SDK Data Compliance - Mobile SDKs

SDK Data Compliance

Compliance

Forter's mobile SDKs do not require and should NOT include any PII as customer identifiers.

If you use the user's email address for a customer's ID, please encode/hash this value before sending in any callback methods.

Identifiers used by Forter SDK

Forter's mobile SDKs can leverage the Identifier For Vendor (IDFV) values if this is passed in the SDK.

Forter's mobile SDKs do NOT use any Identifier for Advertiser (IDFA) values and the information collected by the SDK is used exclusively for fraud prevention purposes. The data passed is not leveraged for marketing, advertising, or any other financial or performance enhancement purposes.

Because Forter does not interact directly with any end users, each merchant can determine exactly what language and updates to your app's Terms of Service and Privacy Policy should be included. For sample language and recommendations, please refer to your Forter contract. For access Forter's full Privacy Policy, click [here](/content/service-privacy-policy/ "here"/index.html).

What Kind of Events and Signals get sent to the Forter Mobile SDKs and how is it sent to Forter's servers?

The Forter Mobile SDK collects information ONLY to provide the Merchant fraud prevention services which are necessary to enable the merchant to complete the payment process and allow the merchant App to perform its function.

Forter is committed to maintaining the security, confidentiality, and integrity of the data processed. Device data is sent to Forter for analysis in a secure manner - compressed and encrypted over HTTPS and is processed in accordance with Forter's security policies which are based on industry best practices.

Forter collects relevant data available based on the Merchant App existing permissions. These may include the following, to the extent covered by existing permission of a merchant's mobile App including Non-Personally Identifiable Information (PII) like:

Forter uses the information to provide Fraud & Policy Abuse Prevention Services as described in [Forter's Privacy Policy](/content/services-privacy-policy/ "Forter's Privacy Policy"/index.html).

Does Forter's SDK intercept any app or system-side events including taps, gestures, or swipes?

Forter’s SDK does NOT intercept app/system wide events. For app lifecycle tracking, we ask the hosting app developers to trigger SDK calls from the AppDelegate on iOS and register an ActivityLifecycleCallback class on Android (though, the hosting app can trigger the calls manually instead, if merchants select this option).

In addition to that, we do register a network-change broadcast-receiver / reachability delegate in order to receive updates about change of networks. Those listeners are registered programmatically and only exist within the context of the app, while it’s running.