SecondFactor
Home Channels▾ SMS WhatsApp Viber RCS Pricing Docs Support Blog
Sign in Get started

Privacy Policy

Effective date: 6 October 2026 · Last updated: 6 October 2026 · Terms & Conditions · Download PDF

On this page
1. Who We Are 2. Scope: Two Roles, Two Kinds of Data 3. Personal Data We Collect 4. Why We Collect and Use Personal Data 5. Automated Decision-Making (PIE Routing) 6. Who We Share Personal Data With 7. International Data Transfers 8. How Long We Keep Personal Data 9. Use of Anonymized and Aggregated Data 10. Data Security 11. Your Rights 12. SMS and Messaging Consent 13. Cookies and Similar Technologies 14. Third-Party Links 15. Changes to This Policy 16. Contact Us

1. Who We Are

SecondFactor ("SecondFactor," "we," "us," or "our") is a product of Digital 360 Pte. Ltd., a company incorporated in Singapore (UEN: 202017689H), with its registered office at 160 Robinson Road, #14-04, Singapore 068914 ("Digital360," "Company").

We operate SecondFactor, a one-time-password (OTP) authentication-as-a-service platform available at secondfactor.ai, including our dashboard, APIs, PIE (Price Intelligence Engine) routing, PIE Playground, Templates, Channel Integrations, and OTP Logs and Analytics (together, the "Services"). It is very important to us to be transparent about what personal data we collect, why, and with whom we share it; this Policy explains exactly that.

2. Scope: Two Roles, Two Kinds of Data

SecondFactor sits between a business ("Customer," "you," when we mean the account holder) and that business's own users ("End Users"), the people who actually receive an OTP on their phone. Because of that position, we hold two different roles depending on whose data is involved:

  • As Data Controller, for Account Data - the information about you or your business that you give us directly to create and run your SecondFactor account (name, email, billing details, templates, and so on). We decide why and how this data is processed, and this Policy governs it in full.
  • As Data Processor, for End User Data - the phone numbers and delivery metadata your application submits to our API so we can send and verify an OTP. Here, you (our Customer) determine why that data is collected and what it's used for; we process it strictly on your instructions, to deliver the Services, and as described below. Our handling of End User Data on your behalf is further governed by our standard Data Processing Terms, available on request.

If you are an End User, someone who received a one-time code because you used an app built by one of our Customers, your primary privacy relationship is with that Customer, not with us. We are not responsible for the privacy policies or data practices of the businesses that use SecondFactor to send you an OTP; please refer to their privacy policy for how they handle your information. This Policy explains, transparently, how we handle your data as the processor behind the scenes.

3. Personal Data We Collect

3.1 Account Data (from you, directly)

  • Identity and contact details: full name, email address, mobile number, password (stored hashed, never in plain text).
  • Business details (optional): company name, company location/country.
  • Billing information: processed through our third-party payment processor, we do not store full card numbers on our own systems.
  • API credentials: your test and live API keys, and a record of when keys are created or rotated.
  • Templates and channel-verification details: message templates you submit for SMS, WhatsApp, Viber, and RCS, and any business/brand information submitted for channel verification (e.g. WhatsApp Business Portfolio details, Viber business application details, RCS agent registration details).
  • Support and correspondence: anything you send us by email, contact form, or chat.

3.2 End User Data (submitted by you via the API, on your instructions)

  • The destination phone number for an OTP.
  • Delivery metadata: destination country, channel used (SMS, WhatsApp, Viber, RCS, or Silent Network Authentication), delivery status, timestamp, and cost of the send.
  • The OTP code itself, generated and validated statelessly, we do not retain OTP codes beyond the short window needed to complete the send/verify cycle.

We do not receive your End Users' account credentials, the content of your own application, or anything about your End Users beyond what's necessary to route and verify a single OTP.

3.3 Data From Third-Party Sign-In

If you sign up using Google or GitHub, we receive your name and email address from that provider, in accordance with the permissions you grant during that sign-in flow.

3.4 Data Collected Automatically

  • Usage data: pages visited on our dashboard, features used, API call metadata (endpoint, timestamp, response status).
  • Device and technical data: IP address, browser type, operating system.
  • Cookies and similar technologies: see Section 13 below.

4. Why We Collect and Use Personal Data

We collect and use personal data only for specific, identified purposes. For each purpose below, we note the legal basis we rely on where data protection law (such as the GDPR) requires one.

4.1 Account creation, authentication, and support

Purpose: to create your account, verify your identity, secure your login, and respond when you contact support.

