PRODUCTNUMBERSPRICINGDOCSAPILIBRARY
PRODUCTNUMBERSPRICINGDOCSAPILIBRARY
LEGAL LAYER
PrivacyTermsAcceptable UseCompliancePayment & ActivationLawful Use

DATA HANDLING

Privacy Policy.

Last updated: June 24, 2026How Textrovault collects, uses, protects, retains, and deletes service, billing, message, support, compliance, website, and LinkedIn application data.

Scope And Covered Services

This Privacy Policy explains how Textrovault collects, uses, discloses, protects, retains, and deletes personal data and business data in connection with Textrovault public pages, onboarding, waitlist, priority payment, dashboard, support, operator review workflows, inbound SMS services, APIs and webhooks where enabled, transactional email, analytics, compliance operations, and Textrovault-owned business applications such as the Textrovault LinkedIn company-page publishing and analytics application.

Textrovault is built for private, assigned, SIM-native inbound SMS workflows. We do not operate public SMS inboxes, outbound SMS campaigns, voice calling, emergency calling, SIM resale, customer-controlled telecom hardware, pooled verification, account farming, platform evasion, or unauthorized-access services.

This policy applies to visitors, prospects, waitlist applicants, customers, authorized users, operators, support contacts, payment contacts, LinkedIn Page administrators who authorize Textrovault applications, and other individuals whose information is processed in connection with Textrovault.

Additional product terms, acceptable-use rules, lawful-use attestations, processor terms, signed order forms, or data processing agreements may apply to particular accounts, services, integrations, countries, or enterprise arrangements. If a signed agreement conflicts with this public policy, the signed agreement controls to the extent of the conflict for that customer relationship.

Controller, Processor, And Contact Roles

Textrovault is operated by BOUNCEBEAM LTD, a company registered in England and Wales with company number 15714718 and registered office at 128 City Road, London, England, EC1V 2NX, United Kingdom.

For most website, onboarding, billing, support, compliance, security, and Textrovault LinkedIn application activities, Textrovault determines the purposes and means of processing and acts as the controller or business under applicable privacy laws.

For inbound SMS content and related routing data that a customer receives through an assigned Textrovault number, Textrovault may act as a processor, service provider, or operator on behalf of the customer where a written agreement says so. In those cases, the customer is responsible for its own lawful basis, notices, permissions, and instructions for the end users, senders, accounts, workflows, or systems involved.

Textrovault does not knowingly process customer message data for sale, resale, unrelated advertising, public disclosure, or third-party profiling. We process message data to provide, secure, troubleshoot, support, enforce, and document the service.

Data We Collect

  • Account and contact data: name, email address, organization, role, authentication state, account identifiers, support contact details, communication preferences, and account status.
  • Onboarding and review data: intended use, urgency, requested countries, requested number count, desired Textrovault capabilities, LinkedIn profile URL if provided, organization website, role title, compliance notes, internal review status, activation status, waitlist status, and support history.
  • Billing and commercial data: selected plan, payment state, Stripe checkout session, subscription or invoice references, invoice links, payment amount, refunds, chargebacks, tax or billing details when provided by Stripe, renewal history, account credits, and purchase or reservation records.
  • Number and telecom operations data: requested countries, assigned number, SIM status, activation status, modem or carrier route identifiers, inventory state, quarantine state, lifecycle events, country readiness, reliability events, latency data, delivery state, and operational health evidence.
  • Inbound message data after activation: sender, recipient number, timestamp, SMS body, delivery state, message identifiers, read state, routing metadata, webhook or API delivery metadata where enabled, and related audit records.
  • Technical and security data: IP address, device and browser information, session data, request logs, authentication events, audit events, security events, error telemetry, rate-limit data, diagnostic logs, and limited analytics events.
  • Website and product analytics data: page views, referral source, route, campaign parameters, event timestamps, conversion events, anonymized or pseudonymized funnel events, and browser metadata needed to measure website and onboarding performance.
  • Compliance and abuse data: lawful-use attestations, accepted policy versions, investigation notes, enforcement decisions, suspension records, appeals, repeat-abuse indicators, legal request records, and evidence needed to protect customers, carriers, processors, regulators, LinkedIn, and Textrovault.
  • Content and marketing operations data: post drafts, public post text, generated image prompts and image artifacts, source references, editorial review notes, approval records, publish windows, post receipts, public post URLs, and performance classifications for Textrovault-owned marketing channels.
  • LinkedIn application data: LinkedIn organization or Page identifiers, Page administrator authorization state, application scopes granted by an authorized LinkedIn user, access and refresh token metadata, token expiry and revocation state, public company-page post identifiers, post content submitted through the app, media references, scheduled or published state where available, comments or reactions where accessed for community management, aggregate or post-level statistics such as impressions, clicks, likes, comments, shares, engagement, and other fields made available by LinkedIn APIs for Textrovault-owned Page management.

