Legal
Privacy policy
Notify-Sim is operated by SDU Tech Solutions, a sole proprietorship based in Hyderabad, India. This policy explains what we hold, why, how long for, and what you can ask us to do about it. It covers notify-sim.io, the console at app.notify-sim.io and the sandbox API.
1. What we collect
Account data
Your email address, your display name if you set one, the organisations and projects you belong to, and your role in them. Sign-in codes are stored hashed and deleted once used or expired. We do not store passwords, because there are none.
Captured message content
Everything your application sends into the sandbox: recipients (phone numbers, email addresses, push tokens), subjects and bodies, HTML, attachments, template names and parameters, provider payloads, and DLT content ids. This is the product - it exists so you can look at it.
If your application sends real customer data into the sandbox, that data sits here too. You are its controller (a "Data Fiduciary" under India's Digital Personal Data Protection Act, 2023) and we process it on your behalf. We recommend test data wherever your flow allows it.
Configuration and logs
Templates, realism settings, webhook endpoints and their delivery logs (including the request we sent and the response your endpoint returned), API key metadata and last use, usage counters, plus standard server logs: IP address, timestamp, request path, status code and user agent.
Payments
We take no payments today - there is no card form on this site and no payment gateway connected. When paid plans open, card and bank details will go to the gateway and never to us; we will receive only the subscription status and billing period needed to apply your plan, and this page will say who that gateway is before it processes anything.
Cookies
One cookie: ns_session, which keeps you signed in to the console. It is HTTP-only, secure, and expires after seven days. Theme choice is kept in your browser's local storage. There are no advertising, analytics or third-party cookies on this site or in the console.
2. Why we process it
- To provide the service - authenticate you, capture and display messages, deliver webhooks, enforce plan limits.
- To keep it working and secure - diagnose failures, investigate abuse, maintain backups.
- To bill you - if you are on a paid plan.
- To communicate - sign-in codes, invitations, service notices, and replies when you contact support. We do not add you to a marketing list without asking.
3. How long we keep it
| Data | Kept for |
|---|---|
| Captured messages | Your plan's retention window (3 to 90 days), then deleted by a scheduled sweep. You can delete sooner at any time. |
| Webhook delivery logs | 14 days |
| Sign-in codes | 5 minutes, or until used |
| Account and organisation data | While the account exists, then deleted within 30 days of closure |
| Usage counters | Retained as plan records, without message content |
| Server logs | Up to 30 days |
| Backups | Rolling 14 days, then overwritten |
4. Who else sees it
Only the processors we need to run the service:
- Our hosting provider, where the servers and database live.
- Our email relay, which delivers sign-in codes and invitations. It sees the recipient address and the message we send.
- A payment gateway, once paid plans open. None is connected today.
- Endpoints you configure: webhooks go where you tell them to go. That is your choice and your responsibility.
We do not sell personal data, and we do not share it for advertising. We disclose data to authorities only where a valid legal requirement applies, and we will tell you unless we are prohibited from doing so.
5. Where it is stored
Data is stored on servers we control, and backups are held in the same jurisdiction. Our email relay and payment processor may process data outside India in the course of their own operations. Tell us if you have a data-residency requirement and we will confirm whether we can meet it before you commit.
6. How we protect it
- HTTPS everywhere, with HSTS. The sandbox SMTP gateway requires STARTTLS before it accepts credentials.
- Secrets - sandbox secrets, API keys, sign-in codes - are stored as hashes, never in plain text, and shown once.
- Every read is scoped to the project it belongs to, so one organisation cannot see another's messages.
- Webhook targets are checked against private, loopback and cloud-metadata address ranges, so a webhook cannot be used to reach inside our network.
- Nightly backups, verified for completeness.
No system is perfectly secure. If we discover a breach affecting your data, we will notify you and the Data Protection Board as required by law, with what we know and what we are doing about it.
7. Your rights
Under the DPDP Act 2023, and as a matter of practice, you can ask us to:
- confirm what personal data of yours we hold, and give you a copy;
- correct anything inaccurate or incomplete;
- erase your data and close your account;
- withdraw consent, and nominate someone to exercise these rights on your behalf if you cannot.
Most of this you can do yourself: delete messages and projects in the console, or ask us and we will do it. Use the data request form - it gives you a reference by email straight away - or write to info@sdutechsolutions.com. Either way we respond within 30 days.
If your personal data is in someone else's sandbox because their application sent it there, they are the controller - contact them, and we will support their response. If you cannot reach them, write to us and we will help.
Grievance officer
Complaints about how we handle personal data: use the data request form and choose "Raise a grievance", or write to info@sdutechsolutions.com with "Grievance" in the subject. We acknowledge within 3 working days and resolve within 30. If you are not satisfied, you may escalate to the Data Protection Board of India. The officer's postal address is on the data request page.
8. Children
Notify-Sim is a developer tool for businesses and is not directed at children. We do not knowingly create accounts for anyone under 18.
9. Changes
If we change this policy in a way that affects you, we will email account admins before it takes effect and update the date at the top. Past versions are available on request.
10. Contact
SDU Tech Solutions
D-212, 2nd Floor, Block-D, Janapriya Lake Front,
Kapra, Secunderabad, Telangana 500062, India
+91 98857 00553
Privacy and data requests: info@sdutechsolutions.com
Everything else: info@sdutechsolutions.com