1. Who We Are
SendAppTo.Me ("SendAppTo.Me", "we", "our", "us") operates the platform available at sendappto.me and related subdomains. We provide a software-as-a-service ("Service") that enables app developers and businesses ("Customers") to embed an SMS widget on their websites. The widget allows website visitors ("End Users") to receive a direct mobile-app download link via SMS.
For the purposes of applicable data protection law, SendAppTo.Me acts as a data controller for information collected from Customers and as a data processor on behalf of Customers for End User data collected through widgets they deploy.
SendAppTo.Me is a product of Adlent LLC.
Contact us at: hello@sendappto.me
2. Scope of This Policy
This Privacy Policy applies to all personal data processed by SendAppTo.Me through the sendappto.me website, the dashboard, the embeddable widget, and any related APIs or services. It covers two distinct groups:
- Customers — individuals or entities that create a SendAppTo.Me account to build and deploy widgets.
- End Users — visitors to a Customer's website who interact with a SendAppTo.Me-powered widget by submitting their phone number.
If you are a Customer deploying a widget, you are also responsible for providing your own privacy notice to your End Users that covers your use of this Service.
3. Information We Collect
3.1 Information from Customers
- Account information: Name and email address provided at registration.
- Authentication credentials: A hashed password. We never store plaintext passwords.
- Billing information: Payment is processed by Stripe, Inc. We receive and store only a Stripe customer ID and subscription ID. We never receive, store, or transmit raw card numbers, CVVs, or bank account details.
- App configuration: App names, App Store URLs, Google Play URLs, widget style preferences, and country-restriction settings you configure in the dashboard.
- Usage data: Log data including IP addresses, browser type, pages visited on the sendappto.me website, and timestamps — collected automatically for security and service improvement.
- Support communications: Email content if you contact us for support.
3.2 Information from End Users (via Customer Widgets)
- Phone number and dial code: Entered by the End User to receive an SMS download link. The phone number is transmitted only as necessary to authorized messaging infrastructure providers for the sole purpose of delivering the SMS message requested by the End User, and is stored in hashed form in SMS logs. Phone numbers are collected solely to fulfill the End User's request for a transactional SMS message and are not used for marketing or promotional purposes.
- User agent string: The browser/device identifier sent automatically by the End User's browser, used solely to determine whether to send an iOS or Android link. It is not stored after the SMS is dispatched.
- Send timestamp: Date and time the SMS was requested.
- Delivery status: Whether the requested SMS message was successfully accepted for delivery.
- IP address: Logged transiently for abuse-prevention rate-limiting and is not stored in End User SMS logs.
3.3 Information We Do Not Collect
- We do not collect names or email addresses from End Users.
- We do not use cookies, fingerprinting, or any tracking technology on Customer websites where a widget is embedded.
- We do not infer demographic, behavioral, or psychographic profiles from any data.
- We do not collect data from children. See Section 14.
4. Legal Basis for Processing
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, we rely on the following legal bases under the General Data Protection Regulation (GDPR) and applicable national law:
| Purpose | Legal Basis |
|---|---|
| Creating and managing a Customer account | Performance of a contract (Art. 6(1)(b) GDPR) |
| Processing subscription payments | Performance of a contract (Art. 6(1)(b) GDPR) |
| Sending transactional SMS to End Users | Legitimate interests of the Customer (Art. 6(1)(f) GDPR) — End User explicitly requests the SMS |
| Providing analytics to Customers | Performance of a contract / Legitimate interests (Art. 6(1)(b)(f) GDPR) |
| Security, fraud prevention, and abuse detection | Legitimate interests (Art. 6(1)(f) GDPR) |
| Communicating service updates | Legitimate interests / Consent where required (Art. 6(1)(a)(f) GDPR) |
| Complying with legal obligations | Legal obligation (Art. 6(1)(c) GDPR) |
For processing not covered above, or where we rely on consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
5. How We Use Information
5.1 To Operate the Service
- Authenticate Customer accounts and maintain sessions.
- Store and serve widget configuration (app name, store URLs, colors, country restrictions).
