SMSRay · Legal · Privacy & data
Privacy Policy
What SMSRay processes, why, for how long, who acts as controller, and the rights you have over your data.
- Version v1.1
- Effective 10 October 2026
- Updated 10 October 2026
- 13 sections · 43 clauses
- 5 min read
At a glance
Plain language- We process what we need to send your messages and run the portal: your account details, recipient numbers, message text and delivery status.
- OTP codes are never stored in readable form. We keep only a hash, and the OTP text is hidden in logs and the dashboard.
- For your recipients' data, you are the controller and Lacspace is your processor. We do not sell personal data or use message content for advertising.
- OTP codes expire after 5 minutes, webhook delivery history is kept for 7 days, and every portal change is recorded in an audit log.
- Write to privacy@lacspace.com for privacy questions, or grievance@lacspace.com to raise a complaint.
This summary is not legal advice and does not replace the full text below. If the summary and the full text differ, the full text applies.
1.Introduction and scope
SMSRay is a product of Lacspace Corporation Pvt. Ltd. ("Lacspace", "we", "us" or "our"), a company registered in India (CIN U46511DL2025PTC079972, RoC-Delhi) and registered in Nepal (Reg. No. 377566/82/83, PAN 622468837).
This Privacy Policy explains how we process personal data when you visit smsray.com, use the portal at app.smsray.com or send messages through the SMSRay API (the "Service"). It works alongside our Terms of Service, Cookie Policy and Data Processing Addendum.
2.Our role: controller and processor
- Customer data about recipients. When you send messages, you decide who receives them and what they say. For recipient numbers, message content and related delivery data, you are the controller and Lacspace acts as your processor, processing that data only on your instructions as set out in the Data Processing Addendum.
- Account, billing and website data. For data about you as our customer (your account, workspace, billing and use of our website and portal), Lacspace is the controller.
If you received a message sent through SMSRay and have a question about it, please contact the business that sent it. We can help direct your request where appropriate.
3.Data we process
- Account data: your name, business details, phone number and/or email address used for sign-in, workspace name and role, the people you invite, and the information you share with our sales team when we set up your workspace.
- Recipient numbers: the mobile numbers you send messages to and receive replies from.
- Message content and templates: the text of messages you send, the templates you submit for approval and our review decisions, and the text of replies recipients send to your messages. For OTP messages, the code itself is not stored in readable form (see below).
- Delivery metadata: message IDs, timestamps, SMS counts, encoding, status changes (such as queued, sent, delivered or failed), the mobile network a message was sent on, routing and retry records, delivery receipts and webhook delivery attempts.
- Technical and security data: IP addresses, browser and session details (such as user agents) for portal sign-ins and API requests, session records, and the end-user IP address if you choose to pass it with an OTP request for rate limiting.
- Audit data: a record of changes made in the portal, such as API key creation, webhook updates and member changes, with who made them and when.
- Plan and billing data: your plan, monthly allowance and usage, top-ups, credits for failed messages and payment records.
4.How we handle OTP codes
When you use the OTP endpoints, SMSRay generates a 6-digit code and sends it to the recipient. We store only a SHA-256 hash of the code, never the code itself, so it cannot be read back from our database.
The text of OTP messages is hidden in message logs and in the dashboard, where it appears as "(OTP hidden)".
A code expires after 5 minutes and allows a limited number of verification attempts. We apply per-number and, where you supply it, per-IP limits to prevent abuse.
5.Why we process data
- To provide the Service: review templates, process and send messages, track delivery, credit failed messages, deliver inbound replies and webhooks, and show you your data in the dashboard.
- To secure the Service: authenticate sign-ins, detect and prevent abuse, spam and fraud, enforce rate limits and keep audit records.
- To operate and improve our delivery infrastructure, including smart routing and automatic retries.
- To set up and manage your account, plan and billing, provide support and send service notices.
- To meet legal obligations and respond to lawful requests from authorities.
We rely on performance of our contract with you, our legitimate interests in running a secure and reliable service, compliance with legal obligations and, where required, consent.
We do not sell personal data, and we do not use your message content or recipient data for advertising or to build profiles of recipients.
6.Retention
- OTP codes (stored as hashes) expire after 5 minutes and can no longer be verified.
- Webhook delivery history is kept for 7 days.
- Audit logs are kept for as long as your workspace is active and for a reasonable period afterwards to meet security, legal and accounting needs.
- Messages, templates, delivery metadata and account data are kept while your workspace is active so you can view history and reconcile usage. When a workspace is closed, we delete or anonymise this data within a reasonable period, except where we must keep it longer by law (for example, billing records).
7.Sharing
We share personal data only as needed to provide the Service:
- with mobile network operators in Nepal, which transmit SMS messages to recipients as part of sending them;
- with service providers who host and operate parts of our infrastructure (cloud hosting, database and email delivery for sign-in codes), under contracts that require them to protect the data;
- with Lacspace affiliates that help operate the Service;
- with authorities where required by law or to protect rights, safety and the integrity of the Service;
- in connection with a merger, acquisition or sale of assets, subject to this Policy.
8.Security
We protect data with measures appropriate to the risk, including encryption in transit, API keys and refresh tokens stored only as hashes, OTP codes stored only as hashes, short-lived access tokens, httpOnly session cookies in the portal, role-based access within workspaces, an audit log of portal changes and signed webhooks.
No system is perfectly secure. If you believe you have found a security issue, contact security@lacspace.com.
9.International processing
Lacspace operates across more than one country, and our service providers may process data in other countries. Where we transfer personal data across borders, we take steps to ensure it remains protected in line with this Policy and applicable law.
10.Your rights
Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent where we rely on it.
To exercise these rights for data where Lacspace is controller, write to privacy@lacspace.com. We may need to verify your identity before acting.
If you are a recipient of messages sent by one of our customers, please contact that business first, since it controls your data. If you contact us, we will forward your request to the customer where we can identify it.
You can also complain to a data protection authority in your country.
11.Children
The portal and API are for businesses and are not directed to children. We do not knowingly collect personal data from children for our own purposes.
12.Changes to this policy
We may update this Policy. The version and effective date at the top show when it last changed. For material changes we will give notice in the portal or by email.
13.Contact and grievance
Privacy questions and rights requests: privacy@lacspace.com.
Complaints and grievances, including under India's data protection and IT laws: grievance@lacspace.com. We aim to acknowledge grievances promptly and resolve them within the time required by law.
Document control
- Document
- Privacy Policy · v1.1
- Effective / updated
- 10 October 2026 / 10 October 2026
- Length
- 13 sections · 43 clauses · about 5 min
- Publisher
- Lacspace Corporation Pvt. Ltd.
The PDF is a watermarked, controlled copy. The authoritative, current version is always the one published on this page. © 2026 Lacspace Corporation Pvt. Ltd..
Contact and grievance
Lacspace Corporation Pvt. Ltd., registered in India (CIN U46511DL2025PTC079972, RoC-Delhi), and registered in Nepal (Reg. No. 377566/82/83, PAN 622468837).
- Legal questions
- legal@lacspace.com
- Privacy and data requests
- privacy@lacspace.com
- Grievance officer
- grievance@lacspace.com
- Report abuse or spam
- abuse@lacspace.com