Privacy Policy
Effective date: 1 September 2026
This policy explains how OCEAN WAVE FINTECH PTY LTD collects, uses, shares and protects personal data in connection with the MEXC Card programme and the website at mexccard.com. It also sets out the rights available to you and how to exercise them.
1. Data Controller
OCEAN WAVE FINTECH PTY LTD is the controller responsible for the personal data described in this policy. Our business address is 7500A Beach Road, #04-307 The Plaza, Singapore 199591. We operate the MEXC Card programme and the website at mexccard.com, and we decide the purposes and means of the processing set out below.
This policy covers personal data we handle when you visit this website, submit an enquiry or application, communicate with our support team, or participate in the programme as an account administrator or authorised cardholder. It also covers personal data about the representatives and beneficial owners of a business that applies to us.
Some processing is carried out by our issuing bank partner as a controller in its own right — for example the maintenance of card records and statutory reporting connected with card issuance. Where that is the case, the partner’s own privacy notice applies to its processing and is provided to you during onboarding. We remain your first point of contact and will direct your request to the right party if it falls outside our control.
Our data protection contact can be reached at privacy@mexccard.com, or by post at the address above marked for the attention of the Data Protection Officer.
2. Data We Collect
We collect only the categories of data we need for the purposes in Section 3. Not every category applies to every person: a website visitor who never applies is covered by the last two categories only.
- Identity and contact data — full name, job title and role, business email address, telephone number, correspondence address, preferred language.
- Business and relationship data — legal name of the applicant business, registration number and place of registration, registered and trading addresses, ownership and control structure, details of directors, authorised representatives and beneficial owners, and a description of business activity and expected usage.
- Verification data — images or scans of government-issued identity documents, document numbers and expiry dates, date of birth, nationality, a facial image captured for identity matching where that check is used, proof of address, and corporate formation documents.
- Screening and compliance data — results of sanctions, politically exposed person and adverse media screening, risk ratings we assign, records of due diligence reviews, and records created when we assess unusual activity.
- Account and transaction data — account and card references, card expiry and status, transaction date, amount, currency, merchant name and category, authorisation and settlement records, fees applied, statements, dispute and chargeback records.
- Communications data — the content and metadata of emails and contact-form submissions, support tickets and notes of telephone conversations. Where a call is recorded, you are told at the start of the call and the recording is handled as described here.
- Technical and usage data — internet protocol address, approximate location inferred from it, device and operating system type, browser type and version, referring page, pages viewed, timestamps, and diagnostic records generated when an error occurs.
- Preference data — your cookie choice as recorded by the consent banner, and any marketing preference you have given or withdrawn.
We do not ask for special category data such as health data, and we ask you not to send it to us. A facial image used for identity matching may constitute biometric data in some jurisdictions; where it does, we process it only for verification and only where the applicable law allows it, and we ask for your explicit consent where that is the required basis. Card security codes are never requested by our support team by email.
3. Purposes of Processing
We use personal data for the following purposes:
- Assessing applications and onboarding — checking eligibility, verifying identity and authority, assessing risk, and setting up accounts and cards for approved applicants.
- Meeting financial crime obligations — customer due diligence, sanctions and restricted-party screening, ongoing monitoring, investigation of unusual activity, and reporting to the authorities where the law requires it.
- Providing and servicing the programme — issuing and replacing cards, applying spend controls and limits you configure, producing statements and expense records, calculating and collecting fees, and handling disputes and chargebacks.
- Security and fraud prevention — authenticating users, detecting and investigating unauthorised access or suspected fraud, maintaining audit records, and protecting our systems and yours.
- Customer support — responding to enquiries and complaints, keeping records of what was asked and what we answered, and training our staff using anonymised or redacted examples.
- Service improvement and measurement — understanding in aggregate how the website is used so we can improve content and performance. This uses the analytics described in our Cookie Policy and depends on your consent.
- Legal and regulatory compliance — record keeping, tax and accounting obligations, responding to lawful requests from regulators, courts and law enforcement, and establishing or defending legal claims.
- Programme communications and marketing — sending service messages that are necessary for the relationship, and sending optional updates about the programme where you have asked to receive them. Every optional message includes a way to unsubscribe.
We do not use personal data to make solely automated decisions that produce legal effects for you without human involvement. Automated checks do support our screening and fraud tools, and a person reviews a match before an application is declined or an account is restricted on that basis.
All applicants are subject to identity verification in accordance with applicable anti-money laundering and know-your-customer regulations.
4. Legal Bases
We rely on the following legal bases, depending on the purpose and on the law that applies to you.
- Performance of a contract, or steps before entering one — assessing your application, setting up and servicing your account, handling transactions, and providing support.
- Compliance with a legal obligation — customer due diligence, sanctions screening, transaction record keeping, suspicious activity reporting, tax and accounting obligations, and responses to lawful requests.
