Skip to main content

Privacy Notice

Version 1.0 · Last updated:

This notice explains what personal data Rainbow Pay collects when you visit this website, contact us, apply to become a merchant or act for a merchant, why we collect it, who we may share it with, how long we keep it and how you can access or correct it. We handle personal data in accordance with the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong. Our services are for businesses, and our website forms never ask for card numbers, passwords or identity documents.

1. Who we are

This website is operated by RAINBOW PAY LIMITED (彩虹匯有限公司), a company incorporated in Hong Kong under company number 3040501 ("Rainbow Pay", "we", "us" or "our"). Our registered address is Room 706A, 7/F, Mirror Tower, 61 Mody Road, Tsim Sha Tsui, Kowloon, Hong Kong.

For the purposes of the Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO"), Rainbow Pay Limited is the data user in respect of the personal data described in this notice, except where we state that we process data on behalf of a merchant or another party.

Questions about this notice or about how we handle personal data can be sent to our privacy contact at privacy@rainbowpay.hk, or by post to the Privacy Officer, Rainbow Pay Limited, at the address above.

2. Scope of this notice

This notice applies to personal data we collect about the following people:

  • Website visitors — people who browse this website.
  • Business contacts — people who contact us, or whom we contact, about our services or a business relationship.
  • Merchant applicants — people who submit, or are named in, an application to use our services.
  • Merchant representatives — directors, beneficial owners, authorised signatories, employees and other individuals who act for, own or control a merchant or prospective merchant.
  • Developers and support users — people who use our developer documentation, integration resources or support channels.

Where we provide payment services to a merchant, the processing of personal data relating to that merchant's own customers is also governed by the merchant's own privacy notice and by the service agreement between the merchant and us. This notice does not replace those documents.

3. Personal data we collect

Depending on how you interact with us, we may collect the following categories of personal data:

Identity and contact data
Name, job title, business email address, telephone number, and the company you work for or represent.
Business information
Information about a business that may identify individuals connected with it, such as company details, the names of directors, shareholders and beneficial owners, business activities, websites and expected use of our services.
Technical and browser data
IP address, browser type and version, device and operating system information, pages viewed, referring pages, date and time of visits, and cookie identifiers, collected as described in our Cookie Policy.
Communications
The content of messages, enquiries, complaints and correspondence you send us, and records of our replies.
Application information
Information provided in or with an application to use our services, including information about the applicant business and the individuals connected with it.
Transaction-related information (where applicable)
Where we provide services to a merchant, records relating to payments, refunds, disputes and payouts processed for that merchant, which may include personal data of individuals involved.
Compliance information (where applicable)
Information we are required or permitted to obtain to meet our anti-money laundering, counter-terrorist financing, sanctions and other legal obligations, such as identity verification results and screening outcomes.

Payment data and website forms

The forms on this website never ask for payment card numbers, card security codes (CVV/CVC), passwords, login credentials or identity documents. Please do not include any of these in a form or email. If identity or business documents are needed during onboarding, we will explain the secure channel for providing them.

4. Where we obtain personal data

We obtain personal data from the following sources:

  • Directly from you, when you complete a form, send us an email, speak with us or submit an application.
  • From the merchant or business you represent, for example when a business names you as a director, beneficial owner, authorised signatory or contact person.
  • From our service providers, such as providers that host our website, handle our communications or support our operations.
  • From public business sources, such as company registries and other publicly available business records.
  • From identity verification, screening and other compliance service providers, where this is lawful and necessary for our legal and regulatory obligations.
  • Automatically through this website, by means of cookies and similar technologies, as described in our Cookie Policy.

5. Why we use personal data

We collect and use personal data for purposes directly related to our functions and activities, namely:

  • responding to enquiries and requests submitted through this website or by email;
  • assessing applications and onboarding merchants, including verifying the identity of businesses and the individuals connected with them;
  • providing, administering and supporting our services, and managing our relationship with merchants;
  • meeting our compliance obligations, including customer due diligence, sanctions screening and record keeping under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615);
  • detecting, preventing and investigating fraud, misuse of our services and security incidents;
  • providing technical and integration support to developers and merchants;
  • complying with legal and regulatory obligations, and with lawful requests from courts, regulators and law enforcement authorities;
  • business administration, including record keeping, audit, handling complaints, and establishing, exercising or defending legal claims; and
  • direct marketing, only where permitted by law and where you have given the consent described in section 11.

We do not use personal data for a new purpose that is not directly related to these purposes without your prescribed consent, unless an exemption under the PDPO applies.

6. Whether you must provide personal data

Fields marked as required on our forms, and information we request during onboarding, are necessary for us to process your enquiry or application and to meet our legal obligations. Other information is voluntary.

