Privacy
policy.
What we collect, why we collect it, and how we protect it.
1. What we collect
Account data — name, email, phone, password hash.
Usage data — API requests, message metadata (recipient, status, timestamps), and system logs.
Billing data — invoice history and payment confirmations from our payment processor.
2. Message content
OTP codes and SMS bodies pass through our system to be delivered. We do not read, mine, or sell message content. Message bodies are retained only as long as needed for delivery and audit (typically 90 days).
3. How we use data
To operate the service, prevent abuse, bill you accurately, and meet legal obligations. We do not sell personal data to third parties.
4. Sharing
We share data only with: our payment processor, Turkmen mobile operators (to route SMS), and authorities when required by law.
5. Retention
Account records are kept while your account is active and up to 6 years after closure for tax and audit purposes. Message content is deleted after 90 days.
6. Your rights
You can access, correct, export, or delete your personal data by writing to privacy@ugrat.com. We respond within 30 days.
7. Security
Data is encrypted in transit (TLS 1.2+) and at rest. API keys are bcrypt-hashed. See our security page for details.
8. Children
Ugrat is a B2B service and is not intended for children under 18.
9. Changes
We will notify account holders by email at least 30 days before any material change to this policy.
10. Contact
Privacy questions? Write to privacy@ugrat.com.