- Legitimate interests — preventing fraud and misuse, securing our systems, maintaining audit trails, managing risk, enforcing our terms, and improving our services. Where we rely on this basis we consider the effect on you and process only what is proportionate; you may object as described in Section 8.
- Consent — optional analytics cookies, optional marketing messages, and any biometric identity check where consent is the required basis. You may withdraw consent at any time, and withdrawal does not affect processing already carried out.
- Legal claims and public interest — establishing, exercising or defending legal claims, and cooperating with authorities acting within their mandate.
For individuals in Singapore, we process personal data in accordance with the Personal Data Protection Act 2012, relying on consent where required and on the exceptions permitted under that Act, including processing necessary for evaluative purposes, for investigation, and to comply with other legal requirements. Where the EU or UK General Data Protection Regulation applies to our processing of your data, the bases above correspond to Articles 6(1)(b), 6(1)(c), 6(1)(f) and 6(1)(a) respectively.
If we ever need to use your personal data for a new purpose that is not compatible with the purposes above, we will tell you and, where the law requires it, ask for your consent first.
5. Data Sharing
We do not sell personal data and we do not share it for third-party advertising. We disclose personal data only to the categories of recipient below, and only to the extent needed for the purpose described.
- Issuing and processing partners — the issuing bank partner that issues cards in the programme, card processors, programme managers and the payment network that authorises and settles transactions. These parties receive application, account and transaction data to issue cards and process payments, and they operate under their own regulatory obligations.
- Identity verification and screening providers — specialist providers that check identity documents, confirm business registration details, and screen against sanctions, politically exposed person and adverse media data sources.
- Cloud and infrastructure providers — hosting, content delivery, database, backup and email providers that operate the technical environment in which the website and our internal systems run.
- Business software providers — customer relationship, support ticketing, document storage, electronic signature and analytics tools used by our team, each limited to the data needed for its function.
- Professional advisers — external legal, audit, tax, accounting, insurance and compliance advisers, bound by professional confidentiality obligations.
- Authorities — regulators, supervisory bodies, tax authorities, courts and law enforcement, where disclosure is required by law or necessary to establish or defend legal claims. Legal constraints may prevent us from telling you about a specific disclosure.
- Corporate transactions — a prospective buyer, investor or successor in the context of a merger, acquisition or reorganisation, under confidentiality undertakings and limited to what is needed for the transaction.
- Your own organisation — where you are an authorised cardholder, the account administrators at your organisation can see the card and transaction records associated with the card issued to you.
Providers that process personal data on our behalf act on our instructions under a written agreement that covers confidentiality, security, the permitted purposes, the handling of sub-processors, the assistance they must give us with your rights requests, and the return or deletion of data at the end of the engagement. We carry out due diligence before engaging a provider and review those arrangements periodically.
6. International Transfers
We are established in Singapore and our primary processing takes place there. Some of the recipients described in Section 5 operate from other countries, which means your personal data may be transferred to, stored in, or accessed from a jurisdiction other than your own — in practice this typically includes locations in the Asia-Pacific region, the European Economic Area, the United Kingdom and the United States.
When we transfer personal data out of Singapore we take steps, as required by the Personal Data Protection Act 2012, to satisfy ourselves that the recipient is bound to a standard of protection comparable to the Act. In practice we do this through contractual commitments in our provider agreements, by relying on recognised certification schemes where they apply, and by limiting the data transferred to what the provider needs.
Where personal data protected by the EU or UK General Data Protection Regulation is transferred to a country without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses, or the UK International Data Transfer Agreement or Addendum, together with a transfer risk assessment and supplementary technical measures such as encryption in transit and at rest and access restrictions.
You can request information about the safeguards that apply to a particular transfer, including a copy of the relevant clauses with commercial terms redacted, by writing to privacy@mexccard.com.
7. Data Retention
We keep personal data only for as long as we need it for the purposes in Section 3, and then for the additional period required by law or by our record-keeping obligations. The periods below are the ones we currently apply; a longer period applies where an authority directs it or where data is relevant to an unresolved dispute, investigation or legal claim.
- Customer due diligence records and transaction records — at least five years from the end of the business relationship, or from the date of the transaction where that is later, in line with anti-money laundering record-keeping requirements.
- Account, billing and accounting records — for the period required by applicable tax and companies legislation, generally five years from the end of the relevant financial year.
- Applications that are not approved or not completed — up to 24 months from the date of the decision, so that we can handle a re-application, respond to a query about the outcome, and demonstrate that our process was followed.
- Support correspondence and complaint files — up to three years after the matter is closed, or longer where a dispute is unresolved.
- Website technical logs and security records — generally up to 12 months, and up to 24 months for records connected with a security investigation.
- Marketing preferences and unsubscribe records — for as long as needed to respect your choice, which in the case of an unsubscribe record means keeping a minimal suppression entry.
When a retention period ends we delete the data or irreversibly anonymise it. Anonymised and aggregated statistics that cannot be linked back to an individual may be kept for longer for reporting and planning. Deletion from live systems is followed by removal from backups in the ordinary backup rotation.
