Product System
Solutions
Risk Control Compliance
Information Security
About Us
Last updated: September 7, 2026
In this Privacy Policy (this “Policy”), we explain how we collect and process personal information about you (whether provided by you or by a third party) when you register for or use our website or our services, and/or when we assist in processing payments on other platforms or websites operated by our clients; when you subscribe to our newsletters, marketing communications, or other communications; and when you interact with us as a prospective customer or user. This Policy sets out the purposes for which we collect and process your personal information, and the legal bases on which we rely to do so.
This Policy applies wherever in the world you access or use our website, mobile application, products, services, or any other channel through which you interact with us (collectively, the “Website” or the “Services”), as well as to any other circumstances in which we process your personal information as a personal information processor or data controller. “Services” means any products, services, technologies, or features provided by iPayLinks (comprising IPAYLINKS LIMITED, PAYLINKS PTE. LTD., and IPAYLINKS UK LLP, individually or collectively referred to herein as “we,” “us,” or “iPayLinks”). Depending on your country or region, the specific product or service you use, and the entity with which you have entered into a service agreement, the iPayLinks entity that provides services to you and is responsible for processing your personal information may vary. Unless expressly stated otherwise, the iPayLinks entity that provides the relevant service to you and establishes a direct business relationship with you is the entity primarily responsible for the corresponding processing of personal information. The specific services we offer may vary depending on your country or region; please refer to the relevant pages on our website for details. Your use of our website and Services, and any dispute concerning your privacy, are governed by this Policy together with our Terms and Conditions of Service.
In this Policy, “you” refers to any individual or business entity that interacts with us directly or indirectly and whose personal information we process, which may include, without limitation:
• End Users: Individuals who directly use, or benefit from, our Services, regardless of whether they use or receive the Services for personal or other purposes. Where a Business Client uses our Services, we may also process the personal information of that Business Client’s End Users in accordance with applicable law.
• Representatives: Individuals who act as owners (including ultimate beneficial owners) of, or on behalf of, a Business Client — for example, employees, directors, or senior officers authorized to manage the Business Client’s account on our platform.
• Visitors: Individuals who visit our website or otherwise communicate with us without having logged into an iPayLinks account — for example, individuals who submit an inquiry to us through a support page.
• Business Clients: Business entities that directly or indirectly use our Services, establish a business relationship with us, or receive our related services, and that provide us with personal information relating to the Business Client and its related activities. Where you (as an End User or Representative) interact with a Business Client, your personal information will be collected, retained, shared, and/or stored in accordance with that Business Client’s own privacy policy, rather than this Policy.
In most cases, the iPayLinks entity that provides the relevant product or service to you determines the purposes and means of processing your personal information, and assumes the role of personal information processor, data controller, or a similar role under applicable law. In certain business scenarios, we may process personal information on behalf of a Business Client. In such cases, we may act as the Business Client’s personal information processor, entrusted party, or other similar role under applicable law, processing personal information in accordance with the relevant Business Client’s instructions; in that processor capacity, the Business Client’s own privacy policy — rather than this Policy — applies to the personal information of the relevant End Users.
If you provide us with any third party’s personal information, you must, to the extent required by applicable law, ensure that you are authorized to provide such information, and that you have fulfilled any notification obligations to, and obtained any necessary authorization from, that third party, including informing them of the content of this Policy so that they understand how iPayLinks will process their personal information. Where required by applicable law, we may ask you to provide evidence that you have fulfilled the relevant notification obligations, obtained the necessary authorization, or otherwise have a lawful basis for providing such information.
Your personal information and privacy are of the utmost importance to us, and we have prepared this Policy to demonstrate our firm commitment to protecting personal information and privacy. We strive to describe our personal information processing activities in clear, easy-to-understand, and concise language. We will highlight in bold terms that may materially affect your rights and interests, as well as content relating to the processing of sensitive personal information, in order to draw your attention to them.
This Policy is intended to set out general privacy and personal information protection principles applicable to our global business. Because different countries and regions impose different legal requirements for the protection of personal information and personal data, additional regional terms (the “Regional Addenda”) attached to this Policy may apply to your jurisdiction. The Regional Addenda further explain, supplement, or restrict this Policy to meet specific requirements under applicable local law. If there is any inconsistency between this Policy and a Regional Addendum applicable to you, or where applicable law imposes mandatory requirements on a given matter, the applicable law and the relevant Regional Addendum shall prevail.
Depending on your location, the Services you use, and the iPayLinks entity providing services to you, among other factors, in addition to the general terms of this Policy, one or more of the following Regional Addenda may also apply to you:
• Additional Terms for Users in Mainland China: applicable to all visitors to our website and mobile application, and users of our products and services, from within mainland China (excluding the Hong Kong, Macau, and Taiwan regions); see Appendix 1 for details.
• Additional Terms for Users in Hong Kong: applicable to all visitors to our website and mobile application, and users of our products and services, from the Hong Kong Special Administrative Region; see Appendix 2 for details.
• Additional Terms for Users in Singapore: applicable to all visitors to our website and mobile application, and users of our products and services, from Singapore; see Appendix 3 for details.
• Additional Terms for Users in the United Kingdom: applicable to all visitors to our website and mobile application, and users of our products and services, from the United Kingdom; see Appendix 4 for details.
