Privacy Policy
Updated: 2026-07-01
The data controller is Global Trade Rhino LLC, 30 N Gould St Ste N, Sheridan, WY 82801, USA (the "Company"). This privacy policy explains how we process personal data about Customers. When the Customer in turn sends SMS to their own recipients, the Customer is the data controller for those and SveaSMS acts as processor under a separate DPA.
1. Data we collect
- Account data: name, email, optional phone number, country, username, hashed password.
- Payment metadata: transaction ID, amount, currency, method, partially masked wallet address. We never store full card numbers.
- Technical data: IP address, login timestamps, user agent, approximate geolocation, session events.
- Sending metadata: sender ID, recipient number, segment count, time, DLR status. Message content is stored only as long as required for delivery, troubleshooting and legal claims.
- Support communications: emails, tickets and internal notes.
2. Purposes and legal basis
- Performance of contract (deliver the Service, manage balance, support).
- Legal obligation (bookkeeping, sanctions and AML screening).
- Legitimate interest (security, abuse handling, product improvement, limited marketing).
- Consent where expressly requested (e.g. optional newsletters, cookies per cookie policy).
3. Sharing
Data is shared only with the subprocessors required to deliver the service, such as cloud hosting, payment processors, email and analytics providers. All of them are bound by confidentiality and data processing agreements and may process data only on our instructions. Otherwise your data is not shared with other companies or outside parties, and we never sell personal data.
Identity and verification data (KYC). Where the Customer submits a verification in order to use numbers or sender identities in regulated countries, the details and documents provided may be shared with the verification and compliance partners and providers the Company works with, and with the operator imposing the requirement in the relevant country. Such sharing takes place only to the extent necessary to assess and register the verification, and recipients are bound by confidentiality and applicable data processing terms.
4. International transfers
The Company operates globally and may process data in the USA and other countries. For transfers from the EU/EEA, the EU Commission's Standard Contractual Clauses or equivalent safeguards are applied.
5. Retention
Account data is retained for the term of the agreement and thereafter as long as required for bookkeeping (up to 7 years) and to defend legal claims. Sending logs are retained up to 24 months. Abuse logs may be retained longer.
6. Rights
To the extent applicable law (e.g. GDPR, CCPA/CPRA) allows, the data subject has the right of access, rectification, erasure, restriction, data portability and objection. Requests to support@sveasms.com. We respond within 30 days and may request identity verification.
7. Security
We apply technical and organisational measures, including encryption in transit, hashed passwords, access control and logging. No service is entirely risk-free and the Company does not guarantee absolute security.
8. Children
The Service is not directed to children under 18. We do not knowingly collect data about minors.
9. Complaints
If you are dissatisfied with how we handle your personal data, please contact us atsupport@sveasms.com so we can attempt to resolve the matter.