8. Your Rights
Subject to the law that applies to you, you have the following rights in relation to your personal data.
- Access — to be told whether we hold personal data about you, and to receive a copy of it together with information about how it is used.
- Correction — to have inaccurate or incomplete data corrected. We may ask for a supporting document where the change affects verification records, and we will pass the correction to recipients where that is practicable.
- Erasure — to have data deleted where we no longer need it, where you withdraw consent that was the only basis for it, or where you successfully object. This right does not extend to records we are legally required to retain, such as due diligence and transaction records.
- Portability — to receive the data you gave us in a structured, commonly used, machine-readable format, and to ask us to transmit it to another controller where that is technically feasible.
- Objection — to object to processing based on our legitimate interests, and to object at any time to direct marketing. Where you object to marketing we stop without needing to assess grounds.
- Restriction — to ask us to limit processing while an accuracy challenge or an objection is being considered.
- Withdrawal of consent — to withdraw consent for optional cookies, optional marketing, or an identity check that relies on consent, at any time and without affecting processing already carried out.
- Complaint — to complain to a supervisory authority. In Singapore that is the Personal Data Protection Commission; in the European Economic Area or the United Kingdom it is the authority for your country of residence.
To exercise a right, write to privacy@mexccard.com and tell us what you would like us to do. We may ask for information to confirm your identity before we act, so that we do not disclose data to the wrong person. We aim to acknowledge within 2 business days and to complete a request within 30 calendar days; where a request is complex we will tell you and explain the expected timing. We do not charge for a request unless it is manifestly excessive or repetitive, in which case we will tell you the cost before proceeding. If we decline a request in whole or in part, we will explain why and tell you how to escalate.
10. Security Measures
We use technical and organisational measures that are designed to protect personal data against loss, misuse, and unauthorised access, alteration or disclosure. These measures are reviewed as our services and the risks change.
- encryption of data in transit using current transport layer security, and encryption at rest for stored records and backups;
- role-based access control on a least-privilege basis, with multi-factor authentication required for administrative access to internal systems;
- separation of production and test environments, and use of redacted or synthetic data for testing;
- logging and monitoring of access to systems that hold personal data, with alerting on unusual patterns;
- security review and contractual security requirements for providers before engagement, and periodic reassessment afterwards;
- confidentiality undertakings and periodic data protection and security training for staff and contractors;
- a documented incident response process, including assessment, containment, remediation, and notification to affected individuals and the relevant authority within the timeframes the law requires.
No method of transmission over the internet or of electronic storage can be free from risk, so we do not claim that our measures remove it entirely. You can help protect your information by keeping your credentials confidential, using the additional authentication options we offer, keeping your devices and browser up to date, and contacting us at support@mexccard.com as soon as you suspect unauthorised access.
11. Children's Privacy
The MEXC Card programme and this website are intended for businesses and for adults acting on their behalf. Our services are not directed at children, and applicants must be at least 18 years old, as stated in our Terms of Service.
We do not knowingly collect personal data from anyone under 18. We do not target our content or communications at children, and we do not knowingly process children’s data for analytics or marketing purposes.
If we become aware that we have collected personal data from a person under 18 without the involvement of a parent or guardian where that is required, we will delete the data promptly and close any account opened in breach of our eligibility rules. If you are a parent or guardian and believe a child has given us personal data, write to privacy@mexccard.com and we will investigate and act.
12. Privacy Contact
For any question about this policy, about how we handle personal data, or to make a rights request, contact our data protection contact:
OCEAN WAVE FINTECH PTY LTD
Attention: Data Protection Officer
7500A Beach Road, #04-307 The Plaza, Singapore 199591
Email: privacy@mexccard.com
General and support enquiries: support@mexccard.com
We aim to respond within 2 business days.
You can also reach us through our contact page. Please tell us what your message concerns — for example access, correction, erasure, or a question about a specific processing activity — so that we can route it to the right team. If you are not satisfied with our response, you may complain to the supervisory authority identified in Section 8.
13. Updates to This Policy
We review this policy periodically and update it when our processing changes, when we engage a new category of provider, or when a legal or regulatory requirement changes. The version published on this page is the version in force, and the effective date shown at the top of the page tells you when it began to apply. This version takes effect on 1 September 2026.
Where a change materially affects how we use your personal data or the rights available to you, we aim to give at least 30 calendar days’ notice before it takes effect by posting a notice on this website and, for programme participants, by email to the address on file. Where a change requires your consent, we will ask for it before the new processing begins. Administrative changes, such as a correction or a change of contact details, take effect when published.
We do not reduce your rights under this policy retrospectively. If you would like a copy of a previous version, or a summary of what changed, request it at privacy@mexccard.com. This policy should be read together with our Terms of Service and our Cookie Policy.
All applicants are subject to identity verification in accordance with applicable anti-money laundering and know-your-customer regulations. Products and services are subject to eligibility, availability, and applicable fees. Availability and features may vary by region and program partners.