MEMBERSHIP PRIVACY POLICY
THIS PRIVACY POLICY IS INTENDED TO ENSURE THE SECURITY OF PERSONAL INFORMATION OF REGISTRANTS AND USERS OF LS.POINT – THE APP JOINTLY MANAGED BY LOTTE SHOPPING PLAZA VIETNAM CO., LTD (“LSPV”) AND LOTTE PROPERTIES HANOI CO., LTD (“LPH”).
This Privacy Policy (“Privacy Policy”) governs the protection and processing of personal data of customers (“Customers”) by LSPV and LPH in the course of Customers’ purchase, use, or interaction with websites/applications, products, and services, and/or registration for the Lotte Shopping Vietnam Membership Program – Membership Program (collectively referred to as the “Services”). Upon successful registration for the Membership Program, Customers shall become members of the Membership Program (“Members”).
This Privacy Policy is intended to provide Customers with information regarding how we process personal data. This Privacy Policy also sets out the technical and organisational measures we implement to ensure data security, as well as the rights of Customers to control and protect their personal data. We are fully committed to respecting the privacy of Customers’ personal data and place the highest importance on Customers’ trust in the manner in which we process and protect personal data.
This Privacy Policy does not apply to any Services, products, websites, or content provided by third parties and/or subject to separate privacy policies. The LS.POINT Application (“Application”) may contain links to third-party websites, applications, or online services that are not owned or controlled by LSPV and/or LPH; accordingly, LSPV and LPH shall not be responsible for the content or privacy practices of such third parties.
By accessing, registering for the Application, and/or using our Services that reference this Privacy Policy through any form of consent permitted under applicable laws, Customers are deemed to have read, understood, and agreed to all terms and conditions of this Privacy Policy. This Privacy Policy may be amended by LSPV and LPH from time to time.
ARTICLE 1: COLLECTION OF PERSONAL INFORMATION
1.1. “Personal Data” means data in digital form or other formats that identifies or can be used to identify a specific individual, including basic personal data and sensitive personal data as defined under the Law on Personal Data Protection and its implementing regulations.
1.2. “Processing of Personal Data” means any operation or set of operations performed on Personal Data, including but not limited to: collection, analysis, aggregation, encryption, decryption, modification, deletion, destruction, anonymisation, provision, disclosure, transfer of Personal Data, and any other activities that impact or affect Personal Data.
1.3. In the course of Customers’ access to or use of our Services, certain data may be automatically generated and collected for the purposes of system operation and service provision. Such data may include, but is not limited to: IP address, cookies, device type, operating system, device login history, information relating to the use of the Services, access history, transaction data (including point accrual history, point redemption, and points forfeited due to expiry or other reasons in accordance with the Membership Policy), and user activities arising during the use of the Services.
1.4. For the purpose of registering for the Membership Program and using the Services, we are required to collect and process certain necessary Personal Data of Customers via the Application, website, or registration forms. Customers under the age of 15 are not eligible to register for the Membership Program.
- For Customers who have not registered or are not eligible to register as Members, such Customers may only access and view publicly available information, including information on events, programs, and our announcements.
- For Customers who have successfully registered as Members, such Customers may use Services designated for Members, including point accrual, point redemption, and the enjoyment of Member-exclusive benefits.
1.5. For the purposes set out in this Privacy Policy, the Personal Data that may be collected and processed by us includes the following:
a. Basic Personal Data:
- Full name, middle name and given name as stated on the birth certificate, and other names (if any);
- Date of birth;
- Gender;
- Nationality;
- Place of birth, place of birth registration, place of permanent residence registration, place of temporary residence registration, current place of residence, place of origin, and contact address;
- Mobile phone number, personal identification number, passport number, driver’s license number, vehicle registration number (license plate);
- Information on family relationships (parents, children, spouse);
- Information relating to an individual’s digital accounts;
- Other information associated with or capable of identifying a specific individual, which does not fall under Sensitive Personal Data as specified in point (b) below, arising in the course of using the Services.
b. Sensitive Personal Data:
- Information relating to private life;
- Calls, messages and/or other forms of communication from and/or to us may be stored in forms including, but not limited to, audio recordings, video recordings, whether automatic or manual, for the purposes of handling requests, updating information systems, improving Service quality, and other lawful purposes;
- Data reflecting behavioural tracking and usage activities relating to telecommunications services, social networks, online communication services, and other services in cyberspace;
- Other Personal Data as prescribed by law that must be kept confidential or subject to stringent security measures.