Sources Of Data

  • Directly from you when you visit the site, sign in, submit onboarding details, provide a LinkedIn profile URL, request support, accept policies, join the waitlist, or communicate with Textrovault.
  • From customers, account administrators, teammates, or authorized operators who invite you, identify you as a contact, submit billing or support information, or configure an authorized workflow.
  • From service providers such as Cloudflare, Stripe, AWS SES, identity providers, email providers, analytics tooling, and security or infrastructure systems that help operate Textrovault.
  • From LinkedIn and Microsoft-operated LinkedIn APIs when an authorized LinkedIn user grants Textrovault application access for Textrovault-owned LinkedIn Page publishing, community management, or analytics.
  • From telecom, SIM, carrier, modem, and delivery infrastructure involved in receiving inbound SMS for assigned Textrovault numbers.
  • From public sources, customer instructions, or internal records where needed for compliance review, fraud prevention, support, legal defense, or enforcement of Textrovault policies.

How We Use Data

  • To provide, maintain, secure, troubleshoot, and improve Textrovault public pages, onboarding, waitlist, customer dashboard, support, inbound SMS receipt, API and webhook surfaces where enabled, and operational tooling.
  • To verify contact details, preserve onboarding progress, authenticate users, maintain sessions, send transactional email, and route customers to the correct account, dashboard, or status page.
  • To review requested countries, number demand, SIM capacity, lawful use, activation readiness, abuse risk, carrier risk, processor risk, and support needs.
  • To create Stripe checkout sessions, receive payment status from Stripe, support invoicing and refunds, maintain accounting records, and show invoice or payment details to authorized users.
  • To receive inbound SMS for assigned numbers, display messages to authorized users, route messages through enabled APIs or webhooks, maintain access controls, and preserve operational evidence.
  • To operate the Textrovault LinkedIn company-page application, including drafting, approving, publishing, scheduling where supported, reconciling, reading public or authorized Page content, measuring post performance, and improving Textrovault-owned marketing experiments.
  • To protect accounts, numbers, SIMs, dashboards, messages, APIs, webhooks, payment flows, infrastructure, and LinkedIn application access from misuse, unauthorized access, fraud, spam, scraping, platform evasion, and security incidents.
  • To enforce Terms, Acceptable Use, lawful-use attestations, compliance policies, support rules, payment terms, and contractual obligations.
  • To measure acquisition, onboarding conversion, product reliability, message latency, content performance, and website effectiveness without intentionally placing SMS bodies, payment secrets, raw card data, or sensitive message contents in analytics events.
  • To comply with law, respond to valid legal process, preserve or defend legal claims, cooperate with processors and platforms, maintain audit trails, and satisfy accounting, tax, security, and regulatory obligations.

Legal Bases Where Required

Where laws such as the GDPR or UK GDPR require a legal basis, Textrovault relies on one or more of the following bases depending on the context: performance of a contract or pre-contractual steps; legitimate interests in operating, securing, improving, and enforcing Textrovault; consent where required for particular communications, cookies, or application permissions; compliance with legal obligations; and protection of vital, public, legal, or safety interests where applicable.

When an authorized LinkedIn Page administrator connects a Textrovault application to LinkedIn, Textrovault processes LinkedIn application data based on that authorization, Textrovault's legitimate interest in managing its own company-page presence, and any applicable contract or platform terms. The LinkedIn user can revoke application authorization through LinkedIn settings or by contacting Textrovault where revocation assistance is available.

Customers are responsible for establishing any required lawful basis, consent, authorization, notice, or contractual permission for their own use of Textrovault numbers, inbound SMS workflows, account access, and webhook destinations.

Sharing, Processors, And Third Parties

Textrovault shares data only as needed to operate, secure, provide, support, analyze, bill for, enforce, and improve the service; comply with law; protect users, carriers, processors, platforms, and Textrovault; complete business transactions; or follow customer instructions.

Current operational processors and recipients may include Cloudflare for hosting, D1, R2, Workers, security, and network services; Stripe for checkout, subscriptions, invoices, payment records, fraud controls, and billing data; AWS SES or other email providers for transactional email; LinkedIn and Microsoft-operated LinkedIn APIs for Textrovault-owned company-page publishing, community management, and analytics; identity providers where a user chooses to authenticate through them; analytics providers for limited website and product analytics; and professional advisers, auditors, insurers, or legal service providers where needed.

Stripe payment card details are handled by Stripe. Textrovault stores Stripe references and invoice/payment state, not raw card numbers.

Textrovault does not sell customer SMS content, LinkedIn API data, payment data, or account data. We do not rent, lease, or disclose LinkedIn API data to data brokers, lead-generation vendors, unrelated advertising networks, or third parties for independent profiling.

