Privacy Policy – Paymently
Important: The Paymently mobile application (the “App”) is intended only for registered Paymently customers who already have a Paymently account and Base URL. It is not a consumer app and has no standalone use for the public. The App does not provide banking, lending, wallet, or consumer financial services. Its sole function is to forward valid Mobile Financial Services (MFS) transactional SMS (e.g., bKash, Nagad, Rocket) to the customer’s self-hosted Paymently server deployed on their own VPS.
What Information the App Processes
1) SMS (MFS Transactional Messages Only)
- The App requests
READ_SMSandRECEIVE_SMSpermissions solely to read Mobile Financial Services (MFS) transactional messages. - Only messages from supported, whitelisted senders are processed. Personal, promotional, or unrelated messages are ignored.
- Processed transaction messages are transmitted securely to your configured Paymently server (your “Base URL”) and then appear in your dashboard at MFS Automation → SMS Data.
- We do not use SMS data for advertising or analytics, and we do not sell or share SMS content with third parties.
- SMS content is not sent to Paymently corporate systems other than the server you configure as your Base URL.
2) Camera (QR Code Scanning Only)
The App requests the CAMERA permission only for scanning QR codes (e.g., to log in or complete
payment
flows). The App does not record, store, or transmit photos or videos.
3) Notifications
On Android 13+ the App requests the POST_NOTIFICATIONS permission to:
- Inform you when background syncing is active or paused (a foreground service notification may indicate the App is running).
- Alert you to important sync results and errors (e.g., failed upload, permission required).
Notifications are local to your device. We do not collect notification content for analytics or advertising. You can control notification preferences from device settings at any time.
4) Account & Authentication
To use the App, you sign in with your Paymently dashboard credentials (Base URL, email, and password). These credentials are used strictly to authenticate you with your Paymently server and to enable secure syncing. They are not used for any other purpose.
5) Technical Log Data
When you use the App, we may collect limited technical information such as device model, operating system version, IP address, app configuration, and diagnostics (e.g., crash logs). We use this information only to monitor performance, troubleshoot issues, and improve reliability.
6) Firebase Crashlytics
We use Firebase Crashlytics to monitor app stability and diagnose crashes. Crashlytics may collect information such as device model, OS version, app version, time of crash, stack traces, and a randomly assigned app instance identifier. This information is used strictly for troubleshooting and improving the App. We do not use Crashlytics for advertising. For more information, please review Firebase Privacy & Security.
7) Advertising ID
The App does not access, request, or use the device’s Advertising ID.
Permissions Summary
| Permission / Feature | Purpose | Data Handling |
|---|---|---|
android.permission.INTERNET |
Securely communicate with your configured self-hosted Paymently server (Base URL). | Network requests are limited to your Base URL and essential third-party services (e.g., crash reporting). |
android.permission.POST_NOTIFICATIONS |
Display operational status, sync results, errors, and foreground-service indicator. | Notification content is local to device; we do not collect it for analytics or ads. |
android.permission.READ_SMS / android.permission.RECEIVE_SMS |
Read and receive MFS transaction SMS to sync to your Paymently dashboard. | Only whitelisted MFS senders are processed. No sale or sharing with third parties. |
android.permission.CAMERA |
Scan QR codes for login and payment flows. | No photos/videos are captured or stored by the App. |
android.permission.FOREGROUND_SERVICE /
android.permission.FOREGROUND_SERVICE_DATA_SYNC
|
Run a foreground service to reliably sync data in the background (required by newer Android versions). | Shows a persistent system notification while active; no additional personal data is collected. |
android.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONS |
Optionally allow the App to remain reliable under aggressive battery optimizations. | User-controlled; requested only to improve delivery/sync stability. No personal data collected. |
android.permission.RECEIVE_BOOT_COMPLETED |
Resume essential background tasks after device restart (e.g., re-establish sync). | No user content is read at boot; only service state is restored. |
com.nextzen.paymently.permission.C2D_MESSAGE |
Internal permission for secure in-app or push message handling. | Used only by the App; not shared with third parties. |
| android.hardware.telephony (feature, not required) | Used if the device supports telephony to receive SMS; the App also works on devices without it. | No additional personal data is collected because of this feature alone. |
| android.hardware.camera (feature, not required) | Used if the device has a camera for QR scanning; optional. | No additional personal data is collected because of this feature alone. |
Hosting Model
Self-hosted: Paymently is deployed by customers on their own VPS. All synced data goes only to the self-hosted Paymently server (the configured Base URL) controlled by the customer or their organization. Paymently corporate systems do not receive SMS content unless explicitly sent there by the customer.
Local Storage & Deletion Controls
- SMS Cleaning Setting: choose a retention period and optionally clean by message status (Failed, Pending, Sent).
- Clean All: delete all locally stored Paymently SMS entries at any time from the App.
Deleting locally does not automatically delete records that have already been synced to your Paymently dashboard. You can manage or delete those records from the dashboard according to your organization’s policies.
User Data Deletion
- Local App Data: delete via Clean All or SMS Cleaning Setting.
- Server Data: your Paymently dashboard is self-hosted on your VPS. Admins can delete SMS transaction records, user accounts, or logs directly in the dashboard.
- General requests: https://paymently.io/data-deletion.html
How We Use Information
- Securely sync valid MFS SMS transaction data from your device to your Paymently dashboard.
- Enable QR-based login and payment workflows.
- Deliver operational notifications about sync status and errors.
- Maintain and improve App stability, performance, and security (including via Crashlytics).
We do not use data for targeted advertising and we do not sell user data.
Data Processing & Security
Paymently is self-hosted software that you deploy on your own VPS. Data is transmitted over encrypted channels (e.g., HTTPS/TLS) to the Paymently server you configure as your Base URL. Access to data within that server is governed by your account permissions. We apply industry-standard safeguards designed to protect information during transmission and within the App on your device. However, no method of transmission or electronic storage is 100% secure.
Data Sharing
We do not share personal or SMS content with advertisers or data brokers. We may engage trusted service providers (e.g., error-reporting tools like Crashlytics) to operate and improve the App; they are bound by confidentiality obligations and may process data only on our instructions.
Retention
The App processes SMS data transiently to sync it to your self-hosted Paymently server on your VPS. Any longer-term retention occurs within your own server environment (your Base URL) under your or your organization’s control and policies. Technical diagnostics (e.g., Crashlytics crash reports) are retained for as long as necessary for troubleshooting and improvement, consistent with the provider’s retention practices.
Your Choices & Controls
- Revoke SMS, Camera, or Notifications permissions at any time from device settings (some features will stop working without these).
- Enable/disable particular whitelisted senders from the Filters tab.
- Use SMS Cleaning Setting or Clean All to remove local data.
- Sign out of the App at any time. To request account or data deletion on your Paymently server, contact your server administrator or reach us using the details below.
Government Apps
Paymently is not developed by or on behalf of any government organization.
Children’s Privacy
The App is not intended for children under the age of 13, and we do not knowingly collect information from children.
No Ads
The App does not contain third-party advertising.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top will reflect the most recent changes. Significant changes will be posted within the App or on our website.
Contact Us
If you have questions about this Privacy Policy or our data practices, contact us. For matters related to your Paymently server (your Base URL), you may also contact your organization’s administrator.