Privacy Policy (draft)
DRAFT for the owner and a qualified person to review. This is not legal advice and it has not been reviewed by a lawyer. Statements below describe how QRPayBD is built at the time of writing (2026-09-20). Check them again before publishing.
Last updated: 2026-09-25
Who we are
QRPayBD is run by Israfil. You can reach us at info@qrpaybd.com.
QRPayBD helps online sellers in Bangladesh confirm wallet payments. It reads payment-confirmation SMS on the seller's own Android phone, matches them to orders, and tells the seller's store. It does not hold or move money.
What we collect from shop owners
When you use QRPayBD as a shop owner, we store:
- Your account: email address, shop or business name, and your password as a one-way hash (we cannot read your password).
- Payment details you enter so customers can pay you: wallet numbers and notes. These are shown to your customers on the payment page.
- Your phones: a label, connection status, the time it last checked in, and the app version. The phone's access key is stored only as a hash.
- Your orders: amount, your own order ID, a reference code, status, the TrxID that confirmed it, and the time it was paid.
- Your store connection: API keys (stored as hashes; only a short prefix is kept to tell them apart), your webhook address, and the signing secret we use to sign webhooks.
- Login sessions: a session token, stored as a hash on our side.
Payment messages from your phone
The Collector app asks for permission to receive and read SMS. It applies these rules on the phone before anything is sent:
- It skips messages from senders that are ordinary phone numbers.
- It never sends messages that look like an OTP, PIN, password or verification code.
- It only sends messages that mention a taka amount.
- To catch messages it missed while the app could not run, it also scans your recent inbox: the last 24 hours the first time, and never further back than 7 days. The same rules apply.
Our server applies the same rules again. It stores the full text only of messages that mention a taka amount. That includes payment messages, and it can also include other money messages from a bank or wallet, such as cash-out notices or offers. These texts can contain a payer's phone number, a TrxID and your wallet balance.
For any other message that reaches us (for example one that looks like an OTP, one with no money amount, or one from an ordinary phone number), we store only a placeholder, not the text. We do not keep OTPs or PINs.
We never ask for, and the app never handles, your wallet PIN or password.
What we collect from your customers
Customers do not create accounts. The payment page shows the shop's name, the amount, and the shop's payment details. The customer types a TrxID, and we store it with the order so we can check it against the payment message.
We do not ask customers for a name, phone number, PIN or password. A payment message on the shop's phone may contain the payer's phone number, and that message is stored as described above.
The payment page uses no third-party scripts or trackers. It asks search engines not to index it.
To limit abuse, we count requests per IP address for a short time. In the current version this count is held in the server's memory and is not written to our database. Our hosting provider (Namecheap) may keep ordinary server logs that include IP addresses. How long the provider keeps those logs is decided by the provider, not by us.
Cookies and browser storage
The dashboard keeps your login token in your browser's local storage. We do not use advertising cookies.
The payment page may remember a language choice in your browser (a cookie or local storage). We do not use analytics, advertising or tracking scripts on this website.
Why we use this data
To run the service: create your account, pair your phone, match payments to orders, show your dashboard, send webhooks to your store, and keep the service safe from misuse.
Who we share it with
We do not sell your data. Order details are sent to your own store through the webhook address you set. We use a hosting provider (Namecheap) to run the service. We do not send your data to bKash, Nagad, Upay, Rocket or any bank, and we are not affiliated with them. We do not sell your data and we do not use it for advertising.
How long we keep it, and deleting it
The current version has no automatic deletion and no self-service account deletion. Removing a phone in the dashboard stops it sending messages, and revoking an API key stops that key working, but past order and message records stay in your account.
To have your account and records deleted, or to ask what we hold about you, email info@qrpaybd.com. For now we keep account and payment records for as long as your account exists, and nothing is deleted automatically. Database backups are kept for a limited time (currently 14 days).
How we protect it
Passwords, API keys, phone keys and session tokens are stored as hashes. The Collector app talks to our server over HTTPS. The app keeps its key in encrypted storage on the phone. Webhooks are signed. No system is perfectly secure, and we cannot promise it is.
Your choices
You can ask to see, correct or delete your data by emailing info@qrpaybd.com. You can uninstall the Collector app, or remove the phone in your dashboard, at any time. The law that applies to your rights depends on where you and we are. We operate under the laws of Bangladesh.
Changes and contact
If we change this policy, we will update the date at the top. Questions: info@qrpaybd.com.