Draft — pending legal review. This document has not yet been reviewed by counsel and may change before it takes effect. Bracketed text such as [Company legal name] marks details still to be completed.

Privacy Policy

Last updated:

This Privacy Policy explains how [Company legal name], [Registered address]("Sendoka", "we") collects and uses personal data when you visit our website, create an account, or use the Sendoka email and SMS platform (the "Service"). It also explains how we handle personal data that our customers send through the Service about their own users.

1. Our two roles

  • Controller — for data about our customers and website visitors: account holders, organization members, billing contacts, and people who contact us. This policy describes that processing.
  • Processor— for data our customers submit about their recipients: email addresses, phone numbers, message content, contacts, and engagement events. We process it on our customer's instructions under our Terms of Service and Data Processing Agreement. If you received a message sent through Sendoka, the sender is responsible for that data — please contact them first; we will help them respond.

2. Data we collect

Account and organization data

  • Name, email address, and — where SMS verification is enabled at signup — a mobile phone number; a password stored only as a bcrypt hash; and, if you sign in with Google, GitHub or a SAML/SCIM identity provider, the profile identifiers that provider returns.
  • Two-factor authentication secrets and single-use backup codes, organization names, memberships and roles, invitations, and settings.
  • Business information you submit for SMS registration — company name, tax or registration numbers, addresses, websites, and contact details for 10DLC brands and campaigns or India DLT entities.

Security and usage data

  • Session and device records (IP address, user agent, sign-in time) for the Devices list, trusted-device sign-in, and session revocation.
  • An audit log of sensitive actions in your organization, including the acting user, IP address and user agent.
  • API request metadata, usage counters and rate-limit state, and server logs used to operate and secure the Service.

Billing data

Plan, invoices and usage. Card details are entered directly with Stripe and never stored by Sendoka; we keep the Stripe customer and subscription identifiers.

Customer Data processed on a customer's behalf

  • Recipient email addresses and phone numbers, message subjects and bodies, templates and template variables, custom headers, tags and metadata. Email attachments are passed to the provider for delivery and their bytes are not stored.
  • Contacts and audiences, including any custom fields a customer adds.
  • Delivery events from providers (delivered, bounced, complained, failed), including diagnostic text that may contain the recipient's address.
  • Open and click tracking.When a customer enables tracking, emails include a tracking pixel and signed redirect links. Opening or clicking records the time, the recipient's IP address, user agent and, for clicks, the URL. Customers can turn tracking off per message.
  • Inbound email and SMS received on a customer's domains and numbers, and opt-outs (unsubscribes and STOP replies), which are kept on a suppression list so they are honored.

Website visitors

Standard request logs (IP address, user agent, pages requested). We do not use advertising or third-party analytics cookies. We set strictly necessary cookies for signing in, verifying your email or phone during signup, and — if you choose — remembering a trusted device for 30 days.

3. How we use it, and our legal bases

  • To provide the Service — create accounts, authenticate you, send and receive messages, deliver webhooks, and bill you (performance of a contract).
  • To secure the Service — detect fraud and abuse such as SMS toll fraud and spam, check new passwords against known breaches, enforce the Acceptable Use Policy, and keep audit records (legitimate interests).
  • To communicate with you about your account, security, billing, usage alerts and changes to the Service (contract and legitimate interests).
  • To comply with legal obligations, such as tax and accounting rules.
  • Where we rely on consent, you may withdraw it at any time. We do not sell personal data, share it for cross-context behavioral advertising, or use Customer Data to train models or for our own marketing.

4. Subprocessors and other recipients

We share personal data only with the service providers below, to the extent each needs it to provide the Service, under contracts that require them to protect it.

ProviderPurpose
Amazon Web Services — SESSending and receiving email; bounce and complaint notifications
Amazon Web Services — End User Messaging (SMS) and SNSSending and receiving SMS, phone numbers, 10DLC registrations, and delivery and inbound notifications
VercelApplication hosting; storage of data exports and archived audit logs (Vercel Blob)
NeonPrimary Postgres database
UpstashRedis for rate limiting, caching and short-lived state
StripePayments, subscriptions and invoicing
GupshupIndia DLT entity, header and template registration, only for customers who send to India

We also call two services without sending them personal data: Have I Been Pwned's range API, which receives only the first five characters of a SHA-1 hash of a candidate password, and Cloudflare's public DNS resolver, which receives the domain names you ask us to verify. Mobile carriers, mailbox providers, and SMS registries (such as The Campaign Registry) necessarily receive the messages and registration details you send through them. We may disclose data when required by law, to protect the rights and safety of Sendoka, our customers or others, or to a successor in a merger or acquisition, which would remain bound by this policy.

