Privacy Policy
Last updated: 10 September 2026
This wording was written from how the platform actually works and is a starting point, not legal advice. It should be checked by someone qualified before you rely on it. A super admin can edit it, and can remove this notice, under Settings → Website.
This explains what personal information GotiSMS holds, why, who else sees it, and how long we keep it.
What this policy covers
This explains what we do with personal information when you use GotiSMS.
There are two different roles to keep apart. For your own account details we decide what happens to the data. For the contact lists and message content you upload, you decide — we only process it to deliver the messages you asked us to send.
Information about your account
When you register we collect your name, company name, work email, mobile number, business type and the IP address the application came from. We record when you accepted these policies.
We keep your password only as an Argon2 hash. We cannot read it, and nobody at GotiSMS can tell you what it is.
Contact lists you upload
Your contacts belong to you. We store them so you can send to them, and we do not use them for anything else — we do not market to them, sell them, or mix them with another customer's data.
You are responsible for having consent to hold those numbers and to message them. If a contact asks you to remove them, do it in your account; a suppressed contact stays suppressed and is not re-subscribed when you import a newer file.
Message content and delivery records
We store the text of the messages you send, the destination numbers, the time, the cost, and the delivery report the operator returned — including the operator's own status text, unchanged, because that is what an investigation needs.
Message content passes through the mobile operator or aggregator that delivers it. SMS is not an encrypted channel: do not send passwords, full card numbers or anything you would not want a network operator to be able to read.
Technical information
We log IP addresses, sign-in times, failed sign-in attempts and API requests. This is how we detect account takeover and abuse, and it is also what we look at when something goes wrong.
Who else sees the data
Mobile operators and aggregators — they receive the destination number, the sender ID and the message text, because that is what delivering an SMS means.
Payment providers — when you top up through bKash or another gateway, that provider handles the payment. We receive a confirmation and a reference; we never see or store your PIN or card details.
Our hosting and email providers, under contract, to run the platform.
Regulators, law enforcement or a court, where we are legally required to. We do not sell personal information to anyone, ever.
How long we keep it
Account records: while the account is open, and for as long afterwards as tax and accounting law requires.
Messages and delivery reports: retained so you can report on your own traffic and so billing disputes can be settled.
Contacts: until you delete them or close the account.
Sign-in and API logs: a rolling period for security investigation.
If you want your data deleted sooner, ask us — we will do it except where we are required to keep a record.
Security
Passwords are hashed, sessions are cookie-based and marked secure, supplier credentials are encrypted at rest, and traffic is served over HTTPS.
No system is perfectly secure. If a breach affects your data we will tell you and the relevant authority without undue delay.
Your choices
You can see and correct your account details in your dashboard, export or delete your contacts, and ask us for a copy of what we hold about you or for it to be deleted.
Some emails are part of the service and cannot be switched off — password resets, security alerts and account notices. Others, such as the daily summary, are optional.
Cookies
We use cookies to keep you signed in and to keep the session secure. There are no advertising or third-party tracking cookies on this site.
Changes
If this policy changes materially we will email the address on your account. The date at the top is when it last changed.
Contact
Questions, or a request about your data: support@gotisms.com
See also our Terms of Service.