Privacy policy

Draft — pending legal reviewDraft dated 28 July 2026

The short version: we collect the minimum the service needs, we delete the sensitive part fast, we never sell your data, and where the law makes us keep something we say so instead of promising a deletion we can’t perform.

1. Who is responsible

“readynum” (a working name) is the data controller for the processing described here. The operating entity and its registered address will be stated on incorporation: [jurisdiction — pending incorporation]. Privacy questions and requests reach us through the contact page.

2. What we collect, why, and for how long

Each class of data has its own purpose, lawful basis (GDPR Art. 6) and clock. Nothing on this list is collected “just in case”.

DataPurposeLawful basisKept for
Account emailDeliver codes, receipts and required noticesContractWhile your account exists
Received SMS contentDeliver your verification code — the service itselfContractAuto-deleted within 24 hours of receipt
Number-to-account mapping and delivery metadataFraud prevention and dispute resolutionLegitimate interestsShort operational window, then deleted or pseudonymised
Wallet and billing recordsPayments, tax and accountingLegal obligationThe period tax and accounting law requires
Identity (KYC/AML) records, where requiredAnti-money-laundering and sanctions complianceLegal obligationThe period AML law requires after the relationship ends
Device and IP risk signalsKeeping the service healthy against abuseLegitimate interestsShort operational window
Marketing email and analyticsProduct news and product analyticsConsent — opt-in, withdrawable, no pre-ticked boxesUntil you withdraw consent

3. The 24-hour delete, honestly stated

Your codes are yours. We auto-delete received messages after 24 hours — often you're the only one who ever sees them.

That promise applies to message content — the sensitive part. Minimal billing and compliance records are kept separately on the statutory clocks in the table above. The two do not conflict: we can delete content fast precisely because the records the law requires are small and kept apart. It also means a legal request for old message content usually has nothing to reach — we no longer hold it.

4. Your rights

  • Access, rectification, erasure, portability, restriction and objection — all exercisable through the contact page, answered within the statutory window (30 days under GDPR, 45 days under CCPA).
  • The honest limit: an erasure request cannot wipe records we are legally required to keep (billing, KYC/AML). Those are held under a legal obligation for their mandated period — we say that here rather than promise a deletion we cannot lawfully perform.
  • We do not sell personal data. Where a right to opt out of “sale or sharing” applies (CCPA/CPRA), we honour it, including Global Privacy Control signals from your browser.
  • You can withdraw marketing consent at any time — every marketing email carries an unsubscribe link.

5. Data minimisation

Signup asks for an email address, nothing else. We do not run third-party advertising trackers, we do not build advertising profiles, and we do not enrich your data from data brokers. Identity checks happen only where anti-money-laundering law requires them for a specific transaction pattern — not by default.

6. Sub-processors

Every vendor that touches personal data on our behalf is a processor under GDPR Art. 28, works under a signed data processing agreement (with SCCs or the UK IDTA where data leaves the EEA/UK), and is named in a public list on this page. That includes upstream number suppliers — the vendor carrying your SMS content is the most disclosure-critical one we have, not a commercial secret.

As of this draft, no sub-processor contract is signed and the list is empty on purpose. It will be populated before the first paid order is served, and adding or switching a vendor updates the list before that vendor goes live.

7. Security

Card processing is PCI-compliant and card numbers never touch our servers — they go directly to the payment processor named at checkout. Internally, access to personal data is restricted to what a task requires, and the fastest security control we have is the one above: data deleted within 24 hours cannot be breached later.

8. International transfers

Where personal data is transferred outside the EEA or the UK, the transfer is covered by an adequacy decision, Standard Contractual Clauses, or the UK International Data Transfer Agreement, and the receiving vendor appears in the sub-processor list above.

9. Changes to this policy

Material changes are announced to account holders by email before they take effect, and this page always carries the date of its current version. Related reading: the Terms of service, the Acceptable Use Policy and the trust page.

Every route below is one click away. Open a country to see its services, or jump straight to a service hub.