1. Who is responsible
“readynum” (a working name) is the data controller for the processing described here. The operating entity and its registered address will be stated on incorporation: [jurisdiction — pending incorporation]. Privacy questions and requests reach us through the contact page.
2. What we collect, why, and for how long
Each class of data has its own purpose, lawful basis (GDPR Art. 6) and clock. Nothing on this list is collected “just in case”.
| Data | Purpose | Lawful basis | Kept for |
|---|---|---|---|
| Account email | Deliver codes, receipts and required notices | Contract | While your account exists |
| Received SMS content | Deliver your verification code — the service itself | Contract | Auto-deleted within 24 hours of receipt |
| Number-to-account mapping and delivery metadata | Fraud prevention and dispute resolution | Legitimate interests | Short operational window, then deleted or pseudonymised |
| Wallet and billing records | Payments, tax and accounting | Legal obligation | The period tax and accounting law requires |
| Identity (KYC/AML) records, where required | Anti-money-laundering and sanctions compliance | Legal obligation | The period AML law requires after the relationship ends |
| Device and IP risk signals | Keeping the service healthy against abuse | Legitimate interests | Short operational window |
| Marketing email and analytics | Product news and product analytics | Consent — opt-in, withdrawable, no pre-ticked boxes | Until you withdraw consent |
3. The 24-hour delete, honestly stated
Your codes are yours. We auto-delete received messages after 24 hours — often you're the only one who ever sees them.
That promise applies to message content — the sensitive part. Minimal billing and compliance records are kept separately on the statutory clocks in the table above. The two do not conflict: we can delete content fast precisely because the records the law requires are small and kept apart. It also means a legal request for old message content usually has nothing to reach — we no longer hold it.
4. Your rights
- Access, rectification, erasure, portability, restriction and objection — all exercisable through the contact page, answered within the statutory window (30 days under GDPR, 45 days under CCPA).
- The honest limit: an erasure request cannot wipe records we are legally required to keep (billing, KYC/AML). Those are held under a legal obligation for their mandated period — we say that here rather than promise a deletion we cannot lawfully perform.
- We do not sell personal data. Where a right to opt out of “sale or sharing” applies (CCPA/CPRA), we honour it, including Global Privacy Control signals from your browser.
- You can withdraw marketing consent at any time — every marketing email carries an unsubscribe link.
5. Data minimisation
Signup asks for an email address, nothing else. We do not run third-party advertising trackers, we do not build advertising profiles, and we do not enrich your data from data brokers. Identity checks happen only where anti-money-laundering law requires them for a specific transaction pattern — not by default.
6. Sub-processors
Every vendor that touches personal data on our behalf is a processor under GDPR Art. 28, works under a signed data processing agreement (with SCCs or the UK IDTA where data leaves the EEA/UK), and is named in a public list on this page. That includes upstream number suppliers — the vendor carrying your SMS content is the most disclosure-critical one we have, not a commercial secret.
As of this draft, no sub-processor contract is signed and the list is empty on purpose. It will be populated before the first paid order is served, and adding or switching a vendor updates the list before that vendor goes live.
7. Security
Card processing is PCI-compliant and card numbers never touch our servers — they go directly to the payment processor named at checkout. Internally, access to personal data is restricted to what a task requires, and the fastest security control we have is the one above: data deleted within 24 hours cannot be breached later.
8. International transfers
Where personal data is transferred outside the EEA or the UK, the transfer is covered by an adequacy decision, Standard Contractual Clauses, or the UK International Data Transfer Agreement, and the receiving vendor appears in the sub-processor list above.
9. Changes to this policy
Material changes are announced to account holders by email before they take effect, and this page always carries the date of its current version. Related reading: the Terms of service, the Acceptable Use Policy and the trust page.