Privacy Policy – Paymently

Last updated: 2025-08-26

Important: The Paymently mobile application (the “App”) is intended only for registered Paymently customers who already have a Paymently account and Base URL. It is not a consumer app and has no standalone use for the public. The App does not provide banking, lending, wallet, or consumer financial services. Its sole function is to forward valid Mobile Financial Services (MFS) transactional SMS (e.g., bKash, Nagad, Rocket) to the customer’s self-hosted Paymently server deployed on their own VPS.

What Information the App Processes

1) SMS (MFS Transactional Messages Only)

2) Camera (QR Code Scanning Only)

The App requests the CAMERA permission only for scanning QR codes (e.g., to log in or complete payment flows). The App does not record, store, or transmit photos or videos.

3) Notifications

On Android 13+ the App requests the POST_NOTIFICATIONS permission to:

Notifications are local to your device. We do not collect notification content for analytics or advertising. You can control notification preferences from device settings at any time.

4) Account & Authentication

To use the App, you sign in with your Paymently dashboard credentials (Base URL, email, and password). These credentials are used strictly to authenticate you with your Paymently server and to enable secure syncing. They are not used for any other purpose.

5) Technical Log Data

When you use the App, we may collect limited technical information such as device model, operating system version, IP address, app configuration, and diagnostics (e.g., crash logs). We use this information only to monitor performance, troubleshoot issues, and improve reliability.

6) Firebase Crashlytics

We use Firebase Crashlytics to monitor app stability and diagnose crashes. Crashlytics may collect information such as device model, OS version, app version, time of crash, stack traces, and a randomly assigned app instance identifier. This information is used strictly for troubleshooting and improving the App. We do not use Crashlytics for advertising. For more information, please review Firebase Privacy & Security.

7) Advertising ID

The App does not access, request, or use the device’s Advertising ID.

Permissions Summary

Permission / Feature Purpose Data Handling
android.permission.INTERNET Securely communicate with your configured self-hosted Paymently server (Base URL). Network requests are limited to your Base URL and essential third-party services (e.g., crash reporting).
android.permission.POST_NOTIFICATIONS Display operational status, sync results, errors, and foreground-service indicator. Notification content is local to device; we do not collect it for analytics or ads.
android.permission.READ_SMS / android.permission.RECEIVE_SMS Read and receive MFS transaction SMS to sync to your Paymently dashboard. Only whitelisted MFS senders are processed. No sale or sharing with third parties.
android.permission.CAMERA Scan QR codes for login and payment flows. No photos/videos are captured or stored by the App.
android.permission.FOREGROUND_SERVICE / android.permission.FOREGROUND_SERVICE_DATA_SYNC Run a foreground service to reliably sync data in the background (required by newer Android versions). Shows a persistent system notification while active; no additional personal data is collected.
android.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONS Optionally allow the App to remain reliable under aggressive battery optimizations. User-controlled; requested only to improve delivery/sync stability. No personal data collected.
android.permission.RECEIVE_BOOT_COMPLETED Resume essential background tasks after device restart (e.g., re-establish sync). No user content is read at boot; only service state is restored.
com.nextzen.paymently.permission.C2D_MESSAGE Internal permission for secure in-app or push message handling. Used only by the App; not shared with third parties.
android.hardware.telephony (feature, not required) Used if the device supports telephony to receive SMS; the App also works on devices without it. No additional personal data is collected because of this feature alone.
android.hardware.camera (feature, not required) Used if the device has a camera for QR scanning; optional. No additional personal data is collected because of this feature alone.

Hosting Model

Self-hosted: Paymently is deployed by customers on their own VPS. All synced data goes only to the self-hosted Paymently server (the configured Base URL) controlled by the customer or their organization. Paymently corporate systems do not receive SMS content unless explicitly sent there by the customer.

Local Storage & Deletion Controls

Deleting locally does not automatically delete records that have already been synced to your Paymently dashboard. You can manage or delete those records from the dashboard according to your organization’s policies.

User Data Deletion

How We Use Information

We do not use data for targeted advertising and we do not sell user data.

Data Processing & Security

Paymently is self-hosted software that you deploy on your own VPS. Data is transmitted over encrypted channels (e.g., HTTPS/TLS) to the Paymently server you configure as your Base URL. Access to data within that server is governed by your account permissions. We apply industry-standard safeguards designed to protect information during transmission and within the App on your device. However, no method of transmission or electronic storage is 100% secure.

Data Sharing

We do not share personal or SMS content with advertisers or data brokers. We may engage trusted service providers (e.g., error-reporting tools like Crashlytics) to operate and improve the App; they are bound by confidentiality obligations and may process data only on our instructions.

Retention

The App processes SMS data transiently to sync it to your self-hosted Paymently server on your VPS. Any longer-term retention occurs within your own server environment (your Base URL) under your or your organization’s control and policies. Technical diagnostics (e.g., Crashlytics crash reports) are retained for as long as necessary for troubleshooting and improvement, consistent with the provider’s retention practices.

Your Choices & Controls

Government Apps

Paymently is not developed by or on behalf of any government organization.

Children’s Privacy

The App is not intended for children under the age of 13, and we do not knowingly collect information from children.

No Ads

The App does not contain third-party advertising.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top will reflect the most recent changes. Significant changes will be posted within the App or on our website.

Contact Us

If you have questions about this Privacy Policy or our data practices, contact us. For matters related to your Paymently server (your Base URL), you may also contact your organization’s administrator.