1. Scope & Purpose of the Application
This Privacy Policy applies to the Payment Confirmation Tool (PCPT / Payment SMS Forwarder) Android mobile application and its associated webhook infrastructure operated under the LifeGood Pay platform. The Application functions strictly as an enterprise background forwarder connecting a merchant's payment reception SIMs to their authorized online store backend to automate order fulfillment.
2. Sensitive Permissions & SMS Handling
To fulfill its core automated payment reconciliation functionality, the Application requests specific Android runtime permissions. Our operational principles regarding these permissions are as follows:
- android.permission.RECEIVE_SMS & android.permission.READ_SMS: Used solely to inspect incoming SMS messages received by the device in real-time. The application executes a strict regex filter to identify incoming payments issued by licensed mobile financial service providers (including but not limited to
bKash,Nagad,Rocket / 16216, andUpay). - Extracted Data Fields: When an authorized financial message is recognized, the tool extracts only:
- Sender Financial Service Identifier (e.g., bKash, Nagad)
- Transaction Reference ID (TrxID)
- Transaction Amount (in BDT)
- Timestamp of transaction
- Masked sender account number (to match the customer's payment proof)
- Strict Exclusions & Data Filtering: All incoming personal SMS messages, conversational chats, two-factor authentication codes (OTPs) for personal accounts, and messages from non-financial contacts are immediately discarded at the device level without processing, storage, or transmission.
3. SIM Identification & Phone State
The application requests android.permission.READ_PHONE_STATE and android.permission.READ_PHONE_NUMBERS for the singular purpose of mapping multi-SIM hardware (e.g., SIM 1 vs. SIM 2 / eSIM) to respective merchant web domains. This ensures payments received on SIM 1 are forwarded to Store A, and payments on SIM 2 are forwarded to Store B. We do not inspect personal call logs, call status, or telephony history.
4. Data Security & Transmission
Security is the highest architectural priority for the LifeGood Pay ecosystem:
- HTTPS Encryption Only: All communications between the mobile application and the merchant backend occur over TLS 1.3 encrypted HTTPS connections (cleartext HTTP is programmatically disabled).
- API Key Authentication: Every webhook transmission requires a cryptographic Device Secret Key provisioned exclusively through the authenticated web dashboard.
- Zero Third-Party Sharing: We do not integrate third-party advertising SDKs, tracking pixels, or data brokerage libraries. No extracted data is ever shared with, monetized by, or sold to external third parties.
5. Background Operation & Battery Optimization
The Application utilizes RECEIVE_BOOT_COMPLETED and low-power FOREGROUND_SERVICE with persistent notification icons so merchant store owners are continuously informed of the active status. This ensures no customer orders fail verification if a device restarts or enters standby mode during business hours.
6. User Rights & Data Deletion
Merchant store owners maintain complete governance over their devices and transaction logs. You have the right to:
- Disconnect or deactivate your device at any time from the Web Dashboard.
- Purge connected domains, secret access keys, and stored transaction archives.
- Request permanent deletion of all platform account records by contacting administrator support.
7. Contact Information
If you have questions, inquiries, or privacy compliance requests regarding the Payment Confirmation Tool (PCPT) or this Privacy Policy, please contact our administrative team:
- Platform: LifeGood Pay Platform
- Support Email: admin@vegastar.top
- Web Console: https://v21.vegastar.top