Privacy Policy

Last updated September 2026

1. What we store

For each payment we store the confirmation SMS your own device forwards to us: the provider, transaction ID, amount, sender wallet number, and the raw message text. We also store your account email, name, and a hashed password.

2. Why we keep the raw SMS

The original message is retained alongside the parsed fields so a disputed payment can be traced back to the exact text your phone received. It is visible only to the merchant who owns it.

3. Customer wallet numbers

Sender numbers appear in your own transaction feed because you need them to reconcile payments. They are masked in the interface and are never shown to other merchants or to the public.

4. Tenant isolation

Every query is scoped to the store that owns the data. One merchant cannot read another's transactions, devices, or credentials.

5. Passwords and tokens

Passwords are stored only as bcrypt hashes. Session and password-reset tokens are stored only as SHA-256 hashes, so a database dump cannot be replayed as a live login.

6. Security logging

We record failed administrator sign-ins, rejected webhook calls, and blocked replay attempts, along with the originating IP address. These logs are used to protect the platform and are visible only to platform administrators.

7. What we never do

We never receive your MFS PIN, never take custody of funds, and never sell or share merchant or customer data with third parties.

8. Deletion

Contact the platform administrator to have your account and its associated transaction history removed.