Cookie policy
Which cookies and browser storage our website and client portal use, what each one does, how long it lasts, and how to accept, refuse or change your choice.
In plain language
- Strictly necessary cookies run the site, the checkout, the client portal sign-in and your cookie choice. They are always on.
- Analytics cookies (Google Analytics) and marketing cookies (Google Ads and our campaign cookie) are optional.
- Wherever you are, optional cookies stay off until you accept them.
- "Reject all" is as easy as "Accept all". Change your mind at any time with "Cookie settings" in the footer.
- When you refuse or withdraw a category, we delete its cookies from our domain.
- PayPal and GlobalPay Hong Kong set their own cookies only on the payment step, to protect the payment.
This summary helps you read the document. If it differs from the full text below, the full text applies.
2. How your choice works
The first time you visit, a banner asks you to accept all, reject all, or choose by category. The analytics and marketing switches start off. You can reopen the banner at any time with "Cookie settings" in the footer, and withdrawing is as easy as accepting.
Analytics and marketing cookies stay off until you accept them, in every country. We do the same if we cannot tell where you are. If your browser sends a Global Privacy Control signal, we treat it as a refusal of marketing cookies.
Our hosting provider supplies your approximate country with each request. We use it only to set the occ_region cookie, which today holds "optin" for every country. We do not store the country.
We use Google Consent Mode. Before any Google tag loads, it is told whether analytics and advertising storage are allowed, and Google tags respect that setting. When you refuse or withdraw a category, we also delete that category's cookies on our domain.
We keep your choice for 180 days. After that, or when we add a new provider to this policy, we ask again.
You can also block or delete cookies in your browser settings. If you block strictly necessary cookies, checkout and your cookie choice may not work.
3. Strictly necessary (always on)
These make the site work or keep it secure. The law allows them without consent. We do not use them for analytics or advertising.
- occ_consent (first-party cookie): stores your cookie choice and when you made it. 180 days.
- occ_region (first-party cookie): stores the consent default that applies to you ("optin", which means optional cookies stay off until you accept them). 24 hours.
- occ_order (first-party cookie, not readable by page scripts): links your browser to the order you placed so only you can see its confirmation and pay. 30 days.
- occ_checkout_v1 (session storage): keeps your checkout progress, including the name, email and phone you typed, in this tab only. Cleared when you submit or close the tab.
- occ-ask-sid (session storage): a random ID for this tab, used to limit Ask OCC to a fair number of messages per hour. Cleared when you close the tab.
- Cloudflare Turnstile (on pages with forms or chat): checks that a person, not a bot, is sending a form. Cloudflare runs it in its own frame and may store short-lived security data. We do not use it for advertising.
- PayPal and GlobalPay Hong Kong (payment step only): when you pay by card or PayPal, the payment provider's hosted fields or page may set cookies to process the payment and prevent fraud. They are set by the provider under its own policy, and only on the payment step.
- payload-token (first-party cookie, admin area only): signs in our staff to the content system at /admin. Not set for visitors. Ends when the staff session ends.
4. Client portal (strictly necessary)
When you sign in to the client area at /myaccount (My account), we set cookies that keep you signed in and protect your account. They are needed for the service you asked for, so they do not need consent. We do not use them for analytics or advertising.
- __Secure-occ_myaccount (first-party cookie, strictly necessary, not readable by page scripts, sent only to /myaccount and the My account sign-in service): keeps you signed in to the client portal. It holds a random session ID; we store only a hashed copy. It lasts at most 30 days, and ends when you sign out or after 7 days without use. You can see your signed-in devices and end a session in your account settings.
- __Secure-occ_myaccount_mfa (first-party cookie, strictly necessary, not readable by page scripts, sent only to the My account sign-in service): remembers that the first sign-in step worked while you enter your second factor (authenticator code or passkey). 5 minutes.
- Passkeys are stored by your device or password manager, not in a cookie. We receive only a public key.
5. Preferences you set (always on)
These remember something you asked for. They stay in your browser and are not sent to us.
- occ-theme (local storage): your light or dark mode choice. Kept until you clear it.
- occ-ask-closed (local storage): remembers that you closed the Ask OCC panel, so it does not open by itself again. Kept until you clear it.
