SMSToGo

Legal

Privacy Policy

How SMSToGo handles personal information across the website and application preview.

Last updated 30 August 2026

Scope

This Privacy Policy explains how SMSToGo handles personal information when you visit smstogo.net, create an account, sign in, or use available account features. It does not govern independent third-party sites or services that may be linked from our site.

Current service status

SMSToGo is currently a marketing site and an early application foundation. Customer payments, temporary-number orders, live SMS delivery, and verification-message storage are not available. As a result, we do not currently collect payment-card details, purchased phone numbers, or customer SMS content through those planned features.

Information you provide

We collect information you choose to provide, including:

  • your email address when you register or sign in;
  • your password, which is converted into a salted cryptographic hash before storage;
  • messages and contact details you include when emailing support; and
  • feedback or other information you voluntarily send to us.

We do not store your account password in readable form. Please do not send passwords, SMS codes, payment details, or other sensitive secrets by email.

Account and wallet records

We store account identifiers, role and status information, account creation and update times, a wallet record, and any administrative wallet adjustments. Wallet adjustments are recorded in an append-only transaction history, including the acting administrator and the reason, for integrity and auditing.

When you add funds, we store the requested amount, the payment identifier and status reported by our payment processor, and, once a transfer is reported, the cryptocurrency and network it arrived on. The payment itself takes place on the processor's own page: we send it the amount and an internal reference for the top-up, we do not send your email address or other account details to it, and it applies its own privacy practices to the payment page and the blockchain transaction.

Information collected automatically

When you use the site, our application and infrastructure may process technical data such as your IP address, browser and device information, request time, requested path, request method, response status, request identifier, and response timing.

We use this information to operate the service, diagnose failures, protect accounts, investigate abuse, and understand basic service performance.

Cookies and sessions

We use a first-party session cookie named smstogo_session to keep registered users signed in. It contains an opaque session token. Only a SHA-256 hash of that token is stored in our database.

The cookie is HttpOnly, uses SameSite=Lax, is limited to the site, and uses the Secure flag for HTTPS requests. It expires after the configured session period or is removed when you sign out. The current application does not use advertising cookies.

How we use information

We use personal information to:

  • create and administer accounts;
  • authenticate users and revoke sessions;
  • maintain wallet and account records;
  • respond to support requests and feedback;
  • secure, monitor, debug, and improve the service;
  • enforce our Terms of Use and prevent misuse; and
  • comply with applicable legal obligations.

How we share information

We may share information with:

  • hosting, infrastructure, security, and support providers that process it for us;
  • professional advisers where reasonably necessary;
  • authorities or other parties when required by law or needed to protect rights and safety; and
  • a successor in connection with a merger, financing, reorganization, or sale of the service.

We do not sell personal information.

Retention

We keep personal information for as long as reasonably necessary to provide the service, secure accounts, maintain reliable records, resolve disputes, and meet legal obligations. Retention periods vary by record type. Session records expire according to the configured session period and can be revoked when you sign out.

Security

We use technical and organizational safeguards designed to protect personal information. Passwords are stored as salted PBKDF2-HMAC-SHA-256 hashes, and raw session tokens are not persisted in the database. No system is completely secure, so we cannot guarantee absolute security.

Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of your personal information, and to receive a portable copy. You may also have the right to complain to a local data-protection authority.

To make a request, email [email protected]. We may need to verify your identity before acting. Some records may be retained where required for security, legal compliance, or legitimate recordkeeping.

Children's privacy

SMSToGo is not directed to children who cannot legally consent to data processing in their jurisdiction. If you believe a child has provided us with personal information unlawfully, contact us so we can review and address it.

International processing

Our service providers may process information in countries other than yours. Where required, we use recognized safeguards for international transfers. Local privacy laws may differ from those in your country.

Changes to this policy

We may update this policy as the product and applicable requirements change. We will post the revised policy here and update the date above. If a change materially affects registered users, we will provide additional notice where reasonably practical.

Contact

Questions or privacy requests can be sent to [email protected].