Legal
Privacy policy
Effective and last updated 11 September 2026
Amafi (HK) Limited operates MergerMatch. This policy explains how we handle personal information when you use mergermatch.ai, the public M&A Network, the MergerMatch Marketplace, the iOS app, MergerMatch Rooms, or contact our team.
Who is responsible for your information
Amafi (HK) Limited is the data user under the Hong Kong Personal Data (Privacy) Ordinance and the controller for account, Marketplace, website, support, security, and billing information described in this policy.
In Rooms, a workspace customer may decide why documents and personal information are uploaded and who may access them. That customer may be the controller or data user for that content, while Amafi (HK) Limited processes it to provide the workspace. If a Rooms invitation concerns information controlled by another organisation, contact that organisation first. You may also contact us and we will direct the request appropriately. Our Data Processing Addendum sets the processing terms for customer-controlled Rooms content.
Information we collect and where it comes from
We collect the following categories:
- Account and professional details. Name, login and contact email, password handled by our authentication provider, organisation, title, role, phone number, general location, biography, website, avatar, and professional profile information.
- Public M&A Network information. A person or company name, photograph or logo, role, organisation, named company contact, category, specialties, industries, markets, languages, typical deal-size range, introduction, public contact details, publication consent, confirmation date, and moderation state.
- Marketplace information. Buyer mandates, anonymous opportunity content, seller or adviser status, geography, sector, revenue, EBITDA, valuation and deal-size ranges, transaction preferences, buyer credibility information, images, matches, interest or pass decisions, reports, and blocked accounts.
- Rooms information. Workspace and room membership, invitations, files, document metadata, versions, permissions, disclosure previews, questions, answers, confidentiality acknowledgements, download and viewing records, exports, and audit history.
- Billing information. Plan, subscription, invoice, payment status, and limited transaction identifiers. Stripe handles payment card and bank details. MergerMatch does not store complete card numbers.
- Device, usage, and security information. IP address, user agent, browser or app information, authentication events, session identifiers, request logs, security events, referral information, and feature interactions.
- Optional website and product analytics. If you allow analytics, PostHog receives public-site page views, clicks, referral and campaign information, masked public-site session recordings, and limited Marketplace milestones such as account creation, buyer-role setup, mandate completion, opportunity views, and interest. We do not send names, contact details, mandate text, financial criteria, company details, listing identifiers, or Rooms content to PostHog.
- Communications. Contact forms, support messages, feedback, content reports, account deletion requests, and related correspondence.
Most information comes directly from you. We can also receive information from another user who invites you to a room, a colleague or adviser acting for an organisation, payment and email providers, security systems, and the website or app you use to reach MergerMatch. We do not compile profiles from data brokers or scrape personal information from public databases.
Fields marked as required are needed to create an account, provide the selected feature, or protect the service. If you do not provide required information, that feature may not be available. Other fields are voluntary. MergerMatch is not designed for special-category or highly sensitive personal information. Do not upload it unless you are authorised, it is necessary for a legitimate transaction purpose, and the selected workflow is appropriate.
Why we use information
| Purpose | Examples | Legal basis where required |
|---|---|---|
| Provide the service | Create accounts, match mandates and listings, make introductions, operate Rooms, send service messages, provide support, and process billing | Perform our contract with you or take requested pre-contract steps |
| Protect users and MergerMatch | Authenticate users, prevent abuse, investigate reports, enforce permissions, preserve audit evidence, and defend legal claims | Legitimate interests in a safe and reliable professional service, and legal obligations where they apply |
| Operate and improve the product | Troubleshoot, measure performance, understand feature use, and improve matching and workflows | Legitimate interests, with information minimised where practical |
| Optional analytics and marketing | Run consented PostHog analytics on the public website and Marketplace, and send marketing that you requested | Consent where required. You may withdraw it at any time |
| Compliance and business administration | Tax, accounting, corporate transactions, lawful requests, sanctions, and regulatory matters | Legal obligations and legitimate business interests |
We do not sell personal information. We do not share it for cross-context behavioural advertising. We do not use Marketplace or Rooms information for third-party advertising, and the current iOS app has no advertising or analytics SDK. We do not use confidential Marketplace or Rooms content to train a third-party general-purpose AI model without express permission.