Please note that you may be subject to the data protection laws of more than one jurisdiction at the same time; in such cases, we will fulfil our personal information protection obligations in accordance with all applicable laws.
“Personal information” or “personal data” means any information that can directly or indirectly identify you, such as your name, address, telephone number, email address, date of birth, bank account information, and any other data related to your identity. The specific categories of personal information we process are set out in Section II (“What Types of Personal Information Do We Collect”). This section describes in detail the channels and methods through which we collect your personal information.
When you access or use our website at www.ipaylinks.com (the “Website”), our mobile application, our API, or other digital channels, we may automatically collect information about your device, browsing behavior, log data, location, and network connection. Our server software records the domain name of your computer or device and may track which pages of our products or services you have visited, for purposes such as measuring traffic, understanding the popularity of different sections, gaining basic insight into our audience, and compiling statistics. We use cookies and other similar technologies to collect information about how you use our website and application. We may apply strictly necessary cookies without relying on your consent; for non-essential cookies or similar technologies that require consent under applicable law, we will obtain your consent or provide you with an appropriate choice mechanism in accordance with applicable law. For further information, please refer to our Cookie Policy.
If you wish to register for and use our products and services, you will need to actively provide certain personal information — for example, when you:
• register for or manage an account;
• apply to use our products or services;
• complete identity verification, Know Your Customer (“KYC”) due diligence, or other compliance procedures;
• make or receive a transaction;
• contact our customer support team;
• submit an inquiry, feedback, complaint, or other request;
• subscribe to marketing or other communications;
• participate in a market survey, event, or promotional activity;
• require our assistance in completing a payment on another platform or website operated by our Business Client.
We may collect the relevant information you provide in order to assess your application to use (or continue to use) the services or products we offer. The types of information we actually collect may vary depending on the product, service, and jurisdiction concerned. Whether you are required to provide specific personal information will depend on the relevant service and applicable law. Where we clearly identify certain information as necessary, if you decline to provide it, we may be unable to process your application, establish or maintain the relevant account, complete a transaction, fulfil a legal obligation, or provide you with the relevant service.
In the course of providing payment, account, identity verification, risk management, or other services, we may collect your personal information from other lawful sources, including partner agents, financial institutions, internet platforms, affiliates, other iPayLinks users, and other third-party service providers (which may include providers of identity verification, KYC, anti-money laundering (“AML”), sanctions screening, fraud detection, credit risk assessment, and other risk management services). Where required by applicable law, we require the relevant third parties to ensure that they have an appropriate legal basis for providing us with personal information, and, where necessary, to fulfil any required notification obligations to the relevant individuals.
Where applicable law requires us to obtain your consent, or where we intend to use personal information for a new purpose that is materially different from the original purpose of collection, we will fulfil our corresponding obligations in accordance with applicable law.
To the extent permitted by applicable law, we may obtain information about individuals or Business Clients from public databases, publicly available information from government or regulatory authorities, corporate registries, commercial information databases, publicly accessible websites, or other lawful sources.
The types of personal information we collect depend on the specific nature of your interaction with our website and/or Services, including where we assist you with processing payments on other platforms or websites operated by our clients, and, to the extent permitted by applicable law and relevant to your use of the Services: depending on the type and nature of the products and services you use (or continue to use), you may be asked to provide us with, or we may obtain from third parties relating to you, the following types of personal information:
• Basic identity information (such as name, contact details, email address, billing or mailing address, telephone number, country of residence, residential address, date of birth, identification card/passport details, and photographs holding identification documents)
• Compliance and risk information (such as KYC information, AML information, sanctions list screening, Politically Exposed Person (“PEP”) screening results, fraud risk information, transaction risk scores, adverse media information, and other information relevant to risk assessment, financial crime prevention, or regulatory compliance)
• Records of our communications with you (including voice recordings and call records)
• Professional details (such as occupation, directorships and other positions held, employment history, and salary and/or benefits)
• Business information (such as information about your business)
• Financial and transaction information (such as bank and credit account information, credit records (where applicable), and details of transactions conducted using any of our services, including the amount and currency, and the products/services purchased)
• Background check information (such as credit records)
• Information you provide when contacting our support team, and any suggestions or complaints you raise
• Your email and marketing preferences, including interest and marketing list assignments, marketing opt-outs, preferred language, and website and application data
• Your device data and log information (obtained through cookies, web beacons, advertising IDs, and similar technologies), including IP address, device ID and type, browser type, geolocation information, wireless and mobile network connection information, details of your use of our website and mobile application, browsing history, search queries, and session frequency
• Any other information we receive or may generate (for example, when you email us or otherwise contact us, or when you choose to participate in a survey or provide feedback on our services), including telephone calls, emails, meetings and related conversations, voicemail, recordings, transcripts, and any other communications
You are responsible for providing accurate and up-to-date information.
Certain jurisdictions classify some personal information as “sensitive personal information,” “sensitive personal data,” “special category personal data,” or other information subject to enhanced protection. Depending on your country or region and the specific products or services you use, such information may include financial account information, identification information, biometric information, or other information subject to enhanced protection.
Whether and how we process such information will be determined based on the specific type of information, the purpose of processing, and applicable law; a single processing activity may be based on more than one legal basis at the same time. We will not treat your continued use of the Services as your consent to all personal information processing activities. For processing activities that require additional protective measures, separate consent, or other special conditions under applicable law, we will comply with the relevant legal requirements.
