Hong Kong supplement — privacy
Last updated 26 August 2026
This supplement applies to Hong Kong and prevails over the general privacy policy for everything it covers. It carries only what Hong Kong adds under the Personal Data (Privacy) Ordinance (Cap. 486): what we collect, why we may hold it and how we protect it is in the general policy, and stays in force. It is mostly about when you are told things, and about the accounting record we keep.
What we tell you when we collect, and the box you tick
- The Ordinance does not ask for your consent to ordinary collection. What it asks is that you are told, at or before the moment we collect, what personal data we are taking, what we will use it for, who it may be given to, and that you may ask to see it and to correct it. That statement is what Cap. 486 calls a collection statement.
- Every way into UnivMenu that creates an account — an owner signing up, an owner claiming a menu, a finder joining, a finder photographing a menu — puts an empty tick box in front of you first, carrying that statement. We never tick it for you and it is never ticked when the page loads. A form sent without it is refused: no account exists, and nothing about you is stored.
- Who it may be given to, in full and with nothing else behind it: the infrastructure and hosting providers that run the servers, the provider that delivers an email where one is sent to you, the payment and banking providers that must see a payment to move it, the providers that read and translate a menu photograph and the text on it, and a Hong Kong authority where the law compels the disclosure. Nobody else. No data broker, no advertiser, no analytics company.
- Cookies are the same in Hong Kong as everywhere else and there is no Hong Kong rider on them: five cookies, all strictly necessary, no banner required. They are named one by one in the cookie policy.
Full detail — DPP1(3) and where the notice sits
Data Protection Principle 1(3) of Schedule 1 to the Ordinance requires that a data subject be informed, on or before collecting personal data from them, of whether it is obligatory or voluntary to supply the data, of the purpose for which it is to be used, of the classes of person to whom it may be transferred, and of the right to request access to and correction of the data together with the name or job title and address of the person to whom such a request should be sent.
UnivMenu gives that statement at the point of collection rather than behind a link, and takes a positive act — an unticked box you tick yourself — as the record that it was given. The Ordinance wants notice, not consent; taking consent as well does not reduce what we owe you and is not relied on to widen what we may do.
Data Protection Principle 1(3) also requires that you be told where to send an access or correction request. That address is hello@univmenu.com, at QUIKFORGE LIMITED, Unit 2A, 17/F, Glenealy Tower, No.1 Glenealy, Central, Hong Kong S.A.R.
There is no special category here, and we protect it as though there were
- Hong Kong has no sensitive-data category. The Ordinance has no equivalent of the special categories other markets define: a guest's allergy or dietary note, and the details of a bank account, are ordinary personal data here.
- That changes the label, not the handling. The necessity rule (DPP1), the security rule (DPP4) and the retention rule (DPP2) apply to them in full, and we hold payout details to the same standard we are held to in the markets that do call them sensitive — one system, one standard, the strictest of them.
- We ask a finder for bank details only when there is a reward to pay, and only to pay it. Withdrawing them is a button on your own account page, and the payout record is destroyed there and then. Writing to hello@univmenu.com does the same thing.
- Withdrawing means we can no longer pay you: a reward still pending cannot be disbursed once the details are gone.
- A guest's allergy and dietary choices stay inside that guest's own browser. They are never sent anywhere, so they never reach us and there is nothing here for us to hold.
Your rights, and how fast we answer
- Access — you may ask whether we hold personal data about you and require a copy of it. Correction — you may require us to correct what is wrong.
- The Ordinance gives us forty days to answer either. We answer well inside it, and where something is genuinely complex we tell you within the forty days what is outstanding.
- It costs nothing. The Ordinance permits a data user to impose a fee for complying with an access request. We do not charge one, and exercising a right never worsens the service you receive.
- If we refuse a request, in whole or in part, we say which part, why, and what your next step is — which is what section 21 of the Ordinance requires of us.
- Erasure — erase the account from your dashboard and it goes, subject only to the seven-year accounting record described below. Write to us from the address on the account, or tell us enough for us to be sure the account is yours — we do not ask for identity documents beyond that.
Full detail — how a Hong Kong request is handled
Sections 18 and 19 of the Ordinance govern a data access request and section 22 a data correction request. The compliance period is forty days from receipt of the request. Where we cannot comply within that period we must tell you so before it expires, give the reason, and comply as soon as practicable afterwards.
Section 28 permits a data user to impose a fee that is not excessive for complying with a data access request. We impose none, in Hong Kong or anywhere else.