Matching, introductions, and visibility
M&A Network profiles are intentionally public and may be indexed by search engines. We publish only profiles submitted from a confirmed account and approved for publication. A profile owner chooses which website, LinkedIn address, email, and telephone details to make public. The login email is not published automatically. Owners can update or remove their profiles. Updates to a published profile may be taken out of public view while they are reviewed.
MergerMatch uses rules supplied by users, including industry, geography, deal size, revenue, and control or minority preference, to identify potential matches. The score is a relevance aid. It is not a valuation, recommendation, eligibility decision, or decision that produces legal or similarly significant effects. Users decide whether to proceed and must perform their own diligence.
An opportunity is visible only to buyers whose mandates match and remains anonymous before an introduction. When a matched buyer with a complete profile selects that they are interested, MergerMatch records that decision and reveals the seller-side professional contact profile to that buyer. The buyer profile is not automatically shared with the seller side, and the seller is not notified through the current Marketplace workflow. Sellers and their authorised advisers instruct us to make this disclosure when they activate a listing. The iOS app presents this disclosure rule and asks for confirmation before activation.
Adviser matching and Rooms use different permission workflows. Adviser requesters and participating advisers receive identity information only through the applicable acceptance flow. Rooms administrators choose members, guests, groups, published document versions, and access permissions.
Who receives information
We disclose information only as needed for these purposes:
- Other users. Matched buyers, sellers, owners, brokers, advisers, workspace members, and invited Rooms guests receive information according to the workflow and permissions described above.
- Service providers. Supabase supports authentication, databases, functions, and Marketplace media. Amazon Web Services supports Rooms storage, compute, security, and email. Vercel hosts the website and Marketplace web app. PostHog provides optional public-site and Marketplace product analytics. Stripe handles Rooms billing. Resend, Amazon SES, and our email services deliver forms and transactional messages.
- Professional advisers and authorities. Lawyers, auditors, insurers, regulators, courts, law enforcement, and other authorities may receive the minimum necessary information for advice, claims, safety, compliance, or a lawful request.
- Corporate transactions. A genuine prospective buyer, investor, lender, or successor may receive information under appropriate confidentiality and use restrictions during a financing, reorganisation, sale, or similar transaction.
Providers act under contracts and data-protection terms appropriate to their role. We require providers that process MergerMatch information on our behalf to protect it consistently with this policy and applicable law. Some providers, including Apple and Stripe for parts of their services, may also act as independent controllers under their own privacy notices.
International transfers
MergerMatch is operated from Hong Kong and serves users in multiple countries. Core Supabase data and Rooms document storage are currently hosted in Singapore. MergerMatch email is sent through infrastructure in Australia. Vercel, Stripe, Resend, PostHog, and their subprocessors may process information in the United States and other countries where they operate.
Privacy laws and government-access rules differ between countries. Where a transfer safeguard is required, we rely on applicable provider data-processing agreements, contractual protections such as recognised standard contractual clauses, and technical measures appropriate to the information. You may contact us for more information about the safeguard relevant to your information.
Website and product analytics choices
PostHog analytics and masked session recording are off until you select Allow analytics. If allowed, PostHog uses a preference and analytics cookie shared between mergermatch.ai and app.mergermatch.ai so we can understand whether a public-site visit leads to a completed product step. The public site can use masked session recording. The Marketplace app does not use autocapture or session recording and sends only the limited milestones described above. We do not intentionally send confidential Marketplace content or any Rooms content to PostHog.
You can refuse analytics without losing service functionality. You can also change your choice at any time. Declining stops future collection and removes PostHog browser storage that MergerMatch can access on these sites.
