1. Introduction
10-DLC Registry Platform ("we," "us," or "our") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our 10-DLC Registry Platform (the "Service").
By accessing or using the Service, you consent to the practices described in this Privacy Policy. If you do not agree with this Privacy Policy, please do not use the Service.
Your Privacy Rights
We comply with applicable privacy laws including GDPR (Europe), CCPA (California), and other regional data protection regulations. You have specific rights regarding your personal information as detailed in this policy.
2. Information We Collect
2.1 Information You Provide Directly
We collect information you voluntarily provide when using the Service:
- Account Information: Name, email address, phone number, password, company name, job title
- Brand Information: Business legal name, EIN/Tax ID, business address, business type, industry, website
- Campaign Information: Campaign name, description, sample messages, use case, call-to-action, help keywords
- Business Documents: Articles of incorporation, tax documents, business licenses, compliance documentation
- Payment Information: Billing address, payment method details (processed securely by our payment processor)
- Communications: Support requests, feedback, survey responses, emails, and other communications with us
2.2 Information Collected Automatically
When you access the Service, we automatically collect:
- Device Information: IP address, browser type, operating system, device identifiers
- Usage Data: Pages viewed, features used, time spent, clicks, navigation paths
- Log Data: Access times, error logs, API calls, system events
- Cookies and Tracking: Session cookies, authentication tokens, analytics data
2.3 Information from Third Parties
We may receive information from:
- The Campaign Registry (TCR): Brand vetting results, campaign approval status, compliance scores
- TNID.com: Registration status, modification requests, carrier feedback
- Payment Processors: Payment confirmation, transaction status, billing information
- Identity Verification Services: Business verification results, fraud detection data
- SSO Providers: Profile information from Google, Microsoft, or other SSO providers (when you choose SSO login)
3. How We Use Your Information
We use the collected information for the following purposes:
3.1 Provide and Improve the Service
- Create and manage your account
- Process brand and campaign registrations with TCR and carriers
- Facilitate document uploads and storage
- Provide customer support and respond to inquiries
- Monitor system performance and troubleshoot issues
- Develop new features and improve existing functionality
3.2 Communications
- Send transactional emails (registration confirmations, status updates, receipts)
- Send service notifications (campaign approvals, rejections, modification requests)
- Deliver welcome emails and onboarding content
- Send compliance alerts and deadline reminders
- Provide platform updates and security alerts
- Send marketing communications (with your consent, you may opt out at any time)
3.3 Compliance and Legal Obligations
- Comply with TCPA, CAN-SPAM, GDPR, CCPA, and other applicable laws
- Verify your identity and prevent fraud
- Detect, prevent, and address security threats
- Enforce our Terms of Service and Acceptable Use Policy
- Respond to law enforcement requests and legal process
- Maintain audit logs for regulatory compliance
3.4 Analytics and Business Operations
- Analyze usage patterns and trends
- Measure service performance and effectiveness
- Conduct internal research and development
- Generate aggregate, anonymized statistics
3.5 Payment Processing
- Process payments and manage billing
- Detect and prevent payment fraud
- Issue invoices and receipts
- Handle refunds and disputes (as per our refund policy)
4. How We Share Your Information
We do not sell your personal information. We share your information only as described below:
4.1 Service Providers and Partners
We share information with third parties who perform services on our behalf:
- The Campaign Registry (TCR): Brand and campaign information for 10-DLC registration
- TNID.com: Registration data and API credentials for campaign management
- Cloud Hosting Providers: AWS for infrastructure and data storage
- Payment Processors: Authorize.net and other payment gateways for transaction processing
- Email Service Providers: For delivering transactional and marketing emails
- Analytics Providers: For usage analytics and service improvement
- Security Services: For fraud detection and prevention
These third parties are contractually obligated to protect your information and use it only for the purposes we specify.
4.2 Mobile Carriers
Your brand and campaign information is shared with mobile carriers as part of the 10-DLC registration process. Carriers use this information to evaluate and approve your messaging campaigns.
4.3 Legal Requirements
We may disclose your information if required by law or if we believe in good faith that such disclosure is necessary to:
- Comply with legal obligations, court orders, or government requests
- Enforce our Terms of Service
- Protect our rights, property, or safety, or that of our users or the public
- Detect, prevent, or address fraud, security, or technical issues
4.4 Business Transfers
If we are involved in a merger, acquisition, asset sale, bankruptcy, or other business transaction, your information may be transferred as part of that transaction. We will notify you via email and/or prominent notice on the Service of any such change in ownership.
