Privacy Policy

How SMS pe SMS collects, uses, shares and protects personal data, and the choices you have.

Last updated: 7 October 2026

Effective date: 7 October 2026.

Deshana IT, a unit of Deshana Enterprises Pvt. Ltd., with its registered office at Jaipur, Rajasthan, India, operates SMS pe SMS (“SMS pe SMS”, “we”, “us”, “our”). We respect your privacy. This Privacy Policy explains what personal data we collect, why we collect it, how we use, share and protect it, and the choices and rights you have.

It applies to smspesms.com and its pages (the “Website”), our accounts, dashboards and APIs, and our bulk SMS, OTP, voice call, WhatsApp marketing and related services (the “Services”). It is issued under the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023 and the rules made under it, to the extent each is in force and applicable.

By using the Website or Services, or by giving us your information, you agree to this Privacy Policy. If you do not agree, please do not use them.

1. Who is responsible for your data

We act in two different roles:

  • As data fiduciary (controller) for personal data about our own website visitors, prospects, customers and their authorised users, such as contact details, KYC and billing information, and how our Website and dashboard are used.
  • As data processor for personal data of message recipients (“End Recipients”) that our business customers upload or send through the Services, such as phone numbers, names and message content. Here the customer decides why and how the data is used and is the data fiduciary. We process it only on the customer’s instructions. If you are an End Recipient and have a question about a message or call you received, please contact the business that sent it. If you contact us, we will help route your request.

2. Information we collect

Information you give us:

  • Enquiries and trial requests: your name, business name, email address, phone number, the service you are interested in, expected message volume and anything you write to us. Where a form asks for it, we keep a record of the consent you gave (the wording you agreed to and when).
  • Account and onboarding (KYC): business legal name, brand name, address, incorporation details, PAN, GSTIN, the authorised signatory’s name, designation, contact details, ID and address proof, and DLT entity, sender ID and template details.
  • Billing: billing name and address, GST details, invoice history and payment status. We receive bank-transfer references; we do not store card or bank-login details.
  • Support and communications: emails, chats and calls with our team (including recordings, where we tell you) and feedback you send us.

3. Information from your use of the Services

  • Messaging data: recipient numbers, sender IDs, template IDs, campaign names, message content, timestamps, delivery status and error codes, and opt-in and opt-out records.
  • Account and API data: user IDs, roles, API keys (stored securely), IP addresses, whitelisted IPs, login and activity logs and settings.
  • Voice data: called and calling numbers, call duration and outcome, keypad replies and, if the customer turns it on, call recordings.
  • Device and log data from the Website: IP address, browser type and version, operating system, device type, pages viewed, time spent and approximate location from the IP address. Optional analytics and marketing cookies are used only if you accept them (see our Cookie Policy).
  • Information from other sources: telecom operators, DLT platforms and other providers (for example delivery status and template approvals), public business directories, and referrals from partners, where lawful.

4. Sensitive data

We do not intentionally ask for sensitive personal data (such as health, biometric or financial account credentials), except what is needed for KYC and legal compliance. Customers should not put such data in message content unless it is essential to their lawful use case and they have every consent required.

5. How we use your information

  • Provide the Services: creating accounts, sending and routing messages and calls, producing delivery reports and supporting integrations.
  • Onboarding and compliance: KYC checks, DLT registration, and checking sender ID and template compliance.
  • Communicate with you: answering enquiries, sending quotes and trial details, service notices, security alerts and invoices.
  • Billing and payments: invoicing, confirming payments, tax compliance and fraud prevention.
  • Security and fraud prevention: detecting spam, phishing, abuse, unauthorised access and breaches of our Terms.
  • Improve the Website and Services: analytics (if you accept it), debugging, performance monitoring and product development.
  • Marketing: product updates and offers, where you agreed or the law allows, with an easy way to opt out in every message.
  • Legal obligations: answering lawful requests from regulators, courts and law enforcement, and keeping records the telecom and tax laws require.

6. Basis for processing and consent

We process personal data where you have given consent (for example when you tick a consent box and submit a form), where it is necessary to provide the Services you asked for, to comply with a legal obligation, or for other legitimate uses the law permits, such as security and fraud prevention. Where we rely on your consent, you can withdraw it at any time by contacting us. This does not affect processing done before you withdrew, and we may then be unable to provide some Services.

