Last updated: 12 September 2026
Privacy policy
This policy explains what data we process when you use KolayOTP, and why.
Data we process
Account data (name, email, company, billing details) and service data (recipient phone number or email address, channel, delivery and verification state, IP address). Verification codes are never stored in plaintext — only HMAC digests.
Purpose
Delivering OTP messages, preventing abuse, billing and meeting legal obligations. We do not use your data for advertising and never sell it to third parties.
Retention
Delivery logs are kept for 90 days; verification codes only for their TTL (10 minutes by default). Account and invoice records are retained for statutory periods.
Sub-processors
Basefyio (database, EU), Buildfyio (hosting), NetGSM (SMS), Resend (email), Meta (WhatsApp), Telegram (bot delivery), Stripe and Garanti (payments). The current list is visible in the panel.
Your rights
Send access, correction, deletion and portability requests to support@kolayotp.com; we respond within 30 days.