Depending on your location and the requirements of applicable law, the legal basis on which we process your personal information may include one or more of the following:
• your consent has been obtained;
• processing is necessary for the conclusion or performance of a contract with you;
• processing is necessary for compliance with a legal obligation to which we are subject;
• processing is necessary to protect your vital interests or those of a third party;
• processing is necessary for the performance of a statutory duty or in the public interest; or
• processing is necessary for the purposes of our legitimate interests or those of a third party, provided that such interests are not overridden by your legitimate rights and interests.
Different jurisdictions may provide other independent bases or exceptions for processing personal information. The specific legal basis and its applicable conditions are subject to the Regional Addenda applicable to you and local law.
We collect and process your personal information in the course of your use of our Services, your access to our website, or your business interactions with us, in accordance with applicable laws and regulations. We will only use your personal information to the extent necessary to achieve the following purposes:
• Identity Verification and Account Security Management: to verify your identity (including, where applicable, via SMS, voice call, or other means), and to confirm your access to and control over the bank account or other account information associated with our Services.
• KYC, AML, Sanctions Screening, Fraud Prevention, Financial Crime Prevention, Transaction Monitoring, and Other Applicable Regulatory or Legal Obligations: to conduct customer identification, customer due diligence, sanctions and risk screening, transaction monitoring, and financial crime prevention, and to fulfil applicable legal and regulatory obligations.
• Providing, Maintaining, and Managing Our Services: to register your account and provide the services you have applied for or use, including services provided jointly with our partners; to support your completion of payments on platforms or websites operated by, or affiliated with, our clients; and to communicate with you regarding service-related matters, including the KYC verification process, service notices, updates to terms and conditions, or changes to this Privacy Policy.
• Responding to Your Requests and Providing Customer Support: to handle requests you make to us, including responding to your inquiries, providing information you need, addressing customer service matters, and communicating with you by SMS, messaging applications, or other appropriate means.
• Optimizing and Personalizing Your Service Experience: to provide you with more suitable content, features, and services based on your usage and preferences, including, where permitted by applicable law, location-based information services, personalized guidance and support, and assessing your eligibility for new services, features, or enhanced service experiences.
• Marketing and Business Promotion: where necessary authorization has been obtained or you have not opted out of the relevant communications, to send you information about our services, products, events, news, offers, or other information that may be of interest to you, including by email, SMS, telephone, mobile application, or other means, and to manage event registrations, prize draws, or reward distribution and related matters.
The processing basis for specific marketing activities will be determined in accordance with applicable law. Certain jurisdictions or specific marketing channels may require us to obtain your consent before sending marketing communications; in other cases, applicable law may permit us to carry out marketing activities on other lawful bases.
You may unsubscribe from or opt out of receiving marketing communications at any time using the unsubscribe or opt-out method provided in the relevant marketing communication.
• Conducting Product Promotion and Marketing Activities: to the extent permitted by applicable law, to promote our products and services through email, third-party websites, social media platforms, telephone, or other channels.
• Analyzing, Improving, and Optimizing Our Services: to understand how users access and use our website and Services, in order to carry out service operations management, technical optimization, security maintenance, product improvement, vendor management, user feedback analysis, and other research and analysis activities. For information on how we collect related information through cookies and similar technologies, please refer to our Cookie Policy.
• Safeguarding Service Security and Preventing Risk: to protect us, our clients, employees, partners, and related assets, including conducting risk management, assessing and managing accounts, detecting and investigating fraud, and preventing unlawful activity, service abuse, harassment, and other conduct that violates applicable law, this Policy, or our terms of service.
• For purposes directly related to, or incidental to, any of the foregoing.
The services we offer are continually being updated and developed. If you choose to use another service not yet described in this Policy, we will separately explain, through page notices, interactive prompts, or contractual arrangements, the scope and purposes of any additional personal information collection, and will obtain your consent. If you choose not to provide the relevant necessary information, you may be unable to use a particular service or part of a service, but this will not affect your ability to use our other services.
As a global company, iPayLinks may share your personal information with our group affiliates, business partners, and related service providers (the “Relevant Parties”) in order to provide you with our Services, fulfil legal and regulatory obligations, safeguard the security of our Services, and improve our products and services.
We may share your personal information with Relevant Parties for the following purposes:
• Group Affiliates: to assist us in providing, maintaining, and managing our products and Services, and to fulfil obligations relating to anti-money laundering, sanctions screening, fraud prevention, business operations, risk management, compliance management, technical support, customer support, or other statutory obligations, where necessary.
• Payment Service Providers and Business Partners: including banks, payment service providers, acquiring institutions, and other financial institutions, to support account opening, transaction processing, funds settlement, account management, and other activities related to the provision of our Services. This includes, but is not limited to, information relating to your identity and that of any ultimate beneficial owner.
• Identity Verification, Risk Management and Security Services, and Technology and Data Service Providers: including providers that carry out identity verification, KYC due diligence, transaction monitoring, fraud detection and risk control; providers of technical or infrastructure support; cloud storage and internet service providers; software service providers; technology providers (including artificial intelligence solutions or machine learning applications); and data and cybersecurity service providers — used to verify your identity, to prevent, detect, and deter fraudulent activity or service abuse, to safeguard account and system security, to protect the lawful rights and interests of users and the public, and to fulfil our compliance obligations.
