Privacy Policy
This Privacy Policy explains how GBA SERVICE GROUP LIMITED (“we”, “us”, “our”) collects, uses, shares and protects personal information when you use the Rock Pay mobile application and the website at gbagroupservices.com (together, the “Service”).
1. Who we are
The Service is operated by GBA SERVICE GROUP LIMITED, a company incorporated in Hong Kong, with its registered office at Rm D10, 9/F, Camelpaint Building Block 2, 62 Hoi Yuen Road, Kwun Tong, Kowloon, Hong Kong. We are the data user (data controller) responsible for your personal information. We handle personal data in accordance with the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong and other data protection laws that apply to you.
For any privacy question or request, contact us at info@gbagroupservices.com.
2. Information we collect
Information you give us
- Account information — your email address, which you use to sign in with a one-time code.
- Profile information — your first and last name and, if you add it, your phone number.
- Identity verification (KYC) information — a photo of your government-issued identity document (for example, a passport or ID card), the details it contains (such as name, date of birth, nationality, document number and expiry date), a selfie and a short liveness check. Liveness detection may use your camera and microphone. This information is collected and processed by our identity verification provider on our behalf (see section 5).
- Communications — the content of messages you send us, for example by email.
Information created when you use the Service
- Wallet and transaction information — the USDT (TRC20) deposit address we assign to you, your balance, deposits, transfers, destination addresses you send to, amounts, network fees, transaction hashes and timestamps.
- Verification status — whether your identity verification is not started, pending, approved or rejected, and the reference of your verification session.
- Technical information — information needed to keep you signed in and to operate the Service securely, such as session tokens, IP address, device and operating system type, app version and server logs. If you enable notifications, we store a push notification token.
Information that stays on your device
Your app passcode and your Face ID / biometric setting are stored only in the secure storage of your device (for example, the iOS Keychain). We never receive or store your biometric data — Face ID and fingerprint checks are performed entirely by your device’s operating system.
Camera and photos
We ask for access to your camera, microphone and photo library only so you can capture or upload your ID document and complete the selfie and liveness check. We do not access them for any other purpose.
3. How we use your information
- To create and manage your account and let you sign in.
- To verify your identity and screen for fraud, sanctions and other financial crime, as required by applicable anti-money laundering and counter-terrorist financing (AML/CTF) laws.
- To provide the wallet: assign your deposit address, detect and credit incoming deposits, process transfers you request and show your balance and history.
- To calculate and display fees and validate destination addresses before you send.
- To keep the Service secure, prevent abuse and investigate suspicious activity.
- To communicate with you about your account, security and important changes, and to respond to your requests.
- To comply with legal obligations, respond to lawful requests from authorities, and establish or defend legal claims.
- To maintain and improve the Service.
We do not sell your personal information, and we do not use it for third-party advertising or to track you across other companies’ apps and websites.
4. Legal bases
Where the law requires a legal basis for processing (for example, if you are in the European Economic Area or the United Kingdom), we rely on:
- Performance of a contract — to provide the Service you signed up for.
- Legal obligation — identity verification, record keeping and reporting under AML/CTF and other laws.
- Legitimate interests — securing the Service, preventing fraud and improving our product, where these interests are not overridden by your rights.
- Consent — where we ask for it, such as for device permissions or biometric verification where consent is required. You can withdraw consent at any time.
5. Who we share it with
We share personal information only as needed to run the Service, and only with service providers bound by confidentiality and data protection obligations:
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Cloud hosting, database, authentication and one-time sign-in codes | Account, profile, wallet and transaction data; technical data |
| Didit | Identity verification, document checks, selfie and liveness checks | ID document images and data, selfie, liveness data, verification result |
| Tatum | Blockchain infrastructure: deposit addresses, deposit notifications and sending transactions | Wallet addresses, transaction data |
| TronGrid (TRON network) | Reading balances and transaction status from the TRON blockchain | Public wallet addresses |
| Apple / Google | App distribution and push notifications | Push token, app store data under their own policies |
We may also disclose information: (a) where required by law, regulation, court order or a lawful request from a government, regulator or law-enforcement authority; (b) to protect the rights, property or safety of our users, the public or us; and (c) to a buyer or successor in connection with a merger, acquisition or sale of assets, in which case this policy will continue to apply to your information.
6. Blockchain data
USDT transfers are recorded on the public TRON blockchain. Wallet addresses, amounts and timestamps of on-chain transactions are publicly visible and are permanent. We cannot change or delete information recorded on a blockchain, including after you delete your account. We do not publish your name or identity on the blockchain.
7. International transfers
Our service providers may store and process information in countries other than the one you live in, including outside Hong Kong. When we transfer personal information internationally, we take steps to ensure it receives an adequate level of protection, such as contractual safeguards with our providers.
8. How long we keep it
We keep personal information for as long as your account is open and as needed to provide the Service. When you delete your account, we delete or anonymise your personal information, except where we must keep certain records to comply with legal obligations — for example, anti-money laundering laws may require us to keep identity verification and transaction records for at least five years after the end of our relationship with you. Records kept for this reason are restricted and used only for that purpose, then securely deleted.
See our account deletion page for details.
9. Security
We use technical and organisational measures to protect your information, including encryption in transit, access controls on our database so that each user can only access their own records, server-side checks on every transfer, and secure on-device storage for your passcode. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. Please keep your device and email account secure and tell us immediately at info@gbagroupservices.com if you suspect unauthorised access to your account.
10. Your rights and choices
Depending on where you live, you may have the right to:
- access the personal information we hold about you and receive a copy;
- correct inaccurate or incomplete information;
- delete your information (subject to our legal retention obligations);
- object to or restrict certain processing, or withdraw consent;
- receive your information in a portable format; and
- complain to a data protection authority — in Hong Kong, the Office of the Privacy Commissioner for Personal Data.
You can update your phone number in the app, and you can delete your account at any time from Settings → Delete account. For any other request, email info@gbagroupservices.com from the email address linked to your account. We may need to verify your identity before acting on a request, and we will respond within the time required by applicable law (in Hong Kong, within 40 days for data access and correction requests).
You can turn off camera, microphone, photo and notification permissions at any time in your device settings; some features, such as identity verification, will not work without them.
11. Children
The Service is not intended for anyone under 18 years of age, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will post the new version on this page and change the “Last updated” date. If the changes are significant, we will notify you in the app or by email before they take effect.
13. Contact us
GBA SERVICE GROUP LIMITED
Rm D10, 9/F, Camelpaint Building Block 2, 62 Hoi Yuen Road, Kwun Tong, Kowloon, Hong Kong
Email: info@gbagroupservices.com
Website: gbagroupservices.com