7. How we share information

We do not sell your personal data. We share it only as described here, and only as needed:

  • Telecom operators and network partners (SMS and voice carriers, aggregators, DLT platforms), to route and deliver messages and calls and meet regulatory requirements.
  • Meta, for WhatsApp Business onboarding, template approvals and message delivery.
  • Service providers who work for us: hosting and storage, email delivery, analytics, customer support tools, banks and payment services, KYC verification, and advisers such as auditors and lawyers. They are bound by confidentiality and data protection duties.
  • Group companies: Deshana IT and Deshana Enterprises Pvt. Ltd., for shared services and support.
  • Legal and regulatory disclosure: where required by law, a court order or a government or regulatory authority, or to protect our rights, property or safety or those of others, or to enforce our Terms.
  • Business transfers: in connection with a merger, acquisition, restructuring or sale of assets, with your data still protected.
  • With your consent or at your direction, for example when you connect a third-party app.

8. Cross-border transfers

Some of our service providers or partners (for example Meta, or global hosting tools) may process data outside India. Where we transfer personal data outside India we do so in line with applicable law and use safeguards such as contract terms. Customers who need data to stay in India should tell us before onboarding so we can discuss the options.

9. How long we keep data

We keep personal data only as long as needed for the purposes in this policy or as the law requires. Typical periods:

  • Website enquiry and trial-request data: [12 months] from the enquiry, then deleted.
  • Account, KYC and contract records: the length of the relationship plus 8 years (tax and company law).
  • Message content: [90 days] from sending, unless the customer chooses a different period or the law requires longer.
  • Delivery reports, logs and consent and opt-out records: at least as long as TRAI and other telecom rules require, and up to [12 months] otherwise.
  • Call recordings (if turned on): [90 days] or as the customer sets.
  • Billing records and invoices: 8 years.
  • Marketing opt-outs: kept so that you are not contacted again, until you ask us to remove them.

10. Security

We use reasonable technical and organisational measures to protect personal data, including encryption in transit, access controls and role-based permissions, IP whitelisting for API access, secure storage of credentials, network monitoring and periodic reviews. Access to personal data is limited to people who need it and who are bound by confidentiality.

No method of transmission or storage is completely secure. If a personal data breach happens, we will tell affected people and the authorities as the law requires. Please keep your passwords and API keys confidential and tell us at once if you suspect someone has got in without permission.

11. Your rights

Subject to applicable law, you may have the right to:

  • Access a summary of the personal data we hold about you and how it is processed.
  • Have inaccurate or incomplete data corrected or updated.
  • Have personal data erased when it is no longer needed or you withdrew consent (subject to legal retention rules).
  • Withdraw consent at any time.
  • Seek redress through our Grievance Officer (see the last section) and, if not resolved, through the Data Protection Board of India once it is operating.
  • Nominate another person to use your rights if you die or become unable to.

12. How to use your rights

Email us from the address linked to your account or enquiry (contact details are in the last section). We may ask for information to confirm who you are. We aim to reply within 30 days, or sooner if the law requires.

End Recipients: if one of our customers uploaded your data, please contact that business directly, because it decides how your data is used. You can also reply “STOP” (or follow the instructions in the message) to opt out, or register your preferences with your telecom provider’s DND service.

13. Marketing messages

We send marketing messages only where you opted in or the law permits. Each one includes a way to opt out, such as an unsubscribe link or a reply keyword. Service notices (for example about security, billing or changes to our Terms) are not marketing and may still be sent.

14. Cookies and tracking

We use only what the site needs to work, plus optional analytics or marketing tools if you accept them. Please see our Cookie Policy for the details and your choices. You can change your choice at any time with the privacy button at the bottom left of every page.

15. Children

The Website and Services are for businesses and are not directed to anyone under 18. We do not knowingly collect personal data of children. If you believe a child has given us data, contact us and we will delete it. Customers must not use the Services to target or track children in breach of applicable law.

16. Third-party websites and services

The Website may link to other sites. Those third parties have their own privacy practices and we are not responsible for them. Please read their policies before sharing data.

17. Changes to this policy

We may update this Privacy Policy from time to time. The “last updated” date at the top shows when it was last revised. For material changes we will give notice through the Website, by email or in your account. Please review this page regularly.

18. Grievance Officer and contact

If you have questions, requests or complaints about this policy or how we handle personal data, please contact:

Grievance Officer and Data Protection Contact: Avinash Upadhyay. Email: avinash@smsdekho.com. Phone: +91 92528 88777. [Owner to confirm these details.]

Postal address: SMS pe SMS, a unit of Deshana IT (Deshana Enterprises Pvt. Ltd.), Jaipur, Rajasthan, India.

General enquiries: sales@smspesms.com, info@smspesms.com, +91 8104 220 220.

We will acknowledge complaints within 48 hours and aim to resolve them within one month of receiving them.