Back
Privacy Policy
Contact

Privacy Policy

mysmartaccesscard

mSAC · by Tekroin

Effective: 23 June 2026·Last Updated: 23 June 2026
Your privacy matters. This policy explains exactly what data mSAC collects, why, how it is stored, and your rights — in plain language, in compliance with the Nigeria Data Protection Act (NDPA) 2023.

What Data We Collect

Identity & Account

  • Full name
  • Email address
  • Phone number (optional)
  • Profile details (role, institution)
  • Google account info (if signing in with Google)

Camera & Scanning

  • Camera access for QR scanning — used to verify identity and record attendance check-ins. No photos or video are stored.
  • Camera access for barcode scanning (Professional Business only) — reads product barcodes during sales. No personal data captured.
  • QR scan events (timestamp, user ID, location) are recorded as attendance records.
  • Barcode scan sessions record only which product was scanned, not who was near it.

Location

  • Location is requested when a business enables geo-fenced attendance
  • Only used to verify that a check-in occurs within an authorised zone
  • Location is not tracked continuously — it is captured only at the moment of a QR scan
  • You can deny location permission; geo-fenced attendance features will not work without it

Payment & Subscription

  • Subscription plan, status, and expiry date
  • Payment reference codes (from Paystack)
  • Bank account details for referral payouts (stored encrypted, never full card numbers)
  • We do not store credit or debit card numbers — all card data is handled by Paystack

Inventory & Sales (Professional Business)

  • Product records: name, price, quantity, shelf location, category, barcode ID, stock levels
  • Sales transactions: items sold, quantities, unit prices, tax, grand total, transaction reference, date/time
  • Employee who processed each sale (name, ID, role) for accountability and auditing
  • Monthly usage billing: barcodes generated, items sold, total charges for the billing month

Church Events (if you register for or support one)

  • Event registration details: full name, phone number, email (optional), age (optional)
  • Payment proof you submit: amount paid and transaction reference (optional) only — we do not store payment screenshots in our database
  • Donation/support records if you choose to support an event without attending: name, phone, email, amount
  • Event check-in records (timestamp and method — QR or NFC)
  • mSAC never collects or processes event payments — money is transferred directly to the church's own bank account. If the church has provided a WhatsApp number, you may be prompted to send your payment screenshot there directly — that exchange happens entirely within WhatsApp and is never stored by mSAC

Technical & Usage Data

IP address and browser type

Device type and OS version

Session duration and page interactions

Error logs and crash reports (anonymised)

How We Store Your Data

All mSAC data is stored on Google Firebase, which runs on Google's global cloud infrastructure. Firebase is ISO 27001 certified and SOC 2 Type II compliant. Data is encrypted at rest and in transit using AES-256 and TLS 1.2+.

Storage breakdown

Authentication: Firebase Auth — handles login credentials and session tokens
User & Business Data: Firestore (Google Cloud) — named database, Nigerian region where available
Attendance Records: Firestore — retained for 12 months after last activity
Inventory & Sales Data: Firestore — product records and sales transactions, retained for 24 months or until the business account is deleted
Payment Records: Firestore — retained for 7 years to comply with financial regulations
Church Event Data: Firestore — registrations and payment-proof records (amount/reference only, no screenshots) retained for 7 years (same financial-record policy), event listings retained until the church deletes them
Email Logs: Resend.com — retained for 90 days for delivery troubleshooting

We implement role-based access control — each user and business can only access data they are explicitly authorised to see. Access to raw data is restricted to authorised Tekroin engineers.

Payments via Paystack

All subscription and term fee payments on mSAC are processed through Paystack, a PCI-DSS Level 1 certified payment provider operating in Nigeria.

When you initiate a payment, you are redirected to Paystack's secure checkout in your device's browser — payment does not happen inside the mSAC app itself.

mSAC never sees or stores your card number, CVV, or PIN — these go directly to Paystack.

mSAC receives only a payment reference and confirmation status after a successful transaction.

Paystack may store a tokenised payment authorisation code to enable future auto-renewals, with your consent.

Paystack's full privacy policy is available at paystack.com/privacy.

Deleting Your Account

You can delete your account directly from within the mSAC app at any time — no need to email us.

How to delete your account in-app

1

Open the app and tap the account menu (top-left logo button)

2

Select "Delete Account" at the bottom of the menu

3

Confirm your password when prompted

4

Your account and profile will be permanently deleted immediately

Upon deletion: your profile, linked businesses, and personal data are removed immediately from the app.

Attendance records may be retained for up to 90 days by the institutions that collected them, as required by their data retention obligations.

Payment records are retained for 7 years to comply with Nigerian financial regulations.

If you cannot access the app, you may also request deletion by emailing support@mysmartaccesscard.com.

Who We Share Data With

We do not sell your personal data. Ever.

We share data only with the following service providers, strictly for operating the platform:

Google Firebase

Database & authentication hosting

Your account data, attendance records, and business data are stored here.

Paystack

Payment processing

Your email is shared with Paystack to process payments. Card data never touches mSAC servers.

Resend

Transactional email delivery

Your email address is used to send system notifications and receipts.

PostHog (optional)

Product analytics

Anonymised usage data only. No personally identifiable information.

Legal Authorities

We may disclose data to law enforcement or regulators only where required by a valid legal order or to protect user safety.

Your Rights (NDPA 2023)

Under the Nigeria Data Protection Act 2023, you have the following rights. To exercise any of them, email support@mysmartaccesscard.com. We will respond within 30 days.

Right to Access

Request a copy of all data we hold about you.

Right to Rectification

Request correction of inaccurate data.

Right to Erasure

Delete your data — do this instantly in-app or by emailing us.

Right to Restriction

Limit how we use your data in certain circumstances.

Right to Portability

Receive your data in a machine-readable format.

Right to Object

Object to processing based on legitimate interest.

If you are not satisfied with our response, you may lodge a complaint with the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng.

Event Registration & Participation Data

If you register for, attend, or support a church's event through mSAC's Events module, additional data is collected on behalf of that church.

Registration details (name, phone, email, age) are visible only to that event's church administrators — never to other churches or businesses on mSAC.

mSAC does not process or hold event payments. Registration/installment fees and donations are paid directly into the church's own bank account, outside mSAC.

Payment proof (amount and an optional transaction reference) is submitted so the church can manually verify your transfer — it is visible only to that church's administrators and is retained for 7 years under our financial-record retention policy. We do not store payment screenshots; if a church provides a WhatsApp number, you may be asked to send your screenshot there directly, entirely outside mSAC.

Attendance check-ins for an event (via QR or NFC) are recorded separately from a business's regular attendance records and are only visible to that event's church.

Registering for an event does not create a separate identity — it uses your existing mSAC account, linked to that church the same way you'd link to any school, gym, hospital, or business on the platform.

8

Children's Privacy

mSAC is available to users aged 16 and above. Users under 18 require parental or guardian consent. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has registered, contact us immediately at support@mysmartaccesscard.com.

9

Policy Updates

This Privacy Policy may be updated periodically. The current version is always available at mysmartaccesscard.com/privacy.

Significant changes will be communicated via in-app notification or email where practicable.

Continued use of mSAC after an update constitutes acceptance of the revised policy.

Questions about your privacy?

Get in touch

Data Protection Contact · mysmartaccesscard (mSAC) by Tekroin

support@mysmartaccesscard.com
© 2026 Tekroin. All rights reserved.

Cookie & Privacy Preferences

We use cookies to keep you signed in and improve your experience.

Essential

Always active — required

Analytics

Anonymised usage data

Chat with us