In short
we need an email address, your orders, and the messages sent to the numbers you use. We never ask for your own phone number, card details go straight to Stripe, and we don’t sell personal data.
01Who we are
Variance Ventures LLC (“we”, “us”) operates passcode.sh and is responsible for the personal data described here. This policy covers the website, web app and API. Contact us at support@passcode.sh.
02What we collect
- Account details: your email address, an optional name, and your password, which we store only as a salted hash.
- Orders and rentals: the services and countries you choose, the numbers assigned to you, prices, timestamps, and your balance history.
- Message content: the text, sender and time of SMS messages sent to numbers while they’re assigned to you, including verification codes. These messages are written by third parties, not by you.
- Payment metadata: when you add funds, Stripe processes the payment. We receive the amount, status and Stripe reference — never your full card number.
- Technical data: IP address and browser user agent for signed-in sessions, security and rate limiting.
- Developer settings: API key names and prefixes (keys themselves are stored only as hashes), your webhook URL, and a log of recent webhook deliveries.
- Waitlist and support: the email you join the waitlist with and where you joined from, and anything you send us.
03What we don’t collect
We never ask for your personal phone number or contacts. We don’t use advertising cookies or cross-site trackers.
04How we use it
- To run the Service: assign numbers, show you incoming messages and codes, process refunds, send webhooks.
- To keep it safe: authenticate sessions, enforce rate limits, and detect and investigate fraud and abuse.
- To handle payments, accounting and taxes.
- To contact you about your account, such as password resets, security notices and changes to our terms. If you joined the waitlist, to tell you when you can create an account.
- To comply with the law and respond to valid legal requests.
05Cookies and local storage
We set one essential cookie, an HTTP-only session cookie that keeps you signed in. Your browser’s local storage remembers interface preferences such as the color theme and your preferred code language in the docs. Neither is used for advertising.
06Who we share it with
We share personal data only with providers that help us run the Service, under contracts that limit their use of it:
- Hosting and database providers that run our application and store its data.
- Stripe, for card payments.
- Our email delivery provider, for account and waitlist emails.
- Telecommunications carriers that route SMS messages to our numbers.
We may also disclose information when the law requires it, to protect people from harm or fraud, or as part of a merger or acquisition (in which case this policy continues to apply). We don’t sell personal data, and we don’t share it for cross-context behavioral advertising.
07How long we keep it
- Sessions expire after 30 days without use.
- Rate-limit counters are deleted within a day.
- Webhook delivery logs keep the most recent 200 deliveries per account.
- Orders, rentals and message content are kept while your account is open and deleted or anonymized within 90 days after it closes, unless we need them longer to investigate abuse.
- Payment and balance records are kept as long as tax and accounting law requires.
- Waitlist emails are kept until you create an account or ask us to remove you.
08Security
Connections are encrypted in transit. Passwords are hashed with scrypt, and session tokens and API keys are stored only as SHA-256 hashes. Access to production data is limited to people who need it to run the Service. No system is perfectly secure; if we learn of a breach affecting your data, we’ll notify you as the law requires.
09Your choices and rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to or restrict some processing. You can update your profile in the app, and you can make any other request by emailing support@passcode.sh. We’ll respond within 30 days and may need to verify your identity first.
If you’re in the EU or UK, you can also complain to your local data protection authority. We process your data to perform our contract with you, to meet legal obligations, and for our legitimate interests in keeping the Service secure and free of abuse.
10International transfers
We’re based in the United States and our providers may process data in other countries. Where the law requires it, we rely on appropriate safeguards such as standard contractual clauses.
11Children
The Service is not for anyone under 18, and we don’t knowingly collect data from children.
12Changes to this policy
We’ll post updates here and, for material changes, notify you by email or in the app before they take effect. See also the Terms of Service.
13Contact
Privacy questions and requests: support@passcode.sh.