- occ-ask-w (local storage): the width you chose for the Ask OCC panel. Kept until you clear it.
6. Analytics (optional)
These help us understand which pages people visit and how the site performs, so we can improve it. We load them through Google Tag Manager, and only as your choice allows. We do not send names, emails or phone numbers to Google Analytics.
- _ga (Google Analytics 4, set on our domain): tells visits from different browsers apart. Up to 2 years.
- _ga_<ID> (Google Analytics 4, set on our domain): keeps the state of your session. Up to 2 years.
- occ_track_<order> (session storage): stops a purchase from being counted twice in this tab. Cleared when you close the tab.
7. Marketing (optional)
These show us which adverts and campaigns bring visitors and clients. They are used only after you accept marketing cookies. Turning marketing off tells Google tags not to use advertising storage or ad personalisation, and deletes our campaign cookie. We do not run Meta (Facebook or Instagram) adverts or tags.
- occ_attr (first-party cookie): stores the campaign that brought you here (UTM tags, advertising click IDs such as Google's gclid, gbraid or wbraid, or fbclid when a link was shared on Facebook or Instagram, the landing page and the referring site). If you send us a form, we add this to your enquiry. 90 days. We write it only after you accept marketing cookies.
- _gcl_au and other _gcl_ cookies (Google Ads, set on our domain): link ad clicks to enquiries and orders. 90 days.
8. Other companies involved
Google (Tag Manager, Analytics, Ads), Cloudflare, PayPal and GlobalPay Hong Kong may receive your IP address and browser details when their code runs in your browser: Google only as your cookie choice allows, PayPal and GlobalPay only on the payment step. Google may use data from its cookies under its own privacy policy. Our privacy notice explains where these companies are and how we protect transfers.
- Google: policies.google.com/privacy
- Cloudflare: cloudflare.com/privacypolicy
- PayPal: paypal.com/privacy
- GlobalPay Hong Kong (Global Payments Asia-Pacific): see the privacy notice linked on its payment page
9. Changes to this policy
We update this policy when we add or remove a cookie. If we add a new provider to an optional category, we ask for your choice again. Questions: privacy@offshorecompanycorp.com.
Change log
What changed in version 2026-09-27-r3 (12)
Strictly necessary (always on): Replaced the live text's general description of session and persistent cookies and web beacons with a list of each cookie and storage item found in the site code, with purpose and duration.
Why: Consent is valid only if people are told what each cookie does and how long it lasts.
Law: Directive 2002/58/EC Art. 5(3); GDPR Art. 4(11), Art. 7; PECR reg. 6(2)
Analytics (optional): Removed Microsoft Clarity and Hotjar (not used by the new site). Google Analytics 4 is now optional and consent-based.
Why: The policy must list only tools actually used; analytics cookies need consent in opt-in regions.
Law: Directive 2002/58/EC Art. 5(3); PECR reg. 6; Decree 356/2025/ND-CP Art. 4
Marketing (optional): Replaced "targeted advertising via third-party networks" with named Google Ads cookies and the occ_attr campaign cookie, all optional.
Why: Online behaviour tracking data is sensitive personal data in Vietnam and needs explicit consent; advertising cookies need prior consent under ePrivacy and PECR.
Law: Law 91/2025/QH15 Art. 28; Decree 356/2025/ND-CP Art. 4; Directive 2002/58/EC Art. 5(3)
How your choice works: New section on the consent banner, consent defaults, Global Privacy Control, Google Consent Mode, deletion on withdrawal and the 180-day renewal.
Why: Withdrawing consent must be as easy as giving it; people must know how to change their choice.
Law: GDPR Art. 7(3); Law 91/2025/QH15 Art. 9; Decree 356/2025/ND-CP Art. 6
Client portal (strictly necessary): New section for client portal sign-in and session cookies.
Why: The platform now includes a client portal with accounts, device sessions and two-step sign-in.
Law: Directive 2002/58/EC Art. 5(3) (strictly necessary exemption); PECR reg. 6(4)
How your choice works: Optional cookies now need consent in every country. The site sets the consent default to "optin" for all visitors.