Basis: performance of our contract with you.

4.2 Delivering the Services - OTP routing, billing, and security

Purpose: to run PIE's routing logic and channel failover, process payments and manage your credit balance, send billing communications (receipts, failed-payment notices, low-balance warnings), and review/approve message templates and channel-integration submissions.

Basis: performance of our contract with you.

4.3 Fraud and abuse prevention

Purpose: to detect and prevent fraud, including SMS pumping and Artificially Inflated Traffic (AIT), across our platform, this may involve analyzing send-volume and delivery patterns at an account level.

Basis: our legitimate interest in keeping the platform, our Customers, and our channel partners safe from abuse.

4.4 Product improvement and aggregated research

Purpose: to understand how our Services and PIE's routing decisions are performing (for example, aggregate delivery-success rates by channel and country) so we can improve accuracy, coverage, and cost efficiency. Wherever possible, we do this using aggregated or anonymized data (see Section 9).

Basis: our legitimate interest in improving the Services.

4.5 Marketing communications

Purpose: to tell you about new features, channels, or pricing changes that may interest you.

Basis: your consent, where required; you can opt out at any time via the unsubscribe link or by contacting us. Opting out of marketing does not opt you out of essential transactional emails about your account.

4.6 Website analytics

Purpose: to understand how visitors use our website and dashboard, so we can improve them.

Basis: your consent for non-essential analytics cookies (see Section 13), or our legitimate interest for essential/aggregated analytics.

4.7 Legal obligations

Purpose: to comply with applicable law, respond to lawful requests from public authorities, and enforce our Terms & Conditions.

Basis: legal obligation, or our legitimate interest in defending our legal rights.

5. Automated Decision-Making (PIE Routing)

PIE automatically decides which delivery channel to try first for a given phone number, based on cost and eligibility, and automatically fails over to another channel if delivery isn't confirmed within our standard time window. This is an automated process, but it is a routing decision about how a message is delivered, it does not evaluate, score, or make any decision about an individual End User, and it has no legal or similarly significant effect on them. We do not use automated decision-making to make decisions about individuals that would trigger additional rights under applicable law; if that ever changes, we will update this Policy accordingly.

6. Who We Share Personal Data With

We do not sell personal data. We share it only with:

  • Telecommunications and channel delivery partners - to deliver an OTP, the destination phone number and message content are necessarily shared with the mobile network operators, messaging platforms, and business solution providers that carry SMS, WhatsApp, Viber, RCS, and Silent Network Authentication traffic on our behalf.
  • Payment processors - to process credit top-ups; we do not store full payment card details ourselves.
  • Cloud infrastructure and hosting providers - to store and run the Services, under confidentiality and security obligations.
  • Professional advisors - lawyers, auditors, and accountants, where necessary and under confidentiality obligations.
  • Regulators and law enforcement - where required by law, regulation, legal process, or a valid governmental request.
  • A buyer or successor - if Digital360 is involved in a merger, acquisition, restructuring, or sale of assets, personal data may transfer as part of that transaction, under this Policy or one offering at least equivalent protection.
  • Affiliates - other companies under common ownership or control with Digital360, for the purposes described in this Policy.

Every third party that processes personal data on our behalf is bound by contractual obligations to protect it and use it only for the purposes we specify.

7. International Data Transfers

SecondFactor delivers OTPs across many countries, so personal data; particularly End User Data, is routinely transferred to, stored, and processed in countries other than the one where it was collected, including countries whose data protection laws may differ from your own.

When we transfer personal data out of the European Economic Area, the United Kingdom, or another jurisdiction with similar restrictions, we rely on an appropriate safeguard such as Standard Contractual Clauses or another lawful transfer mechanism and contractually require recipients to protect the data consistently with this Policy.

8. How Long We Keep Personal Data

We keep personal data only for as long as it serves the purposes above:

  • Account Data: for as long as your account is active, and for a reasonable period afterward to satisfy accounting, tax, audit, or dispute-resolution needs.
  • End User Data / OTP Logs: for a limited period sufficient to support delivery auditing, billing accuracy, dispute resolution, and fraud detection, after which it is deleted or anonymized in the ordinary course. Specific retention periods by data type are set out in our Data Processing Terms, available on request.
  • OTP codes themselves: for only the short window needed to complete the send/verify cycle, then discarded.
  • Marketing preferences: for as long as you remain subscribed, or a reasonable period after you last engaged with our communications.

We may retain data for longer where necessary to comply with a legal obligation, resolve a dispute, or enforce our agreements, including for the duration of an applicable statute-of-limitations period.