If Textrovault is involved in a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar transaction, relevant data may be transferred subject to appropriate confidentiality, security, and continuity protections.

LinkedIn Application Data

Textrovault may operate a LinkedIn developer application to manage the Textrovault LinkedIn company profile, publish or schedule Textrovault-owned company posts, read public or authorized company-page content, moderate or respond to community interactions where enabled, and analyze the performance of Textrovault-owned posts.

The LinkedIn application is intended for Textrovault's own company-page operations. It is not intended to collect private member messages, scrape LinkedIn, build unauthorized profiles, sell LinkedIn data, make eligibility decisions about individuals, or automate activity outside the permissions, documentation, and terms approved by LinkedIn.

When LinkedIn API access is used, Textrovault processes LinkedIn data only for permitted Textrovault business purposes, stores only what is reasonably needed for publishing, analytics, audit, security, debugging, compliance, and improvement, and honors applicable LinkedIn API terms, Marketing API terms, data storage requirements, and deletion requirements.

Textrovault protects LinkedIn access tokens and secrets as confidential credentials. We do not intentionally expose them in client-side code, public repositories, public logs, analytics events, screenshots, support tickets, or documentation.

If LinkedIn application access is revoked, expires, is rejected, or becomes unnecessary, Textrovault will stop using the affected token and will delete or de-identify retained LinkedIn API data when required by LinkedIn terms, applicable law, or a valid deletion request, unless retention is required for security, audit, legal, or compliance reasons.

SMS Content And Sensitive Data

Inbound SMS content may include sensitive information depending on the sender and customer workflow. Textrovault does not ask customers to use Textrovault for unauthorized account access, public inboxes, account farming, platform evasion, spam, impersonation, surveillance, or unlawful activities.

Customers should avoid sending unnecessary sensitive personal data, protected health information, financial account data, government identifiers, passwords, payment card data, or unrelated confidential information through Textrovault unless a signed agreement expressly covers that use and the customer has completed its own legal, security, and privacy review.

Textrovault may use filtering, redaction, access controls, audit logs, role restrictions, webhook controls, retention limits, and abuse monitoring to reduce unnecessary exposure of message content. We do not intentionally place SMS content, OTPs, payment secrets, or sensitive message bodies into website analytics or general marketing analytics.

Cookies, Sessions, And Analytics

Textrovault uses necessary cookies, local storage, session identifiers, and similar technologies to operate authentication, routing, security, preference, dashboard, waitlist, checkout, and support features.

Textrovault may use limited analytics events to understand site traffic, onboarding conversion, campaign attribution, product reliability, and public content performance. Analytics should be configured to avoid SMS bodies, raw payment details, authentication secrets, and sensitive message content.

Browser or device controls may allow users to block or delete cookies. Blocking necessary cookies may prevent sign-in, checkout, waitlist, dashboard, or security features from working correctly.

Retention

  • Inbound SMS content: 30 days by default unless a product setting, retention control, customer instruction, legal hold, abuse investigation, or written agreement specifies a different period.
  • Message metadata, routing metadata, delivery state, access logs, and number lifecycle records: up to 12 months by default, unless longer retention is needed for security, reliability, accounting, legal, carrier, compliance, or abuse-prevention reasons.
  • Account, onboarding, support, dashboard, API, webhook, and operational records: for the life of the account plus a reasonable period needed for support, audit, security, and legal purposes.
  • Billing, invoice, tax, accounting, subscription, refund, chargeback, and payment records: up to 7 years where needed for accounting, tax, fraud prevention, chargebacks, audits, and legal obligations.
  • Compliance, abuse, suspension, enforcement, legal request, and investigation records: up to 6 years after account closure, or longer if needed for legal claims, regulatory requests, safety, platform integrity, carrier requirements, processor requirements, or repeat-abuse prevention.
  • LinkedIn application tokens: until revoked, expired, rotated, replaced, no longer needed, or required to be deleted by LinkedIn terms or applicable law. Token metadata and security logs may be retained longer for audit and security purposes.
  • LinkedIn post, publishing, scheduling, approval, artifact, and performance analytics records for Textrovault-owned company-page operations: up to 36 months by default, or longer in aggregated, de-identified, legal, audit, security, or business-record form.
  • Website and product analytics: up to 24 months by default unless aggregated, anonymized, required for security, or retained under a different configured analytics period.
  • Backups are retained on a rolling basis and deleted, overwritten, or archived according to backup schedules. Deleted data may persist in backups for a limited period until normal backup rotation completes.

