Bank of China's Wallet Rules: Eight Documents, One Footnote
Putting a Bank of China credit card into a phone wallet means accepting eight documents. HaiPay read all of them.
September 29th, 2026
Last updated: September 29
Key takeaways
- Loading a Bank of China credit card into a phone wallet means accepting eight documents, published 2 June and effective 5 June.
- The Visa and Mastercard service agreements are 99.5% identical: the only differences are seven occurrences of the scheme's name.
- The one substantive difference is a footnote: with Mastercard the data recipient is Mastercard NUCC, so the data stays in China.
- Four fields leave the bank: name, card number, expiry and transaction information, to the scheme and to Apple's Shanghai entity.
- Sensitive-data consent is wider, covering CVV2 plus device geolocation, device identifier, network IP address and MAC address.
- Liability turns on a phone call: the customer bears nothing after the loss report takes effect, the bank nothing before it.
Data highlight
8documents
Documents a customer must accept to load a Bank of China credit card into a phone wallet, of which one footnote is the only substantive difference between the Visa and Mastercard sets
2026 editions, published 2 June 2026, effective 5 June 2026
Compiled by HaiPay on 29 September 2026 from documents published by Bank of China. The bank's bank card announcement page carries a notice dated 2 June 2026 announcing that the 2026 editions of the VISA and Mastercard mobile payment (credit application) service agreements and the related authorisation forms take effect from 5 June 2026. Eight PDF files are attached to that notice: for each of the two card schemes, a service agreement of 11 pages, a consent to the processing of customer personal information of 5 pages, a consent to the processing of sensitive customer personal information of 3 pages, and a consent to providing customer personal information to others of 3 pages. HaiPay downloaded all eight from the bank's own content domain and extracted their text by decoding each embedded font's ToUnicode mapping, which is necessary because the files use CID-keyed fonts and a naive extraction returns wrong digits. The comparison in this article is character-level, made on the extracted text after removing page numbers. The VISA service agreement extracts to 5,485 characters and the Mastercard service agreement to 5,482; a sequence comparison gives a similarity of 0.9952, and every difference is an occurrence of the scheme name, seven in total. The same comparison on the personal information consents gives 0.9957 and on the sensitive personal information consents 0.9908, in both cases with the scheme name as the only difference. The consents to providing information to others differ by more: the VISA form names VISA and Apple Technology Services (Shanghai) Co., Ltd. as recipients of the necessary name, credit card number, expiry date and transaction information, while the Mastercard form names Mastercard NUCC and the same Apple entity, and adds a numbered footnote stating that, to ensure that the information provided externally is stored within China, the Mastercard credit card mobile payment business has the relevant systems developed by Mastercard NUCC assisting Mastercard, and that the data recipient is Mastercard NUCC. That footnote is the only substantive difference HaiPay found across the eight documents. The status of Mastercard NUCC is taken from the People's Bank of China announcement that, on 17 November 2023, it issued a bank card clearing business licence to Mastercard NUCC Information Technology (Beijing) Co., Ltd., a joint venture established in China by Mastercard and NetsUnion Clearing Corporation, permitting it to authorise member institutions to issue and accept Mastercard-branded renminbi bank cards in China; HaiPay read that announcement as republished on an official Chinese government website because the original page on the central bank's site returned an error. The categories of sensitive personal information, the enrolment checks, the loss-reporting rule, the deemed-authorisation wording, the transaction limits, the five-device-card ceiling, the 24-hour activation window for cards loaded through a third-party wallet, the 45 days' notice for terminating the service and the amendment-by-announcement mechanism are all quoted or summarised from the service agreement and the consents themselves. All translations from Chinese are HaiPay's. This article does not report on, describe or confirm the accounts circulating on Chinese social media since 26 September 2026 about unauthorised transactions on Bank of China Mastercard cards; HaiPay checked the bank's card announcement list and found no related announcement, the most recent entry being dated 11 September 2026 and concerning a system upgrade. HaiPay did not contact Bank of China, Visa, Mastercard, Mastercard NUCC or Apple
Putting a Bank of China credit card into a phone wallet means accepting eight documents. HaiPay read all of them.
The Visa set and the Mastercard set are the same text. Across the two service agreements, 5,485 and 5,482 characters, the only differences are seven occurrences of the scheme's name. One footnote, in one consent form, is the single substantive difference in the whole set.
The footnote
In the form that permits the bank to hand a customer's personal information to others, the Visa version names Visa as the recipient. The Mastercard version names Mastercard NUCC, and adds a note: to ensure the information provided is stored inside China, the Mastercard mobile payment business has its systems built by Mastercard NUCC assisting Mastercard, and the data recipient is Mastercard NUCC.
