Effective: 1 January 2026
SocioSMS ("we", "us", "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy describes how we collect, use, disclose, and safeguard information when you use our mobile application, website, and related services (the "Service"). It is designed to comply with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), the Apple App Store and Google Play Store privacy requirements, and other applicable data-protection laws.
1. Data Controller
The data controller responsible for your personal data is SocioSMS. You may contact our Data Protection Officer at privacy@sociosms.com.
2. Information We Collect
a) Information you provide:
- Account details: email address, password (hashed), display name, country.
- Payment information: processed by PCI-DSS compliant providers; we do not store full card numbers.
- Support communications you choose to send us.
b) Information collected automatically:
- Device information: model, operating system, language, time-zone, app version.
- Usage data: pages viewed, features used, activations purchased, crash diagnostics.
- Network data: IP address, approximate (city-level) location derived from IP.
c) Verification content:
Inbound SMS messages received on a virtual number you rent are processed for the limited purpose of displaying the verification code to you. Message content is automatically purged within 24 hours of the activation closing, unless a longer period is required by law or to investigate abuse.
3. How We Use Your Data
- To provide and operate the Service, including delivering rented numbers and verification codes;
- To process payments and manage your wallet balance;
- To detect, prevent, and investigate fraud, abuse, and security incidents;
- To comply with legal obligations, court orders, and regulatory requests;
- To improve the Service through aggregated, de-identified analytics;
- To communicate service updates, security notices, and (with your consent) marketing.
4. Legal Bases (GDPR)
We process personal data on the following bases: performance of a contract (Art. 6(1)(b)); compliance with a legal obligation (Art. 6(1)(c)); our legitimate interests in operating, securing, and improving the Service (Art. 6(1)(f)); and, where required, your consent (Art. 6(1)(a)), which you may withdraw at any time.
5. Sharing & Disclosure
We do not sell your personal data. We share data only with:
- Telecommunications providers strictly required to deliver virtual numbers;
- Payment processors to complete transactions you authorize;
- Cloud-infrastructure and analytics processors bound by data-processing agreements;
- Law-enforcement and regulators when legally compelled to do so.
6. International Transfers
Where personal data is transferred outside the EEA, UK, or your country of residence, we rely on appropriate safeguards such as Standard Contractual Clauses approved by the European Commission and equivalent mechanisms.
7. Data Retention
We retain account and transaction data for as long as your account is active and for up to seven (7) years thereafter to comply with tax, accounting, and anti-fraud obligations. SMS content is retained for no more than 24 hours after activation closure. You may request earlier deletion subject to legal retention requirements.
8. Your Rights
Depending on your jurisdiction, you have the right to access, rectify, erase, restrict, or object to the processing of your personal data, to data portability, and to withdraw consent. California residents also have the right to know, delete, correct, and opt-out of any "sale" or "sharing" of personal information (we do not sell or share personal information as defined by CCPA/CPRA). To exercise any right, contact privacy@sociosms.com. You may also lodge a complaint with your local data-protection authority.
9. Children
The Service is not directed at children under 18. We do not knowingly collect personal data from minors. If you believe a child has provided us personal data, contact us and we will delete it.
10. Security
We implement industry-standard administrative, technical, and physical safeguards, including TLS 1.2+ in transit, encryption at rest, hashed passwords (bcrypt/Argon2), least-privilege access controls, and regular security reviews. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.
11. Cookies & Local Storage
We use a minimal set of cookies and local-storage entries strictly necessary for authentication and session management. We do not use third-party advertising cookies.
12. Changes to this Policy
We may update this Privacy Policy from time to time. The "Effective" date above will be revised, and material changes will be notified through the app or by email prior to taking effect.
13. Contact
For privacy questions or to exercise your rights, write to privacy@sociosms.com.