Privacy Policy

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua.

UPPAYLINKS Privacy Policy

Last Updated: June 17, 2026

Welcome to our platform. This Privacy Policy (“Policy”) governs how we collect, process, store, and safeguard your corporate and personal data when you visit our website and utilize our one-stop cross-border global collection, flexible FX settlement, financial tech empowerment, and tailored enterprise solutions (collectively, the “Services”). We understand that data security and privacy are paramount to cross-border B2C e-commerce sellers. We are strictly committed to protecting your data in accordance with international financial and data protection standards, including but not limited to the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and applicable cross-border financial regulations.

1. Information We Collect

To fulfill regulatory compliance obligations and deliver digital capital clearing services, we collect the following four categories of information:

1.1 Identity & Corporate Compliance Data

  • Corporate Qualifications: Legal entity name, business registration number, tax identification number, official business address, and corporate shareholding structure charts.
  • Identity Verification (KYC/AML): Passport or government-issued ID copies, facial biometric data (where applicable), contact phone numbers, and authorized operator emails of the legal representative, ultimate beneficial owners (UBO), and directors.
  • Trade Authenticity Proof: Store transaction histories, logistics and customs declaration records, supply chain purchase contracts, invoices, and service agreements signed between you and global e-commerce platforms.

1.2 Financial & Transactional Data

  • Bank & Routing Information: Local and overseas receiving bank account numbers, intermediary routing codes, cardholder names, and linked card accounts.
  • Platform Integration Data: Upon your explicit authorization, store ledger streams, order granular details, refund histories, and revenue metrics synchronized via APIs or secure tokens from marketplaces.
  • Capital Routing Records: Balance consolidation logs, currency rate lock-in entries, global VAT payment registries, overseas supplier payout orders, and historic clearing statements.

1.3 Technical & Usage Data

  • Device & Location Tracking: IP addresses, browser types, operating system versions, approximate geolocations, and unique device identifiers (UID).
  • Platform Interaction Analytics: Page view durations, navigation clickstreams, network and gateway latency, login timestamps, and device fingerprinting matrix required to block fraudulent access.

1.4 Sensitive Personal Data

To prevent financial crimes, we may collect background screening data (such as Politically Exposed Person (PEP) status and global sanctions lists) via accredited third-party compliance vendors.

2. How We Use Your Information

We process your business and personal data under explicit, lawful bases, including contract fulfillment, statutory legal obligations, legitimate business interests, and your explicit consent:
  • Account Opening & Routing (Contract Performance): Issuing multi-currency local bank accounts, performing global payouts, processing real-time FX conversions, and synchronizing multi-store capital dashboards.
  • Global Screening (Legal Obligations): Fulfilling Anti-Money Laundering (AML), Counter-Terrorism Financing (CTF), Know Your Customer (KYC) requirements, and checking global sanctions checklists.
  • Risk Mitigation & Shielding (Legitimate Interests): Running our proprietary AI fraud prevention engines and 3DS 2.0 authentication to monitor anomalous patterns, blocking malicious chargebacks and card testing to preserve network uptime.
  • Bespoke Enterprise Solutions (Consent): Debugging and optimizing high-concurrency API integrations, dedicated payment gateways, and tailored corporate financial reconciliation pipelines for hyper-scale sellers.

3. Data Sharing and Disclosure

We do not sell your personal or corporate data to any third party under any circumstances. We disclose your information only within the limited and compliant paradigms detailed below:
  • Financial Infrastructure & Banking Networks: To complete cross-border settlement, multi-currency liquidation, and local payouts, essential transaction elements must be shared with collaborating tier-1 international banks, local clearinghouses, card associations, and domestic clearing networks.
  • Global Jurisdictional & Regulatory Authorities: We will cooperate and disclose information when mandated by statutory legal directives from global central banks, financial intelligence units, taxation bureaus, or courts of competent jurisdiction.
  • Compliance & Technical Vendors: Information may be shared with vetted specialists who provide biometric verification, anti-fraud evaluation, and systems stability auditing. These vendors are stringently bound by equal data protection frameworks.