Some identity verification, fraud prevention, risk management, and compliance service providers may, in accordance with their own business models and applicable law, retain, analyze, or use relevant information to the extent necessary to provide the relevant services, in order to maintain and improve their identity verification, risk identification, fraud prevention, or compliance databases and services. To the extent permitted by applicable law, such service providers may, based on relevant risk information, provide identity verification, risk identification, or fraud prevention services to their other clients.
• Advertising, Analytics, and Business Optimization Service Providers: used to analyze and improve our products, services, and user experience, to conduct business operations analysis, and, to the extent permitted by applicable law, to carry out marketing activities, including IT service providers and SMS service providers.
• Government Agencies, Regulatory Authorities, Law Enforcement, and Judicial Bodies: where required by law or regulation, or in response to valid legal process (including court orders, subpoenas, or other lawful requests), we may disclose relevant information. Such disclosures may be made with or without your consent, and with or without notice to you, but will always be made in accordance with the terms of valid legal process, including, without limitation, regulatory inquiries or requests, subpoenas, court orders, or search warrants. Under the terms of such legal process, we are generally prohibited from notifying you of any such disclosure.
• Professional Advisors: including lawyers, auditors, tax advisors, and other professional service providers, for the purpose of providing professional services, fulfilling contractual obligations, conducting audits, or responding to legal proceedings and compliance requirements.
• Parties Involved in a Business Transfer: in the event of a merger, acquisition, reorganization, asset transfer, or similar transaction, we may disclose necessary personal information to the relevant transaction parties, who will continue to bear the corresponding data protection obligations in accordance with applicable law and this Policy.
• Other Third Parties Authorized by You: to share necessary personal information with third parties designated by you, in accordance with your authorization or instructions.
We will not share your personal information in any manner that exceeds what is permitted under applicable law.
For sharing activities that require your consent or the fulfilment of other statutory procedures, we will comply with the relevant requirements to the extent required by applicable law.
Given the global nature of our business, technical infrastructure, and service providers, your personal information may be transferred to, stored in, accessed from, or processed in countries or regions outside of the one in which you are located, including mainland China, the United States, and other countries or regions.
For example, we may use cloud infrastructure and technology service providers located in the United States or other countries or regions to store and process relevant information, and authorized personnel located in other countries or regions may remotely access such information to the extent necessary to provide customer support, operational management, risk control, technical maintenance, or compliance services.
Please note that when your personal information is transferred outside of your country or region, those countries may not offer a level of personal information protection equivalent to that of your own country or region. We will take a variety of measures to ensure that any international transfer is properly managed in accordance with applicable rules and that your data is processed securely. The specific arrangements for cross-border transfers will be subject to the applicable Regional Addenda and local laws and regulations, and may include, without limitation:
• assessing the security measures of the countries or regions to which your personal information is transferred;
• putting in place appropriate contractual clauses requiring the data recipient to process information only in accordance with our instructions; and
• establishing ongoing monitoring, reporting, and resolution procedures relating to the security of your personal information.
We will also take additional protective measures for higher-risk personal information in accordance with applicable law, including access controls, encryption, logging, permission management, de-identification, or other appropriate technical measures.
We may store and process your personal information through our own information systems, or through third-party cloud services or other technology service providers. Based on the nature of the personal information, the purpose of processing, the relevant risks, and applicable law, we adopt physical, electronic, and managerial security measures consistent with industry standards, and endeavor to protect your personal information from unauthorized access, alteration, disclosure, or destruction, including, without limitation: regularly reviewing our information collection, storage, and processing practices (including physical security measures); applying technical measures such as encryption, access controls, and de-identification/anonymization to sensitive information; and limiting access to relevant personal information to employees and related parties who need such access for business purposes and who are subject to strict confidentiality obligations.
You acknowledge that, due to the inherent security risks associated with transmission over the internet, although we will make every effort to protect your personal information, we cannot guarantee the absolute security of data you disclose online, and the risks associated with transmitting data to our website are borne by you. Once we receive your information, we will use strict procedures and security features to make every effort to prevent unauthorized access.
We retain your personal information only for as long as is necessary and reasonable to provide you with our Services, and for such other periods as may be permitted or required by applicable law. In determining the appropriate retention period, we take into account the purpose of collecting and processing personal information, the volume, nature, and sensitivity of the personal information, the risk of harm that could result from unauthorized use or disclosure, and applicable legal, regulatory, tax, and accounting requirements, among other factors. Once personal information is no longer necessary to retain for a lawful purpose, we will delete, anonymize, or otherwise appropriately dispose of your personal information in accordance with applicable law.
You acknowledge and agree that, when you stop using our Services, close your account, or terminate your business relationship with us, we may nevertheless continue to retain certain personal information for such period as may be required for legal, regulatory, tax, accounting, dispute resolution, fraud prevention, financial crime prevention, or other lawful purposes. The specific retention period may vary depending on the type of product/service, type of information, business relationship, KYC/AML requirements, regulatory requirements, dispute resolution needs, and applicable law.
Our website and Services are, in principle, intended for use by adults only. Unless otherwise required by applicable law or necessitated by a specific business scenario involving the processing of a minor’s personal information, we do not knowingly collect personal information directly from minors. If we are required to process a minor’s personal information, we will, to the extent required by applicable law, obtain the consent of the minor’s parent or other guardian and adopt specific protective measures and processing rules.
