Privacy Policy

Privacy for shop owners and cashier teams.

Last updated: 25 June 2026

1. What the product does

MoMo Pay Mirror helps a shop owner forward MoMo Pay confirmation SMS details to authorized staff. Admins can see totals and shop analytics. Cashiers only receive limited payment confirmation details needed to serve customers.

2. Data we collect

  • Owner and staff account details: name, email, hashed password, role, and shop membership.
  • Shop details: shop name, merchant code if provided, phone connection key, invite records, and subscription status.
  • Payment confirmation details parsed from authorized MTN M-Money SMS messages: transaction ID, amount, customer name if present, masked customer phone if present, timestamp, sender, and raw SMS for audit/debugging.
  • Billing details needed to start or verify subscription payments, such as phone number, amount, transaction reference, and provider response.

3. Data we do not need

We do not ask for MoMo PINs, wallet passwords, bank passwords, or SIM credentials. The Android app filters SMS by sender and MoMo Pay payment markers before forwarding. Cashiers must never receive owner PINs, balances, phone connection keys, or admin-only totals.

4. How we use data

We use data to authenticate users, enforce roles, mirror payment confirmations, prevent duplicate transactions, provide admin reporting, support subscriptions, and troubleshoot service issues.

5. Role-based privacy

Access is role-based. Admins and managers can access shop setup, reporting, and totals. Cashiers should only access recent payment confirmations for the shops they belong to. Backend routes enforce these limits server-side.

6. Storage and hosting

The application is hosted on Cloudflare Pages. Database data is stored in Postgres. Subscription requests are processed through the configured Mobile Money checkout. Secrets are stored as server environment variables and are not exposed to the browser.

7. Retention and deletion

Transaction history is retained for operational audit and reporting. Shop owners may request export or deletion of their shop data unless retention is required for fraud prevention, billing, dispute handling, or legal obligations.

Account and associated data deletion requests can be submitted at momopaymirror.rw/delete-account.

8. Contact

For privacy requests, account deletion, or shop data deletion, contact support@momopaymirror.rw or use the deletion request page at momopaymirror.rw/delete-account.