Privacy Notice
Last updated 2026-06-13
This notice describes how MarioSMS collects, uses, and protects your personal data when you use our website and services. Read it together with our Terms of Service and our Acceptable Use Policy.
Who we are (the data controller)
MarioSMS is operated by Mario Digital Services Limited, registered at Unit 1208, 12/F, Tern Centre Tower One, 237 Queen's Road Central, Sheung Wan, Hong Kong, company number 3267810. We are the data controller for the information described below. If you have any question about this notice, contact us at support@mariosms.com.
What we collect
We collect only what we need to deliver the service:
- Account data: email address, password (stored as a hash), preferred language.
- Activation records: the service, country, and timestamp of every number you rent; the SMS code received (so you can retrieve it); the price charged.
- Payment data: on-chain transaction IDs for USDT top-ups, the wallet address you paid from. We do not see or store card numbers.
- Technical data: your IP address, browser user-agent, basic device characteristics, and server-side request logs. Used for security, fraud prevention, and abuse investigation.
- Identity verification data, when required: for service-and-country combinations that require KYC, our identity partner (Veriff) collects a government-issued ID, a selfie, and limited biometric data. We receive a verification result and a level; the underlying images stay with Veriff. Some jurisdictions classify biometric data as a "special category" — Veriff is the controller for that processing, under their own privacy notice.
- Support data: messages you send us, attachments you upload to a support ticket.
Why we use it (purposes and legal bases)
- To provide the service — process activations, deliver SMS codes, manage your balance. Legal basis: performance of a contract with you (GDPR Art. 6(1)(b)).
- To comply with law — sanctions screening, anti-money-laundering checks, tax-record retention, response to lawful authority requests. Legal basis: legal obligation (Art. 6(1)(c)).
- To prevent fraud and abuse — rate-limiting, suspicious-activity detection, account-takeover protection. Legal basis: our legitimate interests (Art. 6(1)(f)) in keeping the service safe.
- To improve the service — aggregate, non-identifying analytics on which services and countries are popular. Legal basis: legitimate interests.
- To verify identity where required — handled by Veriff under their own legal basis (typically compliance with applicable AML/KYC rules).
Who we share it with
We share data only with processors who need it to make the service work:
- Number suppliers — to allocate phone numbers and route SMS codes back to your activation.
- Payment processors (Passimpay; previously Cryptomus) — to settle USDT top-ups.
- Identity verification partner (Veriff) — only when KYC is required for your activation.
- Cloud hosting and infrastructure — our Kubernetes clusters and MongoDB instances run in EU data centres.
- Email delivery — verification and password-reset emails.
- Law enforcement — only in response to lawful, properly served requests, and only to the minimum extent legally required.
We do not sell your data, share it for advertising, or transfer it to advertising networks.
International transfers
Our infrastructure is in the European Union. Some processors (e.g. Veriff in Estonia) are also in the EU. Where data must move outside the EU/EEA — for example, supplier networks for SMS delivery — we use the European Commission's Standard Contractual Clauses or rely on an adequacy decision.
How long we keep it
- Account data: while your account is active, plus 90 days after deletion to handle late-arriving support or legal requests.
- Activation and transaction records: retained for the period required by tax and accounting law in our jurisdiction (typically 7 years).
- Support tickets: 2 years.
- Server-side request logs (IPs, user-agents): 30 days for live analysis, then aggregated.
- Veriff identity data: retained per Veriff's own policy.
Your rights
If you are in the EU, UK, or another GDPR-aligned jurisdiction, you have the right to:
- Access the personal data we hold about you.
- Rectify data that is incorrect.
- Erase your data, subject to legal retention obligations.
- Restrict or object to certain processing.
- Receive your data in a portable format.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with the supervisory authority in your country of residence. EU/UK readers can find their authority at edpb.europa.eu or the UK ICO.
To exercise any of these rights, email us at support@mariosms.com from the address on your account. We respond within 30 days.
Cookies and similar technologies
We use only the strictly necessary cookies the application needs to log you in and keep your session active. We do not use third-party tracking, analytics cookies, advertising pixels, or fingerprinting beyond what is needed for fraud detection. Your language and theme preference are stored in your browser's local storage, not in cookies.
Children
MarioSMS is not intended for users under 18. We do not knowingly collect data from minors. If you believe a child has created an account, contact us and we will delete it.
Changes to this notice
We will update this notice as the service or the law changes. Material changes are flagged on your next sign-in and announced on the home page for at least 30 days.