Why: Owner decision of 27 September 2026: cookie consent everywhere.
Law: Directive 2002/58/EC Art. 5(3); PDPA (Singapore); PDPO DPP1; Decree 356/2025/ND-CP Art. 4
Strictly necessary (always on): Removed the Stripe cookies. PayPal and GlobalPay Hong Kong are named for the payment step only.
Why: Owner provider decision of 27 September 2026: PayPal and GlobalPay Hong Kong for card and wallet payments; no Stripe.
Law: Directive 2002/58/EC Art. 5(3) (strictly necessary exemption)
Marketing (optional): Removed the Meta cookies (_fbp, _fbc) and the Meta tag. No Meta adverts run at launch.
Why: Owner decision of 27 September 2026. The policy must list only cookies actually used.
Law: Directive 2002/58/EC Art. 5(3); GDPR Art. 13
Client portal (strictly necessary): Portal session cookie described by function (strictly necessary sign-in session that ends at sign-out or after inactivity).
Why: The portal is not yet live; the description is kept generic until its cookie names are final.
Law: Directive 2002/58/EC Art. 5(3); PECR reg. 6(4)
What cookies and browser storage are: Published: status, version and effective date 27 September 2026.
Why: Owner decision to publish the legal set on 27 September 2026.
Law: Directive 2002/58/EC Art. 5(3); GDPR Art. 13
Client portal (strictly necessary): Named the client portal cookies, __Secure-occ_portal (sign-in session, at most 30 days, ends after 7 days without use or at sign-out) and __Secure-occ_portal_mfa (second sign-in step, 5 minutes), with their purpose and duration.
Why: The portal cookie names are now final; the policy lists every cookie by name, purpose and duration. Published as a new version: the earlier version is kept under Versions.
Law: Directive 2002/58/EC Art. 5(3); PECR reg. 6(4); GDPR Art. 13
Client portal (strictly necessary): Renamed only: the client portal moved to /myaccount (My account) on the main domain, and its cookies are now __Secure-occ_myaccount and __Secure-occ_myaccount_mfa. Purpose, duration and legal basis are unchanged. An existing sign-in is carried over once to the new cookie and the old cookies are deleted.
Why: Owner decision of 27 September 2026: the client area lives at /myaccount on the main domain. The policy lists every cookie by its current name. Published as a new version: the earlier version is kept under Versions.
Law: Directive 2002/58/EC Art. 5(3); PECR reg. 6(4); GDPR Art. 13
Sources
- OCC Privacy Policy (live text, cookie section), Offshore Company Corp (accessed Sep 2026) (opens in a new tab)
- Directive 2002/58/EC (ePrivacy Directive), EUR-Lex (accessed Sep 2026) (opens in a new tab)
- Regulation (EU) 2016/679 (General Data Protection Regulation), EUR-Lex (accessed Sep 2026) (opens in a new tab)
- Privacy and Electronic Communications (EC Directive) Regulations 2003, legislation.gov.uk (accessed Sep 2026) (opens in a new tab)
- Data (Use and Access) Act 2025, legislation.gov.uk (accessed Sep 2026) (opens in a new tab)
- The Data (Use and Access) Act 2025: what does it mean for organisations?, Information Commissioner's Office (accessed Sep 2026) (opens in a new tab)
- Personal Data Protection Act 2012, Singapore Statutes Online (accessed Sep 2026) (opens in a new tab)
- Luật Bảo vệ dữ liệu cá nhân số 91/2025/QH15, Cổng Thông tin điện tử Chính phủ (vanban.chinhphu.vn) (accessed Sep 2026) (opens in a new tab)
- Nghị định số 356/2025/NĐ-CP quy định chi tiết Luật Bảo vệ dữ liệu cá nhân, Cổng Thông tin điện tử Chính phủ (vanban.chinhphu.vn) (accessed Sep 2026) (opens in a new tab)
Laws and regulator guidance this document follows. They explain our obligations; they are not legal advice for your situation.
One IBC Limited · HK TCSP Licence TC001305 · Unit 1411, 14/F, COSCO Tower, 183 Queen's Road Central, Sheung Wan, Hong Kong