Privacy Policy
This Privacy Policy explains how squard.dev (“we”, “us”) collects, uses, and protects information when you use PayAutomate — the website, merchant dashboard, public checkout, and Android app at payautomate.squard.dev.
1. Information we collect
- Account: name, email, and password (stored hashed) when you sign up, or name and email if you use Google sign-in
- Merchant profile: business name, bKash / Nagad / Rocket numbers, webhook URL, and API keys we generate for you
- Products: names, prices, notes, and public checkout slugs you create
- Payments: provider, Transaction ID, amount in BDT, optional customer reference, and verification status
- SMS (Android app only): payment confirmation messages used solely to extract TrxID, amount, and provider
- Technical data: IP address, browser or device type, and basic logs
- Cookies: session / auth cookies needed to keep you signed in
2. SMS permission
The Android app may request the RECEIVE_SMS permission. It is used only to detect payment confirmation
messages from bKash, Nagad, and Rocket. We do not read unrelated SMS on the device.
3. How we use information
- To verify payments and prevent the same Transaction ID from being used twice
- To show merchants a dashboard, settings, and transaction history
- To notify a merchant website via API or signed webhook after verification
- To authenticate you and provide support, security, and service improvements
- To measure site performance (analytics) and show ads on the website where ads are enabled
- To comply with legal obligations
4. Data retention
Transaction records are kept for financial audit and fraud prevention. You may request deletion of personal data on the delete account page.
5. Contact
Privacy questions: [email protected] · Contact · Terms of Service