If you do not provide required information, we may be unable to respond to your enquiry, assess an application, provide services to the business you represent or meet our legal obligations. Where information is required by law, we may be unable to proceed without it.

7. Who we may disclose personal data to

We disclose personal data only where necessary for the purposes described in this notice, and to the following classes of recipients:

  • service providers and data processors that act on our instructions, such as providers of hosting, communications, document management, customer support and IT services;
  • professional advisers, such as lawyers, auditors, accountants and insurers;
  • banks, acquirers, payment processors, payment schemes and other payment partners, where applicable and necessary to provide or administer our services;
  • identity verification, screening and other compliance service providers;
  • courts, regulators, law enforcement agencies and other government authorities, where we are required or permitted by law to disclose;
  • companies within our corporate group and our service providers, where applicable, for the purposes described in this notice; and
  • a prospective purchaser, successor or other party in connection with a reorganisation, merger or transfer of all or part of our business, subject to appropriate confidentiality protections.

Where we engage a data processor, we use contractual or other means to prevent the personal data transferred to it from being kept longer than necessary and to protect it against unauthorised or accidental access, processing, erasure, loss or use. We do not sell personal data.

8. Transfers outside Hong Kong

Payment infrastructure is international. Some of the recipients listed in section 7, including payment partners, service providers and their facilities, may be located outside Hong Kong, and personal data may be transferred to, stored in or accessed from other jurisdictions.

Where we transfer personal data outside Hong Kong, we take reasonable steps to ensure that it receives appropriate protection, for example through contractual safeguards with the recipient, and we remain responsible for it in accordance with the PDPO.

9. How long we keep personal data

We keep personal data only for as long as is necessary to fulfil the purpose for which it was collected, including any directly related purpose, and to meet our legal, regulatory, accounting and reporting obligations.

Some records must be kept for a period set by law even after a business relationship has ended. In particular, record-keeping requirements under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615) may require us to retain customer due diligence and transaction records. When personal data is no longer required, we take practicable steps to erase or anonymise it.

10. How we protect personal data

We take practicable steps to protect personal data against unauthorised or accidental access, processing, erasure, loss or use. These include technical and organisational measures such as access controls based on job role, encryption of data in transit, confidentiality obligations for staff and service providers, and oversight of the providers who process data for us.

No method of transmission or storage is completely secure. If you believe your interaction with us is no longer secure, please contact us promptly. To report a technical vulnerability, see our Responsible Security Disclosure policy.

11. Direct marketing

We intend to use your name and business contact details (email address and telephone number) to send you information about Rainbow Pay's payment and money services, product updates and events. We may do so only with your consent, as required by Part 6A of the PDPO.

  • Consent to direct marketing is requested separately from any other agreement and is never a condition of making an enquiry or applying for our services.
  • Consent boxes on our forms are never pre-ticked.
  • We do not provide your personal data to any other person for use in their direct marketing.
  • You may withdraw your consent at any time, free of charge, by using the unsubscribe link in any marketing email or by writing to privacy@rainbowpay.hk. We will stop using your data for direct marketing once we receive your request.

Service and operational messages that we need to send in connection with an enquiry, an application or an existing relationship are not direct marketing and are not affected by your marketing choices.

12. Cookies

This website uses cookies and similar technologies. Cookies that are not strictly necessary are used only with your consent. Our Cookie Policy lists the cookies we use and explains how to change your choices.

13. Your rights of access and correction

Under the PDPO you have the right to ask whether we hold personal data about you, to request a copy of that data (a data access request), and to request correction of data that is inaccurate.

To make a request, write to privacy@rainbowpay.hk or by post to the Privacy Officer, Rainbow Pay Limited, Room 706A, 7/F, Mirror Tower, 61 Mody Road, Tsim Sha Tsui, Kowloon, Hong Kong. You may use the Data Access Request Form published by the Office of the Privacy Commissioner for Personal Data. We may need to verify your identity before acting on a request.

We may charge a fee for complying with a data access request, as permitted by the PDPO. Any fee will not be excessive. We will respond to access and correction requests within the period required under the PDPO. Where the law allows us to refuse a request, we will tell you our reasons.

14. Children

Our services are provided to businesses. This website is not intended for children, and we do not knowingly collect personal data from children through it.

15. Changes to this notice

We may update this notice from time to time to reflect changes in our services, our practices or the law. The version number and the date on which the current version takes effect are shown at the top of this page. Where a change materially affects how we use personal data we already hold, we will take reasonable steps to bring it to the attention of those affected.

Legal and regulatory information

Cookie preferences

Choose which optional cookies we may use. Strictly necessary cookies are always active because the website cannot work without them.

  • Strictly necessary

    Security, load balancing, form protection and remembering your cookie choice.

    Always active

Read the Cookie Policy