- Route inbound widget submissions to our SMS delivery pipeline.
- Detect the End User's device type from the user agent to select the correct store link.
- Record SMS delivery outcomes for Customer analytics dashboards.
5.2 For Billing
- Process monthly subscription payments via Stripe.
- Calculate per-SMS charges based on destination country and usage volume.
- Generate invoices and billing history accessible in the dashboard.
5.3 For Analytics
- Aggregate SMS send counts by country, time period, and delivery status for Customer dashboards.
- We do not combine or cross-reference End User data across different Customers.
5.4 For Safety and Security
- Detect and prevent abuse, spam, and fraudulent SMS activity.
- Rate-limit widget submissions to protect against bulk misuse.
- Monitor for unauthorized access to Customer accounts.
5.5 For Service Improvement
- Analyze aggregate, anonymized usage patterns to improve performance and features.
- Diagnose technical errors and platform reliability issues.
5.6 For Communications
- Send transactional emails (account confirmation, password reset, subscription receipts).
- Notify Customers of material changes to the Service, terms, or this Privacy Policy.
- Respond to support and privacy requests.
We do not use personal data for automated decision-making or profiling that produces legal or similarly significant effects.
6. SMS Compliance
SendAppTo.Me is a transactional SMS service. Each SMS is sent only in direct response to an End User's explicit, voluntary request by submitting a phone number in a widget. We do not send unsolicited marketing messages.
6.1 TCPA (United States)
Customers deploying widgets in the United States are responsible for ensuring their widget implementation complies with the Telephone Consumer Protection Act (TCPA) and applicable FCC regulations. The widget includes a consent disclosure stating: "By clicking “Send App Link”, you agree to receive a one-time transactional SMS from SendAppTo.Me containing the requested application download link. Message and data rates may apply. Reply STOP to opt out and HELP for help." Customers must not configure widgets in ways that obscure or remove this disclosure.
6.2 GDPR / ePrivacy (EEA & UK)
For widget deployments targeting EEA or UK End Users, Customers are responsible for ensuring that the collection of the phone number and dispatch of an SMS is lawful under applicable ePrivacy rules. SendAppTo.Me provides the technical infrastructure; the legal responsibility for obtaining appropriate consent from End Users rests with the Customer operating the widget.
6.3 CASL (Canada)
Customers targeting Canadian End Users are responsible for compliance with Canada's Anti-Spam Legislation (CASL). The single transactional SMS sent in response to a direct End User request falls within the transactional message exemption under CASL; however, Customers should obtain express or implied consent as appropriate and maintain appropriate records.
6.4 Phone Number Handling
Phone numbers submitted through SendAppTo.Me widgets are collected solely to deliver the SMS message explicitly requested by the End User.
Phone numbers are used only for processing and delivering that requested message.
Phone numbers are never used for advertising, marketing, behavioral profiling, cross-site tracking, audience building, or promotional communications.
Phone numbers are never sold, rented, licensed, or shared for marketing purposes.
Where retained for operational logging, phone numbers are stored only in hashed or otherwise protected form and only for the period necessary to support service operation, fraud prevention, analytics, and legal compliance.
6.5 Transactional Messaging
SendAppTo.Me provides transactional messaging only.
Each SMS message is sent solely in response to an explicit action initiated by the End User.
We do not send unsolicited marketing text messages.
We do not purchase or use third-party phone number lists.
We do not use collected phone numbers for advertising or promotional campaigns.
We do not use SMS messages for customer acquisition or lead generation.
7. Data Sharing & Third Parties
We do not sell, rent, trade, license, or otherwise disclose personal information for marketing or advertising purposes.
We disclose personal information only when necessary to provide the Service, fulfill user requests, comply with legal obligations, or protect the security and integrity of our platform.
Mobile Messaging Privacy
SendAppTo.Me respects your privacy with respect to mobile messaging.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes.
Text messaging originator opt-in data, consent records, and any associated phone numbers collected for SMS messaging are never sold, rented, licensed, traded, or otherwise shared with third parties or affiliates for marketing, advertising, lead generation, customer profiling, or promotional purposes.
