Privacy Policy

This policy explains how KUMQUAT NETWORK COMPANY LIMITED (“ucake”, “we”) collects, uses, stores, shares and protects personal information when operating this website, API documentation, business communications, sandbox testing and payment technology services.

Last updated: 2026-06-21

This is a website-facing policy for browsing, business communication and integration assessment. Formal merchant contracts, payment licensing matters, cross-border transfers and sensitive personal data processing should be reviewed by qualified Vietnamese counsel.

Policy content

1. Scope and controller

  • This policy applies to the ucake website, API documentation, contact forms, business communications, sandbox testing, technical integration and related payment technology services.
  • “We” means KUMQUAT NETWORK COMPANY LIMITED and authorized teams processing information when providing ucake services.
  • If a separate merchant agreement, data processing agreement or NDA applies, the signed written agreement prevails where it conflicts with this policy.

2. Information we may collect

  • Contact information: name, company, role, email, phone number, messaging account, country or region.
  • Business information: business type, expected transaction volume, target launch date, required product capabilities, bank coverage needs, compliance materials and consultation content.
  • Technical information: IP address, device and browser data, access time, page path, logs, error reports, security events and debugging records.
  • Integration information: MerchantId, CompanyId, callback URLs, order numbers, bank codes, request fields, response fields, sandbox data and developer-submitted materials.
  • Transaction-related information required in formal cooperation, such as status, amount, transfer note, virtual account, QR, collection notification, refund or payout status.

3. Sources of information

  • Information provided by you or your company through forms, email, meetings, chat tools or business communications.
  • Technical logs generated when you access the website, view documentation, use sandbox or call APIs.
  • Information generated by merchant systems, banks, payment partners, cloud infrastructure or support tools within the necessary scope.
  • Publicly available or partner-provided information for enterprise verification, compliance review, risk control and business communication.

4. Purposes of use

  • Respond to inquiries, assess cooperation needs, arrange commercial communication, prepare integration plans and provide technical support.
  • Provide API documentation, sandbox testing, API integration, callback troubleshooting, error diagnosis, service notices and system maintenance.
  • Conduct identity verification, merchant onboarding review, risk assessment, anti-fraud checks, abnormal transaction investigation and compliance review.
  • Support contract performance, reconciliation, billing, transaction tracing, customer support, dispute handling and audit records.
  • Improve website, documentation, API stability, user experience, security protection and product capabilities.

5. Cookies, logs and analytics

  • We may use necessary cookies, logs and similar technologies for website operation, language preference, access security and basic statistics.
  • If third-party analytics or monitoring tools are used, we aim to limit the collection scope and use them for performance, security and experience improvements.
  • You can manage cookies through browser settings, but disabling certain cookies may affect display, language switching or security functions.

6. Sharing and processors

  • We do not sell personal information.
  • Where necessary, information may be shared with cloud providers, communication tools, technical support providers, banks, payment partners, risk or compliance service providers.
  • We may disclose necessary information when required by laws, regulators, courts, arbitration bodies or competent authorities.
  • Relevant partners must process information only for agreed purposes and apply reasonable confidentiality and security measures.

7. Cross-border processing and storage

  • ucake serves cross-border merchants and Vietnam payment scenarios, so information may be accessed or processed in your country, Vietnam or service provider locations.
  • For cross-border transfers, sensitive personal data or higher regulatory requirements, formal agreements, data processing documents and applicable laws will govern.
  • We handle cross-border access and storage based on business necessity, data minimization and reasonable security measures.

8. Information security

  • We use access control, least privilege, encrypted transmission, audit logs, environment separation, key management and internal governance measures.
  • API keys, appSecret, callback URLs and production credentials must be protected by merchants and should not be shared publicly or through insecure channels.
  • If abnormal access, credential leakage or a suspected security incident is identified, please notify us promptly so we can assist investigation and reduce impact.
  • Internet and third-party networks cannot be guaranteed absolutely secure; we will keep improving reasonable security measures.

9. Retention

  • We retain information only for as long as necessary for collection purposes, contract performance, legal compliance, dispute handling or security audit.
  • Inquiry information may be kept for a reasonable period for customer relationship management.
  • Transaction, reconciliation, log and compliance records may be retained longer for audit, regulatory, tax, anti-fraud or dispute purposes.
  • When retention is no longer necessary, we will delete, anonymize or restrict use of relevant information.

10. Your rights

  • Subject to applicable law, you may request access, correction, supplementation, deletion, restriction or a copy of personal information related to you.
  • You may withdraw consent for non-essential marketing or business communications.
  • For information that must be retained by law, contract or security audit needs, we may not delete it immediately but will limit its use.
  • To protect information security, we may need to verify the requester’s identity and authorization.

11. Minors

  • ucake provides services for businesses and developers and does not intentionally provide products or services to minors.
  • If you believe a minor has submitted personal information to us, please contact us and we will take reasonable action after verification.

12. Updates

  • We may update this policy according to changes in products, services, laws or cooperation models.
  • The updated policy will be posted on the website and apply from the date stated on the page.
  • Material changes may be notified through website notice, email or other reasonable methods.

13. Contact

  • To exercise privacy rights, ask privacy questions or report security risks, contact support@ucakepay.com.
  • Please include your company, contact role, request details and necessary verification information.