Privacy Policy
This Privacy Policy explains what information TezVerify ("we," "us," or "our") collects from merchants ("you") who use our automated payment verification service, why we collect it, and how it is secured using envelope encryption.
Because this service utilizes IMAP access to read payment-notification emails, we operate under strict data minimization standards. We urge all merchants to connect a dedicated secondary Gmail account rather than their personal or primary corporate email address.
Information We Collect
How We Use Your Information
- To query your connected mailbox for payment-confirmation emails matching the TID and amount submitted by your checkout system.
- To calculate monthly metered usage fees (5 PKR/success after 10 free, capped at 1,499 PKR) and produce accurate cycle invoices.
- To dispatch HMAC-SHA256 signed outbound webhooks to your store backend when verifications complete.
- To manage autonomous account dunning, grace periods, and instant reactivation upon invoice settlement.
- To comply with regulatory standards and maintain security audit trails.
Scope of Email Access — Please Read Carefully
3.1 Technical IMAP Scope: The 16-character Google App Password you supply provides technical IMAP read access to your mailbox.
3.2 Strict Data Minimization: Our parsing worker runs targeted IMAP search queries specifically for the submitted transaction reference or sender IDs (3737 or 8558). We do not read, export, index, or store personal or unrelated correspondence. There is zero human access to your inbox contents.
3.3 Dedicated Account Recommendation: Because of the sensitive nature of IMAP access, you should strictly connect an email address created exclusively for receiving forwarded payment notifications.
3.4 Third-Party Provider Alerts: Automated IMAP connections from our Hostinger server IP may prompt Google to display "New sign-in on Linux" security alerts. This is normal behavior for server-to-server IMAP protocols.
Security & Cryptographic Protection
Envelope Encryption: All sensitive credentials (Google App Passwords) are encrypted using industry-standard AES-256-GCM / CBC envelope encryption. Each credential record is protected with a unique, cryptographically random salt combined with the server's master key. Plaintext credentials are never saved to disk or logged in plaintext.
Incident Notification: In the unlikely event of a security breach compromising stored encrypted credentials, we will alert affected merchants via their registered email address within forty-eight (48) hours of discovery and guide immediate revocation of the Google App Password.
Data Retention & Account Closure
5.1 Active Retention: Verification transaction logs and invoice history are retained while your account remains active. System health diagnostics and snapshots are automatically pruned after seven (7) days.
5.2 Immediate Deletion on Closure: If you close your merchant account or disconnect your credentials, your stored App Password and salt are immediately and permanently erased from our database.
5.3 Subject Access Requests: Merchants may request a complete export or purge of their personal data by contacting our data protection officer at privacy@example.com.
Third-Party Data Sharing
We never sell your data. We do not share your connected email credentials, customer transaction references, or Easypaisa/JazzCash account details with third parties, except:
- Underlying infrastructure hosting providers (Hostinger) strictly necessary for hosting the database and cron workers.
- Law enforcement or regulatory authorities only when required by valid court order or Pakistani law.