GSMFlow

Legal

Privacy notice

A plain-language pilot notice. Add the legal operator, contact, retention periods, subprocessors, and regional rights before launch.

Information processed

The platform stores account and contact details, service-order identifiers, order notes and results, wallet and deposit records, support messages, API-token metadata, IP addresses, user agents, and security audit events. Raw API secrets are never stored after issuance.

Why it is processed

Information is used to authenticate customers, quote and fulfill authorized services, prevent duplicate or abusive orders, maintain financial records, respond to support, investigate incidents, and meet legal obligations.

Sharing

Only the minimum information necessary should be shared with vetted payment or service providers. Provider contracts, locations, retention, and international transfer safeguards must be documented before integration.

Retention and security

Order identifiers and provider payloads should be retained only as long as operational, dispute, tax, and legal needs require. Production deployment must use encrypted transport, restricted administrator access, protected backups, secret management, and documented deletion procedures.

Your choices

Subject to applicable law, customers may request access, correction, export, restriction, or deletion. Financial, fraud, audit, and legal records may need to be retained after account closure.