Where we refuse a request under section 20 — for example because the data is not ours to give, or because giving it would disclose personal data about somebody else — section 21 requires a written refusal stating the reason, and section 27 requires the refusal to be entered in a log kept for that purpose.
Deletion of an account and destruction of payout details are executed on a verified request and are not deferred to the scheduled job described below. What survives is named in the retention section, and it survives because Hong Kong tax law says so, not because we want it.
Taking your data out of Hong Kong
- QUIKFORGE LIMITED is a Hong Kong company, and the servers that run the portal and host the menus are outside Hong Kong. Data you give us is transferred abroad and processed there.
- The destination is named, not left vague: your personal data goes to a virtual private server we rent from Hostinger International Ltd. in Kuala Lumpur, Malaysia. That is the machine the portal runs on and the machine the database sits on. It is read from Hong Kong by QUIKFORGE LIMITED. Published menu pages, which carry no personal data, are served from Hostinger shared hosting in the United Kingdom.
- Sending it out of Hong Kong is lawful. Section 33 of the Ordinance, which would restrict transfers of personal data outside Hong Kong, has never been brought into force.
- The duty that does bite is about the processor, not the border: where we hand your data to somebody to hold or handle for us, the Ordinance makes us responsible for preventing it being kept longer than necessary and for its security, by contract or by other means. QuikForge is the data user; Hostinger is a data processor and nothing more; and an act by an agent is treated as ours.
Full detail — cross-border transfer and the processor duty
Section 33 of the Ordinance was enacted in 1995 and has never been brought into operation. There is accordingly no statutory restriction on transferring personal data out of Hong Kong.
What applies instead is Data Protection Principle 2(3) and Data Protection Principle 4(2): a data user who engages a data processor, whether inside or outside Hong Kong, must adopt contractual or other means to prevent personal data transferred to the processor from being kept longer than is necessary, and to prevent unauthorised or accidental access, processing, erasure, loss or use. Section 65(2) treats an act done by an agent with authority as done by the principal. The Privacy Commissioner's Guidance on Recommended Model Contractual Clauses of May 2022 applies to those arrangements.
The flow this covers is one specific flow, and we state it so that what is assessed and what is published are the same thing. A person in Hong Kong opens the portal in a browser; the data they type — email address, password, restaurant name, payout details, the statements they accept — travels to portal.univmenu.com, which resolves to a virtual private server rented from Hostinger International Ltd. and physically located in Kuala Lumpur, Malaysia. It is stored there, in a database on that machine, and read from there by QUIKFORGE LIMITED in Hong Kong.
How long records stay, and what Hong Kong law keeps
- Payout details are destroyed three months after an account goes quiet, and the account itself is erased six months after that same point. A scheduled job does both, and a signed-in person can run either immediately from their own account page.
- What stays behind is the accounting record — the payments made and received, the invoices raised, and the minimum identifying detail a business record needs. The Inland Revenue Ordinance (Cap. 112, s. 51C) requires business records to be kept for at least seven years from the date each record is made. Where a record also falls under the accounting law of the market a payment was made in, we keep it for whichever period is longer, and destroy it when the last of them ends.
- They are kept for that purpose alone. They are not used for anything else, and they are not what an erasure reaches. Payment records are append-only: never deleted, never edited.
- That seven-year record is why an erasure can reach your account and still leave a payment behind.
- Everything else follows the retention rule rather than a fixed number: personal data is not kept longer than is necessary for the purpose it was collected for, which is Data Protection Principle 2(2), and the periods above are how we give that a date instead of an opinion.
Marketing
- We do not use your personal data in direct marketing, and we do not provide it to anybody else for theirs.
- Email from us is about your rewards, your invoices, your menu and your account. You choose whether to receive it when you register and you can stop it at any time.
A menu photograph is read by machine
- A photograph you send us is read by an automated vision model to get the dish names and prices off it, and dish text we do not already hold is translated by an automated language model. Both run outside Hong Kong, and the transfer section above covers them.
- Nothing that identifies a person goes with it. No account detail, no payout detail, no consent record, no guest order and no dietary choice a guest made is ever sent to a model.
Who to complain to
- Write to us first: hello@univmenu.com. We would rather fix it than be told to.
- If we do not put it right, the regulator is the Privacy Commissioner for Personal Data, Hong Kong, who enforces the Personal Data (Privacy) Ordinance and to whom you may complain about anything on this page.
- Data user: QUIKFORGE LIMITED, Business Registration No 79555262, Unit 2A, 17/F, Glenealy Tower, No.1 Glenealy, Central, Hong Kong S.A.R. · +370 665 10325.
General privacy policy → · Hong Kong terms supplement → · General terms → · Cookies →