1.6. Personal Data may be collected by us from the following sources:
- Directly from Customers who consent to the collection of their Personal Data when registering for the Membership Program or using our Services;
- Personal Data lawfully provided by our partners or service providers with whom we have entered into strategic cooperation agreements or service contracts, subject to the consent of the data subject;
- Collection of Personal Data via websites, Application pages, fax, telephone, and other channels in the course of providing Service consultation;
- Collection of Personal Data from Customers participating in online and offline trade promotion events;
- Collection of Personal Data relating to payments and point transactions generated in the course of using the Services;
- Through surveys, research activities, and similar initiatives;
- Other methods as permitted by applicable laws.
1.7. At the time prior to the collection of Personal Data, we shall notify Customers of the following:
- The types of Personal Data to be processed and the purposes of such processing;
- The personal data controller or the personal data controller and processor;
- The rights and obligations of the data subject; and
- The right to refuse to provide Personal Data and the potential consequences of such refusal.
The collection and processing of such Personal Data are carried out entirely on the basis of the Customer’s voluntary consent.
1.8. Customers are responsible for ensuring that all Personal Data provided is complete, accurate, and up to date at the time of collection in order to safeguard their rights and ensure proper use of the Services. LSPV and/or LPH shall have no obligation to verify the accuracy of the information provided by Customers during the collection process. In the event that Customers provide inaccurate or incomplete Personal Data, LSPV and LPH reserve the right to determine appropriate measures, including the suspension of Services, and shall not be liable for any loss of Membership benefits arising from the provision of inaccurate or incomplete Personal Data.
ARTICLE 2: SCOPE AND PURPOSE OF PERSONAL DATA USE
2.1. We collect and process Personal Data for one or more of the following purposes:
- To create Membership accounts;
- To verify the purpose of registration for the Membership Program, authenticate Personal Data, prevent abuse of Customer benefits, and perform other related activities to ensure compliance with the Membership Policy;
- To provide the Services (including interactions on the Application), handle inquiries or complaints, and send notifications;
- To verify Personal Data for shopping and payment purposes, and to provide products and Services necessary for the provision of paid Services;
- To send notifications to Members, including but not limited to notifications regarding policies, regulations, and any amendments or updates thereto; as well as notifications and updates relating to security, accounts, and Customers’ cards;
- To display the LS.POINT barcode for point accrual on the Google Wallet platform, based on the Customer’s integration and usage needs;
- To verify Customers’ payment transactions when using the Services;
-
For advertising, marketing, and promotional purposes, specifically:
- Content: Provision of information on events, participation opportunities, and promotional and advertising information.
- Method: Via text messages (SMS), telephone calls, and emails provided by the Customer.
- Frequency: Not exceeding three (03) advertising messages to a single phone number, three (03) advertising emails to a single email address, and one (01) advertising call to a single phone number within a 24-hour period, within the timeframes prescribed by applicable regulations.
Customers hereby consent to receiving advertising and promotional communications until such time as they opt out, as follows:
-
- In the event that a Customer does not wish to receive advertising messages via SMS, the Customer may opt out by sending a message in accordance with the instructions provided in the advertising message.
- In the event that a Customer does not wish to receive advertising calls, the Customer may register for the “Do Not Call List” through the following methods: (i) sending an SMS with the syntax DK DNC to 5656; or (ii) via the website khongquangcao.ais.gov.vn. Subscribers included in the “Do Not Call List” will not receive advertising messages or advertising calls. Under this mechanism, Members will also not receive any advertising calls from any third parties.
- In the event that a Customer does not wish to receive advertising emails, the Customer may click “Unsubscribe” in accordance with the instructions provided in the advertising email.
- Customers may also request to opt out of receiving advertising communications by contacting us using the contact details provided at the end of this Privacy Policy.
- To review records of consent and opt-out preferences in relation to advertising messages, advertising emails, and advertising calls, Customers may contact us using the contact details provided at the end of this Privacy Policy or via our websites (https://lotteshopping.com.vn/ and https://lottemallwestlakehanoi.vn/).
- For Services improvement, We will collect some information such as Service usage history, access frequency, Service usage statistics and customer satisfaction.
- Prevention and sanctions against activities that interfere with the smooth operation of the Services (including theft and fraudulent use of the account).
- Other purposes in accordance with the laws of Vietnam.
2.2. Potential consequences and unintended damages that may arise in connection with the processing of Personal Data include:
- Customers providing inaccurate information, resulting in the inability to verify account ownership in cases of point data errors, handling of complaints or disputes, receipt of gifts and other benefits requiring proof of ownership, and similar circumstances;
- System intrusion or cyberattacks leading to loss of Customer information, loss of points, or system disruption;
Other force majeure events that may result in the leakage or loss of Personal Data.
