1. Introduction & Data Controller
1.1 Who We Are
GetSMSOnline (the "Company," "we," "us," or "our") is a telecommunications aggregation service provider registered in Siedlce, Masovian Voivodeship, Poland. We operate under the laws of the Republic of Poland and the European Union.
1.2 Data Controller
For the purposes of the EU General Data Protection Regulation (GDPR) and the Polish Act on Personal Data Protection (RODO), GetSMSOnline is the Data Controller responsible for your personal information.
1.3 Scope of This Policy
This Privacy Policy explains:
- What personal data we collect and why
- How we use, store, and protect your data
- Your rights under GDPR/RODO
- How to exercise those rights
2. Data We Collect
2.1 Account Registration Data
When you create an account, we collect:
- Email Address: Required for account creation, communication, and password recovery
- Password: Stored as an irreversible cryptographic hash (bcrypt/Argon2)
- Registration Timestamp: Date and time of account creation
2.2 Transaction & Payment Data
When you add funds to your account, we collect:
- Payment Method Type: Credit card, cryptocurrency (we do NOT store full credit card numbers)
- Transaction Amount: USD value of deposit
- Transaction ID: Provided by payment gateway (Stripe, crypto processor)
- Cryptocurrency Wallet Address: For crypto deposits (public blockchain data)
🔒 Payment Security:
We do NOT store credit card numbers or CVV codes. All card payments are processed by Stripe, Inc. (PCI DSS Level 1 compliant). We only receive tokenized payment confirmation.
2.3 Service Usage Data
When you rent a virtual phone number, we record:
- Service Name: E.g., "Telegram," "Discord," "WhatsApp"
- Country Code: E.g., "USA," "Poland," "Indonesia"
- Phone Number Rented: The temporary number assigned to you
- Order Status: Pending, Active, Completed, Refunded
- Timestamp: When the order was placed and completed
2.4 Technical & Log Data
For security and fraud prevention, we automatically collect:
- IP Address: Your public IPv4/IPv6 address
- User Agent: Browser type and version (e.g., "Chrome 120.0 on Windows 10")
- Device Fingerprint: Non-identifiable technical attributes (screen resolution, timezone, installed fonts)
- Session Data: Login timestamps, session duration, logout events
2.5 OAuth Provider Data (Optional)
If you register via Google OAuth, we receive from Google:
- Email Address
- First & Last Name
- Google User ID (alphanumeric identifier)
We do NOT have access to your Google password or other Google account data beyond what you explicitly authorize.
3. How We Use Your Data
3.1 Legal Bases for Processing (GDPR Article 6)
We process your personal data based on the following legal grounds:
- Contract Performance (Art. 6(1)(b)): To provide you with virtual phone number services as per our Terms of Service.
- Legal Obligation (Art. 6(1)(c)): To comply with anti-money laundering (AML) regulations, tax laws, and law enforcement requests.
- Legitimate Interest (Art. 6(1)(f)): To prevent fraud, detect abuse, and ensure platform security.
3.2 Specific Uses
- Service Delivery: Routing your number requests to upstream providers and delivering SMS codes
- Account Management: Maintaining your account balance, order history, and preferences
- Customer Support: Responding to inquiries sent to [email protected]
- Fraud Prevention: Monitoring for patterns of abuse, automated bot activity, or prohibited uses
- Legal Compliance: Responding to valid subpoenas, court orders, or regulatory investigations
3.3 Marketing (Opt-In Only)
We do NOT send marketing emails unless you explicitly opt-in during registration or in your account settings. You can unsubscribe at any time by clicking the "Unsubscribe" link in any marketing email.
4. Zero SMS Content Retention Policy
🔒 Privacy Guarantee
WE DO NOT STORE THE CONTENT OF SMS MESSAGES.
When you receive an SMS verification code (e.g., "Your code is 123456"), we only:
- Display it to you in real-time on our platform
- Store metadata (sender name, timestamp, number it was sent to)
- Delete the message content immediately after 24 hours or when you close the session
4.1 What We Store vs. What We Don't
| Data Type | Stored? | Retention Period |
|---|---|---|
| SMS Message Content | ❌ NO | 24 hours max |
| Phone Number Rented | ✅ YES | 12 months |
| Sender Name (e.g., "Google") | ✅ YES | 12 months |
| Timestamp | ✅ YES | 12 months |
6. Data Security Measures
6.1 Encryption
- In Transit: All data transmitted between your browser and our servers is encrypted using TLS 1.3 (256-bit AES)
- At Rest: Database records are encrypted using AES-256 encryption
- Password Storage: Passwords are hashed using bcrypt with a work factor of 12 (irreversible)
6.2 Access Controls
- Multi-factor authentication (MFA) for admin accounts
- Role-based access control (RBAC) - employees only see data necessary for their role
- Audit logs of all database access
6.3 Infrastructure Security
- Firewalls and intrusion detection systems (IDS)
- Regular security audits and penetration testing
- Automated vulnerability scanning
7. Your GDPR Rights
Under GDPR (Regulation EU 2016/679), you have the following rights:
7.1 Right to Access (Art. 15)
Request a copy of all personal data we hold about you in machine-readable format (JSON/CSV).
7.2 Right to Rectification (Art. 16)
Correct inaccurate or incomplete personal data (e.g., update your email address).
7.3 Right to Erasure / "Right to be Forgotten" (Art. 17)
Request deletion of your account and associated data. Note: We may retain certain data for legal compliance (e.g., transaction records for tax purposes) for up to 6 years.
7.4 Right to Restriction of Processing (Art. 18)
Temporarily halt processing of your data while we verify its accuracy or your objection.
7.5 Right to Data Portability (Art. 20)
Receive your data in a structured, commonly used format (e.g., JSON) to transfer to another service.
7.6 Right to Object (Art. 21)
Object to processing based on legitimate interests (e.g., marketing, profiling).
7.7 Right to Withdraw Consent
If processing is based on consent, you can withdraw it at any time without affecting lawfulness of prior processing.
7.8 Right to Lodge a Complaint
File a complaint with the Polish Data Protection Authority (UODO):
Urząd Ochrony Danych Osobowych
ul. Stawki 2, 00-193 Warszawa, Poland
Website: uodo.gov.pl
How to Exercise Your Rights:
Email us at [email protected] with subject line "GDPR Request - [Your Right]". We will respond within 30 days as required by GDPR.
9. International Data Transfers
Our servers are located in the European Union (Poland). If you access our Service from outside the EU/EEA:
- Data may be transferred to and processed in Poland
- We rely on GDPR Article 49 (consent) for transfers
- We use Standard Contractual Clauses (SCCs) with non-EU service providers
10. Children's Privacy
GetSMSOnline is NOT intended for users under 18 years of age. We do not knowingly collect personal data from children. If you are a parent/guardian and believe your child has provided us with personal data, contact us immediately at [email protected] and we will delete it.
11. Changes to Privacy Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. When we make material changes:
- We will update the "Last Updated" date at the top of this page
- We will notify you via email (if registered)
- Significant changes will be highlighted with a banner on the website for 30 days
12. Contact & Data Protection Officer
For privacy-related inquiries, data access requests, or to exercise your GDPR rights, please contact us:
Data Protection Officer (DPO):
📧 Email: [email protected]
🏢 Registered Address: Siedlce, Masovian Voivodeship, Poland
⏰ Response Time: Within 30 days (GDPR requirement)