This notice explains what personal data SMSVAR.com processes, why, who it is shared with, how long it is kept and what rights you have.
Data controller
SMSVAR.com is operated by Irodev Ltd, which is the controller for your personal data. You can send requests to [email protected].
What we process
1. Account data
Name, e-mail address, your password (stored only in irreversibly hashed form), your API key, balance and spending figures, registration date and last sign-in time. If you sign in with Google, the name and e-mail Google passes to us. If you use the Telegram bot, your Telegram username and user ID.
2. Transaction data
The numbers you order, the country and service you chose, order status, timestamps and the content of the verification message received by the number. Message content is processed solely to deliver the service itself — there is no other way for us to show you the code.
3. Payment data
Amount, method (card, bank transfer or crypto), the transaction identifier issued by the payment provider, and sender details for bank transfers. We never see or store your card number, expiry date or CVV; card payments are taken on the payment provider's own secure page.
4. Technical and security logs
For events such as sign-in, sign-out, password change, payment and order: your IP address, the location derived from it, country code, browser/device information (user agent), language preference, the address requested, the referring address, session identifier and whether the action succeeded. Failed attempts also record the reason for failure.
We want to be direct about why we keep these: to detect fraud and account-takeover attempts, to protect ourselves and other users, and to meet our legal obligations when a lawful request arrives from a competent authority.
Purposes and legal grounds
- Performance of a contract: opening your account, fulfilling orders, handling balance and refunds, answering support requests.
- Legal obligation: retention of financial records, responding to lawful requests from authorities.
- Legitimate interests: detecting fraud and abuse, service security, capacity planning.
- Consent: used only for marketing messages; you may withdraw it at any time.
Who we share with
We do not sell your personal data. To deliver the service we share it, only to the extent necessary, with providers in these categories:
- Payment providers: Stripe for card payments, Cryptomus for crypto payments. They process the payment in their own systems under their own privacy policies.
- SMS infrastructure providers: the operators and intermediaries that actually supply the number, located in Turkey and abroad. They receive only the technical details needed for the order (country, service, number identifier), not your identity.
- Infrastructure and security: our content delivery and security provider (Cloudflare), hosting provider and e-mail delivery infrastructure.
- Authentication: Google, if you use "Sign in with Google".
- Telegram: if you use the bot, messaging runs over Telegram's infrastructure.
- Competent authorities: only upon a valid, lawful request and strictly within its scope.
Some of these providers are established outside Turkey, so your data may be transferred abroad. Such transfers are limited to what is necessary to provide the service.
How long we keep it
- Account data: for as long as your account remains open.
- Payment and invoice records: for the retention period required by financial legislation (as a rule, 10 years).
- Orders and verification messages: until the need for dispute and fraud review has passed.
- Technical and security logs: for as long as needed for security review and to answer legal requests.
At the end of the period, data is deleted, destroyed or irreversibly anonymised.
Cookies
The site uses strictly necessary cookies to keep you signed in and remember your language choice; sign-in is impossible without them. The security service in front of the site may also set its own technical cookies to distinguish bot traffic. You can block measurement or advertising cookies in your browser settings; core site functions will keep working.
Your rights
You have the right to:
- learn whether your data is processed, and request information if it is,
- learn the purpose of processing and whether the data is used accordingly,
- know the third parties, in Turkey or abroad, to whom data is transferred,
- request correction of incomplete or inaccurate data,
- request erasure or destruction, within the conditions set by law,
- request that correction, erasure or destruction be notified to those third parties,
- object to a decision reached solely by automated analysis that produces an adverse outcome for you,
- claim compensation for damage arising from unlawful processing.
Send requests to [email protected]. After verifying your identity we respond within the period set by law (thirty days at the latest). Sending your request from the e-mail address registered to your account speeds up verification.
Security
Passwords are stored in irreversibly hashed form; nobody, including our support team, can read your password. SMSVAR will never ask for your password or card details by e-mail, SMS or Telegram. If you receive such a message, do not reply — report it to us.
Changes to this notice
This notice is updated when the service or the applicable legislation changes. The current version is always published at this address.