Legal
Privacy Policy
Last updated 1 September 2026
Template pending professional review
What we collect
- Account data — your name, email address and a hashed password. We never store your password itself.
- Financial records — deposit requests, the blockchain transaction hash you submit, approvals and rejections, and every movement on your service-credit ledger.
- Order data — the country, service and operator you selected, the number allocated to you, order status, and the messages received on that number.
- Technical data — IP address, user agent, session activity and audit-log entries, used for security, fraud prevention and troubleshooting.
We do not ask for and will never store private keys, seed phrases, or wallet recovery phrases. No member of staff will ever request them.
Why we process it
- To operate the service and fulfil the contract with you.
- To verify deposits and prevent double-spending, fraud and abuse.
- To keep accurate financial and audit records, as required for accounting.
- To secure accounts — rate limiting, session management and suspicious-activity review.
Messages received on your numbers
Verification messages delivered to a number you ordered are stored so you can read them in your dashboard. They are retained for approximately 30 days and then deleted. Because numbers are shared infrastructure sourced from third-party suppliers, messages may also be visible to the supplier. Do not use SMSora numbers for sensitive correspondence.
Sharing
To allocate a number we send the country, service and operator you selected to our upstream supplier. We do not send them your name, email address or balance. Beyond that we share personal data only with infrastructure providers acting on our instructions (hosting, database), and where we are legally required to.
We do not sell personal data and do not use it for advertising.
Retention
- Messages: approximately 30 days.
- Sessions: expired sessions are purged routinely.
- Account, order and financial records: retained while your account is open and afterwards for as long as accounting and legal obligations require.
Financial records are not deleted when an account is suspended or closed — they are the record of money moved.
Your rights
Depending on where you live you may have rights to access, correct, export or erase your personal data, and to object to certain processing. Contact support to exercise them. Note that requests to erase data will not extend to records we must keep for legal or accounting reasons.
Security
Passwords are hashed with bcrypt. Sessions are stored server-side, bound to a peppered token hash, and can be revoked. Supplier API credentials exist only on the server and are never exposed to the browser or written to logs. Access to administrative functions is restricted and every administrative action is recorded in an audit log.