Skip to content

Policies

Privacy, in brief

What we collect, why we collect it, and who it's shared with. A plain-language summary of how we handle your data.

Last updated
Updated
Reading time
1 min read
On this page6
  1. What we collect, and why
  2. What we don't collect
  3. Messages on your numbers
  4. Cookies
  5. Sharing
  6. Your choices

A short summary. The Privacy Policy is the full version and the one that applies. passcode.sh is operated by Variance Ventures LLC.

What we collect, and why

Data Why
Email address, optional name, password hash Your account and signing in.
Sessions: browser user agent, IP address, times Keeping you signed in, security and rate limiting.
Orders, rentals and the SMS messages they receive Delivering the service: showing you codes and messages, and handling refunds.
Balance, ledger and deposit records Billing and accounting.
API key hashes and last-used times Authenticating API requests.
Your webhook URL and recent deliveries Sending you events and showing you how they went.

What we don't collect

  • Card numbers. Stripe handles payments; we receive the payment's outcome, not your card details.
  • Your own phone number. We never ask for it.

Messages on your numbers

SMS received on your numbers are stored with the order or rental so you can read them. They're visible to you, and to our team only when needed to run the service or investigate abuse.

Cookies

We use one essential cookie to keep you signed in. Your theme choice is stored in your browser, not in a cookie. We don't use advertising cookies.

Sharing

We share data only with the providers we need to run the service — hosting, our database, our phone carrier, Stripe for payments and our email provider — and when the law requires it. We don't sell your personal data.

Your choices

To ask for a copy of your data or for your account to be deleted, email support@passcode.sh from the address on your account. See Deleting your account.