Mobile opt-in information is used solely to provide the SMS message explicitly requested by the End User.
We may disclose mobile information only to service providers that support the delivery of the requested SMS message and only to the extent necessary to provide that messaging service. Those providers are contractually obligated to use the information solely for service delivery.
| Third Party | Purpose | Data Shared |
|---|---|---|
| SMS delivery providers | Deliver the SMS message explicitly requested by the End User | Phone number (E.164 format) and message content |
| Payment processors | Subscription billing | Customer billing information |
| Cloud hosting providers | Platform infrastructure | Data necessary to operate the Service |
The disclosures described above do not include mobile messaging consent information.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes.
Text messaging originator opt-in data and consent information are never disclosed for marketing or advertising purposes.
Such information is disclosed only as necessary to facilitate the delivery of the SMS message requested by the End User.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
This restriction applies regardless of whether the recipient is a third party, affiliate, business partner, advertiser, marketing platform, or analytics provider.
Each third party is bound by its own privacy policy and, where applicable, data processing agreements that require them to protect personal data to standards equivalent to those in this policy.
We may also disclose personal data:
- To comply with legal obligations — in response to a court order, subpoena, regulatory request, or other lawful requirement.
- To protect rights and safety — when disclosure is necessary to prevent harm, enforce our Terms of Service, or protect the security of our systems.
- In connection with a business transfer — if SendAppTo.Me is acquired, merged, or its assets transferred, personal data may be part of the transferred assets. We will notify affected Customers by email in advance.
8. International Data Transfers
SendAppTo.Me operates from the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States or other countries where our infrastructure or service providers operate. These countries may not provide the same level of data protection as your home country.
For transfers of personal data from the EEA, UK, or Switzerland to the United States, we rely on appropriate safeguards including Standard Contractual Clauses (SCCs) adopted by the European Commission, and we ensure that third-party processors maintain equivalent protections.
9. Data Retention
| Data Type | Retention Period | Reason |
|---|---|---|
| Customer account data (name, email, plan) | Until account deletion, then 30 days | Service operation; brief grace period for recovery |
| SMS log entries (hashed number, dial code, timestamp, status) | 12 months from send date | Customer analytics; fraud detection |
| Billing records (Stripe customer/subscription ID, invoices) | 7 years | Tax and accounting legal obligations |
| Server access logs (IP, timestamp, request path) | 90 days | Security monitoring and abuse prevention |
| Support emails | 3 years from last correspondence | Service continuity and dispute resolution |
You may request earlier deletion of your account data at any time. See Section 12 for how to exercise this right. Note that we may retain certain data longer where required by law (e.g., billing records) or where legitimate interests justify retention (e.g., fraud investigation).
10. Security
We take reasonable and appropriate technical and organizational measures to protect personal data against unauthorized access, loss, destruction, or alteration. Measures include:
- All data in transit encrypted via TLS 1.2 or higher (HTTPS).
- Passwords stored using a strong one-way hashing algorithm (bcrypt) with per-user salting.
- Database access restricted to application-layer queries; no direct public database exposure.
- Phone numbers in SMS logs stored in hashed form.
- Session tokens regenerated on login; sessions invalidated on logout.
- Access to production systems limited to authorized personnel only.
- Regular review of third-party integrations and API key rotation practices.
No method of electronic transmission or storage is 100% secure. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify affected Customers without undue delay and, where required by law, notify relevant supervisory authorities within 72 hours of becoming aware of the breach.
11. Cookies & Tracking
11.1 On the SendAppTo.Me Website and Dashboard
We use one type of cookie:
- Session cookie (strictly necessary): A single HTTP-only, secure session cookie is set when you log in to keep your session authenticated. It expires when you close your browser or log out. This cookie does not track you across sites and contains only a session identifier.
We do not use advertising cookies, third-party analytics cookies (such as Google Analytics), social media tracking pixels, or any form of cross-site behavioral tracking.
