Effective date
15 August 2026
1. Who we are
The TAN MBS app is provided by Alvaxis ApS, a company incorporated in Denmark (CVR 44710633, registered at Kronhjortvej 1, 2860 Søborg, Denmark) ("Alvaxis", "the Provider", "we", "us").
The Provider owns, develops, and operates the app platform and licenses the platform to TAN GROUP ENTERTAINMENT COMPANY LIMITED, having its registered address at 1st Floor, No. 207A Nguyen Van Thu, Tan Dinh Ward, Ho Chi Minh City, Vietnam ("TAN Group").
TAN Group operates the dining venues and owns and manages the membership program, including its branding, commercial structure, membership benefits, rewards, and program rules. The membership program is powered by the Provider’s app platform.
In data-protection terms, TAN Group decides why and how the user's personal data is used (the data controller), and Alvaxis processes it on TAN Group's behalf to run the app (the data processor). This policy is issued jointly and applies whenever the user uses the TAN MBS app. Questions may be sent to alvaxis.labs@gmail.com.
2. Information we collect
Account and profile. When the user signs up, we collect the user's full name, email address, phone number, date of birth, and password. The password is stored only as a protected cryptographic hash and cannot be read back. The user can update these details and the user's preferred app language at any time in the user's profile.
Membership activity. Using the app creates records of the user's membership: the user's points transactions and balance, membership tier and tier history, venue bookings (date, time, party size, seating, and any note added by the user), vouchers the user has exchanged, purchased, received as tier rewards, or used, and the user's favorite venues.
Claiming points for the user's bills. To collect points for the user's spending, the user selects the venue in the app and enters the bill number printed on the user's receipt. We record the claim details: the venue, the bill number, and - once the claim is matched against the venue's sales records - the bill amount and the points awarded. The app does not use the user's camera for this or for anything else.
Notifications. If the user turns on push notifications, we store a device notification token so we can deliver messages to the user's phone.
What we do not collect. The app does not track the user's location, use advertising identifiers, run third-party analytics or advertising trackers, use the user's camera, or access the user's contacts or photo library.
3. How we use the user's information
To run the user's membership: the user's activity earns points, and the user's membership tier is calculated automatically from the user's membership activity.
To deliver the services requested by the user: managing the user's bookings, delivering vouchers, and confirming voucher use at the venue.
Service messages. To send the user messages needed to operate the user's account - booking confirmations, reminders, changes and cancellations, points and voucher updates, and security notices. These are sent regardless of the user's marketing preferences because the service cannot work without them.
Marketing messages. To send the user news and promotions only as app notifications (in the app’s notification feed and, if enabled by the user, as push notifications on the user's phone) and only according to the notification settings selected by the user. The user can turn these off at any time.
To send the user booking and points updates through Zalo to the phone number in the user's profile. These are on by default because they concern the user's own bookings and points; the user can turn them off at any time in the app’s settings.
To keep the program fair: detecting and preventing fraud or misuse (for example, the same bill being claimed twice).
To meet legal obligations, such as the venues’ accounting record-keeping for bills and voucher purchases.
4A. Sentry error monitoring
If technical error monitoring is enabled, the app sends Sentry minimized reports needed to diagnose crashes and software errors. A report may include the app version, device and operating-system details, an error message, and a technical stack trace. Sentry is configured not to receive the user's identity, screenshots, view hierarchy, session replay, performance profiles, logs, or network-request data. Access tokens and email addresses are filtered from diagnostic text before a report is sent.
Sentry is our technical error-monitoring provider. It processes these minimized reports so we can detect, diagnose, and fix technical problems, based on our legitimate interest in keeping the app secure and reliable. Sentry is not used for analytics, advertising, or user tracking. Minimized technical error reports may be processed outside Vietnam by Sentry under our service and data-processing terms, with the cross-border safeguards described in section 4.
5. How long we keep it, and deletion
We keep the user's information while the user's account is open. The user can delete the user's account at any time in the app: Profile → Settings → Delete Account.
When the user deletes the user's account, the user's profile and personal details are removed from the app. Some records are kept as required for the venues’ accounting obligations and for fraud prevention - in particular, the points and tier history and the voucher transaction ledger - but in de-identified form and no longer linked to the user. Booking records remain with the venue. Upcoming bookings remain active and are not cancelled automatically when the account is deleted; the user should contact the venue if the user wants an upcoming booking cancelled. The user's identity, contact details, and booking notes are removed from retained booking records. Used voucher codes are retained for the venue's accounting. These retained records are unlinked from the user's identity, are used only for those purposes, and are never used to contact the user.
6. The user's rights and choices
The user can view and correct the user's profile at any time in the app.
The user can turn notifications on or off in the app's notification settings or in the user's phone settings. The user can turn Zalo messages off or back on at any time in the app’s settings.
The user can delete the user's account in the app, as described in section 5.
The user may request access to, correction of, or deletion of the user's personal data, or withdraw consent previously given by the user, by writing to alvaxis.labs@gmail.com. We handle requests in line with Vietnam's Law on Personal Data Protection 2025 (Law No. 91/2025/QH15) and Decree 356/2025/NĐ-CP and, because Alvaxis is established in Denmark, the EU General Data Protection Regulation (GDPR) where it applies.
Under the GDPR, the user may also request a copy of the user's data in a portable format (data portability), ask us to restrict how the user's data is processed, or object to processing based on legitimate interests, using the same contact address.
The user also has the right to complain to a data-protection authority: in Denmark, Datatilsynet (the Danish Data Protection Agency, www.datatilsynet.dk); in Vietnam, the state authority responsible for personal data protection.
7. Security
The user's data is encrypted in transit (TLS), passwords are stored only as protected hashes, and database access is restricted by row-level access rules - members can access only their own records, and staff can access only what their roles allow. No system is perfectly secure, but we protect the user's information with measures appropriate to the risk and respond quickly if a problem occurs.
8. Children
TAN Group membership is for adults aged 18 and over. The app is not directed at children, and we do not knowingly collect personal information from anyone under 18. If the user believes a minor has created an account, the user should contact alvaxis.labs@gmail.com, and we will delete the account.
9. Changes to this policy
If this policy changes, the new version will be published in the app. For material changes, the user will be notified in the app before the changes take effect. The effective date at the top shows when the policy last changed.
10. Contact
Privacy questions, data requests, and general support: alvaxis.labs@gmail.com.
Provider: Alvaxis ApS, Kronhjortvej 1, 2860 Søborg, Denmark.
Venue operator & membership program: TAN GROUP ENTERTAINMENT COMPANY LIMITED, 1st Floor, No. 207A Nguyen Van Thu, Tan Dinh Ward, Ho Chi Minh City, Vietnam.