This Privacy Policy explains what information VeroSMS holds about you, why it is held, who it is shared with, how long it is kept and how it is protected. It covers both this website and the VeroSMS Android application we use to send and receive messages.
Who we are, and how to reach us
This service is operated by VeroSMS, and VeroSMS is responsible for the information described in this policy.
If you have a question about your information, want a copy of what we hold, want it corrected or deleted, or want us to stop messaging you, write to VeroSMS and say what you would like us to do. Please write from — or quote — the phone number or email address the request concerns, so that we can find the right record and be sure we are answering the right person.
What this service is, and how a message actually reaches you
VeroSMS is a self-hosted SMS gateway. That means the whole system runs on equipment we control rather than on a messaging company's platform:
Our own server holds the address book and decides what to send. Ordinary Android phones, on our own mobile accounts with our own SIM cards, do the sending. When there is something to send, our server sends a silent signal to the relevant phone to wake it up; the phone then asks our server what is waiting for it, and sends those messages as text messages through its SIM, exactly as a person tapping out a text would.
So the text you receive comes from one of our phones and one of our numbers. It is carried by our mobile operator, on their network, under their terms — the same as any other text. It does not pass through a bulk-messaging platform, and no third-party messaging company is given your number in order to reach you.
Why we send messages at all
We send two kinds of message, and we treat them differently.
Service messages relate to something you asked us to do — an order confirmation, an appointment reminder, a delivery update, a one-time code you requested. We send these because they are part of providing what you asked for.
Marketing messages tell you about things we offer. We send these only to people who have agreed to receive them, and every one of them can be stopped, permanently, by asking.
What information we hold
Contact details for the people we message: a name where we have one, a phone number, and any extra field we use to personalise a message — an order reference, an appointment time, a booking number.
The messages themselves: what was sent, to which number, from which of our phones and which SIM, when, and what the network reported back about whether it arrived. Replies that arrive on those phones are stored the same way, so a conversation reads as a conversation.
A record of an opt-out, if you ask us to stop, including the date you asked.
Technical records of calls made to our own programming interface — an IP address, a timestamp, which operation was called and whether it succeeded — kept so that misuse of a key can be investigated. These never contain message text or phone numbers.
And for each phone we have paired: its model, its Android version, which app version it is running, the labels of its SIM slots, its battery level and the time it last checked in. That is how we can tell whether a phone is able to send before we hand it work.
The Android app: what it can reach on the phone
The VeroSMS app runs on phones that belong to us, not on yours. It is not distributed to the people we message and it does not need to be installed by anyone who receives a text from us. This section is here so that anybody — including whoever reviews the app before it is published — can see exactly what it is able to touch, and why.
Android requires an app to declare every capability it uses. These are the ones this app declares, and there are no others:
Send SMS — the purpose of the app. It puts our outgoing messages on the mobile network through the SIM we chose.
Receive SMS — so that a reply arriving on our SIM reaches our own inbox rather than being lost. The app reacts to messages that arrive while it is running. It does not open, read, index or upload the phone's existing message store, and it is not a replacement for the phone's own messaging app.
Phone state and phone numbers — to tell which SIM is in which slot, so that a message we marked for SIM 1 leaves from SIM 1. Without it the app cannot reliably tell two SIMs apart, and a message can go out from the wrong number at the wrong tariff.
Camera — used for one thing only: scanning the pairing code on screen when the phone is first connected to our server. The app takes no photographs, stores no images, and does not use the camera at any other time.
Internet and network state — to reach our server, and to tell whether there is a usable connection before trying.
Notifications, foreground service and wake lock — Android requires a visible, permanent notification for an app that keeps running in the background, and that notification is what the app posts. These let the app stay awake long enough to receive a wake-up signal and send what is waiting.
Start on boot — so the gateway resumes by itself after the phone restarts, rather than silently stopping until somebody notices.
Ignore battery optimisation — offered as a choice on the app's own settings screen, never requested silently. Without it Android puts the app to sleep and messages arrive hours late in bursts.
What the app deliberately does not do
It does not read the phone's contacts. It asks for no contacts permission at all.
It does not read the messages already stored on the phone, from us or from anybody else.
It does not collect location. It asks for no location permission at all.
It contains no advertising network and no analytics or tracking library. Its only connection to Google is the messaging service described below, which is what wakes a sleeping phone.
It does not send anything to us beyond what is described in this policy, and it sends it only to the server address it was paired with.
Where your information is stored, and who else sees it
Everything described above is stored in a database on our own server.
We do not sell your information, and we do not share it for anyone else's advertising.
Three parties are necessarily involved in a text reaching you, and it is worth being precise about what each one gets:
Our mobile operator carries the message, in the same way they carry any text. They see the number, the content and the time, because that is what carrying a text means, and they handle it under their own terms.
Google's Firebase Cloud Messaging service carries the wake-up signal to our phone. That signal contains no message text and no phone number — only an internal identifier for the phone being woken and a note that work is waiting. The message itself travels between our server and our phone, directly, and never through Google.
Our hosting provider stores the server's data on their infrastructure, as any host does.
Beyond those, information is disclosed only where the law requires it.
How your information is protected
Traffic between the app and our server, and between your browser and our panel, is encrypted in transit.
Credentials are stored as one-way hashes rather than in readable form. That applies to the passwords for the panel, to the keys that let other software send through our installation, and to the credential each paired phone holds — none of them can be read back out of a copy of the database.
Each phone holds a credential that speaks only for itself, so a phone can collect the messages addressed to it and nothing else.
Access to the panel is limited to named accounts, each with only the permissions its holder needs, and every change made in the panel is recorded against the person who made it.
No system is completely secure, and we do not claim otherwise. What we can say is what the protections are, so you can judge them.
How long we keep it, and how it is deleted
Message history is removed automatically once it passes the retention period set on this installation, and the technical records of interface calls are removed on the same schedule.
Contact details are kept while there is a reason to hold them — while you are a customer, while an order is open, or while the law requires us to keep a record.
A recorded opt-out is kept even when the rest is deleted, and deliberately so: it is the only thing that stops a future import of an old list putting you back on it. It holds your number and the date you asked, and nothing else.
If you ask us to delete what we hold about you, write to VeroSMS. We will delete it, except where we are required to keep something by law — and we will tell you if that applies and what it covers.
How to stop receiving messages
Reply to any message asking us to stop, or write to VeroSMS.
We record the request rather than simply deleting your row, because a deleted contact is one that comes straight back the next time a list is imported. Once recorded, every future send skips you automatically.
We will not ask you to justify the request, and stopping marketing messages does not stop a message you specifically asked for, such as a code you requested a moment ago.
Your rights
Depending on where you live, you may have the right to ask what we hold about you, to have it corrected, to have it deleted, to object to how we use it, to ask for a copy of it in a portable form, or to complain to your data protection regulator.
To exercise any of these, write to VeroSMS. We answer these requests without charge.
Children
This service is intended for adults and for business communication. We do not knowingly collect information about children, and we do not knowingly message them. If you believe we hold a child's details, write to VeroSMS and we will remove them.
Changes to this policy
We may update this policy as what we do changes. The version published on this page is the one that applies, and the date it was last updated is shown at the top.