About this application
SMK Consultants operates this restricted financial-readiness recordkeeping application. The staff sign-in application is named SMK FR Bank Details Staff Gateway. Access is limited to Mansoor and individually authorised staff. This notice covers the Bank Details Continuation application only, not SMK's first intake form or other services. Developer and privacy contact: Mansoor, mansoor@smkconsultants.pk.
Google sign-in and permissions
We use your Google account identifier and verified email address to check staff access. A Google-issued identity token is sent to SMK's owner-controlled backend and checked with Google. We retain the account-identifier/email association for access control and record the submitting staff email with each saved submission. Temporary session and security information supports authentication, misuse prevention and duplicate-submission handling.
The gateway requests three permissions:
- openid: identify the signed-in Google account.
- https://www.googleapis.com/auth/userinfo.email: obtain its email address.
- https://www.googleapis.com/auth/script.external_request: make outbound requests to external services. The application uses this permission to communicate with SMK's backend; the permission itself is not restricted by Google to one SMK endpoint.
These gateway permissions do not grant access to your Gmail messages, Contacts, Drive files or spreadsheets. SMK's backend uses its separate authorisation to maintain SMK's restricted case records.
Client information and its use
Authorised staff manually enter the client's Student/Client ID, name, account title, account number or IBAN, account type, opening date, account-associated mobile/email, bank and branch, reported initial deposit, and document-receipt selections. These are linked to an existing intake for financial-readiness case administration. The account number or IBAN is stored in SMK's restricted Google Workspace CRM and included in the confidential receipt for that Form 2 submission. It is not copied to Google Contacts, application logs or shared notifications. Recording it does not verify the account, its ownership or its balance, and does not authorise SMK to access or operate it. Matching recorded details is not independent identity or bank verification.
The backend saves the information, submitting staff email, timestamp and submission-control identifiers in SMK's restricted Google Workspace CRM. Google provides the application hosting, authentication and Workspace infrastructure. Bank details are not copied to Google Contacts. Information collected through this gateway is used for the described case administration, authentication, recordkeeping and security purposes, not advertising or sale.
Access and receipts
The gateway permits a new submission and its immediate own receipt. It does not provide staff with client lists, record browsing, historical receipts, or edit/delete access. Authorised case administration remains separate. Requests use HTTPS and access checks. Downloaded or printed receipts contain confidential information and must be kept in the restricted case file, not shared publicly.
No authority to operate an account
Document-receipt selections record receipt only; they do not verify documents or authorise account access, transactions, signing for an account holder, or SIM activation/use. Never enter passwords, PINs or OTPs. Refer third-party accounts to Mansoor. Staff must show or read the client-facing notice before collecting or entering these details.
Retention, corrections and access withdrawal
Case records and receipts are handled under the retention arrangements applicable to the client's case; this gateway sets no separate fixed deletion period. Contact Mansoor at mansoor@smkconsultants.pk to ask about applicable retention or request access, correction or deletion. Any continuing recordkeeping requirement must be considered when handling a request.
Staff may decline Google authorisation or revoke it through their Google Account controls; the gateway then cannot perform functions requiring that access. Revocation does not automatically delete previously submitted case records. Contact Mansoor about removing staff access and associated records.
If the application's data use changes, we will update this notice and seek renewed authorisation where required before using Google account data for a new purpose.
