1) Scope and Acceptance
This Policy explains how CodySMS.com (“CodySMS”, “we”) processes personal data when you utilize our website, user dashboard, and automated API systems (“Services”). By registering an account or initiating service routing, you accept this Privacy Policy in conjunction with our standard Terms and Conditions and our structural KYC/AML Policy.
🗂 Data Controller Specifications
CodySMS acts as the primary data controller for your account architecture and API credentials. If you integrate or resell our API systems into your independent customer software, you assume the role of data controller for your users; CodySMS operates strictly as a technical data processor under your instructions.
Minimum Age Constraints: Our platform network is reserved exclusively for individuals aged 18 or above. We reserve the authority to deploy verification mechanisms to audit age compliance at any operational checkpoint.
2) Data We Process
To deliver reliable dynamic SMS verifications, we collect and store restricted categories of information:
- Account Metadata: Stored user email address, profile alias, country origin declarations, internal user IDs, and active communications data (e.g., Telegram details).
- Operational Routing Logs: Sequential order history logs (ID hashes, destination service slugs, status data), temporary cellular number strings (MSISDN), and transaction timestamps.
- Technical Telemetry: Dynamic IP addresses, browser user-agent tokens, hardware fingerprints, error event tracking, and advanced anti-abuse metrics (number farming detection thresholds).
- API Metrics: Cryptographic access keys, targeted API endpoints, query volumes, active rate-limiting markers, and general core performance overhead statistics.
- Billing & Financial Logs: Tokenized payment statuses, transaction timestamps, and 3-D Secure compliance checks. We do not capture or store full credit card numbers. For cryptographic payments, we log blockchain transaction IDs (TXID), token networks, and relative asset quantities.
3) Purposes & Legal Bases
We process your metrics and operational parameters under structured legal foundations:
- Contractual Execution: To fulfill order deployments, dynamic wallet balances, and route verification SMS successfully.
- Platform Security: Mitigating automated system abuse, card probing, endpoint saturations, and high systematic failure metrics.
- Legal Regulatory Frameworks: Fulfilling global anti-money laundering requirements, necessary financial bookkeeping, and dormancy control laws.
Automated Profiling Disclaimer: CodySMS does not execute fully automated decision-making processes that carry binding legal implications without human review mechanics.
4) Data Retention Framework
We restrict data lifespan profiles to operational and regulatory windows:
- Account Logs: Retained throughout active relationship lifespan plus up to 2 subsequent calendar years following structural account closure.
- Bookkeeping Records: Retained for a mandatory duration of 5 to 10 years to conform to universal tax compliance laws.
- Security Logs: Fraud diagnostics and technical audit logs are retained for a minimum window of 180 days, scaling to 2 years in cases of open disputes.
5) Sharing and Recipients
CodySMS does not sell user datasets to third-party brokers and does not engage in behavioral advertising profiles. Information sharing occurs exclusively under the following strict conditions:
- With infrastructure partners, dynamic carrier aggregators, token verifiers, and payment gateways strictly required to complete dynamic routing tasks.
- With authorized judicial entities upon delivery of valid legal warrants or enforceable cross-border compliance demands.
6) Rights and Compliance Controls
Users maintain fundamental data management privileges, including the right to request information access, layout adjustments, data erasure requests, operational objections, and human profiling reviews. To execute your administrative rights, submit an official inquiry to our privacy team via support@codysms.com.
Reference Law and Venue: All compliance structures, storage security protocols, and operational management parameters are executed in alignment with the reference jurisdiction rules of New York,United States.