Privacy Policy

Commitment to protect your information and privacy

Commitment: We strictly comply with personal data protection regulations and never share your information with unrelated third parties.

1. Information We Collect

1.1. Personal Information:

  • Account registration email
  • Contact phone number (optional)
  • Payment information (encrypted)
  • IP address and device information

1.2. Service Usage Information:

  • Transaction and order history
  • Types of services used
  • Usage time and frequency
  • System activity logs

Important Note: We do NOT collect OTP/SMS message content. We only confirm successful delivery from the provider.

2. Purpose of Information Use
Information TypePurpose of Use
Account registration emailAccount verification, sending important notifications
Payment information (encrypted)Transaction processing, invoicing
Transaction and order historyCustomer support, dispute resolution
System activity logsSecurity, fraud detection
3. How We Protect Information

SSL/TLS Encryption

All transmitted data is encrypted with 256-bit

Secure Storage

Data is stored on highly secure servers

Access Control

Only authorized staff can access

3.1. Technical Measures:

  • Firewall and intrusion detection systems
  • Encryption of sensitive data in databases
  • Regular backups and data recovery
  • Regular security updates
  • 24/7 monitoring of unusual activities

3.2. Management Measures:

  • Staff training on information security
  • Security incident handling procedures
  • Regular security audits
  • Strong password policy
4. Sharing Information with Third Parties

4.1. We may share information in the following cases:

  • Payment Partners: Payment gateways to process transactions
  • Legal Authorities: When there is a legal request from authorities
  • Support Services: Hosting providers, security (with strict confidentiality agreements)

Commitment: We do NOT sell, rent or exchange your personal information with third parties for commercial purposes.

5. User Rights Regarding Personal Data

5.1. You have the right to:

Access

Request to view personal information we are storing

Edit

Update, modify inaccurate information

Delete

Request deletion of personal data (with some legal exceptions)

Portability

Export personal data in a readable format

Object

Refuse data processing in certain cases

Restrict

Request restriction of data processing

5.2. How to Exercise Your Rights:

To exercise the above rights, please contact us via:

    Response Time: We will process your request within 30 days of receiving a valid request.

    6. Cookies and Tracking Technologies

    6.1. Types of Cookies We Use:

    • Essential Cookies: To maintain login sessions and basic functionality
    • Analytics Cookies: Google Analytics to understand website usage
    • Functional Cookies: Save user preferences and settings

    6.2. Cookie Management:

    You can control cookies through:

    • Browser settings
    • Cookie consent banner on the website
    • Privacy settings page in your account
    7. Payment Security
    PCI DSS Compliant

    Security standard compliance

    SSL 256-bit

    Strong encryption

    3D Secure

    Additional authentication

    No Card Storage

    No card storage

    • We do not store credit/debit card information
    • All transactions are processed through PCI DSS certified payment gateways
    • Use tokenization to protect payment information
    • 3D Secure authentication for card transactions
    8. International Data Processing

    Your data may be processed in:

    • Vietnam: Main server and operations office
    • Singapore: Backup and disaster recovery
    • Other countries: Through service providers (SMSPool, SMS-Activate, Hero-sms)

    We ensure equivalent protection levels for data transferred abroad through:

    • Standard data processing contracts
    • International security certifications
    • Regular compliance audits
    9. Data Breach Notification

    In case of a data breach, we will:

    • Notify the regulatory authority within 72 hours
    • Notify affected users within 7 days
    • Provide detailed information about the incident and remediation measures
    • Implement additional protective measures
    10. Children's Policy

    Our service is not intended for children under 18 years of age. We:

    • Do not knowingly collect information from children under 18
    • Will immediately delete information if found to be collected from children
    • Encourage parents to monitor their children's online activities
    11. Policy Changes
    • We may update this policy to reflect legal or business changes
    • Important change notifications will be sent via email at least 30 days in advance
    • The latest version is always available on the website
    • The last update date will be clearly stated at the beginning of the policy

    © 2026 SMS Online OTP Global. All rights reserved.

    Last updated: 10/11/2026