How long we retain information
We keep information only for the period needed for the purpose described above. The periods below are our current rules or maximums. A shorter period applies when the information is no longer needed. A documented legal hold can require a longer period.
- Account, profile, listing, and mandate information is kept while the account or record is active. After a verified account deletion request, we complete the user-facing deletion process within 30 days, subject to the limited exceptions below.
- Introduction and transaction evidence that is reasonably needed to handle a dispute, confidentiality issue, fraud report, or legal claim may be restricted and retained for up to seven years after the relevant interaction.
- Rooms content is kept while the workspace is active and for an agreed closing or evidence period. Encrypted noncurrent document versions are currently configured to expire no later than seven years after becoming noncurrent, unless an approved deletion process erases them earlier or law requires longer retention.
- Billing, invoice, tax, and accounting records may be retained for seven years.
- Application, access, security, and infrastructure logs are generally retained for no more than 12 months, unless an incident or legal obligation requires a longer period.
- Support, report, and contact correspondence is generally retained for two years after resolution, unless it becomes relevant to a legal, safety, or transaction matter.
- Optional identifiable website and product analytics is retained for no more than 12 months before deletion or aggregation.
Backups and versioned storage can retain isolated copies until the applicable backup or lifecycle cycle expires. Those copies are access-restricted and are not restored for ordinary product use. If restored after a valid deletion, the deletion record is used to prevent the information from returning to active use.
Account deletion
Every user may initiate permanent account deletion from Profile, Account and security, Delete account in the iOS app, or contact us. The authenticated app request covers the shared Marketplace and Rooms identity. We aim to complete verified requests within 30 days and confirm completion by email.
We delete or anonymise associated personal information and user content unless retention is required or permitted for tax, billing, security, fraud prevention, legal claims, regulatory duties, or transaction evidence. Shared workspace ownership may need to be transferred first. Where an exception applies, we isolate the minimum necessary information, stop ordinary product use, record the reason and expiry, and tell the requester in the completion response.
Your choices and rights
Depending on your location, you may ask us to access, correct, export, delete, restrict, or stop certain use of your personal information. You may object to processing based on legitimate interests and withdraw consent at any time. Withdrawal does not affect processing that was lawful before withdrawal.
Hong Kong users have rights to request access to and correction of personal data under the Personal Data (Privacy) Ordinance. You may complain to the Office of the Privacy Commissioner for Personal Data. Users in the EEA or United Kingdom may also have the right to complain to their local data-protection authority. If California privacy law applies, California residents may request access, correction, deletion, and information about collection and disclosure without discriminatory treatment. MergerMatch does not sell or share personal information for cross-context behavioural advertising.
You can update many profile fields and notification settings in the product. For another request, email us or use the contact page. Describe your request and the account email involved. We may verify identity and authority before acting, and an authorised agent may be asked to provide proof of authority. We respond within the period required by applicable law.
Direct marketing
We send promotional email only when you expressly request it or opt in. Silence is not consent. Before using personal information for direct marketing, we will identify the types of information and marketing subjects involved and give you a clear way to refuse. You can unsubscribe through the message or contact us. Service, security, transaction, and account messages are not promotional and may still be sent while relevant to your use of the service.
We do not provide personal information to another organisation for that organisation's direct marketing.
Security
We use measures designed for the sensitivity of the service, including authentication, least-privilege access, row-level permissions, encryption in transit and at rest, private object storage, audit records, malware scanning, monitoring, and incident procedures. No system is completely secure. Protect your credentials, use appropriate workspace permissions, and promptly report suspected unauthorised access.
Children
MergerMatch is a professional service for people aged 18 and over. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. Contact us if you believe a child has provided information.
Changes to this policy
We may update this policy when the service, providers, or legal requirements change. We will post the new version and effective date here. We will provide additional notice before a material change when required by law or when the change significantly affects how existing information is used.
Contact
Amafi (HK) Limited
MergerMatch privacy team
Email contact@mergermatch.ai
You can also use our contact page. Mark the message Privacy request so it reaches the appropriate team.