link.
- Avatar images are the exception: they are held in a public store and their link can be opened by anyone who has it, because the image has to render directly in the interface. Please bear that in mind when choosing an avatar.
- Role-based permissions, so a user can only see data belonging to the store they are a member of.
- Passwords are stored hashed.
- Access logging and system security monitoring.
- The system database is backed up automatically every day.
We apply reasonable measures, but no system can guarantee absolute security. If an incident leads to a data breach, we will remediate immediately, notify the authorities as required, and notify affected users within an appropriate time.
9. User rights
Users have the right to:
- View and edit their personal information within the application.
- Request information about the data we hold about them.
- Request deletion of their data and account, under section 10.
- Withdraw consent to certain processing, by turning off the corresponding permission in the device settings.
- Complain about the processing of their personal data.
Please send any request using the contact details in the final section. We will verify the requester’s identity before acting.
10. Data and account deletion
Users can delete their account directly in the application, under the Personal section, or send a request to support@cambox.vn with the subject "CAMBOX account deletion request".
After the request, the account enters a pending-deletion state for 30 days, during which the user can sign back in to cancel it. After 30 days, all videos, thumbnails, avatar images, passwords, login sessions, and device identifiers are permanently deleted.
Full instructions, including the list of data permanently deleted and the data retained for accounting obligations, are published on the CAMBOX Account & Data Deletion page at cambox.vn/en/policies/account-deletion.
11. Children
CAMBOX is a tool for business operations and is not directed at children. We do not knowingly collect data from children below the age set by applicable law. If we find that we have collected such data, we will delete it.
12. Changes to this Policy
This Policy may be updated as the service changes or as the law changes. New versions are published on this page. Where a change materially affects user rights, we will give notice in the application before it takes effect.
13. Contact
For any request relating to personal data or to this Policy, please contact:
- EVOS VIETNAM TECHNOLOGY JOINT STOCK COMPANY
- Address: No. 9 LK13, Hanh Hoa Street, Xa La Urban Area, Ha Dong Ward, Hanoi City
- Hotline: 0918018183
- Email: evos.com.vn@gmail.com
- Website: cambox.vn