Legal
Privacy Policy
1. Introduction
SMS Philippines ("we", "us", "our") respects your privacy and is committed to protecting personal data in accordance with Republic Act No. 10173, the Data Privacy Act of 2012 ("DPA"), its Implementing Rules and Regulations, and the issuances, circulars, and advisories of the National Privacy Commission ("NPC").
This Privacy Policy explains how we collect, use, disclose, store, retain, and protect personal data when you use the SMS Philippines web application, dashboard, APIs, and related services (the "Service"). It should be read together with our Terms and Conditions.
By using the Service, you acknowledge that you have read and understood this Policy.
2. Our Role: Controller and Processor
Our role under the DPA depends on the data involved:
- As Personal Information Controller (PIC): for data about you, our account holder — your registration details, billing records, API keys, support correspondence, and usage logs. We decide the purposes and means of processing this data.
- As Personal Information Processor (PIP): for data about your message recipients — the contact records, mobile numbers, names, and message content you upload or submit. We process this data solely on your documented instructions. You remain the PIC for that data and are responsible for its lawfulness, including obtaining valid consent.
3. Personal Data We Collect
3.1 Account and Identity Data
- Full name and email address
- Password (stored only in hashed, non-reversible form)
- Account role (user or administrator) and account status
- Authentication data, including one-time passwords (OTPs), session tokens, and single sign-on (SSO) identifiers where you sign in through a supported identity provider
- Password-reset tokens
3.2 Business and Billing Data
- Business or trade name, registered business address, and contact details of your authorised representative
- Business supporting documents submitted for Sender Name registration, including SEC or DTI registration certificates, BIR Certificate of Registration (Form 2303), Mayor's or business permits, Articles of Incorporation or partnership documents, board resolutions or Secretary's Certificates, letters of authorisation or letters of intent, government-issued identification of the authorised signatory, brand ownership or trademark proof, and sample message templates and use-case descriptions
- Sender Names (Sender IDs) you register and their approval status
- Whitelisted URLs you register and their approval status
- Credit purchase records, transaction identifiers, purchase history, and credit balances
- Payment status information received from our payment processor. We do not collect or store full payment card numbers or CVV codes — these are handled directly by the payment processor.
3.3 Contact and Recipient Data (processed on your behalf)
- Recipient first name and last name
- Recipient mobile number
- Contact status (for example, active or inactive)
- Contact group names and group memberships
3.4 Message and Campaign Data
- Message content for quick blasts, campaigns, message sequences, and webhook-triggered campaigns
- Campaign names, descriptions, schedules, recurrence rules, and statuses
- Recipient counts, send timestamps, delivery statuses, and message-segment counts
- Webhook URLs and webhook authentication tokens
3.5 Technical and Usage Data
- IP address, browser type and version, device type, and operating system
- Log data, including timestamps, pages viewed, features used, API endpoints called, and error events
- API key identifiers, key prefixes, and last-used timestamps
- Cookies and similar local-storage technologies (see Section 9)
3.6 Support and Feedback Data
- Messages, feedback, and attachments you submit through support or feedback channels
We do not intentionally collect sensitive personal information as defined in Section 3(l) of the DPA (such as data on race, ethnic origin, marital status, age, colour, religious, philosophical or political affiliations, health, education, genetic or sexual life, proceedings for any offence, government-issued identifiers such as SSS, GSIS, TIN, or PhilHealth numbers, or tax returns). You must not upload sensitive personal information into contact fields or message content. If you do so, you do it at your own risk and remain solely responsible for the lawfulness of that processing.
4. How We Collect Personal Data
- Directly from you — when you register, log in, configure your account, upload contacts, compose messages, purchase credits, or contact support.
- Automatically — through cookies, local storage, server logs, and analytics when you use the Service.
- From third parties — from your identity provider when you use SSO, from payment processors regarding transaction outcomes, and from mobile network operators regarding message delivery status.