Security Measures

  • Keep per-customer inbox access isolated through account, session, and authorization controls.
  • Use TLS in transit and encryption at rest where supported by the hosting, database, object storage, payment, or email layer.
  • Restrict production, dashboard, database, credential, and LinkedIn application access to authorized personnel, systems, and service providers with a legitimate need.
  • Protect API keys, webhook secrets, OAuth secrets, LinkedIn tokens, Stripe references, Cloudflare credentials, and similar secrets from public exposure.
  • Use audit logs, operational evidence, rate limits, redaction, monitoring, incident review, and access controls to detect and reduce misuse.
  • Do not place SMS content, OTPs, message bodies, secrets, raw card data, or sensitive account data in analytics events, URL query strings, client-side tracking events, or public artifacts.
  • Redact OTP-like strings, secrets, and unnecessary personal data in internal logs where feasible.
  • Do not market privacy in a way that implies concealment from lawful process, carrier rules, processor rules, platform terms, or compliance obligations.

International Processing And Transfers

Textrovault may process data in the United States, the United Kingdom, the European Economic Area, and other locations where Textrovault, its infrastructure providers, processors, support providers, payment providers, email providers, or platform providers operate.

Where required, Textrovault relies on appropriate transfer mechanisms such as adequacy decisions, standard contractual clauses, data processing terms, contractual safeguards, or another lawful transfer mechanism. Customers are responsible for assessing their own international transfer obligations for workflows and senders they control.

Privacy Rights And Choices

Depending on location and relationship to Textrovault, individuals may have rights to request access, confirmation, correction, deletion, portability, restriction, objection, withdrawal of consent, appeal of a privacy decision, or information about categories of data collected, used, disclosed, or shared.

California and other U.S. state privacy laws may provide rights to know, access, correct, delete, obtain a portable copy, opt out of sale or sharing, limit certain sensitive personal information uses, and avoid discrimination for exercising privacy rights. Textrovault does not sell personal data as that term is commonly understood. If a future activity requires an opt-out right, Textrovault will provide the required notice and control.

European, UK, Swiss, and similar privacy laws may provide rights to lodge a complaint with a supervisory authority. We encourage individuals to contact Textrovault first so we can try to resolve the issue promptly.

If Textrovault processes data as a processor or service provider for a customer, we may refer the request to that customer or require the requester to contact the customer directly. We will support customer-directed deletion, export, or correction requests as required by contract and law.

Requests can be sent to contact@textrovault.com. Textrovault may need to verify identity, authority, account relationship, or request scope before acting. We may decline or limit requests where allowed by law, including where retention is required for legal, security, accounting, abuse-prevention, carrier, processor, platform, or operational reasons.

Deletion, Revocation, And Offboarding

Users may request deletion of eligible account, onboarding, support, and LinkedIn application data by contacting Textrovault. Authorized LinkedIn users may also revoke application permissions through LinkedIn account or application settings where LinkedIn provides that control.

When an account is closed or application authorization is revoked, Textrovault will stop using inactive credentials and will delete, de-identify, aggregate, or isolate data according to this policy, applicable law, platform terms, signed agreements, and legitimate retention needs.

Deletion is not immediate for all systems. Backups, audit logs, payment records, security logs, legal holds, abuse-prevention records, carrier or processor records, and compliance records may follow separate retention schedules.

Automated Processing

Textrovault may use automated checks, rules, scoring, or monitoring to classify onboarding risk, detect abuse, route support, prioritize reliability work, identify duplicate content, evaluate marketing experiments, or protect the service.

Textrovault does not intend to use LinkedIn API data, SMS content, or website analytics to make automated decisions that produce legal or similarly significant effects about individuals without appropriate human review or a lawful basis.

Children

Textrovault is a business and operational infrastructure service. It is not directed to children, and we do not knowingly collect personal data from children under 16. If we learn that a child has provided personal data without appropriate authorization, we will take reasonable steps to delete it.

Changes To This Policy

Textrovault may update this Privacy Policy to reflect changes in products, legal requirements, platform terms, processors, data practices, or security controls. The updated policy will be posted at this URL with a new last-updated date.

Where required by law or contract, Textrovault will provide additional notice or obtain consent for material changes. Continued use of Textrovault after an updated policy becomes effective means the updated policy applies to future use, subject to applicable law.

Contact

Textrovault is operated by BOUNCEBEAM LTD, company number 15714718, with registered office at 128 City Road, London, England, EC1V 2NX, United Kingdom.

For privacy, compliance, billing, activation, or support questions, contact Textrovault at contact@textrovault.com.

Dedicated SIM-native inbound SMS infrastructure for private, accountable workflows.

contact@textrovault.com
PRODUCTNUMBERSPRICINGDOCSAPILIBRARY
PrivacyTermsAcceptable UseCompliancePayment & ActivationLawful Use
Inbound SMS onlySingle-tenant numbersCompliance-first review
Request access