Privacy Policy
Who this is for: people with a MetroPay login, and visitors to our website. Received an invoice from a business that uses MetroPay? That is a different page.
Who this policy is for
This policy covers people with a MetroPay login and visitors to our website. MetroPay is a product of Studio Metrodesk, Inc, 651 N Broad St, Suite 206, Middletown, DE 19709, United States.
It splits in two, because MetroPay holds two very different kinds of personal data:
- Part I — data we decide about. Your name, your login, how you use the app. Here we are the controller: we chose to collect it, and you ask us to change or delete it.
- Part II — data you decide about. Your customers, their addresses, their invoices, their receipts. Here we are your processor: we act on your instructions and delete when you tell us to.
Part II is the half that matters when a client's lawyer reviews you, because in that relationship you are the controller and we work for you.
Part I — what we collect about you
| What | Why | Kept for |
|---|---|---|
| Name, email address | To identify your account and send service email | While your account is open |
| Password hash, passkeys, two-factor secrets | To sign you in | While your account is open |
| Sign-in records | To show you your own sessions and to detect misuse | While your account is open |
| Workspace settings you enter — business name, address, branding, tax rates | To run the product for you | While your account is open |
| Plan and billing — which plan a workspace is on, the Stripe customer and subscription identifiers, and the invoices Stripe issues you for a MetroPay plan | To run the plan you chose, and to keep the sale records tax law requires | While your account is open; sale records for as long as tax law requires afterwards |
| Email you send us | To answer you | In our mailbox, not in MetroPay |
| Messages you send from the contact form on our website | To answer you, and so a message survives a failed email | 24 months |
| Product measurement | To see which first-run screens people get stuck on | Only if you switch it on — it is off unless you do |
| Notifications — what happened in your workspace and whether you read it | To show you the bell and let you catch up | 12 months |
| Push devices — an identifier for each browser you switch push on for | To deliver push notifications to that device | Until you switch that device off, or close your account |
We do not buy personal data, and we do not enrich your record from third-party sources.
Notifications and push
The bell inside MetroPay keeps a short record of what happened in your workspace — a customer paid, a customer said they had paid, an estimate was decided, an invoice was opened, a teammate joined — and whether you have read it. Each record names the customer and the document. Records older than 12 months are deleted by the same nightly job that enforces every other period on this page, and a workspace reset deletes them at once.
Push notifications are off until you turn them on, device by device, from your own notification settings. When you do, your browser gives us an identifier for that device and we hand it to OneSignal, which delivers the notifications; OneSignal also receives the text of each notification (who paid, how much, which document) and reports whether it was delivered and opened. It does not receive anything about devices you have not switched on. Turning a device off removes it from OneSignal, and closing your account removes everything OneSignal held for you.
Writing to us from the website
The contact form on our website asks for your name, your email address, a topic and your message, and optionally your company and the size of your team. We store the message in MetroPay before we try to email it to ourselves, so it is not lost if that email fails, and we delete it after 24 months in the same nightly job that enforces every other period on this page. We do not record your IP address or browser details with it. If you are signed in when you write, we note which account the message came from, so we can answer in context.
Part II — what we process on your behalf
When you add a customer or send an invoice, you decide what goes in. We hold it, back it up, render it as a PDF, and deliver it — and nothing else. We do not mine it, profile your customers, or use it to train anything.
| What | Where it came from | Deleted when |
|---|---|---|
| Customer name, email, phone, billing and shipping addresses | You typed it, or imported it | You delete it, or close the workspace |
| Invoices, line items, payments, credit notes | You created them | You delete them, or close the workspace |
| Invoice read receipts — that a customer opened the page, and when | Your customer opened the invoice link | With the invoice |
| Payment claims and any receipt file uploaded with them | Your customer reported a payment they had made | With the invoice |
| Email delivery records — recipient, subject, delivery and open events | Our email provider reported them | 24 months, or sooner if you close the workspace |
| Unsubscribe records | A customer used the unsubscribe link | Kept indefinitely, so an unsubscribe is never forgotten |
Your instructions govern all of it. If you delete a customer, we delete their record. If you close your workspace, we delete the lot after the 30-day export window in the Terms.
You can also empty a workspace without closing it — Settings → Reset workspace data removes every customer, invoice, estimate, payment, payment link, recurring profile, item and segment while keeping your settings. Before anything is deleted we write a copy of it to our own private storage, so that we can answer questions about what went; that copy is kept for 30 days and then removed with everything else. A reset is not immediate: nothing is deleted for twelve hours, and you can stop it in that time. Two things survive a reset on purpose — unsubscribe records, so an unsubscribe is never forgotten, and the record that a payment notification arrived, so a redelivered one cannot be counted twice.