5. International transfers

Sendoka and its subprocessors process data in the United States and in other regions where they operate; email may be sent from the AWS region configured for a sending domain. Where we transfer personal data out of the EEA, UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK addendum) or another lawful mechanism, as described in the DPA.

6. Retention

We keep personal data only as long as needed for the purposes above. A nightly job enforces the following windows:

  • Message content(recipient, subject, bodies and similar fields) is redacted after the plan's log retention window — 7 days on Free and 90 days on Pro, or the window of the plan in effect when the message was sent if that was longer. On plans without a stated window (Pay as you go, Enterprise and complimentary accounts), message content is kept for the life of the account unless a platform-wide limit is configured; any such limit applies to every plan, and the shorter window wins. The redacted record of status, channel and timestamps is kept for usage, billing and analytics.
  • Open and click events (IP address, user agent, URL): 90 days.
  • Inbound email and SMS: 90 days.
  • Webhook delivery records: 30 days once delivered, 90 days if failed or pending.
  • Signup email and phone verification codes: 7 days; one-time verification (OTP) records: 2 days.
  • Daily statistics: 180 days, in aggregate.
  • Audit logs: at least 365 days; older entries may be archived rather than deleted, because they are the tamper-evidence record for your organization.
  • Suppressions (unsubscribes, STOP replies, hard bounces and complaints) are kept for as long as the customer account exists, so an opt-out is never forgotten.
  • Sign-in sessions and trusted devices (IP address, user agent), and the contacts and audiences a customer stores, are not removed on a schedule: they are kept until revoked or deleted by the customer, or until the account is deleted. Organization data exports are stored privately and are not yet deleted automatically.
  • Account data is kept while your account is active and deleted when you delete it. Abandoned signups that never verified their email may be deleted after 30 days.
  • Billing records are kept as long as tax and accounting law requires. Database backups maintained by our hosting provider expire on its rolling schedule.

7. Your rights and choices

Depending on where you live — including under the GDPR, UK GDPR and US state privacy laws such as the CCPA/CPRA — you may have the right to access, correct, delete or port your personal data, to object to or restrict processing, and not to be discriminated against for exercising these rights. Much of this is self-serve:

  • Access and portability — download a machine-readable export of your account data from Settings → Security. Organization owners can also export their organization's data from the dashboard.
  • Erasure — delete your account from the dashboard. This removes your profile, memberships, sessions and two-factor secrets; your name is anonymized in organization audit logs rather than leaving a gap in them. A sole owner chooses whether their organizations are deleted too.
  • Correction — organization details can be edited in the dashboard; to correct your name, email address or phone number, contact us at the address below.
  • Marketing— email sent on Sendoka's broadcast stream includes a one-click unsubscribe header; otherwise use the sender's own unsubscribe link or contact the sender. SMS programs must honor STOP; replying STOP should opt you out of that sender — if it does not, report it to us at the address below.

If you are a recipient of a customer's messages, contact that customer: they control your data, and platform customers can erase one of their tenants' data through our API. For anything else, email legal@sendoka.com. We will verify your request and respond within the time the law requires. You also have the right to complain to your local data protection authority.

8. Security

We protect data with measures including TLS in transit, provider-managed encryption at rest, hashed passwords and API keys, two-factor authentication, and a signed audit log. Our Security page describes them. No system is perfectly secure; if we learn of a personal data breach affecting you, we will notify you and the relevant authorities as the law requires.

9. Children

The Service is for businesses and is not directed to children under 16. We do not knowingly collect their personal data; if you believe we have, contact us and we will delete it.

10. Changes

We will post any change to this policy here with a new "last updated" date and notify account owners of material changes by email or in the dashboard before they take effect.

11. Contact

[Company legal name], [Registered address]. Email: legal@sendoka.com. Security reports: security@sendoka.com.