Web3 SMS
Privacy policy
These pages describe how Web3 SMS provides number and verification email services, how user data is handled, and the legal duties, compliance boundaries, and user responsibilities that apply when using the platform.
Effective: 2026-07-22
Data we process
We process, within the scope needed to provide the service, account identifiers, login and authentication events, IP addresses, device and browser information, sessions, wallet balances, payment records, order details, countries, services, operators, phone numbers, email addresses, verification codes, SMS or email messages, API keys, webhook settings, request logs, risk-control records, support communications, and audit logs.
Do not submit sensitive personal information that is unrelated to the service. If you transmit customer data to the platform through an API or downstream system, you must have proper authorization, provide required notices, and hold a valid legal basis for that processing.
Why we process data
Data is used to create and protect accounts, handle login, display catalog inventory, fulfill orders, receive and show verification codes, manage wallets and payments, provide APIs and webhooks, handle support, troubleshoot issues, reconcile accounts, detect abuse, enforce risk controls, maintain security, improve the service, preserve audit records, and meet legal, regulatory, tax, accounting, and supplier requirements.
Verification codes and message content
Numbers, email addresses, verification codes, SMS messages, and email content may contain personal information or sensitive verification information. We process that data only for order fulfillment, status display, troubleshooting, security auditing, and compliance needs.
You must not request, view, store, forward, or use a verification code or message that you are not authorized to receive. Consequences caused by unlawful access, use, or disclosure of verification codes, numbers, emails, or message content by you or your downstream customers are your responsibility.
Payments and blockchain data
Recharges are processed by third-party payment service providers and the relevant blockchain network. Payment providers may process API requests, invoices, payment addresses, on-chain transactions, currency, network, amount, order number, status, IP address, browser information, risk information, and data required by their own KYC or AML programs.
Blockchain transactions are public, traceable, and not easily deleted. Do not use wallet addresses or funds connected to another party without authorization, unlawful funds, or sanctioned persons or entities.
Data sharing
We may share data as needed with upstream suppliers, payment service providers, cloud providers, database and security services, logging and monitoring services, professional advisers, affiliated operators, and other processors that support the platform.
When valid requests are made by laws, regulators, law enforcement, courts, arbitration bodies, payment providers, suppliers, or rights holders, or when needed to protect the platform, users, suppliers, and third parties, we may lawfully disclose or retain relevant account, order, payment, message, log, and communication records.
Security controls
We use access controls, password hashing, CSRF protection, rate limits, audit logs, encrypted configuration, encrypted storage for sensitive content where supported, and one-time display of API tokens after creation or rotation.
No internet service can guarantee absolute security. You should use strong passwords, enable two-factor authentication, limit API key privileges, configure secure webhooks, protect downstream systems, and notify the platform if you detect abnormal activity.
Retention
We retain data for the periods needed for service delivery, accounting, tax, security, risk control, dispute handling, compliance review, legal requirements, and supplier requirements. Different data categories may have different retention periods depending on order status, payment status, dispute status, risk level, and legal requirements.
When data is no longer needed, we delete, anonymize, or archive it with restricted access. Data retained for backup, audit, dispute, regulatory, or security reasons remains protected by access controls.
User rights and requests
Where permitted by applicable law, you may request access, correction, export, or deletion of certain data related to your account, and you may request an explanation of data processing. Some order, payment, log, risk-control, compliance, and legal records may not be immediately deletable.
We may require identity verification and necessary information before handling a data request. If a request affects other parties, platform security, supplier requirements, dispute handling, or legal obligations, the platform may refuse, limit, or delay processing.
International and supplier processing
Because numbers, emails, payments, cloud services, and suppliers may be located in different countries or regions, your data may be transferred, stored, or processed outside your location. By using the platform, you understand that this cross-border processing may occur and you confirm that your downstream data source allows it.
Compliance requests and investigations
If the platform receives requests from regulators, law enforcement, courts, payment providers, suppliers, rights holders, or affected parties, or if we reasonably suspect illegal or non-compliant use, we may preserve, review, freeze, disclose, or transfer necessary data and cooperate with lawful investigations.
The platform does not promise to avoid lawful audits, regulatory requests, law enforcement requests, KYC, AML, sanctions screening, or supplier risk controls. You must not ask the platform to hide, delete, falsify, or avoid preserving or disclosing information that must be kept or disclosed by law.
Privacy contact
For privacy questions or data requests, contact liulianggongju@gmail.com.