BD Secure Pay
  • Home
  • About
  • Services
  • Addons
  • Pricing
  • Developer
  • Android App
  • Login
Transparency & Data Protection

Privacy Policy

How BD Secure Pay collects, protects, and responsibly handles merchant business data, transaction records, and automated Android device synchronization.

Effective Date: January 1, 2026 • Bangladesh Bank & Global Compliance
Merchant Privacy Commitment

We do not sell, rent, or monetize your personal or customer financial data to third-party advertisers. All data is processed solely to fulfill automated payment gateway services.

1 Introduction & Scope

Welcome to BD Secure Pay ("we", "our", or "us"). We operate as an automated multi-channel payment gateway and merchant aggregator platform in Bangladesh. This Privacy Policy governs the collection, processing, storage, and protection of information when you use our website, developer APIs, merchant panel, and our companion BD Secure Pay Android Synchronization Application.

By creating a merchant account, connecting a brand, generating API keys, or using our automated payment services, you acknowledge that you have read and agree to the data practices described in this policy.

2 Information We Collect

We only collect data necessary to provide seamless, secure, and automated payment processing services:

Merchant Account Information

Full name, business name, verified email address, mobile phone number, login credentials, and billing details.

Transaction & Payment Data

Transaction IDs (TrxID), payment amounts, currency (BDT), timestamps, payment methods (bKash, Nagad, Rocket, Upay, Bank), customer names/emails provided on checkout, and transaction verification status.

Connected Device Information

Device model, Android OS version, unique Device Key, IP address, battery optimization status, and device connectivity timestamps.

Technical & API Security Logs

Caller IP addresses, domain whitelists, request headers, API endpoints accessed, error logs, and browser user-agent tokens for fraud mitigation.

3 Android Companion App & SMS Permissions

Critical Privacy Disclosure for Mobile Users:

Our companion Android APK is designed solely as an automated payment listener for merchants. It requires specific Android runtime permissions to detect payment confirmations from official banking and MFS provider shortcodes.

Android Permission Exact Purpose Data Handling & Privacy
RECEIVE_SMS & READ_SMS Automatically intercept transaction verification SMS from official MFS/Bank senders (e.g., bKash, NAGAD, 16216, upay, IslamiBank). Filtered & Isolated — Only financial SMS containing matching TrxIDs are parsed. Personal text messages, contacts, and personal chats are NEVER read, saved, or uploaded.
INTERNET & ACCESS_NETWORK_STATE Transmit verified transaction payloads securely to your BD Secure Pay server instance via 256-bit SSL. Encrypted payload transmission over HTTPS. No unencrypted transmission.
REQUEST_IGNORE_BATTERY_OPTIMIZATIONS Keep the SMS listener active in the background so automated orders are approved 24/7 without being closed by Android battery saver. System level stability only; collects zero personal data.

4 Optional Add-ons & The Data They Use

Some features are sold separately from the subscription plan as optional add-ons. An add-on is switched on for one merchant account only. None of them collects a new category of personal data beyond what is already described above, but each one uses it for a specific purpose, so each is listed here on its own.

  • Priority Auto Verify: reads only the transaction SMS already collected as described in the Android section above, and compares the transaction ID, the amount and the sender with the waiting payment. It reads no additional data and it sends nothing to anybody; it only decides, on our own servers, whether a payment that is already waiting can be approved.
  • WhatsApp Notification: when a merchant switches this on for a brand and saves an alert number, that number and a short summary of the pending payment — amount, method and transaction ID — are transmitted to the WhatsApp messaging provider we use to deliver the message. This is the one add-on that sends data outside our own servers. Customer names, email addresses and addresses are never included, and the alert number is used for nothing else.
  • Payment Number Rotation: stores the merchant's own payment numbers together with counters for how many payments and how much money each one has taken, so that traffic can be shared between them. These are business numbers supplied by the merchant, not customer data.
  • Payment Link & QR Poster: stores the title, amount, brand and expiry date the merchant enters for each link. The QR code encodes only the public web address of that link and contains no personal information, and the poster image is generated on our own servers.
  • Invoice Builder: stores the customer name, phone number, email address, postal address, amount and description that the merchant types into an invoice. This information comes from the merchant, not from us, and the merchant is responsible for having the right to enter it and for the accuracy of it. We hold and display it so that the invoice can be issued and paid.

