Privacy Policy
mysmartaccesscard
mSAC · by Tekroin
What Data We Collect
Identity & Account
- Full name
- Email address
- Phone number (optional)
- Profile details (role, institution)
- Google account info (if signing in with Google)
Camera & Scanning
- Camera access for QR scanning — used to verify identity and record attendance check-ins. No photos or video are stored.
- Camera access for barcode scanning (Professional Business only) — reads product barcodes during sales. No personal data captured.
- QR scan events (timestamp, user ID, location) are recorded as attendance records.
- Barcode scan sessions record only which product was scanned, not who was near it.
Location
- Location is requested when a business enables geo-fenced attendance
- Only used to verify that a check-in occurs within an authorised zone
- Location is not tracked continuously — it is captured only at the moment of a QR scan
- You can deny location permission; geo-fenced attendance features will not work without it
Payment & Subscription
- Subscription plan, status, and expiry date
- Payment reference codes (from Paystack)
- Bank account details for referral payouts (stored encrypted, never full card numbers)
- We do not store credit or debit card numbers — all card data is handled by Paystack
Inventory & Sales (Professional Business)
- Product records: name, price, quantity, shelf location, category, barcode ID, stock levels
- Sales transactions: items sold, quantities, unit prices, tax, grand total, transaction reference, date/time
- Employee who processed each sale (name, ID, role) for accountability and auditing
- Monthly usage billing: barcodes generated, items sold, total charges for the billing month
Church Events (if you register for or support one)
- Event registration details: full name, phone number, email (optional), age (optional)
- Payment proof you submit: amount paid and transaction reference (optional) only — we do not store payment screenshots in our database
- Donation/support records if you choose to support an event without attending: name, phone, email, amount
- Event check-in records (timestamp and method — QR or NFC)
- mSAC never collects or processes event payments — money is transferred directly to the church's own bank account. If the church has provided a WhatsApp number, you may be prompted to send your payment screenshot there directly — that exchange happens entirely within WhatsApp and is never stored by mSAC
Technical & Usage Data
IP address and browser type
Device type and OS version
Session duration and page interactions
Error logs and crash reports (anonymised)
How We Store Your Data
All mSAC data is stored on Google Firebase, which runs on Google's global cloud infrastructure. Firebase is ISO 27001 certified and SOC 2 Type II compliant. Data is encrypted at rest and in transit using AES-256 and TLS 1.2+.
Storage breakdown
We implement role-based access control — each user and business can only access data they are explicitly authorised to see. Access to raw data is restricted to authorised Tekroin engineers.
Payments via Paystack
All subscription and term fee payments on mSAC are processed through Paystack, a PCI-DSS Level 1 certified payment provider operating in Nigeria.
When you initiate a payment, you are redirected to Paystack's secure checkout in your device's browser — payment does not happen inside the mSAC app itself.
mSAC never sees or stores your card number, CVV, or PIN — these go directly to Paystack.
mSAC receives only a payment reference and confirmation status after a successful transaction.
Paystack may store a tokenised payment authorisation code to enable future auto-renewals, with your consent.
Paystack's full privacy policy is available at paystack.com/privacy.
Deleting Your Account
You can delete your account directly from within the mSAC app at any time — no need to email us.
How to delete your account in-app
Open the app and tap the account menu (top-left logo button)
Select "Delete Account" at the bottom of the menu
Confirm your password when prompted
Your account and profile will be permanently deleted immediately
Upon deletion: your profile, linked businesses, and personal data are removed immediately from the app.
Attendance records may be retained for up to 90 days by the institutions that collected them, as required by their data retention obligations.
Payment records are retained for 7 years to comply with Nigerian financial regulations.
If you cannot access the app, you may also request deletion by emailing support@mysmartaccesscard.com.
Who We Share Data With
We do not sell your personal data. Ever.
We share data only with the following service providers, strictly for operating the platform:
Google Firebase
Database & authentication hostingYour account data, attendance records, and business data are stored here.
Paystack
Payment processingYour email is shared with Paystack to process payments. Card data never touches mSAC servers.
Resend
Transactional email deliveryYour email address is used to send system notifications and receipts.
PostHog (optional)
Product analyticsAnonymised usage data only. No personally identifiable information.
Legal Authorities
We may disclose data to law enforcement or regulators only where required by a valid legal order or to protect user safety.
Your Rights (NDPA 2023)
Under the Nigeria Data Protection Act 2023, you have the following rights. To exercise any of them, email support@mysmartaccesscard.com. We will respond within 30 days.
Right to Access
Request a copy of all data we hold about you.
Right to Rectification
Request correction of inaccurate data.
Right to Erasure
Delete your data — do this instantly in-app or by emailing us.
Right to Restriction
Limit how we use your data in certain circumstances.
Right to Portability
Receive your data in a machine-readable format.
Right to Object
Object to processing based on legitimate interest.
If you are not satisfied with our response, you may lodge a complaint with the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng.
Event Registration & Participation Data
If you register for, attend, or support a church's event through mSAC's Events module, additional data is collected on behalf of that church.
Registration details (name, phone, email, age) are visible only to that event's church administrators — never to other churches or businesses on mSAC.
mSAC does not process or hold event payments. Registration/installment fees and donations are paid directly into the church's own bank account, outside mSAC.
Payment proof (amount and an optional transaction reference) is submitted so the church can manually verify your transfer — it is visible only to that church's administrators and is retained for 7 years under our financial-record retention policy. We do not store payment screenshots; if a church provides a WhatsApp number, you may be asked to send your screenshot there directly, entirely outside mSAC.
Attendance check-ins for an event (via QR or NFC) are recorded separately from a business's regular attendance records and are only visible to that event's church.
Registering for an event does not create a separate identity — it uses your existing mSAC account, linked to that church the same way you'd link to any school, gym, hospital, or business on the platform.
Children's Privacy
mSAC is available to users aged 16 and above. Users under 18 require parental or guardian consent. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has registered, contact us immediately at support@mysmartaccesscard.com.
Policy Updates
This Privacy Policy may be updated periodically. The current version is always available at mysmartaccesscard.com/privacy.
Significant changes will be communicated via in-app notification or email where practicable.
Continued use of mSAC after an update constitutes acceptance of the revised policy.
Questions about your privacy?
Get in touch
Data Protection Contact · mysmartaccesscard (mSAC) by Tekroin