Information we process
When a merchant creates or uses a workspace, we process account and business contact details, login and security information, plan and billing records, gateway device identifiers and health information, API and webhook configuration, and payment-verification records. Payment records can include provider, transaction ID, amount, time, account reference, status and privacy-preserving sender fingerprints. We also process technical logs needed to operate and protect the service.
Why we process it
We use this information to provide transaction verification, synchronize gateway observations, manage workspaces and subscriptions, prevent abuse, troubleshoot failures, deliver configured webhooks and respond to support requests. Merchant administrators control access to their workspace and the integrations they configure.
Gateway SMS
The Android gateway filters supported payment notifications on the device. It does not upload or store raw SMS bodies. Only parsed payment details and keyed fingerprints are synchronized. See the Gateway Privacy Policy for the app-specific explanation.
Access and disclosure
Authorized merchant users can access records in their workspace. Information can also be sent to webhook endpoints or integrations configured by that merchant. Service providers that host or support the platform may process information on our behalf. We do not sell SMS content or use it for advertising.
Retention and security
Records are retained as needed to operate the workspace, maintain audit and security history, and meet applicable contractual or legal obligations. Retention varies by record type and account settings; closing an account does not automatically remove records that must be preserved. We use access controls, encrypted transport and other technical safeguards, but no internet service can promise absolute security.
Your choices and requests
Merchant administrators can manage users, integrations and gateway pairing. To request access or correction, email support@digitrixlabs.io. For account and data deletion, follow the steps on our account deletion request page. If your data belongs to a merchant workspace you do not administer, contact that merchant first.
Changes
We may update this policy as the service changes. The effective date above identifies the current version.