Privacy Policy

Wintranx (hereinafter referred to as “we”) attaches great importance to the privacy and personal information security of all users. Trust is the cornerstone of our services. This Privacy Policy fully specifies all rules governing our collection, use, storage, cross-border transmission and external sharing of your personal information, and clearly defines all data rights you hold, security safeguards and compliance obligations. This Policy has the same legal effect as all business agreements signed between you and us.

We shall not be liable for the privacy processing practices of third-party websites or jump links, which are not subject to this Policy.

  1. Core Privacy Values of the Platform (Newly Added, Aligned with Shopify’s Value System)
  2. Data Ownership Belongs to You

We follow the privacy-by-design principle. During product R&D and function iteration, our business, risk control and privacy security teams conduct joint reviews. We only collect the minimum scope of information necessary for business operations. When information is no longer needed for service provision, we will permanently delete or fully anonymize it to avoid unnecessary retention.

  1. Proactively Protect Your Data from Unauthorized Disclosure

We will reject any third-party requests for your personal information without valid user authorization or legal judicial documents. Where disclosure is mandated by law, we will notify you of the disclosure reasons and scope to the extent permitted by applicable laws and regulations.

  1. Empower Customers to Fulfill Privacy Compliance Obligations

We provide enterprise customers with supporting privacy compliance instructions and FAQ documents covering various business scenarios to assist legal representatives, beneficial owners and operators in complying with local data protection laws, as well as guidelines for exercising data subject rights.

  1. Scope of Applicable Parties (Newly Added Multi-Role Classification)

This Policy applies to all parties accessing Wintranx’s products and services, including:

  1. Enterprise merchants who open corporate accounts and use payment collection, withdrawal and cross-border settlement services (including legal representatives, directors, beneficial owners and authorized operators);
  2. Purchasers, payers and individual transaction users who conduct transactions with merchants;
  3. Service providers and channel partners who integrate Wintranx APIs and carry out distribution or marketing cooperation;
  4. All website visitors, online consultation requesters, and individuals contacting customer service via phone or email.

III. Legal Bases for Processing Personal Information (Newly Added Four Categories of Compliance Grounds)

All our personal information processing activities have corresponding legal support, divided into four scenarios:

  1. Performance of Contract: Processing enterprise qualifications, bank account details, contact information and other data to complete account opening, transactions, withdrawals and settlement services;
  2. Legitimate Business Interests: Anti-fraud risk control, transaction data analysis, service optimization, fault troubleshooting and security monitoring;
  3. Performance of Statutory Mandatory Obligations: Anti-money laundering, Know Your Customer (KYC) identity verification, regulatory reporting, audit and tax retention;
  4. Separate Consent from Users: Marketing SMS/email push and personalized targeted recommendations, which you may withdraw at any time.
  1. Information Collection

1.1 Business Purposes for Processing Personal Information

  1. Establish and maintain enterprise customer files, communicate with you regarding your demands, and handle order inquiries, transaction complaints and compensation disputes;
  2. Send critical service notifications such as account balance changes, fund arrivals and system upgrades;
  3. Ensure stable operation of our official website and settlement systems, process transactions, provide after-sales maintenance and optimize function iterations;
  4. Push promotions, new product launches and industry news subject to your separate authorization;
  5. Complete identity verification and anti-money laundering due diligence for enterprises and natural persons in compliance with regulatory requirements;
  6. Identify, alert, investigate and block illegal fraudulent activities including account theft and fake transactions;
  7. Meet compliance and risk control requirements such as financial bookkeeping, regulatory reporting, internal auditing, credit risk monitoring and legal consultation;
  8. Conduct anonymized data statistics and business research to optimize product security and fund settlement service experience.

1.2 Full Classification of Information We Collect (Expanded Sensitive Information List)

  1. Mandatory Enterprise Authentication Qualifications (Required for Account Opening)

Enterprise name, unified social credit code, business license, business scope; name, ID card/passport, document photos and contact information of legal representatives, directors, beneficial owners and authorized operators; equity structure and proof of beneficial ownership.

  1. Transaction and Settlement Information

Order details, product categories, logistics documents, purchase and sales contracts, invoices; payee name, bank card number, issuing bank, SWIFT identifier, withdrawal amount and transfer records.

  1. Device & Online Access Information

IP address, device brand and model, unique device identifier, operating system, browser version, access time, page browsing track and geographic location coordinates.

  1. Customer Service Interaction Information

Consultation records, complaint content, supporting materials you voluntarily provide and feedback suggestions.

  1. Preference & Marketing Information

Contact email address, mobile phone number, language preference, marketing subscription status and unsubscription records.

  1. Information Collected via Cookies & Tracking Technologies (New Independent Subsection)

We deploy Cookies, pixels and embedded tracking tools on our official website and merchant backend for login recognition, access statistics and risk identification. You may disable Cookies via browser settings; disabling Cookies will only affect partial page functions without disrupting core settlement services. The supporting Cookie Policy, including a list of third-party tracking service providers and disablement guidelines, is available at the bottom of our official website.

