Privacy Policy
Last updated August 28, 2026
1. Introduction
Fetch SMS ("Fetch SMS", "we", "us", or "our") operates the website at fetchsms.com together with the related dashboard and API (collectively, the "Service"), which lets you rent non-VOIP US phone numbers to receive SMS verification codes. This Privacy Policy explains what information we collect, how we use it, and the choices you have. By using the Service, you agree to the practices described here.
We are the controller of the personal information described in this policy. Our operations are based in the United States.
2. Consent
By accessing or using the Service, creating an account, or submitting information to us, you consent to the collection, use, and disclosure of your information as described in this Privacy Policy. If you do not agree, please do not use the Service.
3. Information We Collect
We collect only the information needed to operate the Service:
- Account information. Your email address, used for passwordless sign-in (one-time codes and magic links). We do not require or store passwords.
- Transaction and wallet data. Your wallet balance, deposits, charges, refunds, and ledger history.
- Service activity. The phone numbers you rent, the services you request codes for, verification and rental status, and the verification codes delivered to your numbers.
- Payment information. Deposits are made in cryptocurrency, processed on-chain by our payment processor and identified by deposit address and transaction hash. We never collect or store card or bank details.
- API credentials. API keys you generate, which are stored only as hashed values.
- Communications. Information you provide when you contact support.
4. Log Files and Automatically Collected Data
Like most online services, we automatically collect certain information when you use the Service. This may include your IP address, browser type and version, device and operating system information, referring pages, the pages and API endpoints you access, request timestamps, and diagnostic data. We use log files to operate and secure the Service, detect and prevent fraud and abuse, debug problems, and understand usage. We do not use this data to personally identify you beyond what is necessary for security, legal compliance, and operation.
5. Cookies and Local Storage
We use cookies and browser local storage that are strictly necessary to provide the Service — for example, to keep you signed in (your session token) and to remember your preferences. We do not use third-party advertising or cross-site tracking cookies. You can disable cookies and local storage in your browser, but parts of the Service (including sign-in) may not function.
6. How We Use Your Information
- To provide, maintain, and operate the Service, including renting numbers and delivering verification codes.
- To process deposits, charges, and refunds, and to maintain your wallet ledger.
- To authenticate you and secure your account.
- To detect, investigate, and prevent fraud, abuse, and prohibited or illegal activity.
- To screen for compliance with sanctions and other applicable legal restrictions.
- To respond to your support requests and send service-related notices.
- To comply with our legal obligations and enforce our Terms of Service.
Where the EU or UK GDPR applies, we rely on the following legal bases: performance of a contract with you (operating your account and delivering the Service); our legitimate interests (securing the Service, preventing fraud and abuse, and improving the product); compliance with a legal obligation (responding to lawful requests, sanctions screening, and record-keeping); and your consent, where we ask for it.
7. How We Share Information
We do not sell or share your personal information for cross-context behavioral advertising. We share information only with service providers that help us operate the Service, and only as needed — including our payment processor, email-delivery provider, and cloud-infrastructure providers. These providers are bound to use the information only to provide services to us.
We may also disclose information if required by law, legal process, subpoena, or a valid governmental request, or where we believe in good faith that disclosure is necessary to protect the rights, safety, and property of Fetch SMS, our users, or others, to investigate suspected fraud or violations of our Terms, or to enforce our agreements. We may preserve records when we reasonably anticipate a legal request. Where we are legally permitted to do so, we will make reasonable efforts to notify you of a request for your information before disclosing it.
If we are involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction, subject to this policy.
8. Data Retention
We retain information only as long as necessary for the purposes described in this policy. Our current retention periods are:
- Account records — for the life of the account, then up to 24 months after closure.
- Verification codes and message content — retained only for the life of the verification or rental and a short period afterwards so you can retrieve them, then deleted, typically within 30 days.
- Wallet, transaction, and ledger records — retained as required for financial and tax record-keeping, generally up to 7 years.
- Technical and security logs — a minimum of 180 days, and up to 24 months where needed for an active fraud, abuse, or security investigation.
- Support communications — up to 24 months after a ticket is closed.
- Backups — deleted data may persist in encrypted backups for up to a further 90 days.
You may request deletion of your account, after which we will delete or anonymize your personal information except where we are required or permitted to retain it — for example for legal, tax, security, or abuse-prevention purposes, or to enforce our agreements.
9. International Data Transfers
We operate in the United States, and our service providers may process information in the United States and other countries. If you access the Service from outside the United States, you understand your information will be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction. Where we transfer personal information out of the European Economic Area or the United Kingdom, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses, together with encryption in transit, access controls, and data minimization.
10. Your Privacy Rights
10.1 EEA and UK (GDPR)
If the EU or UK GDPR applies to you, you have the right to access your personal information; to rectify inaccurate information; to request erasure; to restrict or object to processing; to data portability; and to withdraw consent where processing is based on consent. You also have the right to lodge a complaint with your local supervisory authority.
10.2 California (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect, use, and disclose; to request deletion; to request correction; and to be free from discrimination for exercising these rights. We do not sell your personal information, and we do not share it for cross-context behavioral advertising, so no opt-out is required — but you may still submit a request confirming this.
10.3 Making a request
To exercise any of these rights, email [email protected] from the address associated with your account. We will respond within the timeframe required by applicable law, generally within 30 to 45 days. We may need to verify your identity before acting on a request, and we may decline requests where an exception applies. You may use an authorized agent where the law permits.
11. Security
We use technical and organizational measures designed to protect your information, including encryption in transit, hashing of credentials and API keys, and access controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. In the event of a data breach affecting your personal information, we will notify you and any relevant regulator as required by applicable law.
12. Children's Privacy
The Service is not intended for anyone under the age of 18, and we do not knowingly collect information from children. If you believe a child has provided us information, please contact us and we will delete it.
13. Changes to This Privacy Policy
We reserve the right to modify or update this Privacy Policy at any time, in our sole discretion. Changes are effective when posted on this page with an updated "Last updated" date. Your continued use of the Service after changes are posted constitutes your acceptance of the revised Privacy Policy. We encourage you to review this page periodically.
14. Contact Us
Questions about this Privacy Policy, our data practices, or to exercise a privacy right: [email protected]. Abuse reports and legal process: [email protected].