4. Cross-Border Data Transfers

Given our presence as an integrated global payout provider, your details may be routed, stored, and compiled in data storage locations outside your home jurisdiction.
  • Compliance Mechanisms: For cross-border transfers originating from the European Union (EU) or United Kingdom (UK), we execute standard European Commission Standard Contractual Clauses (SCCs) as our compliance mechanism.
  • Security Alignment: Every processing entity overseas must undergo formal security audits to assure data defense capabilities matching the enterprise-grade protocols established in this policy.

5. Institutional-Grade Data Security

We implement hardline technical and administrative measures to guarantee data security throughout its lifecycle: collection, transit, storage, and processing.
  • In-Transit Encryption: All network interfaces run strictly via banking-grade TLS/SSL encrypted communication channels.
  • At-Rest Encryption: Core transaction records, historical logs, and confidential client credentials are mathematically obfuscated using AES-256 military-grade hashing and encryption.
  • Logical & Physical Isolation: We apply multi-tenant logical partitioning paired with rigorous Role-Based Access Control (RBAC), removing any cross-linking vulnerability between accounts.
  • Continuous Auditing: Built-in immutable system audit logs track every database call, modification request, or administration entry to trigger instantaneous automated alerts upon anomaly.

6. Data Retention Period

We retain your corporate and personal files no longer than necessary to achieve the business purposes described in this policy:
  • Statutory Holding Period: To fulfill global financial and anti-money laundering mandates (e.g., the Bank Secrecy Act or EU Anti-Money Laundering Directives), basic business corporate filings, KYC histories, and transaction ledgers must remain mandatorily archived for 5 to 7 years following official account termination.
  • Disposal Strategy: Upon the expiration of statutory preservation lifespans, files are irreversibly destroyed, safely overwritten, or completely anonymized, rendering data completely detached from any identifiable natural person.

7. Your Legal Rights

Depending on your local legal jurisdiction (such as GDPR or CCPA frameworks), you maintain total mastery over your stored data assets:
  • Access & Portability: The right to review, request clarification, and securely export standalone copies of all active records we preserve on your behalf.
  • Rectification: The right to require immediate adjustments, corrections, or updates to flawed, incomplete, or outdated platform records.
  • Erasure (“Right to be Forgotten”): The right to prompt full database deletion, provided the target data does not clash with our overriding statutory financial recordkeeping obligations.
  • Restriction & Objection: The right to halt specific data processing conducted under legitimate interests, or request a complete usage restriction during active transactional reconciliation disputes.

To exercise any of these privileges, submit a formal request to our compliance department detailed in Section 9.

8. Cookies and Tracking Technologies

Our architecture employs indispensable Cookies, web beacons, and localized scripts to preserve essential functionalities:
  • Indispensable Cookies: Essential cookies utilized to hold system login sessions, maintain page token security, and supply our AI risk systems with baseline indicators to fend off high-concurrency bot attacks.
  • Analytical Cookies: Provided with your explicit opt-in consent, these trace geometric network response metrics to isolate routing friction and constantly enhance your dashboard layout speed. You can toggle browser controls to disable tracking at any time.

9. Contact Our Compliance Office

If you wish to pursue clarification regarding our privacy logic, raise security issues, or enforce data privacy rights, send direct notifications to our Legal and Regulatory Compliance Office:
  • Global Compliance Email: support@uppaylinks.com.
  • Official Postal Address: 7-2070 Harvey Ave Unit #166 Kelowna BC V1Y 8P8 Canada.
  • Response Window: We guarantee to complete a holistic overview and issue formal written responses within 15 business days (or shorter timelines legally requested under localized regulations) upon receiving your claim.

With the UPPay payment gateway, you can quickly gain access to global payment capabilities and give your business a global reach.

Contact Us

Office Hours

09:00 AM – 06:00 PM

Phone

+852 6978 9022

Email

service@uppaylinks.com