Privacy policy
This policy explains what personal data Uniweb Pte Ltd collects, why it is collected, who it may be disclosed to, how long it is kept and how it is protected. The companion page, the Personal Data Protection Notice, covers your rights and how to exercise them: consent and withdrawal, access and correction requests, and how to reach the Data Protection Officer.
Who is responsible
Uniweb Pte Ltd, trading as Uniweb Pay, of Beach Road #23-08A, Gateway East, Singapore 189721. Uniweb Pte Ltd is a Major Payment Institution licensed by the Monetary Authority of Singapore under the Payment Services Act 2019, Licence No. PS20200612.
Uniweb Pte Ltd is the organisation responsible for the personal data described here. Questions about this policy, and any request under the Personal Data Protection Act 2012 (PDPA), go to the Data Protection Officer at [email protected], or by post to the address above marked for the attention of the Data Protection Officer.
What this policy covers
It covers personal data handled by Uniweb Pte Ltd in the ordinary course of its business: this website, enquiries and applications from prospective merchants, the running of merchant accounts, and the statutory and regulatory obligations that come with a Major Payment Institution licence.
Two things sit outside it, and it is worth being explicit rather than leaving them implied.
- The specific terms on which a merchant’s data is handled in the payment systems are set by the merchant agreement and the applicable card scheme rules. Where that agreement and this policy differ, the agreement governs the relationship.
- Where you follow a link and leave this site — the onboarding application, the merchant portal at merchant.uniwebpay.com, WhatsApp, or a card scheme’s own page — what you send there is handled under the notice or terms of the place you have arrived at.
Personal data we collect
From visitors to this website
This site has no account, no sign-up, no newsletter and no contact form, so there is nowhere on it to type personal data. It sets no cookies, and runs no analytics, advertising or session-recording tags — nothing here follows you between sites.
What still reaches the hosting provider is what reaches every website: the technical information a browser request carries, including an IP address, a user agent string and the page requested. That is handled by the hosting provider as part of delivering the page and keeping it available.
From people who contact us
If you email, call or message us, we hold what you send and what is needed to answer: typically a name, a business email address or phone number, the business you are asking about, and the content of the enquiry.
From merchants and applicants
Applying for a merchant account is a regulated onboarding process, and it collects more than a commercial relationship otherwise would, because the law requires it. In broad categories:
- business identity — the registered entity name, UEN, ACRA information, business address, and the nature of the business;
- individual identity for the people the law requires to be identified — directors, authorised signatories and beneficial owners — including identification documents, for the customer due diligence a Major Payment Institution must carry out;
- contact and operational details for running the account — the people we deal with, the outlets, the settlement bank account;
- transaction records generated by the account in the ordinary course of processing.
Card numbers and cardholder authentication data are not collected by this website. In the payment systems they are handled within the Payment Card Industry Data Security Standard (PCI DSS) framework that applies to card acquiring.
Why we collect it
Each purpose below is a reason data is needed, not a licence to use it for anything else:
- to answer an enquiry and to assess and process an application for a merchant account;
- to provide and operate the service — processing transactions, settling funds, producing statements, handling refunds, chargebacks and disputes;
- to meet legal and regulatory obligations, including customer due diligence, ongoing monitoring, sanctions screening and record-keeping under the Payment Services Act 2019 and the MAS notices on anti-money-laundering and countering the financing of terrorism;
- to detect, investigate and prevent fraud and misuse, and to manage risk;
- to meet card scheme and payment scheme requirements applicable to acquiring;
- to communicate about the service — service notices, operational and account matters;
- to establish, exercise or defend legal claims, and to respond to lawful requests from regulators, the courts and law enforcement.
Where we would like to use contact details to send marketing that is not about the service you already have, we ask for consent for that separately, and it can be withdrawn at any time. See the Personal Data Protection Notice.
Who it may be disclosed to
Personal data is disclosed only where there is a reason above that requires it, and only to the extent required. The categories are:
- the card schemes, payment schemes and wallet operators whose networks a transaction runs through;
- banks and financial institutions involved in settling funds;
- service providers engaged to support the business — technology, hosting, communications, identity verification and screening — acting on instructions and under an obligation of confidentiality;
- regulators and public authorities where disclosure is required or permitted by law, including the Monetary Authority of Singapore, the Suspicious Transaction Reporting Office, the courts and law enforcement;
- professional advisers under a duty of confidentiality, and parties to a corporate transaction, where relevant.
Personal data is not sold, and it is not disclosed to third parties for their own marketing.
Where it goes
Payments cross borders, so some data does too — a transaction on an international card scheme or an overseas wallet is processed on that scheme’s network.
The PDPA’s Transfer Limitation Obligation applies to any transfer of personal data out of Singapore: the recipient must be bound to a standard of protection comparable to the PDPA. Where a transfer is necessary, that is the standard it is made under, whether through contractual terms or another lawful basis recognised by the PDPA.
How long it is kept
Personal data is kept while it is needed for the purpose it was collected for, and after that for as long as the law requires it to be retained.
The retention floor is statutory rather than a matter of policy. The MAS anti-money-laundering and countering-the-financing-of-terrorism notice applicable to payment services requires records relating to customer due diligence and transactions to be kept for at least five years, measured from the end of the business relationship or the date of the transaction. Records are also kept for as long as needed for tax, accounting, audit, and any actual or anticipated legal claim.
Where data is no longer needed for any of those, it is disposed of, or anonymised so that an individual can no longer be identified from it.
How it is protected
Uniweb Pte Ltd maintains security arrangements appropriate to the sensitivity of the data and the harm that would follow from its loss, covering access control, encryption in transit, segregation of production systems, staff confidentiality obligations and oversight of service providers.
Card acquiring additionally operates within the PCI DSS framework, which governs how cardholder data may be stored, processed and transmitted.
No system is beyond risk, and a policy that claimed otherwise would not be worth reading. If a data breach occurs that is notifiable under the PDPA, it is notified to the Personal Data Protection Commission, and to affected individuals, in accordance with the Act.
Cookies and tracking on this website
This site sets no cookies. It runs no analytics, no advertising pixels and no session-recording tools, and it does not build a profile of you or track you across other sites. There is no cookie banner because there is nothing to consent to.
If that ever changes, this section is where it will be described, and the change will be made before any such tag is added rather than after.
Your rights, and how to use them
Under the PDPA you can ask what personal data an organisation holds about you and how it has been used, ask for it to be corrected, and withdraw consent for uses that rely on consent.
How to make each of those requests, what to include, and what happens next is set out in the Personal Data Protection Notice, together with the Data Protection Officer’s contact details and the escalation route to the Personal Data Protection Commission.
Changes, and how to reach us
This policy is updated when the practices it describes change. The date at the top of the page is the date of the current version, and the version in force is the one published here.
Data Protection Officer, Uniweb Pte Ltd — [email protected], +65 8385 3698, or Beach Road #23-08A, Gateway East, Singapore 189721.