If we become aware that we have inadvertently collected personal information from a minor that we should not have collected, we will take reasonable measures to promptly delete the relevant data, unless otherwise required by applicable law or regulation.
Our website may contain links to third-party websites or services, such as third-party integrations, co-branded services, or third-party branded services (“Third-Party Websites”). Clicking on or enabling these links may allow third parties to collect or share personal information about you. We do not own or control these Third-Party Websites, and when you interact with them, you may provide your personal information directly to the Third-Party Website, to iPayLinks, or to both. The collection, use, and disclosure of your personal information by a Third-Party Website will be governed by that Third-Party Website’s own privacy policy. Please review the relevant policy for further information.
We may use automated processing, risk scoring, identity verification, and other technical tools for identity verification, KYC/AML, fraud prevention, transaction monitoring, account security, and risk management purposes.
Where applicable law provides that a particular automated process constitutes a decision made solely through automated processing that produces legal or similarly significant effects on you, we will provide appropriate safeguards in accordance with applicable law, including, where applicable, the provision of an explanation, human intervention, and the right to object or request a review.
We may update this Policy from time to time to reflect changes in our business, products, technology, or applicable laws and regulations. In the event of a material change to this Policy, we will notify you in a timely manner through pop-up notices, push notifications, email notices, or announcements on our official website.
You may review the latest version of this Policy at any time via the “Privacy Policy” page at www.ipaylinks.com. Except as otherwise provided by law, we expressly reserve the right to amend this Policy at any time. Updates to this Policy will take effect from the date of publication or the effective date specified therein. For material changes, we will provide notice to you through appropriate means in accordance with applicable law; where applicable law requires your consent, we will obtain your consent in accordance with law before the relevant changes take effect. We recommend that you regularly review this Policy for updates or changes and read it carefully whenever you visit our website.
Subject to applicable law, you may request a copy of your personal information, request correction or deletion of a copy of personal information that is inaccurate, incomplete, unclear, or outdated, request that we restrict processing, object to processing, request data portability, request human intervention, or object to an automated decision. The foregoing rights are subject to any exceptions, restrictions, and conditions provided under applicable law. To exercise any such rights, please contact us through any of the communication channels listed in the “How to Contact Us” section of this Policy.
This Policy is intended to explain to you how we collect, use, disclose, store, and protect your personal information, as well as the rights you are entitled to under applicable law. The application of this Policy does not mean that we rely on your consent as the legal basis for all personal information processing activities. Depending on the specific processing activity and applicable law, we may process your personal information based on contractual performance, legal obligation, legitimate interest, public interest, your consent, or other bases permitted under applicable law. By clicking to register and/or agreeing to and checking the box for this Policy, you agree that the personal information you provide, and that we collect from time to time, may be used and processed for the purposes described in this Policy, and disclosed to the appropriate parties described in this Policy.
If you are a user of iPayLinks’ Services and wish to update your personal information, please log in to your “iPayLinks Account” to update certain information, or contact us using the contact details below. If you are not a user of iPayLinks’ Services but have provided us with personal information, or if your personal information was provided by a third party, and you wish to update it, you may contact us through any of the communication channels listed below.
If you wish to exercise any rights granted to you under applicable law with respect to your personal information or personal data, or if you have any questions, comments, or complaints regarding the processing of your personal information, please contact us according to your region and the iPayLinks entity with which you have a business relationship, using the following contact details:
IPAYLINKS LIMITED
Email: data-protection@ipaylinks.com
Mailing Address: Unit 1119, 11/F, Admiralty Centre Tower 2, 18 Harcourt Road, Admiralty, Hong Kong
Contact Number: 400-137-0157
PAYLINKS PTE. LTD.
Email: singapore@ipaylinks.com
Mailing Address: 36 Robinson Road, #02-125, City House, Singapore 068877
IPAYLINKS UK LLP
Email: data-protection@ipaylinks.com
Mailing Address: Floor 18, 100 Bishopsgate, London, United Kingdom, EC2N 4AG
The specific rights and obligations relating to the processing of your personal information under this Policy shall be governed by the mandatory data protection laws of your jurisdiction. For other matters not governed by mandatory data protection laws, the applicable law and dispute resolution arrangements shall be as set out in the service agreement applicable to you.
Appendix 1: Additional Terms for Users in Mainland China (Excluding Hong Kong, Macau, and Taiwan)
This Appendix applies to all users who access our website or mobile application, or use our products and services, from within mainland China (excluding the Hong Kong, Macau, and Taiwan regions). This Appendix is formulated in accordance with the Personal Information Protection Law of the People’s Republic of China (“PIPL”), the Cybersecurity Law of the People’s Republic of China, the Data Security Law of the People’s Republic of China, and other applicable laws and regulations. For Business Clients in mainland China, the relevant services are generally provided by IPAYLINKS LIMITED. Personal information provided by employees, directors, authorized representatives, or other relevant personnel of a mainland China Business Client is primarily processed by that service entity in accordance with applicable law.
