What the gateway does
MFS Gateway is installed on a merchant-controlled Android phone to identify incoming payment notifications from supported bKash, Nagad, Rocket and Upay SMS senders. SMS access is requested only after an in-app explanation and your permission. Without that permission, automatic SMS capture does not work.
Data processed
The app filters incoming SMS locally. Unrelated messages are ignored. For supported payment messages, it extracts transaction details such as provider, transaction ID, amount, currency, time and limited sender context. It creates keyed fingerprints for verification. The raw SMS body is not stored or uploaded by the gateway. The app also processes device pairing credentials, sync status and limited device diagnostics needed to operate and secure the gateway.
Use and sharing
Parsed payment observations are stored in the app’s private database and sent over HTTPS to the merchant’s MFS Verify workspace for transaction verification and gateway monitoring. The service makes these records available to authorized workspace users and integrations configured by that merchant. We do not use SMS content for advertising or sell it to data brokers.
Storage, security and deletion
Gateway credentials are protected with Android Keystore. Successfully synchronized local observations are eligible for cleanup after a seven-day recovery window; unsynchronized observations can remain on the device until delivered or manually cleared. Server-side transaction and audit records are retained according to the merchant account’s settings and applicable operational or legal requirements. A merchant administrator can request access or deletion of eligible data by contacting support. Unpairing or uninstalling the app removes its local data, but does not by itself erase server records.
Your choices
You can deny or revoke SMS permission in Android settings. You can unpair the gateway in the app. To request deletion of your merchant account and eligible server-side data, see the account deletion request page. If you do not control the merchant workspace, contact its administrator about records associated with that workspace.