  1. Complete List of Sensitive Personal Information

Government-issued identity documents and passports; account login credentials and SMS verification codes; precise device location; special identifiers such as nationality or ethnic origin. We undertake not to collect full bank card magnetic track or chip data.

  1. Information Obtained from Third-Party Channels (New Data Source Disclosure)

We obtain basic information required for verification from payment cooperation institutions, banks, credit reporting service providers and compliant government public channels, solely for risk control and identity verification, and shall not use such data for any other purposes.

1.3 Statutory Exceptions Where Your Consent Is Not Required for Information Collection

  1. Matters related to national security and national defense security;
  2. Performance of statutory duties prescribed by applicable laws, regulations and regulatory authorities;
  3. Public security and major public health emergencies;
  4. Investigation, prosecution, trial and enforcement of criminal cases;
  5. Protection of your or a third party’s life and significant property interests where consent cannot be obtained in a timely manner;
  6. Information you voluntarily disclose to the public;
  7. Legitimate news reports and government public disclosures;
  8. Conclusion and performance of contracts between you and us;
  9. Ensuring stable operation of systems and fund services, and resolving system faults and fraudulent acts;
  10. Legitimate news coverage for public interest;
  11. Other circumstances explicitly permitted by applicable laws and regulations.
  1. Rules for the Use of Personal Information
  1. Fulfill all collection purposes specified in this Policy;
  2. Identity verification, suspicious transaction monitoring, anti-money laundering risk control and account security protection;
  3. Submit data to regulatory and judicial authorities as required by law;
  4. Invite you to participate in product research and service follow-up surveys;
  5. Conduct aggregated statistics and business optimization after desensitization and anonymization of data;
  6. Supplementary Clauses on Automated Machine Learning/AI Risk Control (Newly Added)

We adopt machine learning technology to identify fraudulent transactions and optimize settlement processes. All automated risk assessment results are subject to manual review. There is no fully automatic mechanism for fund disposal or account suspension without appeal channels. Machine learning will not generate unilateral decisions that impose material legal impacts on you.

  1. Information Storage, Security Protection and Retention Periods

3.1 Security Protection System

  1. Full SSL encryption for data transmission between browsers and servers, and encryption for core data storage;
  2. Hierarchical access permission control; only authorized employees may access business data, and all staff receive regular privacy security training;
  3. Full data lifecycle management system with PCI DSS international data security certification;
  4. Formulated emergency response plans for personal information security incidents with regular drills. In the event of data leakage risks, we will immediately notify users and regulatory authorities, and provide risk mitigation solutions simultaneously;
  5. Independent third-party auditors conduct annual inspections on the security of fund and user data storage systems. No online transmission or electronic storage method can guarantee 100% absolute security, and we will continuously iterate protective measures.

3.2 Refined Information Retention Rules (Expanded from Original Clauses with Scenario-Based Breakdown)

  1. General Standard: Data shall only be retained for periods necessary for service provision or statutory retention deadlines. The retention duration is determined based on data sensitivity, leakage risks and business purposes;
  2. Enterprise Account Termination Scenarios: After you cancel your enterprise account or terminate cooperation, we will cease all information collection. Settlement, tax and anti-money laundering statutory archives shall be retained for 2 years in accordance with regulatory requirements and permanently deleted or anonymized upon expiry;
  3. Where we only act as a service provider undertaking business for third-party merchants: The retention period for end-user data of merchants shall be determined by the corresponding merchants, and you may directly submit data subject requests to the merchants;
  4. Aggregated anonymized statistical data has no fixed deletion deadline and cannot be associated with any natural person.
  1. Rules for External Provision of Personal Information

4.1 Sharing

Your information may only be shared under the following scenarios. All third parties shall sign data protection agreements, and we conduct regular audits of their compliance capacity:

  1. Sharing necessary order and payment information with transaction counterparties to complete transactions;
  2. Sharing information with cooperative service providers within the scope authorized by you in writing or online;
  3. Mandatory provision upon receipt of legal documents issued by courts or regulatory authorities;
  4. Protection of material property interests of the Platform, users and the general public;
  5. Third-party service providers undertaking core settlement and risk control functions;
  6. Minimum information required for distributing activity benefits under joint marketing campaigns;
  7. Stipulated in business contracts between both parties;
  8. In line with public interest requirements.

Recipients of shared information include group affiliates, banks, payment institutions, risk control service providers, advertising analytics vendors and third parties authorized separately by you.

  1. Entrusted Processing

We may entrust third parties to process data solely for settlement, risk control and customer service scenarios, limited to the minimum necessary information scope. If entrusted parties use personal information beyond the entrusted scope, they must obtain separate consent from you.

4.3 Transfer

  1. Written consent from you;
  2. Mandatory requirement by judicial or regulatory authorities;
  3. In the event of business merger, acquisition or asset transfer: the transferee shall be bound by this Privacy Policy, otherwise we shall obtain new consent from you.

4.4 Public Disclosure

We will only publicly disclose your personal information with your voluntary consent or upon receipt of valid legal judicial documents. All disclosed materials shall be stored encrypted, and we will strictly verify the legality of law enforcement documents.