The processing of personal information starts when the customer signs up for the Membership Program, or uses our Services, and concludess in accordance with Article 5 of this Privacy Policy.
2.3. The processing of Personal Data shall commence when the Customer registers for participation in the Membership Program or uses our Services, and shall terminate in accordance with Article 5 of this Privacy Policy.
ARTICLE 3: PROVISION AND SHARING OF PERSONAL INFORMATION
3.1. Customers’ Personal Data may be provided to third parties for the purposes of facilitating the provision and operation of Services at Lotte Department Store and Lotte Mall West Lake Hanoi, on the basis that: (i) the Customer has given separate, explicit, and verifiable consent for each specific processing purpose; or (ii) upon request of competent state authorities; or (iii) as required by mandatory provisions of applicable laws:
Certain third parties, including but not limited to affiliates, service providers in Vietnam and overseas, as well as strategic partners of Lotte Department Store and/or Lotte Mall West Lake Hanoi, in cases where Customer benefits have been communicated to Customers and the sharing of information is necessary to ensure such benefits. The provision of Personal Data in these cases shall be limited to the extent necessary and proportionate to the purposes previously notified to Customers, including but not limited to: provision and operation of the Services; implementation of promotional programs and customer care activities; execution of delivery and payment services; transmission of information via mail, SMS, or email; data analysis, processing, and optimization; support for advertising, marketing, and trade promotion activities; and other lawful activities related to the provision of the Services, specifically as follows:
In order to provide better Services quality for information system operation and management, the APP uses some third-party service providers with details as follows:
|
No. |
Provider |
Service |
Duration of personal data sharing |
|
1 |
Lotte Innovate Vietnam Co., Ltd |
Cloud storage service |
Upon membership withdrawal or service providing agreement termination Upon subcontractor agreement termination |
|
Website, APP development |
|||
|
System operation and maintenance |
|||
|
Marketing Email Service |
|||
|
2 |
CMC Co., Ltd |
OTP SMS |
|
|
3 |
NEW POST Express Delivery Joint Stock Company |
Postal services |
|
|
4 |
VIETTEL POSTAL JOINT STOCK CORPORATION (VIETTEL POST) |
Postal services |
LSPV and LPH may delegate certain necessary tasks related to the Services to the aforementioned third-party service providers. In such cases, we shall strictly define, manage, and supervise the relevant requirements to ensure that the processing of Personal Data is carried out securely, in compliance with the applicable laws of Vietnam, and in accordance with relevant binding agreements. In the event that a Customer does not use Services associated with tasks delegated to such third-party service providers, the Personal Data of such Member shall not be disclosed to those third parties.
-
Google Wallet Application: For the display and management of the LS.POINT barcode for point accrual and redemption in accordance with the Customer’s integration and use of the Google Wallet application. When a Customer integrates Google Wallet with the LS.POINT Application, the Customer acknowledges and agrees that:
- The LS.POINT barcode may be displayed on the Google Wallet platform for the purpose of point accrual and redemption transactions within the Service system;
- Google Wallet may apply its own privacy policy and terms of use. Members are advised to review Google Wallet’s privacy terms to fully understand their rights and obligations, and shall be responsible for any risks arising from the use of this third-party service.
- Banks/Payment Channels: Any authorized bank or payment channel used by the Customer to make payments at Lotte Department Store and/or Lotte Mall West Lake Hanoi, as required for transaction verification by such bank/payment channel or by the Member from time to time. Such banks/payment channels may apply their own privacy policies; Customers are advised to review the applicable privacy terms (if any) to understand their rights and obligations.
- Competent State Authorities: Customers’ Personal Data may be provided to competent state authorities where there is a lawful request in accordance with applicable laws.
We are committed to sharing Personal Data only to the extent necessary and in compliance with applicable laws, and to ensuring that all recipients and processors of such data adhere to corresponding data protection standards, as well as implement appropriate technical and organisational measures to safeguard Customers’ Personal Data against unauthorized access, use, or disclosure.
3.2. Cross-Border Transfer of Personal Data: Within the scope of providing services integrated with Google Wallet, a portion of Customers’ Personal Data may be transferred outside the territory of Vietnam and stored and processed on systems located overseas, including but not limited to information such as Membership ID, name, email address, and technical data related to the use of the Application. The data recipients include Google LLC and/or its affiliated companies, as well as relevant technical infrastructure service providers.
