1. Who we are
NineLogix Global Commerce Limited, 12th Floor, Infinitus Plaza, 199 Des Voeux Road Central, Sheung Wan, Hong Kong controls the personal data covered by this Notice. Privacy questions and rights requests may be sent to contact@ninelogix.com.
2. Data we collect
Depending on how you interact with us, we may collect:
- Identity and contact data, including name, email, address and account details.
- Business, product and application information submitted for review.
- Order, billing and transaction metadata; we do not intentionally store complete card numbers or card security codes.
- Support messages, delivery evidence, refund and dispute records.
- Device, browser, IP address, cookie, security and activity logs.
- Compliance and fraud-prevention information supplied by you or trusted providers.
- Business-verification information submitted through an authenticated merchant workspace, which may include corporate records and, where necessary, identity-document metadata. Sensitive documents must not be sent as ordinary email attachments.
3. Sources of data
We receive data directly from you, from your organization, from product providers whose checkout you use, and from payment, identity, fraud-prevention, analytics and infrastructure providers. We may also use lawful public sources for business verification.
4. How and why we use data
We process data only where we have an appropriate legal basis, including:
- To take steps at your request, form and perform a contract, deliver services and administer orders.
- For legitimate interests such as security, support, service improvement, eligibility review and fraud prevention, balanced against your rights.
- To comply with tax, accounting, sanctions, anti-fraud, payment-network and other legal obligations.
- With consent where law requires it, including certain cookies or direct marketing. You may withdraw consent at any time.
5. Payments
Payment details are submitted to the payment provider shown at checkout. We may receive payment status, method type, payer identifiers, risk signals and transaction references. Payment providers process information under their own privacy notices and security obligations.
6. Sharing and service providers
We may share data, only as reasonably necessary, with product providers, payment processors, acquiring banks, fraud and identity providers, cloud and communications suppliers, analytics providers, professional advisers, insurers, auditors, potential business transaction parties and competent authorities. We do not sell personal data.
7. International transfers
Recipients may process data in Hong Kong or other countries. Where required, we use contractual, organizational or other recognized safeguards and assess whether additional protection is appropriate. Local laws in a recipient country may differ from those where you live.
8. Retention
We keep personal data only for as long as needed for the purpose collected. Account and application records are generally kept while active and for up to 7 years afterward where needed for contract, tax, audit, fraud or dispute obligations. Support and security records are generally kept for up to 3 years, unless a longer period is required for an active case or by law. Sensitive verification files for an incomplete, withdrawn or rejected onboarding may become deletion candidates under the configured policy (initially 90 days), but legal, compliance or litigation holds override that schedule. Candidate status is not automatic physical deletion; deletion requires authorized review and an audit record.
9. Security
We use proportionate technical and organizational safeguards, including access controls, encryption where appropriate, logging, supplier review and data minimization. No internet service is completely secure; please use strong credentials and do not send full payment credentials or secret keys by email.
10. Cookies and analytics
We use strictly necessary technologies to operate and secure the site and may use analytics or preference technologies where permitted. Browser settings can control many cookies. Where applicable, a consent tool will provide more granular choices; refusing non-essential cookies does not prevent basic site access.
11. Marketing
We may send service communications necessary for your account or order. We send promotional communications only where permitted and provide an unsubscribe method. Opting out of marketing does not stop essential service, security, billing or policy notices.
12. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability or objection; withdraw consent; or complain to a data protection authority. Hong Kong users may exercise access and correction rights under the Personal Data (Privacy) Ordinance. We may verify identity and retain information required by law.
13. Children
Our services are intended for adults and businesses and are not directed to children. We do not knowingly collect personal data from children below the applicable age of digital consent. Contact us if you believe a child provided data without appropriate authorization.
14. Changes and contact
We may update this Notice as services or legal requirements change and will publish the revised effective date. Material changes will be highlighted where reasonably practicable. Contact: contact@ninelogix.com.
These public policies are operational terms and are not a substitute for advice from qualified legal counsel.