Legal

Privacy Policy

This policy explains what we collect, why, how long we keep it, and what you can ask us to do with it. It is written to be read, not to be survived.

Last updated 14 February 2026

On this page

1. Who we are

The data controller is the company named in our company details. You can reach our privacy contact at the address at the bottom of this page.

2. What we collect

Account data: email address, password hash, display name, chosen language and time zone, and the country you optionally declare. Usage data: activations, rentals, transactions, API requests, and the IP address and user agent attached to logins and API calls. Payment data: the OxaPay invoice identifier, the asset and network, the amount and the transaction hash. Message data: the text of the SMS delivered to you, for as long as retention allows. We never receive or store card numbers, and we do not run advertising trackers.

3. Why we process it

To provide the service you bought (contract), to bill correctly and prevent fraud and abuse (legitimate interest), to comply with anti-money-laundering and record-keeping duties (legal obligation), and to send product announcements where you opted in (consent).

4. How long we keep it

SMS bodies: 30 days, then permanent deletion. Activation and transaction records: 7 years, as required for accounting. Login IP and user agent: 12 months. Account data: until you delete the account, then 30 days in backups. You can delete the messages of an individual activation earlier from the dashboard.

5. Who we share it with

Upstream number providers receive the service and country of a request, never your identity. OxaPay receives the invoice amount and reference for payment processing. Our hosting and email providers process data on our instructions under written agreements. We do not sell personal data, ever, to anyone.

6. Where it is processed

Primary infrastructure is in the European Union. Some sub-processors operate outside the EEA under standard contractual clauses. The current sub-processor list is available on request and to business customers as an annex to the DPA.

7. Your rights

Access, rectification, erasure, restriction, portability and objection. Write to the privacy address and we answer within 30 days. If you are in the EEA or the UK you can also complain to your supervisory authority; we would rather you gave us a chance to fix it first.

8. Cookies

We set a session cookie when you log in, a preference cookie for language and theme, and nothing else. There is no analytics cookie, no advertising pixel and no consent banner, because there is nothing to consent to. See the Cookie Policy for the exact list.

9. Security

Passwords are hashed with bcrypt. API keys are stored hashed and shown once. Transport is TLS 1.3. Database access is restricted to the application role, backups are encrypted at rest, and access to production is limited to named engineers with hardware-key two-factor authentication.

10. Changes

Material changes are announced by email and on the changelog 14 days before taking effect.

Company details

VirtualSMSNumbers Technologies OÜ

Registration number
16428091
VAT number
EE102534871
Registered address
Sepapaja tn 6, 15551 Tallinn, Estonia

Questions about this document go to [email protected].