Such data transfers are carried out for the purposes of displaying, synchronizing, managing, and enabling the use of LS.POINT on the Google Wallet platform, thereby ensuring continuity, stability, and optimization of the Customer’s Service experience. We undertake to:
- Apply measures for the protection of Personal Data in accordance with the laws of Vietnam;
- Ensure that Personal Data is transmitted only through secure channels and is encrypted;
- Require the data recipients to implement all necessary measures to ensure that the transferred Personal Data of Customers is kept secure and protected;
- Prepare and maintain dossiers on the assessment of cross-border Personal Data transfer impacts and fulfill other related obligations in accordance with applicable laws;
- Not share Personal Data with third parties beyond the extent necessary for the provision of the Services;
- Ensure that Members retain full discretion to choose whether or not to integrate Google Wallet, and may unlink their LS.POINT account from Google Wallet at any time in accordance with their needs.
ARTICLE 4: USAGE AND SECURITY OF OTP
To ensure the security and protection of Personal Data when Customers register as Members and use the LS.POINT Application of LSPV and LPH, a One-Time Password (“OTP”) shall be used as a means of customer identity authentication during registration and use of the Application. The provisions of this Article set out the use, responsibilities, and terms relating to OTP as follows:
(i) Purpose of use
- Membership registration authentication: When a Customer registers to become a Member, an OTP will be sent to the registered phone number to verify the Customer’s identity and personal information.
- Password recovery: In the event that a Member forgets their password and requests a reset, an OTP will be sent to verify the account recovery request.
(ii) Method of Receiving OTP
- The OTP shall be sent via SMS to the phone number provided by the Customer during account registration.
(iii) Validity and Effectiveness of OTP
- The OTP shall only be valid for a period of three (03) minutes from the time it is sent. After this period, the Customer must request a new OTP to proceed with authentication.
- The OTP cannot be reused once it has expired or has been successfully used for authentication purposes.
- To ensure security and prevent misuse, Customers may request an OTP a maximum of five (05) consecutive times within a short period. Upon five (05) consecutive requests, the system will temporarily suspend OTP issuance for ten (10) minutes. After such suspension period, the Customer may request a new OTP. However, if the Customer continues to request an OTP five (05) additional consecutive times, the suspension period shall be re-applied.
- If the Customer is subject to five (05) consecutive suspensions (each lasting ten (10) minutes), the system shall permanently block the issuance of OTPs to such Customer. In such case, the Customer will no longer be able to request OTPs and must contact our customer service department for assistance or restoration of access.
(iv) OTP security
- Customers are responsible for maintaining the confidentiality of their OTPs and must not disclose the OTP and/or any device storing such OTP to any third party.
- Any disclosure or misuse of an OTP may result in loss of account access or risks relating to the security of Personal Data.
- LSPV and LPH shall not be liable for any loss or damage arising from the Customer’s disclosure or misuse of the OTP.
(v) No third-party interference
- OTP information is encrypted when transmitted to Customers. The process of sending and receiving OTPs is fully secured, and no party other than the Customer and the systems of LSPV and LPH shall have access to the OTP.
(vi) Handling of OTP-Related violations
- Any misuse of OTPs, unauthorized sharing with third parties, or intentional circumvention of authentication procedures shall be deemed a violation of security regulations. Depending on the severity of the violation, the Customer’s account may be suspended or the Customer may be subject to handling in accordance with applicable laws.
(vii) Customer obligations
- Customers are obliged to provide accurate contact information to receive OTPs. In the event of any change to the phone number, Customers must promptly update such information to avoid disruption in the authentication process (for changes to phone numbers, Members should refer to Article 11: LDSM-P-011 on Member Information Update in the “Membership Policy 2024 – Terms and Conditions”).
- Customers must promptly notify our customer service department in the event of: loss or misplacement of the phone number used to receive SMS messages; fraud or suspected fraud; hacking or suspected hacking incidents related to OTP receipt during use of the Application.
- Members are required to verify and correctly enter the OTP within its validity period in order to complete the registration process on the LS.POINT Application or to reset their password.
(viii) Support contact
- If Customers encounter any issues related to OTPs, they are requested to contact our customer service department for timely assistance.
By registering as a Member of Lotte Department Store and Lotte Mall West Lake Hanoi, the Customer acknowledges and agrees to the security terms relating to OTPs. These provisions may be amended from time to time to meet evolving security requirements and shall be publicly published on the Application.
ARTICLE 5: DESTRUCTION AND RETENTION OF PERSONAL DATA
As a general principle, we shall delete Customers’ Personal Data immediately upon termination of their Membership status at the Customer’s request. However, the Customer’s Personal Data and LS.POINT balance prior to such termination may be restored if the Customer re-registers for the Membership Program within seven (07) days from the date of termination.