In accordance with the Personal Information Protection Law of the People’s Republic of China, we will select the applicable legal basis depending on the specific processing activity, including:
1. your consent has been expressly obtained (including, in certain circumstances, separate consent or written consent as required by the PIPL);
2. processing is necessary for the conclusion or performance of a contract to which you are a party;
3. processing is necessary for the performance of a statutory duty or statutory obligation;
4. processing is necessary to respond to a public health emergency, or, in an emergency, to protect the life, health, and property safety of a natural person;
5. processing is carried out within a reasonable scope for news reporting, public opinion supervision, or other activities conducted for the public interest;
6. processing is carried out within a reasonable scope of personal information that you have already disclosed or that has otherwise been lawfully made public; or
7. processing is carried out in other circumstances provided by law.
For processing activities requiring consent under applicable law, we will obtain your consent in an appropriate manner in accordance with applicable law.
If you withdraw your consent, we will, in accordance with applicable law, stop processing the relevant personal information based on that consent; however, withdrawal of consent will not affect the lawfulness of any personal information processing activities carried out prior to the withdrawal based on your consent.
Sensitive personal information refers to personal information that, if leaked or unlawfully used, could easily infringe upon your personal dignity or endanger your personal or property safety, including information relating to biometric characteristics, religious belief, specific identity, medical history and health, financial accounts, and location tracking, as well as the personal information of minors under the age of fourteen. We only process such information where there is a specific purpose and sufficient necessity, and subject to strict protective measures. Depending on the specific product/service, this may involve financial account, transaction, identification, or biometric-related information. Where applicable law requires separate consent, we will obtain your separate consent before processing.
Subject to applicable law, you are entitled to exercise the following rights:
1. the right to be informed of our personal information processing rules and related processing activities;
2. the right to access and obtain a copy of your personal information;
3. the right to request correction or completion of inaccurate or incomplete personal information;
4. the right to request deletion of your personal information;
5. the right to withdraw consent;
6. the right to request that we explain our processing rules;
7. the right, in accordance with applicable law, to request that we restrict a specific personal information processing activity;
8. the right, where the conditions specified by the national cyberspace administration are met, to have your personal information transferred to another personal information processor designated by you;
9. the right, with respect to a decision made solely through automated decision-making that has a material effect on your rights and interests, to request an explanation and to refuse to have such a decision made solely through automated decision-making; and
10. such other rights of a personal information subject as may be provided by law.
You may submit relevant requests through the channels listed in the “How to Contact Us” section of the main body of this Policy. We may take reasonable measures to verify your identity in order to prevent unauthorized access to, alteration of, or deletion of personal information.
As the relevant services are provided by an offshore entity, your personal information may be collected, stored, accessed, and processed outside of mainland China, including through the use of cloud infrastructure located in the United States or other countries or regions.
To provide customer support, operations, risk control, technical maintenance, and compliance services, authorized personnel may remotely access your personal information from mainland China or other countries or regions.
We will adopt applicable personal information export compliance mechanisms in accordance with applicable Chinese laws, regulations, and the specific data processing scenario. For personal information that may lawfully be transferred cross-border on the basis of contractual performance, statutory obligation, your consent, or other legally prescribed circumstances, we will process such information within the scope permitted by law.
We may use automated decision-making tools during account registration review and payment transaction processes to fulfil statutory compliance obligations such as anti-money laundering (AML) and Know Your Customer (KYC), and to assess your eligibility to use our Services and related security risks. Such tools will conduct authenticity verification and risk screening based on the identity information, identification document images, and selfie photographs that you actively submit, and may produce outcomes such as requiring additional supporting materials or temporarily restricting transactions. If such an automated decision has a material effect on your personal rights and interests (such as account eligibility or transaction execution), you have the right to request that we provide an explanation, and you have the right not to be bound by a decision made solely on the basis of automated processing.
We will retain your personal information for the minimum period necessary to achieve the purpose of processing, and will delete, anonymize, or otherwise handle it in compliance with applicable law and regulatory requirements, or other legitimate and necessary grounds. Information that must continue to be retained for AML, KYC, anti-fraud, regulatory, tax, or dispute resolution purposes will not be affected by closure of your account.
Where laws and regulations prescribe a minimum retention period, or where retention of relevant information is necessary for fulfilling statutory obligations, resolving disputes, meeting regulatory requirements, or protecting our legitimate interests, we may continue to retain the relevant information for the applicable period.
You should note that your personal information will be collected outside of mainland China, and that such personal information is necessary for iPayLinks to provide the Services. Your personal information may be collected and stored at a destination outside of mainland China.
In the event of an actual or potential personal information security incident, we will take appropriate remedial measures in accordance with applicable laws and regulations of the People’s Republic of China, and, where required by law, report the incident to the relevant competent authorities. Where applicable law requires that specific information about the incident be provided to affected individuals, we will fulfil our notification obligations in accordance with law.
This Appendix applies to all users who access our website or mobile application, or use our products and services, from the Hong Kong Special Administrative Region. IPAYLINKS LIMITED generally acts as the primary data user of the personal data of relevant Hong Kong users. This Appendix is formulated in accordance with the Personal Data (Privacy) Ordinance (Cap. 486 of the Laws of Hong Kong) (“PDPO”) and other applicable laws and regulations.
Providing us with your personal data under the main body of this Policy is voluntary. However, if you do not provide the necessary information we request, we may be unable to provide you with the relevant Services, or the provision of such Services may be affected.
