Skip to content
PayRecord

Legal · 01

Privacy policy

Updated 2026-09-08
What PayRecord collects, why, how long it is kept, and how to delete it.
Credentials collected
None, ever
Notifications read
Incoming payments only
Unmatched notifications
Deleted after 7 days
Data sold
Never

01

Two separate disclosures

Confirmation images. When you scan or import a customer's payment confirmation, the image is stored in a private bucket for your workspace with location metadata removed. Text is extracted on your phone. Images are kept 30 days on the Free plan and 90 days for paid plans or purchases, then deleted; the structured record stays.

Payment notifications (Android payment phone only). If a workspace owner pairs an Android phone and you grant Notification Access, PayRecord reads notifications from the wallet apps enabled for that workspace (GCash, GoTyme, Maya and MariBank). Only positive incoming-payment notifications are parsed; the amount, masked sender, reference (when shown), and timestamps are uploaded. OTPs, security prompts, outgoing payments, promotions, other apps and unrecognised formats are discarded on the phone and never uploaded. Unmatched notifications are deleted after 7 days unless linked to a record.

02

What we do not collect

  • Wallet login, MPIN, OTP, balance or transaction history.
  • GPS location, contacts, installed-app inventory, IMEI or other hardware identifiers. Devices use an app-generated ID.
  • SMS messages. PayRecord does not read Messages notifications as a workaround.

03

Who can see what

Workspace owners see all workspace records and the incoming-payment inbox. Cashiers see records they created and only minimal, masked candidate details needed to review a match. We do not sell data and do not maintain any cross-business list of customers or references.

04

Retention summary

  • Unmatched notifications: 7 days.
  • Confirmation images: 30 days (Free) / 90 days (paid or with prepaid credits), fixed when the image is saved.
  • Structured records and audit trail: 12 months by default, exportable and deletable. This is operational recordkeeping, not a tax-record guarantee.
  • Export files: 24 hours.

05

Deletion

You can delete your account from Settings → Privacy & data in the app, or by request at support@payrecord.ph. Workspace owners can delete an entire workspace. Sole owners must transfer ownership or delete the workspace first so business records are never silently orphaned.

06

Processors

Hosting and authentication: Supabase. In-app purchases: Apple App Store / Google Play via RevenueCat (purchase identifiers only). Error monitoring is configured to scrub amounts, names, phone numbers, references, tokens and image URLs.

07

Honesty about matching

“Notification matched” means PayRecord saw a notification on your own phone that agreed with the record. It is not a confirmation from GCash, GoTyme, Maya or any bank, and PayRecord is not affiliated with them.