1. Who we are
This Policy explains how Oryn Labs, LLC (“we”), the operator of SMSGo, processes personal data collected through the API, web dashboard, and support channels. Read it together with our Terms of Use and LGPD compliance notice.
2. Data we collect
2.1. Registration and account data
- Name, email, phone number, and company data;
- Access credentials and API tokens;
- Billing data and credit purchase history.
2.2. Service usage data
- Contacts and lists you import into the platform;
- Content and metadata of sent messages (destination numbers, delivery status, and time);
- Access logs, IP address, device, and browser.
2.3. Shopify app data
- Phone number and contact details of your store customers, when provided in an order or cart;
- Limited order and cart information (order number, status, total amount, products, and tracking links) needed to trigger transactional SMS messages;
- Encrypted Shopify OAuth access token and store identifier (
shop_domain).
3. Data-processing roles
For your contacts’ and recipients’ data, you act as the controller and SMSGo acts as the processor, handling that data according to your instructions and solely to provide the Service. For your own account data, SMSGo acts as the controller.
4. Use of Shopify data
When you install the SMSGo app in your Shopify store, we process your end-customer data solely to:
- Send transactional SMS messages requested by you, such as order confirmation, payment approved, order shipped, and abandoned-cart reminders;
- Generate delivery logs, send reports, and message history inside the SMSGo dashboard;
- Keep your store OAuth access token encrypted so we can communicate securely with the Shopify API.
We do not use your store customer data for our own marketing, we do not sell it, and we do not share it with anyone other than the SMS routing providers strictly required to deliver the messages. You remain the controller of your end-customer data; SMSGo acts only as a processor according to your template and trigger settings.
5. How we use data
- Provide, operate, and maintain the Service;
- Process sends, validations, and delivery reports;
- Process payments and manage credits;
- Prevent fraud and abuse and maintain security;
- Meet legal and regulatory obligations;
- Communicate operational and support notices.
6. Legal bases
We process personal data to perform a contract, comply with legal obligations, pursue legitimate interests (Service security and improvement), and, where applicable, based on the data subject’s consent.
7. Sharing
We may share data with:
- Carriers and SMS routing providers, to deliver messages;
- Payment processors (such as Stripe), for billing;
- Cloud infrastructure providers, for hosting;
- Authorities, when required by law or court order.
We do not sell personal data.
8. International transfers
Some infrastructure and providers may be located outside Brazil. In those cases, we adopt appropriate safeguards to ensure a level of protection compatible with Brazilian law.
9. Retention
We retain data for as long as necessary for the purposes described and to comply with legal obligations. Retention periods are:
- Account data: while the account is active plus five years (tax obligation);
- Access logs: 90 days;
- Login attempts: 24 hours;
- Test SMS: 48 hours;
- Send data: while the account is active (anonymized upon deletion);
- Financial records: five years (legal tax obligation).
After account closure, personal data is anonymized unless retention is legally required. Financial records (invoices and transactions) are retained in anonymized form for five years.
10. Security
We use technical and organizational measures — encryption in transit, access controls, and monitoring — to protect data from unauthorized access, loss, or alteration. No system is completely immune; if a material incident occurs, we will provide notice as required by law.
11. Data-subject rights
You and the data subjects whose data is processed may request access, correction, anonymization, portability, deletion, and information about processing. The dashboard provides self-service channels:
- Export data:
My Account > Export data— JSON download; - Delete account:
My Account > Security > Delete account— requires password confirmation; - Manage cookies: consent banner displayed on the first visit.
See full details in our LGPD compliance notice.
12. Cookies
We use essential cookies for authentication and dashboard operation. Optional analytics cookies (Google Analytics) and marketing cookies (Google Tag Manager) are enabled only with consent collected through the banner shown on the first visit.
At any time, you may:
- Accept all optional cookies;
- Reject optional cookies (only essential cookies remain active);
- Choose which categories to enable.
Your preference is stored in a cookie for 365 days. Clear browser cookies to change it. Disabling essential cookies may prevent dashboard use.
13. Changes
This Policy may be updated. Material changes will be communicated through the dashboard or by email, together with the update date.
14. Contact and Data Protection Officer (DPO)
For privacy questions or to exercise your rights, contact our Data Protection Officer at privacidade@SMSGo.io.