Skip to content

Legal

Privacy Policy

How SMS21 handles personal data, written to meet India’s Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, and what you can ask us to do with yours.

Effective 27 September 2026

We never sell personal data

No advertising, no data brokers, and no tracking or analytics cookies.

Message content is deleted

Message bodies are purged and phone numbers masked after 30 days by default.

Your rights, one form away

Access, correct or erase your data, withdraw consent or nominate someone.

Answered within 48 hours

Requests and grievances are acknowledged within 48 hours and resolved within 30 days.

1.About this policy

This policy explains how SMS21, “we” or “us”, collects and processes personal data when you visit our website, create an account, use our dashboard or APIs, pay us, or contact us. It is our notice under section 5 of the Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and the Digital Personal Data Protection Rules, 2025.

Words used here have the meaning the DPDP Act gives them. In short: you are the Data Principal (the person the data is about); a Data Fiduciary decides why and how personal data is processed; a Data Processor processes it on a Data Fiduciary’s behalf.

You can ask for this notice in English or in any language listed in the Eighth Schedule to the Constitution of India through the contact form.

2.Our two roles

  • Data Fiduciary. For the people who use SMS21 (account holders, team members, visitors to this website and anyone who writes to us), we decide how their data is used. This policy covers that data in full.
  • Data Processor. When our customers send OTPs, SMS or WhatsApp messages through us, the phone numbers, message text and replies belong to the customer’s own relationship with their users. The customer is the Data Fiduciary for that data and we process it only on their instructions, under our Terms. See If you received a message.

3.Personal data we collect

We collect only what we need for the purposes in the next section.

CategoryWhat it includesWhere it comes from
AccountName, email address, mobile number, password (stored only as a one-way hash), company name, role, two-step verification settingsYou, when you sign up or are invited by a team
Business and KYCLegal business name, address, GSTIN, DLT entity and sender ID registrations, WhatsApp Business account detailsYou or your organisation
BillingWallet top-ups, invoices, UPI transaction references (UTR), payment status. Card and bank details are handled by the payment gateway, never stored by usYou and our payment gateway
Usage and securityIP address, browser, sign-in times, API request logs, audit logs of changes made in your accountGenerated automatically when you use the service
Messages (as processor)Recipient phone numbers, message text, delivery status, replies, WhatsApp mediaOur customers, through the API or dashboard
CorrespondenceWhat you tell us through the contact form, email or phone, including data-protection requestsYou

4.Why we use it

PurposeGround under the DPDP Act
Create and secure your account, sign you in, verify your mobile numberYour consent, given when you sign up
Deliver messages you ask us to send and report their deliveryYour consent, and our customer’s instructions for their recipients’ data
Charge your wallet, process top-ups and issue GST invoicesYour consent; and compliance with tax and accounting law (section 7)
Prevent fraud, spam and abuse; enforce DLT and messaging rules; keep audit logsLegitimate uses for compliance with law and to protect the service (section 7)
Answer your questions, requests and grievancesData you provide voluntarily for that purpose (section 7(a))
Service emails: password resets, low-balance alerts, receipts, security noticesYour consent, as part of using the service
Respond to lawful requests from courts, regulators, TRAI, telecom operators and law enforcementCompliance with law and judicial orders (section 7)

We do not use personal data for advertising, we do not build profiles for marketing, and we do not make decisions about you by automated means alone.

6.If you received a message

If you received an OTP, SMS or WhatsApp message sent through SMS21, the business named in the message sent it and is responsible for why it holds your number. Please contact that business first to access or erase your data or to withdraw consent.

  • Stop promotional messages. Reply STOP to a message where the sender offers it; opted-out numbers are blocked for that sender automatically. For SMS in India you can also register a preference on the National Customer Preference Register by calling or texting 1909.
  • Tell us too. If the business does not respond or you believe a message was spam, write to us under “Grievance” and include the sender name, the time and your number. We investigate and can suspend senders who break our rules.

7.Who we share it with

We share personal data only as needed, under contracts that require it to be protected:

  • Messaging carriers. Telecom operators and messaging providers that deliver SMS and WhatsApp messages (for example MSG91, Twilio and Meta Platforms for the WhatsApp Business Platform).
  • Payments. Our payment gateway (Razorpay) processes card, UPI and net-banking payments; banks process UPI transfers.
  • Infrastructure. Hosting, database, email-delivery and backup providers that store or transmit data for us.
  • Authorities. Government bodies, regulators, courts and law enforcement when the law requires it.
  • Business transfers. A buyer or successor if our business is merged or sold, bound by this policy.