9. Use of Anonymized and Aggregated Data

Where we combine or strip data of identifying details so it can no longer reasonably be linked back to you or an End User, that anonymized or aggregated data is no longer personal data, and we may retain and use it indefinitely; for example, to analyze delivery-success trends by country and channel, benchmark PIE's routing accuracy, or build rate-card and channel-penetration models. We do not attempt to re-identify anonymized data.

10. Data Security

We implement technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction including encryption in transit, access controls limiting who within Digital360 can view personal data, and secure handling of API keys and credentials. No method of transmission over the internet, or method of electronic storage, is completely secure, and we cannot guarantee absolute security but we work continuously to maintain safeguards appropriate to the sensitivity of the data involved.

11. Your Rights

Subject to applicable law, you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete personal data.
  • Delete your personal data, subject to legal or contractual retention requirements.
  • Restrict or object to certain processing.
  • Port your data to another provider, in a structured, commonly used format.
  • Withdraw consent at any time, where processing is based on consent, without affecting processing carried out before withdrawal.
  • Lodge a complaint with your local data protection authority.

If you are an End User and want to exercise rights over data submitted about you by one of our Customers, please contact that Customer directly, they control what data is collected from you and why. We will support them in responding to your request, consistent with our Data Processing Terms.

To exercise any of these rights over your own Account Data, contact us at support@secondfactor.ai.

12. SMS and Messaging Consent

SecondFactor delivers messages (including OTPs) only at the direction of our Customers. Obtaining any consent required from an End User before their phone number is submitted to us including consent required under telecom regulations or messaging-platform policies such as WhatsApp's is the Customer's responsibility, not ours; see our Terms & Conditions. We do not use phone numbers submitted for OTP delivery for our own independent marketing purposes.

Consent from you, as an account holder. When you create a SecondFactor account, you are asked to tick a checkbox confirming that you have read and accept this Privacy Policy and our Terms & Conditions. By ticking that checkbox and providing your mobile number, you give us your express consent to send one-time passwords and service messages to that number and the device associated with it, through SMS, WhatsApp, Viber, RCS, or any other channel we support, for the purposes of verifying your number, signing you in, and keeping your account secure. We record the fact, date, time, and IP address of that consent as proof that it was given.

Consent from End Users. Where a one-time password is sent to an End User's device, we send it solely on the documented instructions of the Customer whose application requested it. By submitting a phone number to our API, the Customer confirms to us that it has obtained the consent required from that End User to receive a one-time password on their device under applicable telecommunications, data protection, and messaging-platform rules, and that it can produce evidence of that consent on request. This confirmation is a binding obligation under Section 6 of our Terms & Conditions.

Withdrawing consent. You may withdraw consent for marketing messages at any time, as described in Section 4.5, without affecting your account. One-time passwords and service messages are different: they are necessary to authenticate you and to operate your account securely, so they cannot be switched off while the account remains open. If you no longer wish to receive them, you may close your account by contacting support@secondfactor.ai. Withdrawal of consent does not affect the lawfulness of processing carried out before it was withdrawn. An End User who wishes to withdraw consent for one-time passwords should contact the Customer whose application requested them.

13. Cookies and Similar Technologies

Our website and dashboard use cookies and similar technologies to:

  • Keep you signed in and remember your session (essential - cannot be disabled without affecting core functionality).
  • Understand how the Services are used, so we can improve them (analytics).
  • Remember your preferences (functional).

Where required by law, we present a cookie banner allowing you to accept or reject non-essential cookies. You can also control cookies through your browser settings.

14. Third-Party Links

The Services may reference or link to third-party websites, applications, or services; for example, when connecting your WhatsApp Business Portfolio via Meta, or completing a payment via our payment processor. This Policy does not apply to those third parties; we encourage you to review their own privacy policies.

15. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, or for legal, operational, or regulatory reasons. We will post the updated Policy on this page with a revised effective date, and where changes are material, we will provide additional notice (for example, by email or an in-dashboard notice).

16. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact:

Digital 360 Pte. Ltd. (operating SecondFactor)
160 Robinson Road, #14-04, Singapore 068914
Email: support@secondfactor.ai
Website: secondfactor.ai
SecondFactor

One stop solution for your OTPs. Send and verify through the lowest-cost eligible channel.

HomeChannelsPricingDocsBlog
SMSWhatsAppViberRCS
SupportPrivacy PolicyTerms and Conditions
© 2026 SecondFactor.ai. All rights reserved.Rates shown are indicative and quoted in USD.