Payment providers send us a webhook when a payment succeeds or fails — whether it is your customer paying you, or you paying us for a MetroPay plan — and those messages contain the payer's details. We keep the record that the message arrived — we have to, or a redelivered message could be counted twice — but the payer's details inside it are erased after 90 days, leaving only the fact that an event happened.
These periods are enforced by a job that runs every night, not by a promise. We would rather publish a period we keep than a shorter one we do not.
Where your data is held
MetroPay runs on DigitalOcean in Bangalore, India. Your application database, uploaded files, generated PDFs and backups are all there. Studio Metrodesk, Inc is a United States business, so your application data is held outside the country we are established in, and you should know about it.
| Country | What is there | Because |
|---|---|---|
| India | Everything — database, uploaded files, PDFs, backups | Our hosting region |
| United States | Invoice emails and their delivery records; card payment details; payments to us for MetroPay plans | Our email provider and Stripe |
| United States | Push notifications and the device identifiers they go to | OneSignal, only if you turn push on |
| Bangladesh | Taka payments — payer name, phone, amount | SSLCommerz |
| Global edge network | IP addresses and request metadata, in transit | Our CDN and certificate provider |
The full list of companies involved, and what each one sees, is on the sub-processors page.
Cookies and measurement
We set a small number of first-party cookies and no advertising trackers of any kind. There is no third-party analytics script on our pages by default.
Product measurement is off until someone switches it on under Settings, Privacy. When it is on, what we collect is a short list of fixed labels naming a screen and its state. It never includes your name, your email, your customers, invoice numbers, amounts, anything you type, or your IP address.
An organization can also exclude itself entirely, which overrides every individual choice inside it.
Who else handles your data
We use a small number of providers to run MetroPay — for email delivery, card payments (your customers' to you, and yours to us for a plan), hosting, content delivery, error monitoring and, for people who switch it on, push notifications. Each is listed on the sub-processors page along with what it sees and where it operates.
We will publish any addition to that list 30 days before it starts handling data, so you have time to object.
We do not sell personal data. We do not share it with anyone outside that list except where the law requires us to — or where a member of your workspace has connected an AI assistant and asked it to read something, which the next section explains — and we will tell you if the law ever requires us to, unless we are forbidden from doing so.
AI assistants you connect
A member of your workspace can connect an AI assistant — Claude, ChatGPT, Cursor, Claude Code or another program that speaks the Model Context Protocol — to MetroPay, if the workspace's owners have turned that module on. The connection is made through a sign-in screen of ours: the member chooses one workspace and how much the assistant may do (read only; read and draft; or full access), and can end it at any time under Settings → AI assistants. Owners and admins can end any member's connection.
While it is connected, the assistant reads what the member asks it to read — customers, invoices, payments, figures — and, at the higher levels, creates drafts or, with full access, sends invoices and records payments as that member. Whatever the assistant reads is sent to the company that runs it, at the member's direction, under that company's own terms and privacy policy. That company is not one of our sub-processors: we do not choose it, we do not send it anything you have not asked an assistant to fetch, and we cannot delete what it keeps. Choose assistants you would trust with the same information on a screen.
We keep a record of every connection and every action an assistant takes — which tool it used, on which record, by number, and whether we refused — in the workspace's activity, in the connecting member's name. We never record the contents it passed to us. Each assistant's connection expires after fifteen days without use.
How we protect it
Traffic is encrypted in transit. Passwords are hashed, never stored in a readable form, and per-workspace payment gateway credentials are encrypted at rest. Access to a workspace is scoped to its own members, and sensitive changes ask for your password again even when you are already signed in.
No system is perfectly secure. If a breach affects your personal data, we will tell you.
Your rights
You can ask us to show you the personal data we hold about you, correct it, delete it, or give you a copy to take elsewhere. Most of it you can do yourself from Settings — including switching push off for any device, which removes it from OneSignal — and for the rest, write to us.
If you are asking about data that belongs to a business that uses MetroPay — because you received an invoice from them — the request goes to that business first, and the recipient privacy page explains why.
Children
MetroPay is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18.
Changes to this policy
We may update this policy. The version and effective date at the top of the page always tell you which text is current, and previous versions stay published.
Contact
Write to [email protected], or to Studio Metrodesk, Inc, 651 N Broad St, Suite 206, Middletown, DE 19709, United States.