How BD Secure Pay collects, protects, and responsibly handles merchant business data, transaction records, and automated Android device synchronization.
Welcome to BD Secure Pay ("we", "our", or "us"). We operate as an automated multi-channel payment gateway and merchant aggregator platform in Bangladesh. This Privacy Policy governs the collection, processing, storage, and protection of information when you use our website, developer APIs, merchant panel, and our companion BD Secure Pay Android Synchronization Application.
By creating a merchant account, connecting a brand, generating API keys, or using our automated payment services, you acknowledge that you have read and agree to the data practices described in this policy.
We only collect data necessary to provide seamless, secure, and automated payment processing services:
Full name, business name, verified email address, mobile phone number, login credentials, and billing details.
Transaction IDs (TrxID), payment amounts, currency (BDT), timestamps, payment methods (bKash, Nagad, Rocket, Upay, Bank), customer names/emails provided on checkout, and transaction verification status.
Device model, Android OS version, unique Device Key, IP address, battery optimization status, and device connectivity timestamps.
Caller IP addresses, domain whitelists, request headers, API endpoints accessed, error logs, and browser user-agent tokens for fraud mitigation.
Our companion Android APK is designed solely as an automated payment listener for merchants. It requires specific Android runtime permissions to detect payment confirmations from official banking and MFS provider shortcodes.
| Android Permission | Exact Purpose | Data Handling & Privacy |
|---|---|---|
RECEIVE_SMS & READ_SMS |
Automatically intercept transaction verification SMS from official MFS/Bank senders (e.g., bKash, NAGAD, 16216, upay, IslamiBank). |
Filtered & Isolated — Only financial SMS containing matching TrxIDs are parsed. Personal text messages, contacts, and personal chats are NEVER read, saved, or uploaded. |
INTERNET & ACCESS_NETWORK_STATE |
Transmit verified transaction payloads securely to your BD Secure Pay server instance via 256-bit SSL. | Encrypted payload transmission over HTTPS. No unencrypted transmission. |
REQUEST_IGNORE_BATTERY_OPTIMIZATIONS |
Keep the SMS listener active in the background so automated orders are approved 24/7 without being closed by Android battery saver. | System level stability only; collects zero personal data. |
Some features are sold separately from the subscription plan as optional add-ons. An add-on is switched on for one merchant account only. None of them collects a new category of personal data beyond what is already described above, but each one uses it for a specific purpose, so each is listed here on its own.
For every add-on we additionally keep a billing record: which add-on, when it was activated, renewed or expired, how it was paid for — from the account balance or directly through the payment page — and the amount. This is ordinary accounting data, kept with the rest of the balance history described below, and it is what allows a charge to be explained or disputed later.
A merchant's registered email address is used to send the add-on notices — activated, expiring soon, renewed, renewal failed, expired. These are service messages about a paid feature, not marketing, and the wording of every one of them is set by the administrator, never generated from the merchant's data.
When an add-on expires, only the feature stops. Invoices, payment links, saved numbers and settings created while it was active are not deleted, and are governed by the retention and deletion rights described further down this page.
We implement industry-standard administrative, technical, and physical safeguards to ensure the confidentiality and integrity of your data:
We do not sell, trade, or distribute your information. We may only disclose data under the following strictly defined circumstances:
We retain transaction logs, device records, and API history for as long as necessary to maintain accurate merchant balance reports, resolve payment disputes, and fulfill statutory tax obligations. Temporary logs and transient SMS queue entries are automatically purged on a scheduled cycle.
Merchants may at any time request the permanent deletion of their account, brand data, and connected devices by contacting our support team.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data handling practices, please contact our Data Protection Team:
Gazipur,Bangladesh
bdhost.org1@gmail.com • +8801570212139