Privacy Policy – PipraPay Companion

Important: The PipraPay Enterprise Companion mobile application (the “App”) is intended only for authorized PipraPay enterprise customers who have a self-hosted PipraPay server. The App is not a consumer app and has no standalone use for the public. Its sole function is to archive and sync authorized business SMS messages from company-owned devices to the customer’s self-hosted PipraPay server for CRM, record-keeping, and auditing purposes.

Last updated: 2026-01-17

What Information the App Processes

1) SMS (Enterprise / Business Messages Only)

2) Camera (QR Code Scanning Only)

The App requests the CAMERA permission only for scanning QR codes to log in or access enterprise features. The App does not record, store, or transmit photos or videos.

3) Notifications

On Android 13+, the App requests the POST_NOTIFICATIONS permission to:

Notifications are local to your device; we do not collect notification content for analytics or advertising.

4) Account & Authentication

Users log in with authorized PipraPay enterprise credentials to authenticate with the self-hosted server. Credentials are used strictly for secure syncing and enterprise operations, and are not used for other purposes.

5) Technical Log Data

The App may collect technical information such as device model, operating system version, IP address, app configuration, and crash diagnostics. This data is used only to monitor performance, troubleshoot issues, and improve reliability.

6) Firebase Crashlytics

We use Firebase Crashlytics to monitor app stability. Crashlytics may collect device model, OS version, app version, time of crash, stack traces, and a randomly assigned app instance ID. This data is used only for troubleshooting and improving the App.

7) Advertising ID

The App does not access, request, or use the device’s Advertising ID.

Permissions Summary

Permission / Feature

Purpose

Data Handling

android.permission.INTERNET

Communicate securely with your self-hosted PipraPay server.

Network requests limited to your server and essential third-party services (e.g., crash reporting).

android.permission.POST_NOTIFICATIONS

Display operational status, sync results, and errors.

Notification content is local; not collected for analytics or ads.

android.permission.READ_SMS / android.permission.RECEIVE_SMS

Archive enterprise SMS messages for CRM and auditing.

Only whitelisted business sources are processed; no personal SMS accessed.

android.permission.CAMERA

Scan QR codes for enterprise login and workflows.

No photos/videos are stored or transmitted.

android.permission.FOREGROUND_SERVICE / android.permission.FOREGROUND_SERVICE_DATA_SYNC

Run foreground service to sync data reliably in the background.

Persistent notification shown; no additional personal data collected.

android.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONS

Improve sync stability under battery optimization.

User-controlled; no personal data collected.

android.permission.RECEIVE_BOOT_COMPLETED

Resume essential background tasks after device restart.

No user content is read at boot.

Hosting Model

Self-hosted: PipraPay Enterprise is deployed on customer-controlled servers. All synced data stays within the customer’s environment.

Local Storage & Deletion Controls

User Data Deletion

How We Use Information

No data is used for advertising or shared with third parties outside enterprise operations.

Data Processing & Security

Data is transmitted over encrypted channels to your self-hosted server. Access is controlled by your account permissions. Industry-standard safeguards protect information during transmission and on-device storage.

Data Sharing

No personal or business SMS content is shared with advertisers or external data brokers. Trusted service providers (e.g., Crashlytics) may process limited technical data only as instructed.

Retention

SMS data is processed only to sync with your self-hosted server. Longer-term retention occurs on your server under your organization’s policies. Crash reports are retained per provider standards for troubleshooting.

Your Choices & Controls

Government Apps

The App is not developed by or for any government organization.

Children’s Privacy

The App is not intended for children under 13, and we do not knowingly collect data from children.

No Ads

The App contains no third-party advertising.

Changes to This Privacy Policy

We may update this policy occasionally. The “Last updated” date will reflect the most recent changes. Significant changes will be posted in the App or on our website.

Contact Us

If you have questions, contact your organization’s admin or reach us for support regarding your self-hosted server.