Notwithstanding the foregoing, where the Customer has provided separate consent for the retention period of Personal Data, such as in the cases set out in Article 1 above (Collection and Processing of Personal Data), or where we are legally obligated to retain Personal Data for a specified period, we shall securely retain such information for the applicable duration.
Information that is required by law to be retained for a certain period shall be permanently deleted in a manner that renders it irrecoverable and incapable of reproduction immediately upon expiry of such retention period.
We may retain online the Personal Data of Customers who do not use the Application’s Services for a period appropriate to the purposes of data processing in certain cases as consented to by the Customer, unless otherwise required by law. The maximum retention periods for Personal Data are as follows (and may be subject to change in accordance with applicable laws):
|
No. |
Category |
Time |
Items |
|
1 |
Personal Information |
2 years |
Identification information, withdrawal information |
|
2 |
Records of electronic financial transactions |
5 years |
Transaction information |
|
3 |
Service visit records |
2 years |
Log, IPs, etc. |
ARTICLE 6: RIGHTS AND OBLIGATIONS OF CUSTOMER
6.1. Rights of Customers:
- To be informed of the processing of Personal Data;
- To view, access, update, and amend their Personal Data;
- To request suspension or restriction of access to or processing of their Personal Data, in accordance with applicable laws;
- To request the provision, deletion, or restriction of processing of Personal Data, and to submit objections to the processing of Personal Data;
- To request withdrawal of consent for the processing and sharing of Personal Data by terminating their Membership status. To exercise these rights, Customers may access the “My Profile” section on the Application or visit Lotte Department Store or Lotte Mall West Lake Hanoi to submit requests directly. We may require certain information to verify the Customer’s request;
- Members may discontinue use of the Services and remove the LS.POINT barcode from the Google Wallet application at any time. The removal of the LS.POINT barcode shall be performed directly by the Member on the Google Wallet application;
- Other rights as prescribed by applicable laws.
6.2. Obligations of Customers:
- To protect their own Personal Data and request relevant organizations and individuals to safeguard such data;
- To respect and protect the Personal Data of others;
- To provide complete and accurate Personal Data in accordance with applicable laws or when consenting to the processing of their Personal Data;
- To promptly notify LSPV and/or LPH upon discovering or suspecting that their Personal Data has been disclosed or compromised through the use of the Services;
- To regularly review the Privacy Policy of the Membership Program on the LS.POINT Application or on our official websites (https://lotteshopping.com.vn/ and https://lottemallwestlakehanoi.vn/);
- To fulfill other obligations as prescribed by applicable laws.
ARTICLE 7: MEASURES TO ENSURE THE SECURITY OF PERSONAL INFORMATION
LSPV and LPH endeavor to protect Customers’ Personal Data in a secure manner through the following measures:
- We establish and implement internal management plans for the protection of Personal Data, including the development of internal policies addressing Personal Data protection activities, the designation of qualified personnel responsible for Personal Data protection, the application of technical and organisational measures, the provision of periodic training, and the annual monitoring and assessment of compliance with such internal management plans.
- We implement access control measures and restrict access rights to Personal Data. To prevent unauthorized access, we have established and implemented standards for the granting, modification, and revocation of access rights to Personal Data processing systems, and have deployed and operated intrusion prevention and intrusion detection systems. In addition, we mitigate the risk of data leakage within Personal Data processing systems by segregating external internet networks from internal networks for workstations of authorized personnel handling Personal Data.
- We implement encryption measures to securely store and transmit Personal Data. Passwords, unique identification information, and identification documents (including ID cards, citizen identification cards, and passports) are encrypted and stored in accordance with applicable laws. Furthermore, Personal Data is transmitted and received securely via encrypted communication channels.
- We implement measures to maintain access logs and prevent tampering or unauthorized alteration. Individuals processing Personal Data are required to maintain access logs within Personal Data processing systems, and such logs are securely retained to prevent forgery, alteration, theft, or loss.
- We install and regularly update security programs for the protection of Personal Data. To prevent damage to Personal Data, data is regularly backed up and the latest anti-virus software is used to prevent leakage or damage to Personal Data or Members’ data.
- We implement physical security measures for the safe storage of Personal Data. To prevent leakage or damage due to attacks, unauthorized access, or computer viruses, systems are located in restricted-access areas and are subject to access control procedures.
- We shall not be liable for any disclosure or loss of data resulting from the fault of the Member or any third party.
- We shall not be liable for any technical errors, service interruptions, security breaches, or any other faults arising from Google Wallet.
For inquiries, requests, or complaints, please contact:
- LSPV: Service Lounge at 024 3333 2514
- LPH: Service Lounge at 024 3333 8041