Privacy policy
What we collect, why we collect it, and when it is deleted.
What we collect
Account information
- Your email address — required, and used to identify you and send account emails.
- A display name, if you choose to provide one.
- A password, stored only as a scrypt hash. We never store, log or transmit your actual password.
Usage information
- Orders you place: country, service, price, timestamps and status.
- Wallet transactions, which we are required to retain for accounting purposes.
- IP addresses and user-agent strings for sign-ins and security events.
- API request logs: path, status code, latency and which key was used.
Message content
SMS messages received on numbers allocated to you are stored so that you can read them. The sender, the body, and any verification code we detect are retained.
What we do not collect
- Card details. Payments are handled entirely by the payment provider. We store a reference, an amount and a status — never a card number.
- Government identity documents, unless a specific legal obligation requires it.
- Location data beyond the coarse inference available from an IP address.
- Tracking data for advertising. We do not run third-party advertising trackers.
Why we process this data
- To provide the service — allocating numbers, delivering messages and maintaining your balance.
- To bill you correctly and to resolve disputes about charges.
- To keep the platform safe — detecting fraud, abuse and unauthorised access.
- To meet legal obligations, including financial record-keeping.
How long we keep it
- SMS message content is automatically redacted after 30 days. The record that a message arrived, and when, is kept; the text is removed.
- API request logs are deleted after 30 days.
- Expired sessions are deleted automatically.
- Wallet and order records are retained for as long as required for accounting and dispute resolution.
- Audit logs of administrative actions are retained as a security control.
Who can access it
Access is limited to what a role requires. Support staff can see your orders and tickets. Administrators can additionally see wallet activity and risk signals. Supplier and payment credentials are encrypted at rest and are not readable through any interface.
We share data with third parties only where necessary to run the service: the payment provider you choose, and the upstream supplier of the number you buy. We do not sell personal data.
Your choices
- Notification preferences are under dashboard settings. Security alerts cannot be disabled — they are how you would learn about unauthorised access.
- You can end every other session from dashboard security.
- You can request deletion of your account by opening a support ticket. Records we are required to retain for accounting will be anonymised rather than removed.
Security
Passwords are hashed with scrypt. Sessions are opaque random tokens stored only as hashes, delivered in httpOnly cookies. Supplier and payment credentials are encrypted with AES-256-GCM. Webhook payloads are verified before being acted on. Administrative actions are recorded in an append-only audit log.
Contact
Privacy questions can be raised through our contact page or a support ticket.