Skip to content

Legal

Privacy Policy

Last updated 1 September 2026

This policy explains what SMSora collects, why, and how long it is kept. We collect as little as the service can operate on.

Template pending professional review

This document is a starting template supplied with the platform. It has not been reviewed by a lawyer and is not legal advice. Have qualified counsel review and adapt it to your jurisdiction, entity and payment arrangements before you rely on it.

What we collect

  • Account data — your name, email address and a hashed password. We never store your password itself.
  • Financial records — deposit requests, the blockchain transaction hash you submit, approvals and rejections, and every movement on your service-credit ledger.
  • Order data — the country, service and operator you selected, the number allocated to you, order status, and the messages received on that number.
  • Technical data — IP address, user agent, session activity and audit-log entries, used for security, fraud prevention and troubleshooting.

We do not ask for and will never store private keys, seed phrases, or wallet recovery phrases. No member of staff will ever request them.

Why we process it

  • To operate the service and fulfil the contract with you.
  • To verify deposits and prevent double-spending, fraud and abuse.
  • To keep accurate financial and audit records, as required for accounting.
  • To secure accounts — rate limiting, session management and suspicious-activity review.

Messages received on your numbers

Verification messages delivered to a number you ordered are stored so you can read them in your dashboard. They are retained for approximately 30 days and then deleted. Because numbers are shared infrastructure sourced from third-party suppliers, messages may also be visible to the supplier. Do not use SMSora numbers for sensitive correspondence.

Sharing

To allocate a number we send the country, service and operator you selected to our upstream supplier. We do not send them your name, email address or balance. Beyond that we share personal data only with infrastructure providers acting on our instructions (hosting, database), and where we are legally required to.

We do not sell personal data and do not use it for advertising.

Retention

  • Messages: approximately 30 days.
  • Sessions: expired sessions are purged routinely.
  • Account, order and financial records: retained while your account is open and afterwards for as long as accounting and legal obligations require.

Financial records are not deleted when an account is suspended or closed — they are the record of money moved.

Your rights

Depending on where you live you may have rights to access, correct, export or erase your personal data, and to object to certain processing. Contact support to exercise them. Note that requests to erase data will not extend to records we must keep for legal or accounting reasons.

Security

Passwords are hashed with bcrypt. Sessions are stored server-side, bound to a peppered token hash, and can be revoked. Supplier API credentials exist only on the server and are never exposed to the browser or written to logs. Access to administrative functions is restricted and every administrative action is recorded in an audit log.