Mastercard NUCC is the joint venture of Mastercard and NUCC, the Chinese clearing house. The People's Bank of China issued it a bank card clearing licence on 17 November 2023, allowing it to authorise members to issue and acquire Mastercard-branded renminbi cards in the country.
So the same act, loading a card into a wallet, sends the same fields to a different legal entity depending on which brand is printed on the card. With Visa the data goes to the scheme. With Mastercard it goes to a Chinese joint venture, and the form says why.

What actually leaves the bank
Four things: name, card number, expiry date and transaction information. They go to the scheme and to Apple Technology Services (Shanghai). That is the whole external list in the form.
A separate consent covers what the bank may process as sensitive personal information. It names document type and number; card number, expiry, CVV2, account type, account status and transaction information; and then device geolocation, device identifier, network IP address and MAC address.
The device block is the part a risk team will notice. Location, device fingerprinting data and network identifiers are consented for a purpose list that includes risk monitoring and management, dispute checking and statistical research.

The line about who pays
The agreement's pivotal sentence is in Article 2. If the mobile device is lost or stolen, the customer must report the device card lost by calling the credit card service line. The report takes effect once the formalities are complete, timed by the bank's own system record. The customer bears no loss from misuse after that moment, and the bank bears no loss from transactions before it.
There is no shared-liability band and no zero-liability promise. Liability turns on a phone call and a timestamp the bank keeps.
Around that line, the agreement is firm about what counts as the customer's own transaction. Anything completed with the card password, or with other verification methods agreed with the bank or a third party, is treated as done by the cardholder. So is anything done with the fingerprint or passcode stored on the device. The customer may not refuse to pay on the grounds that there was no receipt, that the signature is not theirs, or that no password was entered. Losses caused by leaked card numbers, phone numbers or SMS codes fall on the customer.
The bank keeps a matching right: where it detects impersonation, theft or counterfeit-card risk, it may suspend payment on the card.
Article 3 is headed errors and dispute resolution, and it allocates responsibility for the service not working. Apple Technology Services (Shanghai) is named for faults on its side, such as NFC failures. The scheme is named for its own, such as abnormal transaction routing. Force majeure brings partial or total relief. The article does not say who pays for a transaction the customer disputes.
The numbers in the agreement
Device card spending is capped at ¥100,000 per transaction and ¥300,000 a day, with foreign-currency equivalents set out for US dollars, euros, pounds and Australian dollars. The bank may adjust them.
One credit card can have up to five device cards across different devices, and one per product on any single device.
Enrolment checks the card number, expiry, CVV2, card status and the phone number on file, then sends the user into the bank's own app for identity verification. A card loaded through a third-party wallet must be activated within 24 hours or it lapses.
The bank may terminate the service on 45 days' public notice, and may amend the agreement by announcement, with continued use counting as acceptance.
What this is not
This article does not report on the accounts circulating on Chinese social media since 26 September about unauthorised transactions on Bank of China Mastercard cards. HaiPay found nothing about them on the bank's card announcements page, where the most recent item is dated 11 September and concerns a system upgrade. Nothing here describes or confirms any incident.
The documents are in Chinese and the translations are HaiPay's; where wording matters, the article follows the Chinese text. The 99.5% figure is a character-level comparison of the two extracted agreements, not a legal opinion. HaiPay did not contact Bank of China, Visa, Mastercard, Mastercard NUCC or Apple.
What to watch
Whether other Chinese issuers name the joint venture in their Mastercard wallet consents, which would make the split a market-wide feature rather than one bank's drafting.
Whether the device data block grows. It is already the widest category in the set.
And whether the report-and-timestamp rule holds when a dispute is about a token rather than a card. The agreement was written for a lost phone.
How to cite
HaiPay News, "Bank of China's Wallet Rules: Eight Documents, One Footnote", https://www.haipay.net/news/bank-of-china-wallet-terms-eight-documents, September 29th, 2026
About the author
Crystal
Digital Public Relations
A digital PR specialist with a Master's in Journalism & Communication from UNSW. Started as an intern at ABC Australia, now leads public relations at Haipay, crafting press releases and media strategies that bring brand stories to life.
Reviewed by WeiJun TangEditorial policy
5 sources
- Bank of China
Announcement on the 2026 editions of the VISA and Mastercard credit card mobile payment (credit application) service agreements and related authorisation forms, effective 5 June 2026
- Bank of China
Bank of China Mastercard Mobile Payment (Credit Application) Service Agreement, 2026 edition
- Bank of China
Bank of China Mastercard Mobile Payment (Credit Application) Authorisation for Providing Customer Personal Information to Others, 2026 edition
- Bank of China
Bank of China VISA Mobile Payment (Credit Application) Authorisation for Providing Customer Personal Information to Others, 2026 edition




