DATA & PRIVACY

Understand the data
behind the payment.

A practical overview of the information used to receive, match and trace payments in ISP Billing Pay.

This page describes the current product’s data flow. Retention and operational arrangements need to be established for each deployment.

FROM PHONE TO PURCHASE

What the gateway handles.

A dedicated receiving phone forwards eligible mobile money messages. The gateway extracts payment details and compares them with the purchase information supplied by your billing platform.

These records support matching, reconciliation, claims and delivery of payment events. They can contain personal information and should be treated as customer records.

Payment information

Transaction reference, provider, amount, currency, payer number, payer name when present, message sender and receipt time. The original SMS can also be stored, including additional personal information or balances it contains.

Purchase information

The purchase reference, expected amount, payer details, expiry and matching state supplied or generated during the payment-intent flow.

Operational information

Merchant and device records, credential records, last-seen times, claim attempts and webhook delivery details used to operate and investigate the integration.

ON THE ANDROID PHONE

Incoming messages.
A temporary delivery queue.

The listener requests permission to receive new SMS messages. It does not request inbox-reading permission. Messages from configured mobile money senders are queued for delivery to the gateway.

The local queued copy is removed after confirmed delivery. This does not remove the original SMS from the phone’s messaging app or delete the gateway’s payment record.

Use a dedicated receiving phone, restrict physical access and revoke its credential if it is lost or retired.

Learn about the listener ↗

ACCESS & RETENTION

Keep access purposeful.
Set clear retention rules.

Who uses these records?

Authenticated merchant integrations can access records for their own merchant account. Matched payment details are delivered to the configured billing endpoint. People operating the gateway or its database may also have administrative access, which must be controlled by the deployment operator.

How long are records retained?

The current product does not establish one universal automatic deletion period. Payment records, original messages and operational logs can remain in the gateway database. The deployment operator needs a documented retention and access policy appropriate to the service.

What should be shared with support?

Start with the business name and a description of the issue. Remove unrelated customer information before sending screenshots or receipt examples. Never share mobile money PINs, merchant API keys or device credentials.

ON THIS WEBSITE

Examples in
a familiar currency.

The homepage uses GeoJS to estimate your country from your IP address and show local-currency examples. Your browser contacts that service directly, so GeoJS and its delivery infrastructure receive your IP address. We do not send payment records, phone numbers or credentials with this request, and do not request precise device location.

The website keeps only the detected country code and a one-hour expiry in your browser session storage. If you choose a country yourself, that preference is remembered in local storage and automatic lookup is skipped on future visits. Choose the automatic option again to clear that preference and refresh detection.

IP location can be wrong, especially with a VPN. These are sample figures, not prices or exchange-rate conversions. Your choice never changes an actual merchant account, payment currency or country availability.

ASK ABOUT YOUR DATA

Need to understand
a particular record?

Contact your ISP about your internet account and payment. For gateway data-handling questions, contact the ISP Billing Pay team.

Contact the team ↗