4.5 Statutory Circumstances Where Consent Is Not Required for Sharing, Transfer or Public Disclosure

Circumstances related to national security, statutory obligations, public health, criminal judicial procedures, protection of major personal and property interests, information voluntarily disclosed by you, and legally disclosed public information.

  1. Your Complete Data Subject Rights (Significantly Expanded to Cover Missing Rights)

Regardless of your country or region of residence, you shall enjoy all the following rights. Exercising your rights will not result in price hikes, service restrictions or differential treatment (New Anti-Discrimination Commitment):

  1. Right to Know
  2. Right of Access & Rectification
  3. Right to Erasure
  4. Right to Data Portability
  5. Right to Restrict Processing & Object to Automated Risk Control
  6. Right to Withdraw Consent
  7. Right to Exercise Rights via Authorized Agents
  8. Right to Appeal & Complain
  9. Notice on Do Not Track Signals

Channels for Exercising Rights:

  1. Self-service modification of basic information via personal accounts and merchant backends;
  2. Submit written or email data subject requests with identity verification as required;
  3. Customer service & marketing unsubscription email: cs@Wintranx.com
  4. Privacy policy feedback & appeal email: marketing@shwytx.com
  5. If you are a transaction customer of a third-party merchant, you shall contact the corresponding merchant first for data subject requests, and we may assist in forwarding your application.
  1. Protection of Minors’ Personal Information

Our Platform is intended for enterprise and adult individual users. We may only collect personal information of minors under 14 years old with written authorization from their guardians. If we discover data of minors collected without prior guardian consent, we will permanently delete such data immediately. Minor information shall only be used or disclosed within the scope permitted by guardians or necessary for protecting minors’ legitimate rights and interests.

  1. Cross-Border Transmission of Personal Information (Refined Region-Specific Rules)
  1. Under global business scenarios, your data may be transmitted to overseas affiliates and cooperative service providers subject to your consent;
  2. Cross-border protection measures: full encrypted transmission, restricted access permissions and signing of standard cross-border data protection agreements to comply with local data exit laws and regulations;
  3. Regional Compliance Mechanisms:
    • Users in the European Economic Area, the United Kingdom and Switzerland: Their data will be received by a designated EU-compliant entity. Data transmission to Canada meets the EU adequacy recognition standard; standard contractual clauses will be signed for transmission to other third countries;
    • Users in Asia-Pacific, the Americas and the Middle East: Their data will be received by regional entities subject to local privacy laws and regulations;
  4. Your access to and use of this Platform constitutes your acknowledgment of cross-border data transmission under compliant conditions. Services shall not be available to users in regions where cross-border data transmission is prohibited by law.
  1. Supplementary Privacy Statement for Users in the United States (New Overseas Compliance Clause)

Scope of Application

This supplementary clause applies to users residing in California, Virginia, Colorado, Connecticut, Utah and other U.S. states subject to state privacy laws (including CCPA).

  1. We will not “sell” your personal information as defined under U.S. state privacy laws;
  2. Categories of collected information: identity identifiers, enterprise business information, device network data, geographic location, image materials, inferred preferences, sensitive identity documents and account credentials;
  3. Recipients of information: payment service providers, cloud storage vendors, risk control vendors, cooperating merchants and law enforcement authorities for compliance purposes;
  4. Sensitive information shall only be used subject to your explicit consent;
  5. Sources of information: data voluntarily submitted by you, data automatically collected from devices and data obtained from compliant third-party service providers;
  6. You enjoy all rights prescribed by applicable state laws including the right to know, right to rectification, right to erasure and right to exercise rights via authorized agents. We shall not discriminate against users exercising their data subject rights.
  1. Policy Update Mechanism
  1. We will notify you in advance via merchant pop-ups, SMS, email and official website announcements for material changes to this Policy;
  2. Material changes include adjustments to service models, changes to operating entities, adjustments to external information sharing recipients, revisions to rules governing your data subject rights and changes to complaint channels;
  3. The latest version of this Policy will be permanently published on the Privacy Policy page of our official website. Your continued use of our services constitutes your acceptance of the updated terms.
  1. Public Guidelines for Law Enforcement Information Requests (Newly Added)

We have formulated standardized review procedures for legal document requests including court subpoenas, regulatory investigation orders and public security assistance inquiries. We will verify the legality of documents and the requested data scope, and synchronize relevant request matters with you to the extent permitted by law. All relevant request records will be archived and stored encrypted for inspection.

  1. Contact Information (Improved Regional Entities & Communication Channels)
  1. General customer service & marketing unsubscription: cs@Wintranx.com
  2. Privacy policy feedback & data subject appeal: marketing@shwytx.com
  3. Dedicated email for judicial and regulatory document submission (Newly Added): legal@Wintranx.com
  4. The full registered names, office addresses and dedicated privacy compliance contacts of regional operating entities will be published on our official website in due course.
  1. Your Consent

Your access to our official website, account registration and use of Wintranx payment collection and settlement services confirm that you have fully read, understood and agreed to all clauses of this Updated Privacy Policy, and authorize us to lawfully process your personal information in accordance with this Policy.