You can ask us for the identities of the Data Fiduciaries and Data Processors your data has been shared with, as part of your right to access.

8.Processing outside India

Some providers, such as international SMS carriers and the WhatsApp Business Platform, process data in other countries. We transfer personal data outside India only as section 16 of the DPDP Act allows, never to a country the Central Government has restricted, and with contractual safeguards equivalent to this policy.

9.How long we keep it

We keep personal data only as long as the purpose requires, then erase it, unless a law requires us to keep it longer. Current defaults:

DataKept for
Message text30 days, then purged; the phone number is masked (e.g. 91******3210)
OTP codesNever stored readable: only a one-way hash, kept 30 days
Replies received (inbound messages)90 days, then text removed and numbers masked
API request logs and webhook events30 days
Test (sandbox) data7 days
Signed-out and expired sessions30 days
Security and traffic logsAt least one year, as the DPDP Rules, 2025 require, to detect and investigate misuse
Invoices, payments and wallet ledgerAs long as tax and company law requires, usually 8 years
Account dataWhile the account is open; erased within 30 days after you ask us to close it, except records the law requires us to keep
Contact-form messagesUntil resolved, then up to 3 years, or erased on request

10.How we protect it

We use reasonable security safeguards, including:

  • Encryption in transit (HTTPS/TLS) and encryption of provider credentials and email content at rest.
  • Passwords, OTP codes and API keys stored only as one-way hashes; API keys shown once.
  • Two-step verification, IP allow-lists for API keys, and role-based access for teams.
  • Tamper-evident audit logs of administrative actions, and least-privilege staff access.
  • Rate limits, fraud monitoring, backups and regular security reviews.

No system is perfectly secure. Please keep your password and API keys secret and tell us immediately if you suspect misuse. Read more on our Security page.

11.Personal data breaches

If a personal data breach affects you, we will tell you without delay, in plain language: what happened, when, the likely consequences, what we are doing about it, what you can do to protect yourself, and whom to contact. We also report breaches to the Data Protection Board of India as the DPDP Act and Rules require, with a detailed report within 72 hours of becoming aware of it.

12.Your rights

Under the DPDP Act you have the right to:

  • Access. a summary of the personal data we process about you, the processing we carry out, and the Data Fiduciaries and Processors we have shared it with.
  • Correction and completion. of inaccurate or incomplete data, and to update it. Most account details can be changed in the dashboard under your profile.
  • Erasure. of data we no longer need, unless the law requires us to keep it.
  • Withdraw consent. at any time, as explained above.
  • Grievance redressal. through our Grievance Officer, and then the Data Protection Board of India.
  • Nominate. another person to exercise your rights if you die or become incapable of doing so.

How to make a request

Use the data protection request form or email the Grievance Officer at the address in section 16. Tell us which right you want to exercise. We may ask you to confirm your identity (for example from the email address on your account) before acting — this protects your data from others. We acknowledge requests within 48 hours and complete them within 30 days. There is no charge.

13.Your duties

Section 15 of the DPDP Act asks Data Principals to comply with the law, not to impersonate anyone, not to suppress material information, not to file false or frivolous grievances or complaints, and to give only verifiably authentic information when exercising the right to correction or erasure.

14.Children’s data

SMS21 is a business service for people aged 18 and over. We do not knowingly process a child’s personal data, and we do not carry out tracking, behavioural monitoring or targeted advertising directed at children. If you believe a child has given us personal data, contact us and we will erase it.

Customers whose own users include children are responsible, as Data Fiduciaries, for obtaining verifiable consent from a parent or lawful guardian before sending them messages.

15.Cookies

We use only strictly necessary cookies: two secure, HTTP-only session cookies that keep you signed in to the dashboard. We use no analytics, advertising or third-party tracking cookies, so there is nothing to opt out of. Signing out deletes the session cookies.

16.Grievance Officer and the Board

Grievance Officer

Grievance Officer

SMS21

Use the contact form

Data Protection Board of India

If you are not satisfied with our response, or we do not respond within 30 days, you may complain to the Data Protection Board of India under section 13 of the DPDP Act, after using our grievance process.

To raise a grievance, use the grievance form. We acknowledge it within 48 hours and resolve it within 30 days, well inside the 90 days the DPDP Rules, 2025 allow.

17.Changes to this policy

We will update this policy when our processing or the law changes. The effective date at the top shows the current version. For material changes we will notify account holders by email or in the dashboard before they take effect and, where we rely on consent, ask for it again.

Effective date

This version is effective from 27 September 2026.