Notify-Sim sandbox

Legal

Privacy policy

Last updated 28 July 2026

Notify-Sim is operated by SDU Tech Solutions, a sole proprietorship based in Hyderabad, India. This policy explains what we hold, why, how long for, and what you can ask us to do about it. It covers notify-sim.io, the console at app.notify-sim.io and the sandbox API.

The short version: we hold your email address so you can sign in, whatever your app sends into the sandbox so you can inspect it, and operational logs. We do not sell anything, we run no advertising or analytics trackers, and captured messages are deleted automatically on your plan's retention schedule.

1. What we collect

Account data

Your email address, your display name if you set one, the organisations and projects you belong to, and your role in them. Sign-in codes are stored hashed and deleted once used or expired. We do not store passwords, because there are none.

Captured message content

Everything your application sends into the sandbox: recipients (phone numbers, email addresses, push tokens), subjects and bodies, HTML, attachments, template names and parameters, provider payloads, and DLT content ids. This is the product - it exists so you can look at it.

If your application sends real customer data into the sandbox, that data sits here too. You are its controller (a "Data Fiduciary" under India's Digital Personal Data Protection Act, 2023) and we process it on your behalf. We recommend test data wherever your flow allows it.

Configuration and logs

Templates, realism settings, webhook endpoints and their delivery logs (including the request we sent and the response your endpoint returned), API key metadata and last use, usage counters, plus standard server logs: IP address, timestamp, request path, status code and user agent.

Payments

We take no payments today - there is no card form on this site and no payment gateway connected. When paid plans open, card and bank details will go to the gateway and never to us; we will receive only the subscription status and billing period needed to apply your plan, and this page will say who that gateway is before it processes anything.

Cookies

One cookie: ns_session, which keeps you signed in to the console. It is HTTP-only, secure, and expires after seven days. Theme choice is kept in your browser's local storage. There are no advertising, analytics or third-party cookies on this site or in the console.

2. Why we process it

3. How long we keep it

DataKept for
Captured messagesYour plan's retention window (3 to 90 days), then deleted by a scheduled sweep. You can delete sooner at any time.
Webhook delivery logs14 days
Sign-in codes5 minutes, or until used
Account and organisation dataWhile the account exists, then deleted within 30 days of closure
Usage countersRetained as plan records, without message content
Server logsUp to 30 days
BackupsRolling 14 days, then overwritten

4. Who else sees it

Only the processors we need to run the service:

We do not sell personal data, and we do not share it for advertising. We disclose data to authorities only where a valid legal requirement applies, and we will tell you unless we are prohibited from doing so.

5. Where it is stored

Data is stored on servers we control, and backups are held in the same jurisdiction. Our email relay and payment processor may process data outside India in the course of their own operations. Tell us if you have a data-residency requirement and we will confirm whether we can meet it before you commit.

6. How we protect it

No system is perfectly secure. If we discover a breach affecting your data, we will notify you and the Data Protection Board as required by law, with what we know and what we are doing about it.

7. Your rights

Under the DPDP Act 2023, and as a matter of practice, you can ask us to:

Most of this you can do yourself: delete messages and projects in the console, or ask us and we will do it. Use the data request form - it gives you a reference by email straight away - or write to info@sdutechsolutions.com. Either way we respond within 30 days.

If your personal data is in someone else's sandbox because their application sent it there, they are the controller - contact them, and we will support their response. If you cannot reach them, write to us and we will help.

Grievance officer

Complaints about how we handle personal data: use the data request form and choose "Raise a grievance", or write to info@sdutechsolutions.com with "Grievance" in the subject. We acknowledge within 3 working days and resolve within 30. If you are not satisfied, you may escalate to the Data Protection Board of India. The officer's postal address is on the data request page.

8. Children

Notify-Sim is a developer tool for businesses and is not directed at children. We do not knowingly create accounts for anyone under 18.

9. Changes

If we change this policy in a way that affects you, we will email account admins before it takes effect and update the date at the top. Past versions are available on request.

10. Contact

SDU Tech Solutions
D-212, 2nd Floor, Block-D, Janapriya Lake Front,
Kapra, Secunderabad, Telangana 500062, India
+91 98857 00553
Privacy and data requests: info@sdutechsolutions.com
Everything else: info@sdutechsolutions.com

Registered address and company identification details are listed on the contact page.