1. Overview & Data Controller
SharkSMS ("SharkSMS", "we", "our", or "us") is dedicated to protecting your privacy. This Privacy Policy explains our practices regarding the collection, processing, transfer, and protection of personal data when you visit sharksms.com, use our Android gateway application, or integrate with our messaging APIs.
For the purposes of the General Data Protection Regulation (GDPR), SharkSMS operates as a Data Controller for your account registration and billing details, and as a Data Processor on your behalf regarding the message payloads and contact lists you process through our services.
2. Information We Collect
We collect information in three categories to deliver and safeguard our services:
A. Information You Provide to Us
- Account Credentials: Name, email address, password hashes, company name, and contact details provided during registration.
- Billing & Subscription Details: Payment transaction identifiers, subscription plan choices, and invoicing details (processed via secure PCI-DSS certified payment processors; SharkSMS never stores raw credit card numbers).
- Support Communications: Inquiries, technical bug reports, and correspondence submitted via our contact forms or email.
B. Telemetry & Gateway Device Data
- Device Telemetry: Model of paired Android devices, Android OS version, battery percentage, charging state, SIM carrier name, signal strength, and gateway synchronization heartbeat timestamps.
- Network Identifiers: IP addresses, browser user agent strings, access timestamps, and API authentication request headers used for security monitoring and fraud prevention.
C. Messaging Data Processed on Your Behalf
- Message Metadata: Destination phone numbers, timestamps, character counts, encoding types, and delivery status receipts (sent, delivered, failed).
- Contact Lists: Phone numbers, recipient names, and custom attributes imported by you into contact groups for automated campaigns.
3. How We Use Your Information
We use the collected information solely for legitimate business operations:
- To provision, maintain, and coordinate your messaging gateways and REST API services.
- To synchronize outbound message queues with your paired Android SIM devices and WhatsApp instances.
- To provide delivery reports, analytics, and webhook notifications.
- To authenticate API requests and prevent abusive spamming, brute-force attacks, or credential theft.
- To process subscription payments and manage customer accounts.
- To deliver technical support, security updates, and critical operational notices.
4. Lawful Basis for Processing (GDPR)
If you reside in the European Economic Area (EEA) or the United Kingdom, our lawful bases for collecting and processing personal data include:
- Performance of a Contract (Art. 6(1)(b) GDPR): Processing necessary to fulfill our service commitments under our Terms of Service.
- Legitimate Interests (Art. 6(1)(f) GDPR): Improving platform security, detecting fraud, optimizing gateway telemetry, and maintaining network reliability.
- Legal Compliance (Art. 6(1)(c) GDPR): Complying with applicable telecommunications, accounting, and anti-fraud statutory obligations.
5. Contact Ownership & Zero-Monetization Guarantee
Our Privacy Commitment to You:
We never sell, rent, lease, or monetize your contact lists, recipient numbers, or message payloads. Your customer database belongs exclusively to you. SharkSMS processes this data strictly to fulfill message routing instructions initiated by your account.
6. Infrastructure, Sub-processors & Security
SharkSMS implements enterprise-grade technical and organizational security measures:
- Encryption: All communication between browsers, Android gateway devices, APIs, and our servers is secured using modern TLS/SSL encryption with HSTS enforcement.
- Infrastructure Hosting: Hosted in SOC 2 and ISO 27001 certified data centers with 24/7 security monitoring and firewalls.
- Edge Security: Protected by Cloudflare for global CDN delivery, DDoS mitigation, and edge caching of public marketing content.
8. Data Retention & Right to Erasure
We retain your personal data for as long as your account remains active and as required to provide our services. You have the right to request the permanent deletion of your account, contact lists, and message dispatch logs at any time.
Upon account cancellation or an erasure request, your contact lists, gateway pairings, and associated message logs will be permanently deleted from our primary databases within 30 days.
9. Your Privacy Rights (GDPR & CCPA)
Depending on your location, you have statutory rights concerning your personal data:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete personal information.
- Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data.
- Right to Data Portability: Export your contacts, templates, and logs in standard machine-readable formats (CSV, JSON).
- Right to Object & Restrict Processing: Object to or restrict specific data processing activities.
10. Contact Our Privacy Team
If you have any questions about this Privacy Policy, wish to exercise your data privacy rights, or need assistance with a data processing request, please contact our team at: