SmartAgent does not sell personal information. Never enter your Mobile Money PIN or Agent PIN in SmartAgent forms. SmartAgent account passwords and verification codes are processed for sign-in, account verification and recovery, as explained below. Biometric templates remain with your device’s authentication system.
Scope
This Privacy Policy applies to the SmartAgent mobile application, its related website and the services used to create an account, manage business records, synchronize supported data, pay for subscriptions, receive messages and contact support. SmartAgent is the service responsible for the account information it collects; our privacy contact is listed below.
Information we process
Depending on the features you use, SmartAgent may process the following information:
Account information
Your name, email address, phone number, account identifier, account status and creation date. If you use Google sign-in, this includes your verified Google/Firebase account identifier, email, verification status and name.
Business profile and location
The Business Name / Name on Agent SIM you enter, your selected Ghana region and your city. These are profile details supplied by you, not GPS measurements or proof of SIM ownership. You can update them in Update Profile.
Business records
Customer phone numbers, transaction type, amount, reference, status, receipt details, cash balance, MoMo float and commission records you choose to save.
Authentication and device information
SmartAgent account passwords and one-time codes submitted for verification, password/code hashes, temporary verification records, session tokens, an app-generated device identifier, device name, operating platform, app version, IP address and relevant security events.
Subscriptions and payments
Plan, trial and subscription status, expiry dates, payment amount and currency, gateway and transaction references, payment status, payment phone number where needed, and receipt details.
Preferences
Theme, selected agent SIM, transaction assistance, receipt, review, warning-limit, biometric-lock and backup settings.
Support and diagnostics
Issue descriptions, screenshots or references you submit, plus basic app and device information needed to investigate a problem.
Notification data
A Firebase Cloud Messaging device token and notification interaction data needed to deliver account and service notifications.
Optional backup data
Supported settings, customer history, balances, SIM assignments and transaction records when you explicitly use cloud backup.
Sign-in, phone verification and account recovery
Google sign-in: Google/Firebase authenticates your Google account and supplies a signed identity token. SmartAgent verifies that token on its server and uses the verified identity to create or link your SmartAgent account. We do not receive your Google password or request access to your Gmail messages or Google contacts for sign-in.
Phone ownership: Google email verification does not verify a phone number you type into SmartAgent. New Google signups must verify that number with an SMS code before account creation. Changing the phone number in Update Profile also requires SMS verification of the new number.
Passwords and codes: SmartAgent processes your account password when you submit it for signup, sign-in or a password change. Account passwords are stored as password hashes, not readable passwords. SMS/email verification codes are generated and delivered for the requested action; server-side verification records use hashes, expiry times and attempt limits. These codes are different from your MoMo or Agent PIN.
Code assistance: On supported verification screens, Android may offer to fill a one-time code. Where SMS User Consent is used, Android asks you to allow access to the relevant verification message. You can decline and type the code yourself. SmartAgent does not request general SMS-inbox access for this feature.
Device security: Account and device records help enforce the configured device-access rules, identify unauthorized attempts and verify a requested device transfer. Verification does not bypass account restrictions or device-transfer checks.
Subscriptions, payments and messages
SmartAgent uses the subscription payment gateway enabled by its administrator, currently Orchard or Paystack. Depending on the selected payment method, the provider receives the contact and transaction details needed to process the payment. Paystack payments use hosted checkout. Payment authorization is handled by the payment provider or mobile network, not by entering a MoMo PIN into a SmartAgent profile or support form.
SmartAgent receives payment references and status information to confirm payment, activate or renew a subscription and maintain receipt records. When email or SMS delivery is enabled, we may send welcome messages, verification or recovery codes, account/service announcements, subscription confirmations and payment receipts. A receipt email can include the amount, currency, payment reference, gateway, plan and subscription expiry date.
Resend processes recipient email addresses and message contents for email delivery. Orchard and the relevant mobile network process recipient phone numbers and SMS contents for SMS delivery. These messages are separate from optional push notifications; turning off push notifications does not stop a verification code you request or necessary account/payment messages.
Accessibility Service
SmartAgent offers an optional Android Accessibility Service to assist with supported USSD workflows that you start. While an automation is active, the service examines visible USSD prompt text and selects or fills the next expected response using transaction details you already provided.
- It operates only for supported workflows initiated by you.
- It is not used to monitor unrelated applications or activity.
- The Accessibility Service is not used to obtain SmartAgent verification codes or automate entry of MoMo/Agent PINs, passwords or other authentication credentials.
- Automation stops before authentication or final transaction approval when those prompts are detected, so you can review and continue manually.
- You can disable the service at any time in Android Accessibility settings.