We will only use personal data to the extent that it is directly related to, and reasonably necessary for, the purpose for which it was collected.
Before using your personal data for direct marketing purposes, we will clearly inform you of the marketing purpose and obtain your separate consent, and you have the right to withdraw your consent at any time, upon which we will immediately cease the relevant use.
If personal data is to be disclosed to a third party for marketing purposes, we will obtain your additional written authorization. Such third parties may include our group affiliates, marketing service providers, and unaffiliated partners with whom we jointly promote financial products. Only after you have provided such authorization will we and the above-mentioned partners send you promotional information.
The PDPO grants you the right to access and obtain a copy of the personal data we hold about you. If you find that any personal data is inaccurate, you have the right to request that we correct it.
Your personal data may be transferred outside of Hong Kong and may be accessed or processed by group affiliates, service providers, or authorized personnel located in other jurisdictions, including for the purposes of providing Services, cloud storage, identity verification, KYC, AML, fraud prevention, and technical support, or other lawful business purposes.
We will adopt reasonable security measures based on the nature and purpose of the personal data and applicable legal and regulatory requirements, and will delete or anonymize the relevant data once it is no longer necessary to retain it.
This Appendix applies to all users who access our website or mobile application, or use our products and services, from Singapore. This Appendix is formulated in accordance with the Personal Data Protection Act (the “PDPA”) and the advisory guidelines issued by Singapore’s Personal Data Protection Commission (“PDPC”). Under the PDPA, the data controller/organisation responsible is PAYLINKS PTE. LTD.
Providing us with your personal data under this Policy is voluntary. However, if you do not provide the necessary information we request, we may be unable to provide you with the relevant Services, or the provision of such Services may be affected.
Except where otherwise permitted by law, we will only collect, use, or disclose your personal data with your consent or where there is another lawful basis for doing so (such as contractual performance, legal obligation, or legitimate interest).
If you provide us with a third party’s personal data, you confirm that you are entitled and duly authorized to provide us with that third party’s personal data.
You may withdraw any consent previously given at any time by giving us reasonable notice. Upon receipt of a valid withdrawal request, we will cease collecting, using, or disclosing your personal data to the extent covered by the withdrawal, unless the PDPA or other applicable law permits or requires us to continue processing.
We will inform you of the practical consequences that may result from withdrawing your consent before you do so — for example, that we may as a result be unable to continue providing certain products or services.
You may request that we provide you with the personal data we hold about you, and information about how that data has been used and disclosed during the twelve months preceding your request, and you may request correction of any inaccurate personal data, in each case as permitted by law.
You may be required to verify your identity when exercising these rights. Where permitted by applicable law, we may charge you a reasonable fee to process your request.
We will process access requests as soon as reasonably practicable, while reserving the right to refuse a request, in whole or in part, in accordance with the PDPA.
Except where required by law or necessary to establish or verify an individual’s identity with a high degree of accuracy, we generally do not use the whole or any part of a Singapore National Registration Identity Card (“NRIC”) number as an account login password, default verification credential, or other identity verification factor.
Your personal data may be transferred, stored, or accessed outside of Singapore, including in the United States and other countries or regions. We will take appropriate measures in accordance with the PDPA and applicable regulations to ensure that overseas recipients provide a standard of protection for personal data that is comparable to that required under the PDPA.
In the event of a personal data breach, we will assess, in accordance with the PDPA, whether the incident meets the threshold requiring notification to the PDPC or to affected individuals, and will fulfil the corresponding notification obligations as required by law.
This Appendix applies to all users who access our website or mobile application, or use our products and services, from the United Kingdom. This Appendix is formulated in accordance with the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (“PECR”), and the Data (Use and Access) Act 2025 (“DUAA”).
Under the UK GDPR, the data controller is IPAYLINKS UK LLP, located at Floor 18, 100 Bishopsgate, London, United Kingdom, EC2N 4AG. The company is incorporated in the United Kingdom and, in its capacity as data controller/processor, is subject to the regulatory oversight of the UK Information Commissioner’s Office (“ICO”). If you have any questions about this Appendix, please contact our Data Protection Officer (“DPO”) at data-protection@ipaylinks.com.
We process your personal data on the basis of one or more of the following legal bases set out in Article 6 of the UK GDPR:
(1) performance of the contract with you (i.e., the terms and conditions applicable to our Services), or to take steps requested by you prior to entering into a contract;
(2) compliance with a legal obligation;
(3) protection of vital interests;
(4) performance of a task carried out in the public interest or in the exercise of official authority;
(5) processing necessary for the purposes of our legitimate interests or those of a third party, where those interests are not overridden by your interests or fundamental rights and freedoms requiring protection of your personal data, and, where applicable, subject to completion of the necessary balancing test. This may include processing your personal information to identify or prevent suspicious or high-risk transactions or fraudulent activity, conducting internal research and analytical assessments in order to communicate with you, and informing you about new products and services we are offering, or promoting other parties’ new products and services that we believe may be of interest to you; where applicable, we may rely on a recognized legitimate interest processing mechanism introduced or confirmed by the DUAA;
(6) your consent.
Before relying on legitimate interests, as described in Section IV (“Why Do We Process Your Personal Information”) of the main body of this Policy, to process your personal information, we assess whether such processing is necessary and carefully consider the impact of our processing activities on your fundamental rights and freedoms. Overall, we consider that such processing is consistent with our legitimate interests and that the processing we carry out does not create any new adverse impact on your fundamental rights and freedoms.