4.5 With Your Consent
We may share your information with other parties when you explicitly consent to such sharing.
5. Data Security
We implement industry-standard security measures to protect your information from unauthorized access, alteration, disclosure, or destruction:
- AES-256-GCM encryption for sensitive data at rest
- TLS/SSL encryption for data in transit
- Secure authentication with JWT tokens and optional two-factor authentication (2FA)
- Regular security audits and penetration testing
- Access controls and role-based permissions
- Firewall protection and intrusion detection systems
- Secure document storage in encrypted S3 buckets
- Regular data backups and disaster recovery plans
Important Security Notice
While we implement strong security measures, no system is completely secure. You acknowledge that you provide information at your own risk. Please protect your account credentials and enable two-factor authentication for enhanced security.
6. Data Retention
We retain your information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
Retention Periods:
- Account Data: Retained while your account is active and for 3 years after account closure
- Transaction Records: Retained for 7 years for tax and audit purposes
- Communication Logs: Retained for 3 years for compliance and support purposes
- Audit Logs: Retained for 5 years for security and compliance audits
- Marketing Data: Retained until you opt out or request deletion
After the retention period expires, we securely delete or anonymize your information. Some information may be retained in backup systems for a limited time before permanent deletion.
7. Your Privacy Rights
Depending on your location and applicable laws, you may have the following rights regarding your personal information:
7.1 General Rights (All Users)
- Access: Request a copy of your personal information
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your information (subject to legal retention requirements)
- Opt-Out: Unsubscribe from marketing emails (transactional emails will continue)
- Data Portability: Request your data in a machine-readable format
7.2 GDPR Rights (European Users)
If you are in the European Economic Area (EEA), you have additional rights:
- Right to Erasure: Request deletion of your data ("right to be forgotten")
- Right to Restriction: Request limited processing of your data
- Right to Object: Object to processing based on legitimate interests or direct marketing
- Right to Withdraw Consent: Withdraw consent for data processing at any time
- Right to Lodge a Complaint: File a complaint with your local data protection authority
7.3 CCPA Rights (California Residents)
If you are a California resident, you have the right to:
- Know: Request disclosure of information we collect, use, and share
- Delete: Request deletion of your personal information
- Opt-Out of Sale: We do not sell your personal information
- Non-Discrimination: We will not discriminate against you for exercising your rights
7.4 How to Exercise Your Rights
To exercise any of these rights, please contact us at privacy@10-dlc.com or through your account settings. We will respond to your request within 30 days (or as required by applicable law). We may need to verify your identity before processing your request.
8. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience, analyze usage, and provide personalized content.
Types of Cookies We Use:
- Essential Cookies: Required for authentication and core functionality
- Performance Cookies: Collect anonymous usage data to improve the Service
- Functional Cookies: Remember your preferences and settings
- Analytics Cookies: Help us understand how users interact with the Service
Managing Cookies:
You can control cookies through your browser settings. Please note that disabling certain cookies may affect the functionality of the Service. Essential cookies cannot be disabled as they are necessary for the Service to function.
9. Third-Party Links and Services
The Service may contain links to third-party websites, services, or integrations. We are not responsible for the privacy practices or content of these third parties. We encourage you to review the privacy policies of any third-party services you access.
10. Children's Privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child under 18, we will delete it promptly.
11. International Data Transfers
Your information may be transferred to and processed in the United States or other countries where we or our service providers operate. These countries may have different data protection laws than your country of residence.
For users in the EEA, we ensure that such transfers comply with GDPR through appropriate safeguards such as Standard Contractual Clauses (SCCs) or other approved transfer mechanisms.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by email or through a prominent notice on the Service at least 30 days before the effective date.
Your continued use of the Service after the effective date constitutes acceptance of the updated Privacy Policy. We encourage you to review this policy periodically.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Privacy Team
Email: privacy@10-dlc.com
Support: support@10-dlc.com
Address: [Your Business Address]
Data Protection Officer: dpo@10-dlc.com
BY USING THE SERVICE, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY AND CONSENT TO THE COLLECTION, USE, AND DISCLOSURE OF YOUR INFORMATION AS DESCRIBED HEREIN.