Skip to main content

Privacy Policy

How we collect, use, and protect your personal information

Your Privacy Matters

At Tavoxsms, we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, store, and protect your data when you use our SMS marketing platform, including campaign management, AI-powered messaging, and contact management services.

Information We Collect

Account Information

  • Name, email address, and organization details
  • Billing information and payment method details
  • Account preferences and subscription plan
  • Login credentials and authentication data

Contact Data

  • Phone numbers and contact information you upload
  • Contact names, email addresses, and company details
  • Contact lists, groups, and segmentation data
  • Opt-in/opt-out preferences and consent records
  • Message delivery status and engagement metrics

Campaign & Usage Data

  • SMS campaign content and scheduling information
  • Message delivery and delivery failure data
  • Campaign performance analytics and metrics
  • AI agent responses and conversation history
  • Platform usage patterns and feature access

Technical & System Data

  • IP addresses and device information for security
  • Browser type and version for compatibility
  • Operating system and platform information
  • Session cookies for authentication and preferences
  • Error logs and system performance data

Identity Verification (KYC) Data

  • Business name, registration number, and address
  • Authorized representative details (name, email)
  • Government ID or company documents where required
  • Phone number ownership and brand registration metadata
  • Verification outcomes from third-party KYC providers

We collect KYC data only when needed to comply with carrier or regulatory requirements and to prevent fraud and abuse.

How We Use Your Information

We use your information for the following purposes:

  • Providing and maintaining our SMS marketing services
  • Processing payments and managing billing
  • Sending SMS messages on your behalf
  • Managing your contacts and campaigns
  • Providing customer support and technical assistance
  • Improving our platform and developing new features
  • Ensuring compliance with legal obligations
  • Preventing fraud and maintaining security
  • Conducting identity verification (KYC) where required
  • Cooperating with carriers on brand/traffic registration

Data Sharing & Disclosure

We do not sell, trade, or rent your personal information. We may share your data in these limited circumstances:

  • Service Providers: With trusted third-party services that help us operate our platform
  • SMS Carriers: With telecommunications providers to deliver your messages
  • Verification Vendors: With identity/KYC providers solely to verify your organization or brand and satisfy carrier or regulatory requirements
  • Legal Requirements: When required by law or to protect our rights and safety
  • Business Transfers: In connection with a merger, acquisition, or sale of assets
  • Consent: When you explicitly authorize us to share your information

Data Security

We implement comprehensive security measures to protect your data:

  • End-to-end encryption for data in transit and at rest
  • Secure data centers with physical and digital security
  • Regular security audits and vulnerability assessments
  • Access controls and authentication requirements
  • Employee training on data protection practices
  • Incident response and breach notification procedures
Security Commitment: We continuously monitor and improve our security measures to protect your data against unauthorized access, alteration, disclosure, or destruction.

Data Retention

We retain your data only as long as necessary for business operations and legal compliance:

  • Account Data: Retained while your account is active and for 2 years after closure for support purposes
  • Contact Data: Retained until you delete it or close your account, with automatic cleanup after 12 months of inactivity
  • Campaign Data: Retained for 2 years for analytics and compliance, then anonymized
  • Message Logs: Retained for 90 days for delivery troubleshooting, then archived
  • Billing Records: Retained for 7 years for tax and legal compliance
  • AI Conversations: Retained for 30 days for service improvement, then anonymized
  • KYC/Verification Records: Retained for as long as required by carriers or applicable law and then securely deleted or archived per regulatory guidance

Your Rights & Choices

You have the following rights regarding your personal data:

  • Access: Request a copy of your personal data
  • Correction: Update or correct inaccurate information
  • Deletion: Request deletion of your personal data
  • Portability: Export your data in a machine-readable format
  • Restriction: Limit how we process your data
  • Objection: Object to certain types of processing
  • Withdrawal: Withdraw consent for data processing

To exercise these rights, contact us at privacy@tavoxsms.com

International Data Transfers

Tavoxsms operates globally and may transfer your data to countries outside your residence. We ensure adequate protection through:

  • Standard Contractual Clauses (SCCs) for EU data transfers
  • Adequacy decisions where applicable
  • Binding corporate rules and internal policies
  • Regular assessments of data protection standards

Cookies & Tracking Technologies

We use cookies and similar technologies for essential platform functionality:

  • Authentication and session management
  • User preferences and account settings
  • Security and fraud prevention
  • Platform performance monitoring
  • Campaign analytics and reporting

We use essential cookies for platform functionality. You can control cookie preferences through your browser settings, but disabling certain cookies may affect core platform features like authentication and session management.

Third-Party Services

Our platform integrates with these essential third-party services:

  • Twilio: SMS delivery, phone number management, and message routing
  • Stripe: Payment processing, subscription management, and billing
  • Inngest: Background job processing for scheduled campaigns
  • Convex: Real-time database and notification services
  • NextAuth: Authentication and user session management

These services are essential for our platform functionality. Each service has its own privacy policy and data handling practices. We recommend reviewing their policies to understand how they process your data.

Important: Tavoxsms acts as a platform to help you manage messaging. You are the sender of record for your campaigns and are responsible for lawful content, valid consent, and compliance with carrier and regulatory rules.

Children's Privacy

Our services are not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected such information, please contact us immediately.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

  • Email notification to your registered email address
  • Prominent notice on our platform
  • Updated "Last updated" date at the top of this policy

Continued use of our services after changes constitutes acceptance of the updated Privacy Policy.

Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

Privacy Officer: privacy@tavoxsms.com

Data Protection Officer: dpo@tavoxsms.com

General Support: support@tavoxsms.com

Address: Tavoxsms Ltd, London, United Kingdom

Legal Inquiries: legal@tavoxsms.com

For EU residents, you also have the right to lodge a complaint with your local data protection authority.