Accessibility permission is optional and requires a separate in-app disclosure and your consent before you enable it in Android. Authentication codes requested by SmartAgent’s account screens are handled by the separate verification flow described above, not by Accessibility Service.
Never place a PIN, OTP, password or authentication code inside a custom automation, support report, reference or description field.
App permissions
| Permission or capability | Why SmartAgent uses it |
|---|---|
| Internet | Account verification, profile services, supported synchronization and cloud backup, subscription payments, online shop services, support and notifications. |
| Phone state and SIM information | Display available SIM choices and use the agent SIM selected by you. |
| Phone calls | Start a USSD session after you choose a workflow. |
| Accessibility Service | Assist with supported USSD prompts during an automation you initiate. |
| Notifications and vibration | Deliver and alert you to account, service and transaction-related updates. |
| SMS code assistance | On supported verification screens, suggest a code or, with Android’s SMS User Consent prompt, read the relevant verification message. Manual entry remains available; this is not permission to read your whole inbox. |
| Files and images you select | Attach a screenshot to a support report, import supported files, or export/share receipts when you request it. |
| Biometric authentication | Unlock the app locally. SmartAgent does not receive or store your biometric template. |
How information is used
We use information only as reasonably necessary to:
- create, authenticate and maintain your SmartAgent account, verify contact details and support password recovery;
- save your business name, region and city as part of your agent profile;
- process subscription payments, manage trial/subscription access and send confirmations or receipts;
- provide transaction tools, records, customer suggestions, receipts, limits and statistics;
- perform an optional cloud backup or restoration requested by you;
- deliver notifications and respond to support requests;
- protect accounts, diagnose faults and improve reliability; and
- meet applicable legal, security and regulatory obligations.
Storage and security
Operational records, cached profile details and preferences may be stored locally on your device so supported features remain available offline. Account/profile information, verification and subscription records, device registrations and supported synchronized records are processed on SmartAgent servers. Cloud backup is a separate feature and is not the only reason information may be sent to our servers. Authentication tokens are stored using Android secure storage. Information sent to SmartAgent services is transmitted over encrypted HTTPS connections.
Optional cloud backups exclude passwords, authentication tokens, biometric templates, Mobile Money PINs, Agent PINs and OTPs. No security method can guarantee absolute protection, so keep your device locked, use a strong password and report suspected unauthorized access promptly.
Retention and account deletion
Local app records and cached profile details generally remain until you remove them, clear app data or uninstall SmartAgent. Exported files, cloud copies and receipts shared elsewhere may remain separately. Account, business profile and supported server records are retained while needed to provide your account and selected services. Verification codes expire; the new phone-verification flow uses a 10-minute code validity period, and a successful one-time verification proof is valid for a further 10 minutes. Expired verification metadata may remain until server cleanup runs; expiry prevents it from authorizing an action.
You can request account deletion from Profile → Delete Account. If you cannot access the app, email support@smartagent.smartcast.online with the subject “SmartAgent account deletion request” and the phone number or email registered to your account. We may need to verify ownership without asking you to disclose a password, PIN or OTP to support. We aim to handle verified email requests within 30 days.
Account deletion removes the associated account and business profile, including business/agent SIM name, region and city, and associated server records handled by our deletion process. Restricted records may be retained where necessary for security, fraud prevention, accounting, legal obligations or unresolved disputes, for the period needed for that purpose. Backup copies may remain until the applicable backup-retention cycle completes. Payment providers, mobile networks and message providers may retain records under their own requirements. Deleting SmartAgent does not delete your Google account, reverse a completed payment or remove receipts already shared with other people or applications.
Your choices and rights
You can review or update your name, business/agent SIM name, region and city in Update Profile. Changing a phone number requires verification. You can use the available email/phone-and-password sign-in options instead of Google sign-in, decline optional code autofill, manage notification permission, disable network detection and phone suggestions, change receipt and backup settings, disable biometric lock, revoke Accessibility Service access and remove locally stored records. Some account or payment functions require the relevant information and cannot operate if it is not supplied.
Depending on applicable law, you may also request access, correction, deletion or restriction of personal information associated with your account. Submit requests through in-app support or the privacy contact below. Contact us if you want to discuss optional messages or how information associated with your account is handled.
Children's privacy
SmartAgent is a business application intended for authorized mobile money agents and is not directed to children. We do not knowingly collect personal information from children.
Changes to this policy
We may update this policy when SmartAgent features, legal requirements or data practices change. The revised version will display a new “Last updated” date. Material changes may also be communicated through the application or a notification.
Contact us
For privacy questions, access/correction/deletion requests or complaints, email support@smartagent.smartcast.online or use Help → Report an Issue inside SmartAgent. Include only the information needed to handle your request, and never send support a PIN, OTP or password.
Visit SmartAgent support