1. Introduction
Welcome to NinzaSMS (referred to as "Company," "We," "Us," or "Our"). We are committed to protecting your privacy and ensuring that your personal information is handled in a safe and responsible manner.
This Privacy Policy explains how we collect, use, store, and protect your personal data when you visit our website or use our Services. By using our Services, you agree to the collection and use of information in accordance with this policy.
We comply with the Information Technology Act 2000 and its respective rules, including the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
2. Information We Collect
We collect various types of information to provide and improve our Services:
2.1 Personal Information
- Contact Information: Name, email address, phone number, and company name.
- Account Credentials: Username and securely hashed password.
- Payment Information: Transaction details, billing address, and payment method data (processed securely via Razorpay).
- Communication Data: Messages, emails, and support requests you send to us.
2.2 Usage Data
- API Usage: Number of SMS/OTP requests, timestamps, and API key usage.
- Device Information: IP address, browser type, operating system, and device identifiers.
- Interaction Data: Pages visited, time spent, and navigation patterns on our website.
- Cookies: We use cookies to enhance your experience. See Section 7 for details.
2.3 SMS/OTP Content Data
- Message Content: The actual text of SMS messages sent through our platform.
- Recipient Information: Phone numbers of message recipients.
- Delivery Status: Confirmation of message delivery status and logs.
IMPORTANT: We do NOT store the full content of your SMS messages for more than 30 days. We only retain delivery logs and metadata for operational and compliance purposes.
3. How We Use Your Information
We use your personal data for the following purposes:
- Service Delivery: To process and deliver SMS/OTP messages, maintain your account, and provide customer support.
- Account Management: To manage your registration, authenticate your identity, and handle billing.
- Security: To detect and prevent fraud, abuse, and unauthorized access to your account.
- Communication: To send you important notifications, updates, and promotional offers (only with your consent).
- Analytics: To analyze usage patterns, improve our Services, and develop new features.
- Legal Compliance: To comply with applicable laws, regulations, and court orders.
4. Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Contractual Necessity: Processing is necessary to fulfill our contractual obligations to you.
- Legitimate Interests: Processing is necessary for our legitimate business interests, such as improving our Services and preventing fraud.
- Legal Obligation: Processing is required to comply with applicable laws and regulations.
- Consent: Where you have given explicit consent for specific processing activities.
5. Data Sharing and Transfer
We may share your data with the following third parties:
- Service Providers: Third-party vendors who assist us with payment processing (Razorpay), hosting, analytics, and customer support.
- Telecom Partners: SMS delivery partners who route your messages to mobile networks.
- Legal Authorities: When required by law, court order, or to protect our rights and safety.
We ensure that all third-party service providers adhere to strict data protection standards and only process data for specified purposes.
Data Security: We do NOT sell, rent, or trade your personal information to third parties for marketing purposes.
6. Data Security
We implement bank-grade security measures to protect your data:
- 256-bit Encryption: All data is encrypted in transit and at rest.
- SHA-256 Hashing: Passwords and API keys are securely hashed.
- TLS 1.3: Secure communication between your browser and our servers.
- Regular Audits: Vulnerability scanning and security audits are performed regularly.
- MFA Support: Multi-factor authentication available for enhanced account security.
- Data Isolation: Your data is isolated from other users' data.
While we take all reasonable precautions, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.
7. Cookies and Tracking
We use cookies and similar tracking technologies to enhance your experience:
- Essential Cookies: Required for website functionality, authentication, and security.
- Analytics Cookies: To understand how users interact with our website and improve our Services.
- Preference Cookies: To remember your preferences and settings.
You can manage your cookie preferences through your browser settings. However, disabling certain cookies may affect website functionality.
8. Data Retention
We retain your personal data for as long as necessary to:
- Provide and maintain our Services.
- Comply with legal obligations (e.g., tax, audit, and regulatory requirements).
- Resolve disputes and enforce our agreements.
Generally, we retain account data for up to 5 years after account closure, subject to legal requirements.
SMS/OTP logs are retained for up to 30 days for operational purposes and delivery confirmation.
9. Your Rights
You have the following rights regarding your personal data:
- Access: You can request a copy of the personal data we hold about you.
- Correction: You can request correction of inaccurate or incomplete data.
- Deletion: You can request deletion of your personal data (subject to legal obligations).
- Objection: You can object to certain processing activities.
- Data Portability: You can request a copy of your data in a structured format.
- Withdraw Consent: You can withdraw your consent at any time.
To exercise these rights, please contact us at support@ninzasms.com.
Business Information
NINZASMS is a brand and service operated under
DRISHTI ELECTRONIC, a registered Proprietorship
enterprise in India.
Our platform provides only legitimate OTP SMS API and Transactional
SMS services for businesses and developers.
We strictly prohibit the use of our platform for phishing,
scam, fraud, spoofing, identity theft, spam,
fake verification, or any other illegal activity.
Any account found violating our Terms & Conditions or applicable
laws is suspended or permanently terminated immediately.
USER'S DATA RESPONSIBILITY:
As a user of NinzaSMS, you are responsible for:
1. Maintaining the confidentiality of your account credentials and API keys.
2. Not sharing sensitive personal information of others through our Service without proper consent.
3. Complying with data protection laws regarding the collection and processing of recipient data.
4. Notifying us immediately of any unauthorized access to your account.
You are solely responsible for any legal consequences arising from the misuse of your account or violation of data protection laws.
11. Third-Party Links
Our Service may contain links to third-party websites. We are not responsible for the privacy practices or content of such third-party sites. We encourage you to review the privacy policies of any external sites you visit.
12. Children's Privacy
Our Services are not intended for children under the age of 18. We do not knowingly collect personal data from minors. If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately.
13. Changes to Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the updated policy on this page.
- Updating the "Last Updated" date at the top of the page.
- Notifying you via email (if you have provided one).
We recommend reviewing this Privacy Policy periodically to stay informed about our data practices.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, please contact us:
15. GDPR Compliance
For users in the European Union, we comply with the General Data Protection Regulation (GDPR). Under GDPR, you have additional rights including:
- Right to access, correct, and delete your data.
- Right to restrict or object to processing.
- Right to data portability.
- Right to withdraw consent.
- Right to lodge a complaint with a supervisory authority.
We process personal data based on the legal grounds outlined in Section 4.