Last updated: 1 July 2026
Privacy Policy
SMSPorta ("we", "us", "our") is committed to protecting your personal data. This policy explains what data we collect, why we collect it, how we store it, and what rights you have under the General Data Protection Regulation (GDPR).
1. Data controller
SMSPorta is a service operated by Triforge LLC. ("we", "us", "our"), the data controller for the personal data you provide when using this service. For data-related enquiries, contact us at info@triforge.net.
2. What data we collect
We collect only the data necessary to operate the service:
- Account data — email address and encrypted password, collected at registration.
- Message content — the body and recipient phone number of SMS messages you send or receive through the gateway. This data is yours; we act as a processor.
- Device data — the name and connection status of Android devices you register as gateways.
- API keys — hashed tokens used to authenticate API requests.
- Billing data — subscription plan and payment status. Card details are handled exclusively by Stripe and never stored on our servers.
- Usage logs — timestamps and delivery status of messages, used for analytics and debugging.
- Support communications — messages you send through the in-app support channel.
- Shopify order data — if you install SMSPorta from the Shopify App Store, we process the customer's phone number and first name from order and fulfillment webhooks, solely to send the order-notification SMS you've configured. We do not receive or store the customer's email, address, or payment details.
3. Legal basis for processing
- Contract performance (Art. 6(1)(b) GDPR) — account data, message data, device data, and usage logs are processed to deliver the service you signed up for.
- Legitimate interests (Art. 6(1)(f) GDPR) — security monitoring and abuse prevention.
- Legal obligation (Art. 6(1)(c) GDPR) — billing records retained as required by applicable tax law.
4. How we store and protect your data
- All servers are located in the EU (Frankfurt and Amsterdam). No data is replicated to infrastructure outside the EU.
- Message bodies are encrypted at rest using AES-256 with rotating keys.
- All data in transit is protected by TLS 1.2 or higher.
- API keys are stored as one-way hashes and cannot be recovered by us.
- Passwords are hashed using bcrypt and never stored in plaintext.
- Shopify access tokens are encrypted at rest and are never logged; order phone numbers and message bodies are likewise never written to logs.
5. Data retention
- Message data — retained for 90 days from send date, then permanently deleted.
- Account data — retained for the lifetime of your account. Deleted within 30 days of account closure.
- Billing records — retained for 7 years as required by EU tax law.
- Support messages — retained for 12 months after the ticket is closed.
- Shopify webhook records — retained for 90 days, then permanently deleted. If you uninstall the Shopify app, your shop's data (including the access token) is permanently deleted 30 days after uninstall.
6. Data sharing
We do not sell, rent, or share your personal data with third parties for marketing purposes. We share data only with:
- Stripe — payment processing. Stripe's privacy policy applies to card data.
- Infrastructure providers (Fly.io, Hetzner) — hosting within the EU under data-processing agreements.
- Law enforcement — if required by a valid legal order.
We never read, analyse, or train machine-learning models on your message content.
7. Your rights under GDPR
If you are based in the EU or EEA, you have the following rights:
- Access — request a copy of the data we hold about you.
- Rectification — ask us to correct inaccurate data.
- Erasure — ask us to delete your data ("right to be forgotten").
- Portability — receive your data in a machine-readable format.
- Restriction — ask us to restrict processing in certain circumstances.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, email info@triforge.net. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority.
8. Cookies
We use a single session cookie to keep you logged in. No tracking cookies, advertising cookies, or third-party analytics scripts are loaded on this site.
9. Children
SMSPorta is intended for users aged 18 and over. We do not knowingly collect data from anyone under 18.
10. Changes to this policy
If we make material changes, we will notify registered users by email at least 14 days before the change takes effect. The "Last updated" date at the top of this page will always reflect the current version.
11. Contact
For any privacy questions, data requests, or complaints:
info@triforge.net