Privacy & Data Protection

Privacy Policy

How PayLens Business collects, handles, protects, and manages information for Ethiopian merchants and businesses.

Last Updated: August 30, 2026

Non-Custodial Service

PayLens verifies transactions independently. We never hold, custody, or touch customer funds.

Encrypted Transmission

All API and web traffic is encrypted using industry-standard TLS protocols.

Zero Data Monetization

We never sell, rent, or monetize your transaction logs or merchant profiles to third parties.

Right to Deletion

Easily request complete account and data deletion at any time via email or support.

01

1. Introduction

PayLens ("PayLens", "PayLens Business", "we", "our", or "us") provides digital payment verification, fraud prevention, and business management software services tailored for Ethiopian merchants, cafes, restaurants, hotels, retailers, and commercial enterprises.

This Privacy Policy explains in transparent detail how we collect, process, maintain, protect, and delete information when you visit our website (https://paylens.et), use the PayLens Business mobile application, access our web portals, or connect with our verification services.

02

2. Information We Collect

We collect only the categories of data strictly necessary to provide reliable payment verification, user authentication, and business management:

A. Account & Registration Data

Business name, owner/manager name, contact phone number, email address, and one-way bcrypt-hashed passwords.

B. Business Profile & Payment Accounts

Business type (Cafe, Restaurant, Hotel, Resort, Retail, Other), operational city, and registered receiving bank account numbers used solely for matching incoming payment receipts.

C. Staff & Team Accounts

Staff member names, phone numbers, assigned operational roles (Owner, Manager, Staff/Cashier), and secure 4-digit till authentication PINs.

D. Transaction & Verification Records

Bank transaction reference IDs, verification timestamps, bank/provider name, payment age, verified monetary amounts, and verification outcome status (e.g. Verified, Duplicate, Authentic Expired, Invalid, Receiver Mismatch).

E. Device & Diagnostic Telemetry

Device model, operating system version, app version, IP address, request response latency, and error diagnostics for platform uptime.

F. Push Notification Device Tokens

Google Firebase Cloud Messaging (FCM) device registration tokens used exclusively to deliver instant payment verification alerts and sound notifications.

03

3. How We Use Information

We process and utilize the collected data strictly for the following operational purposes:

  • To authenticate and verify customer digital payments in real time.
  • To detect and prevent payment fraud, counterfeit receipt screenshots, and duplicate receipt reuse.
  • To dispatch instant push notifications and audible confirmation chimes to merchant devices.
  • To maintain daily transaction logs, audit trails, and financial reconciliation reports.
  • To manage business subscription periods, wallet balances, promo codes, and referral reward credits.
  • To ensure platform security, server stability, rate limiting, and system diagnostic integrity.
04

4. Payment Verification & Non-Custodial Declaration

Important Notice: PayLens is an Independent Verification Software

PayLens is NOT a bank, financial institution, money transmitter, or digital wallet. We do NOT hold, process, transfer, custody, or deposit customer funds. Payments flow directly from the customer's bank account to the merchant's bank account.

How Verification Operates: When an operator scans a payment QR code or enters a reference ID, PayLens queries official banking verification channels and receipt confirmation endpoints (such as Commercial Bank of Ethiopia, Telebirr, Bank of Abyssinia, Awash Bank, and CBE Birr Plus) solely to confirm that the funds were legitimately credited to the merchant's account.

We never request, collect, or store bank account passwords, debit/credit card CVVs, or online banking login credentials.

05

5. Information Sharing & Disclosure

We respect your confidentiality and do NOT sell, rent, or trade your data to third-party marketing companies. Information is shared only under these strictly limited conditions:

  • Banking Verification Systems: Transaction reference IDs entered by operators are queried against supported banking systems to verify authenticity.
  • Cloud Infrastructure Providers: Trusted infrastructure providers (secure VPS hosting, PostgreSQL database, and Google Firebase for push notifications).
  • Legal Compliance: When required to comply with applicable Ethiopian laws, regulations, court orders, or official law enforcement requests.
06

6. Data Security

We implement rigorous technical and organizational security controls to protect your data:

  • TLS 1.3 Encryption: All web and API communications are encrypted in transit.
  • Bcrypt Hashing: Passwords and PIN credentials are securely hashed and never stored in plain text.
  • Role-Based Access Control: Strict isolation ensures staff members only access their authorized branch operations.
  • Encrypted Daily Backups: Regular automated database snapshots with integrity verification.
07

7. Data Retention

We retain merchant verification logs and transaction records for as long as the business account remains active to provide continuous audit logs, daily summaries, and bookkeeping history. When an account is terminated or deletion is requested, personal data is permanently purged in accordance with our deletion policy.

08

8. User Rights & Choices

You have comprehensive control over your business data:

  • Access, review, and update your business profile, staff roster, and payment accounts at any time.
  • Instantly activate, deactivate, or delete staff profiles.
  • Enable or disable push notifications and audio alerts via device settings.
  • Export transaction records to CSV or JSON formats for offline auditing.
09

9. Account & Data Deletion

Business owners and users have the right to request permanent deletion of their account, staff records, and associated personal information.

Step-by-Step Deletion Procedure

  1. Send an email from your registered account email to paylenset@gmail.com with the subject line "Account Deletion Request".
  2. Specify your registered business name and phone number in the body.
  3. Alternatively, submit your deletion request via official Telegram support (@paylenss).

Upon ownership verification, account credentials, active sessions, staff profiles, device tokens, and business records will be permanently purged within 14 business days.

10

10. Children's Privacy

PayLens Business is a commercial business management application intended exclusively for business owners, cashiers, and enterprise operators of legal working age (18+). We do not knowingly collect personal data from children under the age of 18.

11

11. Third-Party Services & Links

Our platform interacts with select third-party services to deliver reliable features:

  • Google Firebase (FCM): For delivering real-time push notifications to mobile devices.
  • Bank Confirmation Endpoints: For querying payment receipt status.
  • Official Support Channels: Official Telegram channels (@paylenss) for customer care.
12

12. International Hosting & Data Transfers

Our cloud servers, databases, and verification APIs are hosted in secure, enterprise-grade data centers equipped with hardened firewalls, automated DDoS protection, and strict access controls.

13

13. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect new features, operational practices, or legal updates. When revisions occur, the "Last Updated" date at the top of this page will be revised accordingly.

14

14. Contact Us

If you have any questions, inquiries, or deletion requests regarding this Privacy Policy, please reach out through our official channels:

Addis Ababa, Ethiopia • https://paylens.et