Privacy Policy
Last updated: 4 October 2026
1. Who we are
SMS Code (the “App”) and the website simnetiq.xyz (the “Site”) are operated by SIMNETIQ LTD (“we”, “us”, “our”), a company registered in England and Wales. We act as the data controller for the personal data described in this policy. You can reach us at support@simnetiq.com.
Company number: 16861177. Registered office: 2 Frederick Street, Kings Cross, London, United Kingdom, WC1X 0ND. Contact: support@simnetiq.com.
2. What the App does
The App provides temporary virtual phone numbers that can receive SMS verification codes, so you can sign up for online services without sharing your personal phone number.
3. Data we collect
- Account data. An anonymous account identifier created when you first open the App, and your email address if you choose to provide it.
- Purchase data. Records of coin packs you buy. Payment itself is processed by the Apple App Store — we never see your card details.
- Activation data. The service, country, virtual number and the text of verification SMS messages received on that number, kept for the time needed to deliver the code to you and to resolve disputes.
- Device data. Two things, and only if they apply to you. If you allow notifications, the push token your device is issued, so we can tell you a code has arrived. And the two-letter region code your device reports (for example GB), sent with the country list so we can mark one country “Recommended” — this is a device setting, not your location, and no location permission is involved.
- Support data. When you contact support through the Site or by email, we collect your name, email address and the content of your message. Support requests submitted on the Site are stored in our database (hosted on Supabase) and processed through our email tooling in order to respond to you. We also store your browser’s user-agent string and a salted one-way hash of your IP address, to block automated abuse of the form.
- Website analytics. Only if you accept analytics in the Site’s cookie banner, the Site uses Vercel Web Analytics, which counts page views without cookies, and Google Analytics, which sets first-party cookies (_ga) to recognise a returning browser. Neither is used for advertising or to profile you across other websites. Our Cookie Policy lists every cookie, and you can withdraw consent at any time under Cookie settings at the bottom of every page. The App contains no analytics, advertising or attribution SDK of any kind.
- Advertising measurement. Only if you accept marketing in the Site’s cookie banner, the Site loads the Meta Pixel, which sets a first-party cookie (_fbp) and tells Meta when a visit came from one of our ads, so we can measure which ads work. The App does not use it.
What we deliberately do not collect: your own phone number, your contacts, your location, advertising identifiers, and any usage, crash or diagnostic telemetry from inside the App. There is no analytics or crash-reporting SDK in the App, so there is nothing of that kind to send. This matches the App Store privacy label for SMS Code.
4. How we use your data
- To provide virtual numbers and deliver verification codes to you (performance of a contract).
- To maintain your coin balance and restore purchases across devices (performance of a contract).
- To answer support requests (legitimate interests / performance of a contract).
- To detect and prevent fraud, abuse and violations of our Terms of Service (legitimate interests).
- To understand which pages of the Site people find useful, using website analytics — only if you accept it in the cookie banner (consent, which you can withdraw at any time).
- To measure how our ads on Facebook and Instagram perform, using the Meta Pixel — only if you accept marketing in the cookie banner (consent, which you can withdraw at any time).
We do not sell your personal data. We share Site visit data with Meta only if you accept marketing cookies, to measure our own ads. App data is never shared with advertisers.
5. Sharing and processors
We use the following providers to operate the service. Their roles depend on the service they provide:
- Supabase — the database and backend behind the App. It holds everything described in section 3 that is stored at all.
- Apple — processes every in-app purchase, and handles Sign in with Apple if you use it. We never see your payment details.
- RevenueCat — validates purchase receipts and tells our backend which coin pack you bought. It receives your account identifier, purchase data and basic device information.
- Expo — delivers push notifications and App updates. It receives your push token and the text of the notification.
- Vercel — hosts the Site and provides its cookieless page-view analytics.
- Google — provides Google Analytics on the Site, only if you accept analytics. It receives page views, device and browser information and the identifier stored in the _ga cookie, with advertising features switched off.
- Meta — provides the Meta Pixel on the Site, only if you accept marketing. It receives page views, browser information, your IP address and the identifier in the _fbp cookie, and may also use this data for its own purposes, as an independent controller under its own privacy policy.
- Our email tooling — carries support correspondence.
- Our telephony provider — supplies the virtual numbers. It is sent only the service and country you asked for; it receives no identifier of yours at all, and we do not send your app account identifier. The provider processes numbers and SMS content to deliver the service.
Providers acting as processors must be subject to appropriate data processing terms. We do not sell your data, and apart from Meta (only with your marketing consent) we share nothing with advertisers. We may also disclose data where required by law.
6. International transfers
Some providers are located outside the United Kingdom. Where data leaves the UK or the European Economic Area, applicable data protection law requires an appropriate transfer basis, such as an adequacy decision or contractual safeguards. Vercel and Google may process website analytics data in the United States; those transfers rely on the EU–US Data Privacy Framework and its UK Extension, or on standard contractual clauses. Contact us for information about the safeguards for your data.
Meta may process marketing data from the Site in the United States, on the same transfer bases.
7. Retention
- Activation data — 90 days. The rented number and the text of any SMS received on it are erased on a scheduled daily cleanup after 90 days from activation creation. What remains after that is a record with no number and no message text: the service, the country, the date, the outcome and the coins involved. We keep that because it is the accounting record for coins you spent, and the evidence we need if a payment is disputed.
- Account data — until you delete your account. Deleting your account removes your live account, email address and activation history. Limited financial and fraud-prevention records remain as described below and in section 9.
- Purchase records — as required by law. A pseudonymised financial record of each purchase — transaction reference, pack, amount, date, and whether it was later refunded — is retained for the period tax and accounting law requires, and survives account deletion. It contains no phone number, no message text and no email address.
- Support correspondence — up to 24 months after the request is closed.
8. Your rights
Under the UK GDPR and the EU GDPR you have the right to access, correct, delete or receive a copy of your personal data, to restrict or object to its processing, and to withdraw consent at any time where processing is based on consent. To exercise any of these rights, email support@simnetiq.com. You can also complain to the UK Information Commissioner’s Office (ico.org.uk) or your local supervisory authority.
9. Account and data deletion
You can delete your account directly in the App (Settings → Delete account) or by emailing us. Deletion removes your account identifier, your email address, your coin balance and your activation history, including every rented number and every SMS body still held. It does not require contacting support and it is not reversible. Limited financial and fraud-prevention records remain: purchase transaction references, the former account identifier, aggregate activity and coin counts, refund shortfalls, timestamps and hashed device-token links. These support accounting, disputes and prevention of repeated refund abuse. They contain no retained activation phone numbers, SMS bodies or account email, but they are pseudonymised, not guaranteed anonymous, and may be linked to purchase records or other accounts using the same device token.
10. Children
The App is not directed at children and is intended for users aged 18 or over. We do not knowingly collect data from children; if you believe a child has used the App, contact us and we will delete the data.
11. Security
Data is encrypted in transit, access is restricted to personnel who need it, and our databases enforce row-level access controls. No system is perfectly secure, so we also keep the amount of data we hold to a minimum.
12. Changes to this policy
We may update this policy from time to time. Material changes will be announced in the App or on the Site, and the “Last updated” date above always reflects the current version.