This version is no longer in force. It was replaced by version 2026.7, effective Sep 08, 2026. Read the current Privacy Policy.
Privacy Policy
Who this is for: people with a MetroPay login, and visitors to our website. Received an invoice from a business that uses MetroPay? That is a different page.
Who this policy is for
This policy covers people with a MetroPay login and visitors to our website. MetroPay is a product of Studio Metrodesk, Haque Chamber, 89/2 West Panthapath, Tejgaon, Sher-E-Bangla Nagar, Dhaka 1215, Bangladesh.
It splits in two, because MetroPay holds two very different kinds of personal data:
- Part I — data we decide about. Your name, your login, how you use the app. Here we are the controller: we chose to collect it, and you ask us to change or delete it.
- Part II — data you decide about. Your customers, their addresses, their invoices, their receipts. Here we are your processor: we act on your instructions and delete when you tell us to.
Part II is the half that matters when a client's lawyer reviews you, because in that relationship you are the controller and we work for you.
Part I — what we collect about you
| What | Why | Kept for |
|---|---|---|
| Name, email address | To identify your account and send service email | While your account is open |
| Password hash, passkeys, two-factor secrets | To sign you in | While your account is open |
| Sign-in records | To show you your own sessions and to detect misuse | While your account is open |
| Workspace settings you enter — business name, address, branding, tax rates | To run the product for you | While your account is open |
| Email you send us | To answer you | In our mailbox, not in MetroPay |
| Messages you send from the contact form on our website | To answer you, and so a message survives a failed email | 24 months |
| Product measurement | To see which first-run screens people get stuck on | Only if you switch it on — it is off unless you do |
We do not buy personal data, and we do not enrich your record from third-party sources.
Writing to us from the website
The contact form on our website asks for your name, your email address, a topic and your message, and optionally your company and the size of your team. We store the message in MetroPay before we try to email it to ourselves, so it is not lost if that email fails, and we delete it after 24 months in the same nightly job that enforces every other period on this page. We do not record your IP address or browser details with it. If you are signed in when you write, we note which account the message came from, so we can answer in context.
Part II — what we process on your behalf
When you add a customer or send an invoice, you decide what goes in. We hold it, back it up, render it as a PDF, and deliver it — and nothing else. We do not mine it, profile your customers, or use it to train anything.
| What | Where it came from | Deleted when |
|---|---|---|
| Customer name, email, phone, billing and shipping addresses | You typed it, or imported it | You delete it, or close the workspace |
| Invoices, line items, payments, credit notes | You created them | You delete them, or close the workspace |
| Invoice read receipts — that a customer opened the page, and when | Your customer opened the invoice link | With the invoice |
| Payment claims and any receipt file uploaded with them | Your customer reported a payment they had made | With the invoice |
| Email delivery records — recipient, subject, delivery and open events | Our email provider reported them | 24 months, or sooner if you close the workspace |
| Unsubscribe records | A customer used the unsubscribe link | Kept indefinitely, so an unsubscribe is never forgotten |
Your instructions govern all of it. If you delete a customer, we delete their record. If you close your workspace, we delete the lot after the 30-day export window in the Terms.
You can also empty a workspace without closing it — Settings → Reset workspace data removes every customer, invoice, estimate, payment, payment link, recurring profile, item and segment while keeping your settings. Before anything is deleted we write a copy of it to our own private storage, so that we can answer questions about what went; that copy is kept for 30 days and then removed with everything else. A reset is not immediate: nothing is deleted for twelve hours, and you can stop it in that time. Two things survive a reset on purpose — unsubscribe records, so an unsubscribe is never forgotten, and the record that a payment notification arrived, so a redelivered one cannot be counted twice.
Payment providers send us a webhook when a payment succeeds or fails, and those messages contain the payer's details. We keep the record that the message arrived — we have to, or a redelivered message could be counted twice — but the payer's details inside it are erased after 90 days, leaving only the fact that an event happened.
These periods are enforced by a job that runs every night, not by a promise. We would rather publish a period we keep than a shorter one we do not.
Where your data is held
MetroPay runs on DigitalOcean in Bangalore, India. Your application database, uploaded files, generated PDFs and backups are all there. Studio Metrodesk is a Bangladeshi business, so this is a cross-border transfer and you should know about it.
| Country | What is there | Because |
|---|---|---|
| India | Everything — database, uploaded files, PDFs, backups | Our hosting region |
| United States | Invoice emails and their delivery records; card payment details | Our email provider and Stripe |
| Bangladesh | Taka payments — payer name, phone, amount | SSLCommerz |
| Global edge network | IP addresses and request metadata, in transit | Our CDN and certificate provider |
The full list of companies involved, and what each one sees, is on the sub-processors page.
Cookies and measurement
We set a small number of first-party cookies and no advertising trackers of any kind. There is no third-party analytics script on our pages by default.
Product measurement is off until someone switches it on under Settings, Privacy. When it is on, what we collect is a short list of fixed labels naming a screen and its state. It never includes your name, your email, your customers, invoice numbers, amounts, anything you type, or your IP address.
An organization can also exclude itself entirely, which overrides every individual choice inside it.
Who else handles your data
We use a small number of providers to run MetroPay — for email delivery, card payments, hosting, content delivery and error monitoring. Each is listed on the sub-processors page along with what it sees and where it operates.
We will publish any addition to that list 30 days before it starts handling data, so you have time to object.
We do not sell personal data. We do not share it with anyone outside that list except where the law requires us to, and we will tell you if that ever happens unless we are forbidden from doing so.
How we protect it
Traffic is encrypted in transit. Passwords are hashed, never stored in a readable form, and per-workspace payment gateway credentials are encrypted at rest. Access to a workspace is scoped to its own members, and sensitive changes ask for your password again even when you are already signed in.
No system is perfectly secure. If a breach affects your personal data, we will tell you.
Your rights
You can ask us to show you the personal data we hold about you, correct it, delete it, or give you a copy to take elsewhere. Most of it you can do yourself from Settings; for the rest, write to us.
If you are asking about data that belongs to a business that uses MetroPay — because you received an invoice from them — the request goes to that business first, and the recipient privacy page explains why.
Children
MetroPay is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18.
Changes to this policy
We may update this policy. The version and effective date at the top of the page always tell you which text is current, and previous versions stay published.
Contact
Write to [email protected], or to Studio Metrodesk, Haque Chamber, 89/2 West Panthapath, Tejgaon, Sher-E-Bangla Nagar, Dhaka 1215, Bangladesh.