OnionPay / LEGAL

Privacy policy

Our handling of website enquiries, personal information and privacy requests.

Version · 7 September 2026

01Data user & scope

The operator named below is the data user responsible for personal information handled through this website and its consultation form. This policy is framed by Hong Kong’s Personal Data (Privacy) Ordinance (Cap. 486), with other mandatory privacy rules applying where relevant. The privacy contact below handles access, correction and other privacy enquiries.

This notice covers website enquiries and related correspondence. A later application, identity check or financial transaction may require additional information and a separate provider privacy notice. Merely following an external link does not submit your consultation record to that provider.

02Information collected & whether it is required

The form requires a name, work email, company name, service selection, timezone and permission to respond. The preferred date and message are optional. Language, a request identifier, submission time and a value used to recognise duplicate submissions are also recorded. Without required fields, the online request cannot be processed; you can instead contact the business email to discuss your enquiry.

When you contact us directly, we handle the contact information and correspondence you choose to send. Website delivery and security involve connection data such as IP address, request path, time and browser headers. The consultation database has no IP-address field; hosting or security systems may separately process connection records. The appearance preference is stored in your browser as explained in the Cookie policy.

Do not include payment credentials, full card numbers, passwords, private keys, identity-document copies or unrelated sensitive information in an enquiry. We do not request these items through the consultation form. It is intended for business enquiries, not for children’s use or emergency account support.

03Purposes, contact permission & marketing

We use enquiry data to respond, assess the services relevant to your request, arrange a conversation and keep necessary correspondence records. Technical data supports website delivery, fault investigation, duplicate prevention and abuse protection. Information may also be needed to handle complaints, comply with legal obligations or establish, exercise or defend legal claims.

The form’s contact permission concerns this enquiry only. Submission does not subscribe you to advertising or authorise sale of your data. We do not use consultation details for unrelated direct marketing or supply them to others for that purpose without the separate notice and consent required by law. You may withdraw contact permission by writing to the privacy contact; we will stop optional follow-up, while retaining information where a separate lawful need remains.

04Who may receive information

Access is limited to personnel handling enquiries and authorised service providers performing hosting, storage, communications, maintenance or security tasks. Professional advisers may receive information needed for a specific legal, audit or dispute matter. Courts, regulators or law-enforcement bodies may receive information where disclosure is legally required or lawfully justified.

A service referral is handled separately: we explain the intended provider and purpose before sharing enquiry details for that referral, and obtain any required permission. Processors may use data only within their authorised role and are subject to contractual or other measures addressing confidentiality, security, retention and onward handling. We do not publish consultation records.

05International handling

Information may be processed outside Hong Kong when the hosting, communications or support providers used for your enquiry operate elsewhere. Processing location depends on the actual service arrangement; this policy does not promise storage in a single country. You may ask the privacy contact about the recipients and locations relevant to your information.

For such arrangements we require appropriate purpose, confidentiality, security, onward-transfer and retention controls. Where another applicable law requires a transfer assessment, specific contractual mechanism, separate consent or other safeguard, the transfer must meet those requirements. Consent to a consultation is not a waiver of cross-border protection requirements.

06Retention & deletion

Enquiry information is kept only while needed to handle the request and related correspondence, or for a specific legal or dispute purpose. The criteria are whether follow-up remains active, whether an issue or claim remains unresolved, and whether a legal duty requires a particular record to be retained. Once those purposes end, unnecessary personal information is to be deleted or irreversibly anonymised. Deletion requests are assessed individually; we explain a lawful reason for retaining information where one applies.

A consultation record is not automatically a regulated transaction record. If you later enter a financial-service relationship, records collected for that service may be subject to separate statutory periods and provider notices. Withdrawing an enquiry does not require destruction of records that the law requires a provider to retain.

07Security & incidents

We take reasonably practicable measures appropriate to the information and risks, including restricting access, validating submissions and limiting abusive requests. No website or communication channel is completely secure. Report a suspected website vulnerability through the security contact without accessing other people’s data or including live credentials. Where an incident requires notification under applicable law, we will follow the relevant requirements.

08Access, correction & complaints

You may ask whether we hold your personal data and request a copy or correction through the privacy contact, addressed to the person responsible for privacy requests. Provide enough information to locate the record; proportionate identity verification may be necessary. Under Hong Kong law, a data access request is normally handled within 40 calendar days of receipt, subject to statutory requirements and exceptions. If compliance is not possible within that period, we give the required explanation and comply as soon as practicable. Any permitted access fee must not be excessive and will be explained.

You may also ask us to stop optional contact or delete information no longer needed. Where other privacy laws apply, additional rights may include objection, restriction, portability or withdrawal of consent, subject to their conditions. We will explain any lawful refusal. You can complain directly to the Hong Kong Privacy Commissioner for Personal Data or another competent authority without first completing our internal process.

09Policy updates

The date shown identifies this policy version. Material changes affecting information already held will be communicated appropriately. A policy update alone does not provide consent for a new, unrelated purpose or remove an existing statutory right.

Operator details & contact

Legal name
ACU MONEY CHANGER LIMITED
Registration jurisdiction
Hong Kong
Companies Registry number
3002384
Business Registration number
72480270
Public contact address
UNIT 51, G/F., CARSON MANSION, Hong Kong
Business enquiries
business@onionpay.com
Privacy contact
privacy@onionpay.com
Complaints & legal notices
complaints@onionpay.com
Security reports
security@onionpay.com
Business enquiries