Last Updated: October 2026
We collect essential merchant credentials (business name, email, contact number) and transaction receipt images uploaded for verification. Bank slip metadata (amount, transaction ID, date, bank name) is extracted strictly for transaction auditing.
Bank receipt images are passed securely to our localized forensic checks and vision models over TLS-encrypted connections. Extracted image hashes (pHash/SHA-256) are stored to defend merchants against duplicate slip replay attacks. We do not sell or monetize banking data to third parties.
All merchant API tokens, credentials, and transaction registries are hosted in encrypted databases with restricted firewalls. System access keys are rotated routinely.
Merchants may request full deletion of their historic receipt records and API credentials at any time by contacting our data protection desk.