SMSRay · Legal
Privacy Policy
What SMSRay processes, why, for how long, who acts as controller, and the rights you have over your data.
- Version
- v1.0
- Effective
- 10 October 2026
- Last updated
- 10 October 2026
- 13 sections · 45 clauses
At a glance
- We process what we need to send your messages and run the portal: your account details, recipient numbers, message text and delivery status.
- OTP codes are never stored in readable form. We keep only a hash, and the OTP text is hidden in logs and the dashboard.
- For your recipients' data, you are the controller and Lacspace is your processor. We do not sell personal data or use message content for advertising.
- OTP codes expire after 5 minutes, webhook delivery history is kept for 7 days, and every portal change is recorded in an audit log.
- Write to privacy@lacspace.com for privacy questions, or grievance@lacspace.com to raise a complaint.
This summary is not legal advice and does not replace the full text below. If the summary and the full text differ, the full text applies.
1.Introduction and scope
SMSRay is a product of Lacspace Corporation Pvt. Ltd. ("Lacspace", "we", "us" or "our"), a company registered in India (CIN U46511DL2025PTC079972, RoC-Delhi) and registered in Nepal (Reg. No. 377566/82/83, PAN 622468837).
This Privacy Policy explains how we process personal data when you visit smsray.in, use the portal at app.smsray.in or send messages through the SMSRay API (the "Service"). It works alongside our Terms of Service, Cookie Policy and Data Processing Addendum.
2.Our role: controller and processor
- Customer data about recipients. When you send messages, you decide who receives them and what they say. For recipient numbers, message content and related delivery data, you are the controller and Lacspace acts as your processor, processing that data only on your instructions as set out in the Data Processing Addendum.
- Account, billing and website data. For data about you as our customer (your account, workspace, billing and use of our website and portal), Lacspace is the controller.
If you received a message sent through SMSRay and have a question about it, please contact the business that sent it. We can help route your request where appropriate.
3.Data we process
- Account data: your name, phone number and/or email address used for sign-in, workspace name and role, and the people you invite.
- Recipient numbers: the mobile numbers you send messages to and receive replies from.
- Message content: the text of messages you send and of inbound replies sent to our pool numbers. For OTP messages, the code itself is not stored in readable form (see below).
- Delivery metadata: message IDs, timestamps, segment counts, encoding, status changes (such as queued, sent, delivered or failed), which network and SIM handled a message, delivery receipts and webhook delivery attempts.
- Device and SIM telemetry from our own pool phones: health signals from the Android phones and SIM cards Lacspace owns and operates, such as battery, signal, connectivity, app state and send results. This telemetry is about our equipment, not about your recipients' devices.
- Technical and security data: IP addresses and user agents for portal sign-ins and API requests, session records, and the end-user IP address if you choose to pass it with an OTP request for rate limiting.
- Audit data: a record of changes made in the portal, such as API key creation, webhook updates and member changes, with who made them and when.
- Billing data: your workspace balance, top-ups and per-message charges and refunds.
4.How we handle OTP codes
When you use the OTP endpoints, SMSRay generates a 6-digit code and sends it to the recipient. We store only a SHA-256 hash of the code, never the code itself, so it cannot be read back from our database.
The text of OTP messages is hidden in message logs and in the dashboard, where it appears as "(OTP hidden)".
A code expires after 5 minutes and allows a limited number of verification attempts. We apply per-number and, where you supply it, per-IP limits to prevent abuse.
5.Why we process data
- To provide the Service: route and send messages, track delivery, refund failed messages, deliver inbound replies and webhooks, and show you your data in the dashboard.
- To secure the Service: authenticate sign-ins, detect and prevent abuse, spam and fraud, enforce rate limits and keep audit records.
- To operate our SIM pool: monitor the health of our phones and SIMs and route around problems.
- To manage your account and billing, provide support and send service notices.
- To meet legal obligations and respond to lawful requests from authorities.
We rely on performance of our contract with you, our legitimate interests in running a secure and reliable service, compliance with legal obligations and, where required, consent.
We do not sell personal data, and we do not use your message content or recipient data for advertising or to build profiles of recipients.
6.Retention
- OTP codes (stored as hashes) expire after 5 minutes and can no longer be verified.
- Webhook delivery history is kept for 7 days.
- Audit logs are kept for as long as your workspace is active and for a reasonable period afterwards to meet security, legal and accounting needs.
- Messages, delivery metadata and account data are kept while your workspace is active so you can view history and reconcile billing. When a workspace is closed, we delete or anonymise this data within a reasonable period, except where we must keep it longer by law (for example, billing records).
- Pool-phone telemetry is kept for as long as needed to operate and improve routing and troubleshoot our equipment.
7.Sharing
We share personal data only as needed to provide the Service:
- with mobile network operators, which carry SMS messages to recipients as part of sending them;
- with service providers who host and operate parts of our infrastructure (cloud hosting, database and email delivery for sign-in codes), under contracts that require them to protect the data;
- with Lacspace affiliates that help operate the Service;
- with authorities where required by law or to protect rights, safety and the integrity of the Service;
- in connection with a merger, acquisition or sale of assets, subject to this Policy.
8.Security
We protect data with measures appropriate to the risk, including encryption in transit, API keys and refresh tokens stored only as hashes, OTP codes stored only as hashes, short-lived access tokens, httpOnly session cookies in the portal, role-based access within workspaces, an audit log of portal changes and signed webhooks.
No system is perfectly secure. If you believe you have found a security issue, contact security@lacspace.com.
9.International processing
Lacspace operates across more than one country, and our service providers may process data in other countries. Where we transfer personal data across borders, we take steps to ensure it remains protected in line with this Policy and applicable law.
10.Your rights
Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent where we rely on it.
To exercise these rights for data where Lacspace is controller, write to privacy@lacspace.com. We may need to verify your identity before acting.
If you are a recipient of messages sent by one of our customers, please contact that business first, since it controls your data. If you contact us, we will forward your request to the customer where we can identify it.
You can also complain to a data protection authority in your country.
11.Children
The portal and API are for businesses and are not directed to children. We do not knowingly collect personal data from children for our own purposes.
12.Changes to this policy
We may update this Policy. The version and effective date at the top show when it last changed. For material changes we will give notice in the portal or by email.
13.Contact and grievance
Privacy questions and rights requests: privacy@lacspace.com.
Complaints and grievances, including under India's data protection and IT laws: grievance@lacspace.com. We aim to acknowledge grievances promptly and resolve them within the time required by law.
Contact and grievance
Lacspace Corporation Pvt. Ltd., registered in India (CIN U46511DL2025PTC079972, RoC-Delhi), and registered in Nepal (Reg. No. 377566/82/83, PAN 622468837).
- Legal questions
- legal@lacspace.com
- Privacy and data requests
- privacy@lacspace.com
- Grievance officer
- grievance@lacspace.com
- Report abuse or spam
- abuse@lacspace.com