MyDynaPay

MyDynaPay Business — Privacy Policy

Written against what the code actually does as of 2026-08-19, not against what a generic template would claim. Every statement below is checkable in Mydynapay/mdp-business-app; where something is deliberately not collected, that is stated as plainly as what is.


1. Who this app is for

MyDynaPay Business is a merchant point-of-sale app. Its users are business owners and their staff. It is not a consumer app, and it has no consumer sign-up.

Two different groups of people appear in this policy, and the distinction matters:

2. Payment card data — what we do NOT collect

This is the part most people want answered, so it comes first.

MyDynaPay never receives, processes, stores, or transmits full payment card numbers or security codes. There is no code path in this app that puts a card number into MyDynaPay's memory, logs, or servers. Concretely:

Manually keyed cards. When a merchant types a card in, the card number, expiry and CVV fields are not part of our app. They are rendered inside a web view that loads a page served by CardConnect (a Fiserv company) from CardConnect's own domain. The keystrokes go from the device to CardConnect. CardConnect returns an opaque token — a reference number that is useless to anyone who steals it — and that token is the only thing our app receives. Our code validates that what came back is a token and nothing else.

Cards read by a card reader. When a card is tapped, inserted, or swiped on a supported ID TECH VP3350 reader, the reader encrypts the card data in hardware before it leaves the reader. Our app relays that encrypted block to CardConnect, which holds the keys. Our app cannot decrypt it and never sees a card number.

What is kept afterwards. Once a payment completes we store, against the transaction: the payment token, the card brand (e.g. Visa), the last four digits, the expiry month and year, and the cardholder name if the merchant typed one. We do not store the full card number or the CVV, because we never have them.

This design is deliberate: it is what keeps our merchants in the smallest PCI DSS compliance category (SAQ A) rather than a much heavier one.

3. What we do collect

From merchant users (account holders)

Account and identity Email address, name, and the business you belong to. Used to sign you in and to attribute actions (e.g. which staff member took a sale).
Authentication data Credentials are handled by Amazon Cognito. We hold session tokens on the device so you are not signed out constantly. We do not store your password ourselves.
Business content you enter Your product catalogue, prices, tax settings, product images you choose to upload, and business branding.

From transactions

Amount, currency, tax, shipping, line items, date and time, approval or decline status, the processor's reference, and the card details listed in section 2.

Shipping addresses

If a sale is shipped, the merchant enters the buyer's delivery address. That address is stored with the transaction so the order can be fulfilled. It is entered by the merchant, not collected from the buyer by this app.

Diagnostics

Crash and diagnostic logs, including card-reader logs used to troubleshoot hardware faults. Card-reader diagnostic logs contain encrypted reader output and do not contain card numbers. In internal test builds only, these logs can be streamed to a developer machine on the local network; this is disabled in the production build.

4. What we deliberately do not collect

5. Who we share data with

We use a small number of processors, and only to run the service:

Who What for What they get
Fiserv / CardConnect Card tokenization and payment processing Card data (directly from the device or reader — never via us), transaction amounts
Amazon Web Services (AWS) Hosting, database, authentication, content delivery. Region: US East. All service data described above

We disclose data otherwise only where legally required, or to protect our rights or the safety of others.

We do not sell personal information, and we do not share it for cross-context behavioural advertising.

6. Where data is held, and for how long

Data is held in the United States on AWS infrastructure.

Transaction records are retained for as long as the merchant's account is active and afterwards for as long as tax, accounting, and card-network rules require — commonly seven years. Account records are deleted on request (section 8), except where we are required to keep transaction history.

7. Security

Traffic is encrypted in transit (TLS). Credentials are managed by Amazon Cognito. Access to production systems is restricted and authenticated. Sessions are long-lived by design because the app is used all day on a merchant's own device; the security boundary is the device's own passcode or biometric lock, so device lock should be enabled on any phone running this app.

No system is perfectly secure, and we do not claim otherwise.

8. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to withdraw consent. Merchant users can exercise these by contacting us at the address below; we respond within the period the applicable law requires.

Deleting your account

Merchant accounts are created by your business administrator — this app has no self sign-up — so an account is deleted by request rather than by a button.

To delete your account and the personal information held about you, email contact@mydynapay.com from the address your account uses, with the subject Delete my account. We will confirm within one business day and complete the deletion within 30 days.

Deleting your account removes your user record, your name and email address, and your sign-in credentials. Completed transaction records are retained, because tax, accounting, and card-network rules require it (section 6); those records are the business's, not personal profile data, and they hold no card numbers.

If you are the last administrator of a business and want the whole business account removed, say so in the same email and we will confirm before acting.

Buyers: we hold your information only as part of a merchant's transaction record. Please contact the merchant you bought from first — they control that record. If you contact us directly, we will work with the merchant to help.

9. Children

This app is for business use by adults. It is not directed to children, and we do not knowingly collect personal information from anyone under 13 (or under 16 where that is the applicable threshold).

10. Changes

If we change this policy we will update the "last updated" date and, for significant changes, notify merchant users in the app or by email.

11. Contact

Mydynamenu, Inc., trading as MyDynaPay

Privacy enquiries: contact@mydynapay.com