Satispay: Pay and invest Security & Privacy Scorecard
Android
In-app activity is tracked by AppsFlyer for attribution and by Braze, a marketing automation service, meaning payment behavior may be linked to targeted outreach. Firebase Analytics also records how users navigate the app. Three marketing and analytics companies receive data about how users interact with their account.
Best for
Everyday mobile payments with standard analytics
Avoid if
Users who don't want payment patterns used for marketing
Findings
- 0 critical
- 0 high
- 0 medium
- 0 low
- 0 info
0 issues identified across security and privacy analysis.
Top security issues
- SSL/TLS Hostname Verification Completely Disabled
- Master Encryption Key Stored in Plaintext SharedPreferences
- Client Certificates Stored in Plaintext SharedPreferences
Top privacy issues
- Extensive PII sent to Braze (name, email, phone, DOB, tax code, IBAN)
- Background location tracking via Braze geofencing (20 geofences)
- Device fingerprinting across 3 analytics platforms (AppsFlyer, Braze, Firebase)
Full analysis
Satispay: Pay and invest
com.satispay.customer | Version 4.24.6 (Build 9511) | Scanned 2026-02-01
What This Means for You
In-app activity is tracked by AppsFlyer for attribution and by Braze, a marketing automation service, meaning payment behavior may be linked to targeted outreach. Firebase Analytics also records how users navigate the app. Three marketing and analytics companies receive data about how users interact with their account.
Recommendation: Use With Caution
Best For: Everyday mobile payments with standard analytics
Avoid If: Users who don't want payment patterns used for marketing
Key Findings
Data Security - 4 findings (2 critical, 1 high, 1 medium)
Network Security - 3 findings (1 critical, 2 high)
Code Safety - 0 findings
Privacy - 0 findings
Privacy Concerns
What Data is Collected
The app collects data on how users use and navigate it, including payment activity and account interactions. Location access is used for proximity-based payment features. Customer support conversations are routed through Zendesk, where user messages may be stored. Image and media content is loaded through third-party libraries integrated into the app.
Third-Party Data Sharing
Activity data is shared with the following third-party services:
- AppsFlyer - Tracks how users arrived at the app and records user behavior after install
- Braze - Receives data about in-app activity for marketing automation and targeted outreach
- Firebase Analytics - Records how users navigate and interact with the app
- Zendesk - Handles customer support conversations
- Google Maps / Google Nearby - Used for location-based proximity payment features
- Botpress - Supports in-app chat or automated support interactions
Understanding the Scores
| Category | Score |
|---|---|
| Security | 25/100 |
| Privacy | 100/100 |
| Data Security | 30/100 |
| Network Security | 20/100 |
| Code Safety | 40/100 |
| Data Collection | 100/100 |
| Data Sharing | 100/100 |
| User Control | 100/100 |
Positive Security Features
- No notable positive security practices were identified in this version of the app.
Areas for Improvement
- Payment and account data stored on user devices could be better protected against unauthorized access.
- Data traveling between user devices and the app's back-end systems does not fully meet current protection standards.
- Reducing the number of third-party services that receive data about user payment behavior would provide stronger financial privacy.
About This Analysis
This scorecard reflects automated analysis of the app's code and configuration at the time of this scan. Scores and findings represent a point-in-time assessment and may not reflect subsequent updates to the app.
App Details
- App Name: Satispay: Pay and invest
- Package: com.satispay.customer
- Version: 4.24.6 (Build 9511)
- Scan Date: 2026-02-01
- Platform: Android
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 62/100 |