Privacy Policy
Last updated: August 2026 · Effective for visitors in the European Economic Area (EEA), the UK and Switzerland under the GDPR
1. Who We Are (Data Controller)
Koipabo operates the SMS gateway platform at koipabo.com. We are the data controller for the personal data described in this policy — the data you provide when you create an account and use the platform.
For any privacy question, data-subject request, or to reach our data-protection contact, write to: [email protected]. We respond to verified requests within 30 days.
2. What Data We Collect
- Account data — name, email address, role (customer, reseller, supplier), and a hashed password. Google SSO accounts store the Google subject ID; we never receive or store your Google password.
- Service data — SMS recipients and message content you send through the platform, your devices (names, models, SIM slots, countries), API keys (stored hashed), webhook URLs, and message delivery status.
- Financial data — payment records (amount, date, provider reference, card country/fingerprint), payout details for suppliers, and crypto/bank payout methods you register. We never store full card numbers — card payments are handled entirely by Stripe.
- Technical data — IP address (used for security, rate limiting and fraud checks), approximate country derived from your IP, and request logs.
We do not buy data from third parties, and we do not sell or rent personal data to anyone.
3. Why We Process Data (Legal Bases)
We process personal data on the following legal bases under Article 6 GDPR:
- Performance of a contract (Art. 6(1)(b)) — creating and managing your account, delivering SMS through the platform, processing payments, and providing customer support.
- Legal obligation (Art. 6(1)(c)) — keeping payment/invoice records required by tax law, and complying with lawful requests from authorities.
- Legitimate interest (Art. 6(1)(f)) — securing the platform (fraud prevention, rate limiting, blocking abusive traffic), diagnosing faults, and improving the service. We weigh these interests against your rights and never use this basis for marketing.
- Consent (Art. 6(1)(a)) — only where we ask for it explicitly (for example, coverage notifications). You can withdraw consent at any time.
5. Who We Share Data With (Subprocessors)
We share personal data only with the service providers needed to run the platform, under written data-processing agreements, and only to the extent necessary:
- OVH — server hosting. Our servers and database are hosted in the EU.
- Cloudflare — CDN, DDoS protection and proxying. Processes minimal technical data (IP address) under Cloudflare's GDPR terms.
- Stripe — card payment processing. Handles your card data directly; we never see full card numbers.
- Resend — transactional email delivery (verification codes, password resets, notifications).
- Google — only when you choose "Sign in with Google": Google authenticates you and shares your name, email and subject ID with us.
We never share your data with advertisers, data brokers, or any other third party for their own purposes.
6. International Transfers
Our primary servers and database are located in the European Union (OVH), so your data stays in the EEA. Where a subprocessor operates outside the EEA (for example, Cloudflare's edge network), we rely on the European Commission's adequacy decisions and/or Standard Contractual Clauses, together with any supplementary safeguards required, to keep your data protected to GDPR standards.
7. Data Retention
- Message data (recipients and content) is retained for 30 days, after which it is deleted.
- Account data is kept while your account is active. When you delete your account (see section 8), your personal data is erased promptly.
- Payment records are kept as long as required by applicable tax law (invoices must be retained), and are not erased on account deletion where the law requires their retention.
- Support tickets and notifications are kept while relevant and deleted with your account.
8. Your Rights
Under the GDPR you have the right to:
- Access (Art. 15) — get a copy of the personal data we hold about you.
- Rectification (Art. 16) — correct inaccurate or incomplete data.
- Erasure (Art. 17) — ask us to delete your data.
- Restriction (Art. 18) — limit how we process your data in certain situations.
- Data portability (Art. 20) — receive your data in a machine-readable format.
- Objection (Art. 21) — object to processing based on legitimate interest.
- Withdraw consent at any time where processing is based on consent.
Most rights are available instantly in your account:
- Export your data (JSON, incl. profile, messages, payments, devices) — Dashboard → Settings → Data & Privacy → Export my data.
- Delete your account — Dashboard → Settings → Data & Privacy → Delete account. This erases your account and associated data promptly.
You also have the right to lodge a complaint with your local supervisory authority (for example, the Swedish IMY, the Dutch AP, or the authority of the country you live in). Please contact us first — we will always try to resolve any concern.
9. Our Role vs. Yours (Controller & Processor)
When you send SMS to your own recipients (for example, OTP codes to your app users), you are the data controller of those recipients' phone numbers and message content, and we act as your data processor under Article 28 GDPR. We process that content only to deliver your messages and never for our own purposes. It is your responsibility to have a lawful basis for messaging your recipients and to comply with applicable messaging laws (GDPR, PECR/ePrivacy, local SMS rules). Our Terms of Service reflect this division of roles.
10. Security
We protect personal data with industry-standard measures: HTTPS everywhere, passwords stored as bcrypt hashes, API keys stored as SHA-256 hashes, AES-256 encryption for stored secrets, database isolation per tenant, rate limiting, and security headers (CSP, HSTS, frame protection). Access to production data is limited and monitored.
11. Children
The service is not directed at children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
12. Changes to This Policy
We may update this policy as the service evolves. Material changes will be announced on the site and, where required, by email. The "Last updated" date at the top reflects the current version.
13. Contact
Privacy questions, data-subject requests, or DPA requests: [email protected]. We aim to answer within 30 days.