1. Who is responsible
MIRIFNO operates ChatVendor and decides how the data described here is handled. Contact us about privacy at info@chatvendor.net.
A note about the people you message
For the recipients of your messages, you are the party responsible for their data. You decide who to message and why; we process those numbers on your behalf and on your instructions. Your obligations to those people — consent, notice, honouring opt-outs — are yours, and are covered in our Acceptable Use Policy.
2. What we collect
Account
- Name, email address, hashed password.
- Workspace name and plan.
- Sign-in history: time, IP address, and a rough device description from the browser's user-agent string. This exists so you can spot access you do not recognise.
From the phones you pair
- Manufacturer, model, Android version, app version.
- Battery level, charging state, network type, signal strength — so the dashboard can show whether a phone can actually send.
- SIM card details: carrier, slot, country, and the SIM's own number when the card exposes it (most do not). Numbers are encrypted at rest.
- An identifier generated on the phone at install time. It is not an advertising ID and is not linked to anything outside ChatVendor.
We do not collect your location, your contacts, your call history, or the contents of your inbox. The app does not request the permissions that would allow it to.
Messages
- The recipient number, the message body, and delivery status and timings.
- Which device and SIM sent it, and any error the phone reported.
Message bodies are encrypted at rest. They are decrypted when a paired phone fetches the message to send it, and when you view the message in your own dashboard.
API usage
- Method, path, response status, latency, IP address, and a correlation ID per request.
- Which API key was used — identified by its public prefix. We never store the key itself.
3. Why we hold it
| Purpose | Data |
|---|---|
| Delivering your messages | Message content and recipient, device and SIM state |
| Showing you what happened | Status timeline, delivery attempts, errors |
| Keeping your account secure | Sign-in history, API request logs, audit records |
| Preventing abuse and protecting networks | Usage counters, rate-limit state, abuse reports |
| Support you ask for | Whatever is needed to investigate the specific issue |
| Legal obligations | Records we are required to keep |
4. How long we keep it
| Data | Retention |
|---|---|
| Message content | 90 days, then deleted |
| Message metadata (status, timings, no body) | 365 days |
| Device telemetry (battery, signal, heartbeats) | 7 days |
| API request logs | 30 days |
| Audit and sign-in records | 365 days |
| Account details | While the account exists, then deleted or anonymised |
Deletion is enforced by a scheduled job, not left to manual housekeeping.
5. What we never store or log
- Raw API keys and device tokens — only a lookup prefix and a SHA-256 hash.
- Passwords — only a bcrypt hash.
- Message bodies in application logs or audit records. Our audit logger strips those fields before writing.
6. Who else sees it
We do not sell personal data and we do not share it for advertising.
Data is disclosed only:
- To infrastructure providers that host the Service, acting on our instructions.
- To your own paired phones — that is how a message gets sent.
- Where the law requires it, or to protect people from harm.
If you configure a webhook, the payloads you asked for are sent to the URL you nominate. Where that data goes next is your responsibility.
7. Where it is held
The Service runs on servers in the European Union. If you or your recipients are elsewhere, your data will be processed there.
8. How it is protected
- HTTPS everywhere.
- Message bodies, webhook secrets, SIM numbers and two-factor secrets encrypted at rest.
- Credentials hashed, never recoverable.
- Every record scoped to its workspace, so one customer cannot reach another's data.
- Layered rate limits and audit logging.
No system is perfectly secure; if you find a weakness, please tell us at info@chatvendor.net.
9. Your choices
- Access and export — your messages and their status are available through the dashboard and the API at any time.
- Correction — account details are editable in settings.
- Deletion — deleting your account removes your workspace, devices and messages, subject to records we must keep by law.
- Unpair a phone — this erases the credentials stored on that device and stops it receiving messages immediately.
To exercise any of these, or if you are unhappy with how we handled your data, write to info@chatvendor.net. Depending on where you live, you may also have the right to complain to a data protection authority.
10. Cookies
The dashboard sets a session cookie to keep you signed in and a CSRF cookie to protect forms. Your light or dark theme choice is stored in your browser and never sent to us. We use no analytics or advertising cookies.
11. Children
The Service is for business use and is not directed at children.
12. Changes
We will update this policy as the Service changes. The date at the top reflects the current version, and we will notify account owners by email before a material change takes effect.