5. Purposes and Lawful Bases for Processing
| Purpose | Lawful basis under the DPA |
|---|---|
| Create and administer your account; authenticate you | Performance of a contract with you |
| Transmit the SMS messages and campaigns you submit | Performance of a contract; your documented instructions as PIC |
| Process credit purchases, billing, invoicing, and refunds | Performance of a contract; legal obligation (tax and accounting) |
| Provide customer support and respond to feedback | Performance of a contract; legitimate interests |
| Monitor, detect, and prevent spam, fraud, abuse, and security incidents | Legitimate interests; legal obligation |
| Verify your business identity and legitimacy through submitted business documents | Performance of a contract; legal obligation; legitimate interests |
| Screen and approve Sender Names and whitelisted URLs, and submit registration applications and supporting documents to the NTC, mobile network operators, and other relevant agencies on your behalf | Performance of a contract; legal obligation |
| Maintain audit trails, logs, and delivery records | Legitimate interests; legal obligation |
| Improve, troubleshoot, and develop the Service | Legitimate interests |
| Send service, security, and transactional notices | Performance of a contract; legitimate interests |
| Send marketing communications about our own services | Your consent (withdrawable at any time) |
| Comply with lawful orders, subpoenas, and regulatory requirements | Legal obligation |
We do not use your recipient contact data for our own marketing, and we do not sell personal data.
6. Automated Processing and AI Features
The Service offers optional AI-assisted message drafting. When you use this feature, the prompt text you enter is transmitted to a third-party AI provider to generate suggested wording. Do not enter personal data, sensitive personal information, or confidential material into AI prompts. No decision producing legal effects or similarly significant effects on any individual is made solely by automated means through the Service.
7. Disclosure of Personal Data
We disclose personal data only as follows:
- Mobile network operators and aggregators (including Globe and Smart and their routing partners) — recipient mobile numbers, Sender Names, and message content, strictly to deliver your messages, together with your business name, business address, and supporting business documents where required to register and maintain a Sender Name.
- The National Telecommunications Commission (NTC) and other relevant regulators or accrediting bodies — your business name, business address, authorised representative details, supporting business documents, and intended message templates, where required to obtain, renew, or defend approval of a Sender Name or to respond to a regulatory query or complaint.
- Payment processors (including PayPal) — transaction data necessary to process credit purchases.
- Cloud hosting, infrastructure, and platform providers — for hosting, storage, database, and application delivery.
- AI service providers — only the prompt text you voluntarily submit through AI-assisted features.
- Professional advisers — legal, accounting, and audit advisers under duties of confidentiality.
- Government authorities, regulators, and law enforcement — including the NPC, the NTC, the Bureau of Internal Revenue, and the courts, where required by law, subpoena, or valid lawful order.
- Successors in interest — in connection with a merger, acquisition, reorganisation, or sale of assets, subject to this Policy continuing to apply.
All third parties who process personal data on our behalf are bound by written agreements requiring confidentiality, adequate security measures, and processing limited to our documented instructions, consistent with Section 44 of the DPA IRR. We do not sell, rent, or trade personal data.
8. International Transfers
Some of our service providers may store or process data on servers located outside the Philippines. Where personal data is transferred abroad, we remain accountable for it and ensure that comparable protection is applied through contractual safeguards, as required by the DPA and NPC issuances. By using the Service, you acknowledge that such transfers may occur.
9. Cookies and Local Storage
We use strictly necessary cookies and browser local storage to keep you signed in, maintain session security, remember interface preferences (such as dismissed tutorial banners and sidebar state), and support basic analytics. Strictly necessary cookies cannot be disabled without impairing the Service. You may control or delete cookies through your browser settings; doing so may prevent you from logging in or using certain features.
10. Data Retention
We retain personal data only as long as necessary for the purposes described in this Policy or as required by law:
| Data category | Retention period |
|---|---|
| Account and profile data | For the life of the account, then up to thirty (30) days after closure |
| Contact and recipient data | Until you delete it, or up to thirty (30) days after account closure |
| Message content and campaign records | Up to twelve (12) months from the send date, unless a longer period is required by law or a dispute |
| Delivery and audit logs | Up to twelve (12) months |
| Business documents submitted for Sender Name registration | For as long as the Sender Name is active, then five (5) years, to evidence lawful registration to the NTC and network operators |
| Billing, invoicing, and tax records | Ten (10) years, as required by BIR regulations |
| Support and feedback correspondence | Up to twenty-four (24) months |
| API keys and access logs | For the life of the key, then twelve (12) months |
After the applicable period, data is securely deleted, anonymised, or aggregated so that it can no longer identify an individual. Data subject to a legal hold, investigation, or dispute is retained until the matter is fully resolved.
