1. Who we are
The data controller is the company named in our company details. You can reach our privacy contact at the address at the bottom of this page.
2. What we collect
Account data: email address, password hash, display name, chosen language and time zone, and the country you optionally declare. Usage data: activations, rentals, transactions, API requests, and the IP address and user agent attached to logins and API calls. Payment data: the OxaPay invoice identifier, the asset and network, the amount and the transaction hash. Message data: the text of the SMS delivered to you, for as long as retention allows. We never receive or store card numbers, and we do not run advertising trackers.
3. Why we process it
To provide the service you bought (contract), to bill correctly and prevent fraud and abuse (legitimate interest), to comply with anti-money-laundering and record-keeping duties (legal obligation), and to send product announcements where you opted in (consent).
4. How long we keep it
SMS bodies: 30 days, then permanent deletion. Activation and transaction records: 7 years, as required for accounting. Login IP and user agent: 12 months. Account data: until you delete the account, then 30 days in backups. You can delete the messages of an individual activation earlier from the dashboard.
5. Who we share it with
Upstream number providers receive the service and country of a request, never your identity. OxaPay receives the invoice amount and reference for payment processing. Our hosting and email providers process data on our instructions under written agreements. We do not sell personal data, ever, to anyone.
6. Where it is processed
Primary infrastructure is in the European Union. Some sub-processors operate outside the EEA under standard contractual clauses. The current sub-processor list is available on request and to business customers as an annex to the DPA.
7. Your rights
Access, rectification, erasure, restriction, portability and objection. Write to the privacy address and we answer within 30 days. If you are in the EEA or the UK you can also complain to your supervisory authority; we would rather you gave us a chance to fix it first.
8. Cookies
We set a session cookie when you log in, a preference cookie for language and theme, and nothing else. There is no analytics cookie, no advertising pixel and no consent banner, because there is nothing to consent to. See the Cookie Policy for the exact list.
9. Security
Passwords are hashed with bcrypt. API keys are stored hashed and shown once. Transport is TLS 1.3. Database access is restricted to the application role, backups are encrypted at rest, and access to production is limited to named engineers with hardware-key two-factor authentication.
10. Changes
Material changes are announced by email and on the changelog 14 days before taking effect.