Where we process your data on the basis of special category personal data as defined under Article 9 of the UK GDPR — such as health information, biometric information, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, genetic information, or data concerning sex life or sexual orientation — we will, in addition to satisfying a general lawful basis for processing, meet the additional conditions required under Article 9.
Depending on the specific processing activity and applicable law, you may have the following rights:
(1) Right to be informed: You have the right to understand how we collect, use, store, and disclose your personal data, including our purposes of processing, legal basis, the source of the data, the recipients of the data, the data retention period, and your related rights under applicable law.
(2) Right of access: You have the right to request confirmation as to whether we are processing your personal data, and to obtain a copy of that personal data. You will generally not be required to pay for a copy of your personal data; however, if your request is unfounded, excessive, or made with unreasonable frequency, we may charge a reasonable fee depending on the circumstances. We will notify you of any applicable fee before completing your request.
(3) Right to rectification: If you believe that personal data we hold about you is inaccurate, incomplete, or requires updating, you have the right to request that we correct it. If we have disclosed the relevant personal data to a third party, we will, where applicable, take reasonable steps to notify that third party of the correction. If we are unable to fulfil your request to correct your personal data, we will inform you and explain the reasons.
(4) Right to erasure: You have the right, in certain circumstances, to request that we delete your personal data. This right is not absolute, and we may be unable to delete the relevant personal data where the law permits or requires us to continue to retain it.
(5) Right to restrict processing: In certain circumstances, you have the right to request that we restrict the processing of your personal data.
(6) Right to data portability: Where applicable, you have the right to request that we provide you, in a structured, commonly used, and machine-readable format, with the personal data that you have actively provided to us, and to request that we transmit that data to another data controller designated by you.
(7) Right to object: You have the right to object to our processing of your personal data based on legitimate interests or the public interest. If you object, we will stop the relevant processing unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defense of legal claims. You have an absolute right to object to processing for direct marketing purposes. You may ask us at any time to stop using your personal data for direct marketing, including any related profiling activities.
When conducting direct marketing by email, SMS, or other electronic communications, we will also comply with PECR and other applicable electronic communications marketing rules.
(8) Right to withdraw consent: Where we process your personal data on the basis of your consent, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of processing carried out on the basis of consent prior to its withdrawal.
(9) Rights relating to automated decision-making and profiling: If we carry out automated decision-making or profiling, you may, under applicable law, have related rights, including the right to request human intervention, to express your point of view, and to contest the relevant decision. See Section 5 of this Appendix for further details.
(10) Right to lodge a complaint with the UK ICO: If you believe that our processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with the UK Information Commissioner’s Office (“ICO”). You may also contact us using the contact details set out in the main body of this Policy before lodging a complaint with the ICO, so that we may address your query or request.
We generally aim to respond within one calendar month of receiving a valid request; for complex requests or a high volume of requests, we may, where legally permitted, extend the response period.
The rights described above may be subject to restrictions and exceptions under the UK GDPR, the Data Protection Act 2018, the DUAA, and other applicable laws.
Given the global nature of our business, group operations, and technical infrastructure, your personal data may be transferred to, stored in, accessed from, or processed in countries outside the United Kingdom, including the United States, mainland China, and other countries or regions.
Authorized personnel located in mainland China or other jurisdictions may remotely access your personal data to the extent necessary for providing customer support, operations, risk management, technical maintenance, or compliance services.
Where required by the UK GDPR and other applicable UK data protection laws, we will implement appropriate data transfer safeguards, including applicable adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum, other recognized data transfer mechanisms, or other measures permitted by law.
Where a transfer risk assessment or other assessment is required, we will fulfil the corresponding requirements in accordance with applicable law.
In certain business processes, we may use automated processing and risk assessment tools to assess your eligibility to use our Services, transaction risk, and related security matters. Such automated processing is used primarily to prevent fraud, to conduct security and risk assessments, and to assist us in fulfilling applicable anti-money laundering (AML) and Know Your Customer (KYC) regulatory obligations.
Automated processing may include, without limitation:
(1) Review of registration applications: We may use automated tools to analyze the information you provide during registration to help determine whether your application can be approved, or whether you need to provide further supplementary information or documentation;
(2) Review of payment transactions: We may use automated tools to assess the risk of your payment transactions, to help determine whether a transaction can be executed, or whether further verification of information is required;
(3) Identity verification and document review: To fulfil applicable AML and KYC obligations, we may use automated tools to assist in verifying your identity, for example through selfie images, identification documents, or other identity information.
Where the relevant automated processing constitutes an automated decision under applicable law that produces a legal or similarly significant effect on you, you may, under applicable law, have the following rights:
(1) to request that we provide information about the relevant automated decision;
(2) to request human review of the relevant decision;
(3) to express your point of view to us and to submit relevant supplementary information or explanation; and
(4) to contest the outcome of an automated decision or request that it be reassessed.
The above rights are not absolute. Where permitted by law — for example, where the automated processing is necessary for entering into or performing a contract, is expressly authorized by law, or is based on your explicit consent — we may continue the relevant automated processing, while taking appropriate measures to protect your legitimate interests.
To process your request to exercise the above rights, we will take necessary internal steps to verify your identity.