For every add-on we additionally keep a billing record: which add-on, when it was activated, renewed or expired, how it was paid for — from the account balance or directly through the payment page — and the amount. This is ordinary accounting data, kept with the rest of the balance history described below, and it is what allows a charge to be explained or disputed later.

A merchant's registered email address is used to send the add-on notices — activated, expiring soon, renewed, renewal failed, expired. These are service messages about a paid feature, not marketing, and the wording of every one of them is set by the administrator, never generated from the merchant's data.

When an add-on expires, only the feature stops. Invoices, payment links, saved numbers and settings created while it was active are not deleted, and are governed by the retention and deletion rights described further down this page.

5 How We Use Your Information

  • Automated Payment Verification: Matching incoming MFS/Bank transaction SMS with checkout invoices to provide instantaneous order fulfillment.
  • Instant Webhook Notification: Sending cryptographically signed IPN/Webhook responses to your e-commerce website upon successful payment.
  • Fraud Prevention & Security: Preventing double-spending of Transaction IDs, detecting unauthorized IP access, and blocking automated brute-force attacks.
  • Customer Support & Dispute Resolution: Assisting merchants in tracing missing payments, bank settlement reconciliation, and ticket resolutions.
  • System Reliability: Monitoring API latency, device connection heartbeats, and server health.

6 Security & Data Protection

We implement industry-standard administrative, technical, and physical safeguards to ensure the confidentiality and integrity of your data:

256-Bit SSL Encryption
All web, API, and webhook traffic is strictly encrypted in transit using HTTPS/TLS 1.3.
Double-Spend Prevention
Database-level uniqueness locks prevent malicious users from reusing transaction IDs.
IP & Domain Isolation
API requests are restricted to merchant-whitelisted IP addresses and registered domains.

7 Information Sharing & Third Parties

We do not sell, trade, or distribute your information. We may only disclose data under the following strictly defined circumstances:

  • Merchant Authorization: Returning transaction statuses to the merchant's configured webhook URL and checkout redirect endpoints.
  • WhatsApp Message Delivery: Where a merchant has activated the WhatsApp Notification add-on and switched it on for a brand, the alert number and a short payment summary are passed to the WhatsApp messaging provider that delivers the message, for that purpose only. See the add-ons section above.
  • Legal & Regulatory Compliance: When required by the laws of Bangladesh, court order, or authorized government financial regulators (including Bangladesh Bank and BTRC).
  • Protection of Rights: To enforce our Terms of Service, investigate fraud, and protect the safety and security of our platform and users.

8 Data Retention & Deletion Rights

We retain transaction logs, device records, and API history for as long as necessary to maintain accurate merchant balance reports, resolve payment disputes, and fulfill statutory tax obligations. Temporary logs and transient SMS queue entries are automatically purged on a scheduled cycle.

Merchants may at any time request the permanent deletion of their account, brand data, and connected devices by contacting our support team.

9 Contact Us & Privacy Officer

If you have any questions, concerns, or requests regarding this Privacy Policy or our data handling practices, please contact our Data Protection Team:

BD Secure Pay Support & Privacy Desk

Gazipur,Bangladesh

bdhost.org1@gmail.com • +8801570212139

Contact Support
BD Secure Pay

Bd Secure Pay is your one-stop platform for seamless and secure payment automation. We specialise in streamlining payment processes for businesses and individuals, offering features like recurring billing, real-time transaction tracking, and integration with multiple payment gateways. With a focus on efficiency and user-friendliness, Auto Pay Solution ensures your payments are handled effortlessly, giving you more time to focus on growth. Experience the convenience of automated payments with our cutting-edge technology and reliable customer support.

Quick Links

  • About Us
  • Terms & Conditions
  • Privacy & Policy

Help

  • FAQs
  • Pricing
  • Our Services

Contact Us

Gazipur,Bangladesh Phone: +8801570212139
Email: bdhost.org1@gmail.com

Copyright © BD Host . All Rights Reserved.