This policy explains how VoltService Ltd collects, uses, stores, shares, and deletes personal data when you use the PaySmart Android app and related services at pay-smart.net.
Effective and last updated: September 3, 2026
Who is responsible for your data
VoltService Ltd is the controller of personal data described in this policy. PaySmart is an invoice productivity product that helps users manage business profiles, clients, work records, and professional invoices.
This policy applies to PaySmart accounts, the Android app, our website, and support interactions. A third-party service may also act as an independent controller under its own privacy policy when you choose to use that service.
Information we collect
Account and authentication
Your account identifier, name, email address, phone number, verification status, authentication provider, sign-in events, and security settings. Depending on the method you choose, this includes phone one-time-code records, email-link status, federated account identifiers, or passkey credential metadata.
Profile and business details
Details you provide such as profile photo, date of birth, business or trading name, contact details, postal address, invoice preferences, tax details, and payment instructions displayed on invoices.
Clients, work, and invoices
Client names and contact details, service addresses, work descriptions, dates, hours, rates, line items, taxes, totals, notes, invoice status, and generated invoice documents. You are responsible for having authority to provide personal data about your clients.
Address and map information
Addresses you enter, address suggestions and validation results, and map coordinates derived from an entered address when you use address lookup or map confirmation. PaySmart does not request background location access.
Photos, camera, and files
Images or files you choose to upload, such as a profile or business image. Camera access is used only after you choose a feature that needs it and grant Android permission.
Device and operational data
Device and app version, operating system, network and IP information, language, session and notification identifiers, app-integrity signals, crash reports, performance traces, diagnostic events, and security logs.
Subscriptions and transactions
If you purchase a subscription, we receive product, purchase token, order, entitlement, status, and renewal information from Google Play. We do not receive your full payment-card number from Google Play.
Communications and preferences
Support messages, notification preferences, consent choices, and communications required to operate or secure your account.
Google user data
If you choose Continue with Google or link a Google account, PaySmart requests the openid, email, and profile scopes. We may receive your stable Google account identifier, name, email address, email-verification status, and profile image, depending on what Google makes available.
Access and use
We access only the basic account data needed to authenticate you, link the Google identity to your PaySmart account, prefill relevant account details, show the linked sign-in method, prevent duplicate or fraudulent accounts, and help secure or recover access.
Storage and protection
The Google account identifier and relevant profile fields may be stored with your PaySmart account in Firebase and Google Cloud. Authentication tokens are handled by the authentication service and protected through encrypted connections and access controls.
Sharing
Google user data is shared only with service providers acting for PaySmart where needed for authentication, hosting, security, support, or legal compliance. We do not sell Google user data or disclose it to data brokers.
Retention and deletion
We retain linked Google account data while the PaySmart account or link remains active and remove or de-identify it when the account or link is deleted, subject to limited security, dispute, and legal retention needs.
PaySmart does not use Google user data for targeted advertising, advertising profiles, creditworthiness or lending decisions, sale to data brokers, or training general-purpose artificial-intelligence models.
PaySmart's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
How and why we use information
Provide PaySmart
Create and authenticate accounts; maintain profiles; manage clients and work; create, store, export, and share invoices; provide subscriptions and support. The legal basis is performance of our contract with you.
Verify and secure accounts
Verify phone numbers and email addresses, link sign-in providers, detect abuse, investigate incidents, enforce access controls, and recover accounts. We rely on our contract and legitimate interests in protecting users and the service.
Improve reliability
Diagnose crashes, measure performance, troubleshoot failed operations, and improve app features and accessibility. We rely on our legitimate interests in operating and improving PaySmart.
Communicate and comply
Send verification codes, service notices, invoice-related notifications and security alerts; respond to support; meet legal duties; and protect legal rights. We rely on contract, legitimate interests, legal obligations, or consent where required.
When we share information
We do not sell personal data. We disclose only the information reasonably necessary to these recipients:
Google and Firebase: authentication, databases, file storage, server functions, app integrity, crash and performance monitoring, notifications, maps and address services, and Google Play subscriptions.
Meta: Facebook authentication when you choose Facebook as a sign-in or linked-account provider.
Communications providers: delivery of email, verification, support, and service messages.
Your chosen recipients: clients or other people when you direct PaySmart to export or share an invoice or document.
Professional advisers and authorities: where reasonably necessary to comply with law, enforce agreements, respond to valid legal process, or protect users, PaySmart, or the public.
Business transaction participants: under confidentiality safeguards if VoltService Ltd is involved in a merger, financing, acquisition, reorganisation, or sale of assets.
Processors acting for us must handle personal data under contractual and security obligations and may use it only to provide their services to us.
Storage and security
PaySmart primarily stores account and product data using Firebase and Google Cloud services. Data may be processed in countries where our providers operate. Where required, we use contractual and other safeguards for international transfers.
We use safeguards appropriate to the risk, including encrypted network connections, provider encryption at rest, authentication and role-based access controls, restricted production access, application-integrity checks, monitoring, and incident-response procedures. No internet service can guarantee absolute security, so users should also protect their device and sign-in methods.
Passkeys and device biometrics are verified by your device or platform. PaySmart does not receive or store your fingerprint, face template, device PIN, or private passkey key.
Retention and deletion
Account, profile, linked-provider, client, work, and invoice data is normally retained while your account is active or until you delete the relevant record.
Google or Facebook link data is retained until you unlink that provider or delete your PaySmart account, except where a limited record is needed for security, legal claims, or compliance.
Subscription and transaction records are retained as needed to administer entitlements, resolve disputes, prevent fraud, and meet accounting or legal duties.
Security, diagnostic, crash, and performance records are retained only for the operational period needed to protect, troubleshoot, and improve the service, then deleted or de-identified.
Deleted information may remain temporarily in protected backups until those backups cycle out. Backup data is isolated from ordinary use and restored only for continuity or disaster recovery.
Retention can be longer where required by law, valid legal process, fraud prevention, safety, dispute resolution, or enforcement of our agreements. When information is no longer needed, we delete it or de-identify it.
Your choices and rights
Review and correct available profile, business, client, and invoice details in PaySmart.
Choose whether to link Google or Facebook and unlink an optional provider from account settings. Unlinking does not itself delete your PaySmart account.
Manage camera and notification permissions in Android settings and communication preferences in the app where available.
Revoke PaySmart's Google access from your Google Account security settings. Revocation stops future access but does not automatically delete information already stored in your PaySmart account.
Request access, correction, deletion, restriction, portability, or objection where applicable under data-protection law.
To delete your account and associated data, use the in-app account deletion control, follow our data deletion instructions, or email us. We may need to verify your identity before completing a request.
Children
PaySmart is a business productivity service and is not directed to children. We do not knowingly collect personal data from children under 13. If you believe a child has provided personal data, contact us so we can investigate and delete it where required.
Changes to this policy
We may update this policy when PaySmart's features, providers, or legal obligations change. We will publish the revised policy here, update the date above, and provide additional notice in the app or by email when a change materially affects your rights or how we use personal data.
Contact
For privacy questions or requests, contact VoltService Ltd at voltservice@metalbrain.net. Include the email address or phone number associated with your PaySmart account when making an account-specific request.