11. Security Measures
We implement organisational, physical, and technical security measures proportionate to the risks, including:
- Encryption of data in transit using industry-standard TLS
- Hashed, salted password storage and OTP-based verification
- Role-based access control and row-level security so that each account can access only its own records
- API key prefixing, rotation, and revocation capabilities
- Access logging, monitoring, and least-privilege administrative access
- Confidentiality obligations for personnel and contractors
- Regular review of security practices and provider due diligence
No system can be guaranteed absolutely secure. You are responsible for safeguarding your password, API keys, and webhook tokens, and for the security of your own devices and networks.
12. Data Breach Notification
In the event of a personal data breach that meets the notification threshold under the DPA and NPC Circular 16-03, we will notify the NPC and the affected data subjects within seventy-two (72) hours of knowledge of, or reasonable belief in, the breach, and will describe the nature of the breach, the data involved, the measures taken, and the contact point for further information. Where we act as your Processor, we will notify you without undue delay so that you can meet your own obligations as Controller.
13. Your Rights as a Data Subject
Under Chapter IV of the DPA, you have the right to:
- Be informed whether your personal data is being or has been processed;
- Access your personal data and receive details of its processing, sources, recipients, and purposes;
- Object to processing, including processing for direct marketing, automated processing, or profiling;
- Rectify inaccurate or erroneous personal data;
- Erasure or blocking — to suspend, withdraw, or order the blocking, removal, or destruction of your personal data where it is incomplete, outdated, false, unlawfully obtained, used for unauthorised purposes, or no longer necessary;
- Data portability — to obtain a copy of your data in an electronic, structured, and commonly used format;
- Damages — to be indemnified for damages sustained due to inaccurate, incomplete, outdated, false, unlawfully obtained, or unauthorised use of personal data;
- Lodge a complaint with the National Privacy Commission;
- Withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
To exercise any right, email legal_privacy@smsphilippines.com with your registered email address and a description of your request. We will verify your identity and respond within fifteen (15) calendar days, extendable once with notice where the request is complex. Requests may be refused, in whole or in part, where the law permits — for example, where compliance would prejudice an investigation, breach a legal retention obligation, or infringe another person's rights.
Message recipients: if you received an SMS through our platform and wish to exercise your rights, please contact the business that sent it, as they are the Controller of your data. You may also write to us at legal_privacy@smsphilippines.com and we will forward your request to the relevant account holder and assist as their Processor.
14. Opting Out of Messages
To stop receiving marketing SMS from a sender using our platform, reply to the message using the opt-out instructions provided, or contact the sender directly. Our account holders are contractually required to honour opt-out requests within two (2) business days. If a sender fails to do so, you may report it to us at legal_privacy@smsphilippines.com and we may suspend the offending account.
15. Children's Privacy
The Service is not directed to, and may not be used by, individuals under eighteen (18) years of age. We do not knowingly collect personal data from minors. If we learn that we have collected such data without the consent of a parent or legal guardian, we will delete it promptly. You must not upload contact data of minors without the verifiable consent of their parent or guardian.
16. Third-Party Links and Services
The Service may contain links to, or integrations with, third-party websites and platforms. This Policy does not apply to those third parties. We encourage you to review their privacy notices before providing them with personal data.
17. Changes to This Policy
We may update this Policy from time to time. Material changes will be announced through the Service or by email at least fifteen (15) days before taking effect, and the "Last Updated" date above will be revised. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.
18. Contact Us and Data Protection Officer
For privacy questions, data subject requests, breach reports, or complaints, contact our Data Protection Officer:
Email: legal_privacy@smsphilippines.com
If you are not satisfied with our response, you may file a complaint with:
National Privacy Commission
5th Floor, Delegation Building, PICC Complex, Roxas Boulevard, Pasay City 1307, Metro Manila, Philippines
Website: privacy.gov.ph
19. Governing Law
This Policy is governed by the laws of the Republic of the Philippines. Any dispute relating to it shall be resolved as provided in our Terms and Conditions, with venue in the proper courts of Makati City, Metro Manila, without prejudice to your right to complain to the National Privacy Commission.