11.2 In Embedded Widgets
The SendAppTo.Me widget is delivered via a JavaScript embed. The widget script does not set any cookies on the Customer's website domain. No tracking scripts, pixels, or fingerprinting code is injected into third-party websites through the widget.
12. Your Rights
Depending on your jurisdiction, you may have some or all of the following rights regarding personal data we hold about you. To exercise any right, contact us at hello@sendappto.me. We will respond within 30 days (or as required by applicable law).
🔍 Right of Access
Request a copy of the personal data we hold about you and information on how it is processed.
✏️ Right to Rectification
Request correction of inaccurate or incomplete personal data we hold about you.
🗑️ Right to Erasure
Request deletion of your personal data, subject to certain legal limitations (e.g., billing records).
⏰ Right to Restrict Processing
Ask us to pause processing of your data in certain circumstances, such as while a dispute is resolved.
📤 Right to Data Portability
Receive a copy of personal data you provided to us in a structured, machine-readable format.
🚫 Right to Object
Object to processing based on legitimate interests, including direct marketing.
🛑 Right to Withdraw Consent
Where processing is based on consent, withdraw it at any time without affecting prior lawful processing.
🧾 Right Not to Be Profiled
We do not engage in automated decision-making or profiling. If this changes, you will have the right to opt out.
We will not discriminate against you for exercising any of these rights. To verify your identity before fulfilling a request, we may ask you to confirm the email address associated with your account. We aim to fulfill all requests within 30 calendar days, or notify you if we need additional time (up to 90 days total for complex requests).
13. California Privacy Rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you additional rights regarding your personal information.
13.1 Categories of Personal Information Collected
In the preceding 12 months, we have collected the following categories of personal information as defined by the CCPA:
- Identifiers: Name, email address, IP address.
- Commercial information: Subscription history and billing records (processed by Stripe).
- Internet or network activity: Server access logs, browser type.
- Geolocation data: Country-level location inferred from dial code only (not precise geolocation).
13.2 Sources
Directly from you at account registration, through use of the Service, and through our payment processor.
13.3 Business or Commercial Purpose
To provide, maintain, and improve the Service as described in Section 5.
13.4 Do Not Sell or Share My Personal Information
We do not sell personal information and we do not share personal information for cross-context behavioral advertising. You do not need to opt out because we do not engage in these activities.
SendAppTo.Me does not sell or share mobile phone numbers, SMS consent information, or SMS opt-in records for marketing or advertising purposes.
13.5 Your California Rights
California residents may:
- Request to know what personal information we collect, use, disclose, and sell.
- Request deletion of personal information (subject to exceptions).
- Request correction of inaccurate personal information.
- Opt out of the sale or sharing of personal information (not applicable — we do not sell).
- Limit the use and disclosure of sensitive personal information (not applicable to our current processing).
- Not be discriminated against for exercising these rights.
To exercise your California rights, contact us at hello@sendappto.me with the subject line "California Privacy Request." We will respond within 45 days.
14. Children's Privacy
The Service is not directed at or intended for use by children under the age of 13 (or under 16 in the EEA and UK). We do not knowingly collect personal information from children. If you are a parent or guardian and believe we have inadvertently collected personal information from a child, please contact us immediately at hello@sendappto.me and we will delete the information as quickly as possible.
Customers are responsible for ensuring that their widget deployments comply with the Children's Online Privacy Protection Act (COPPA) and equivalent laws if their websites or apps are directed at children.
15. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will:
- Update the "Last updated" date at the top of this page.
- Notify registered Customers by email at least 14 days before material changes take effect.
- Where required by law, obtain renewed consent for any new uses of personal data.
Your continued use of the Service after a change takes effect constitutes acceptance of the revised policy. If you do not agree to the revised policy, you should discontinue use of the Service and may request account deletion under Section 12.
16. Contact & Complaints
Privacy Requests
For all privacy-related questions, access requests, deletion requests, or concerns:
Email: hello@sendappto.me
We aim to acknowledge all requests within 2 business days and
resolve them within 30 calendar days.
General Inquiries
Email: hello@sendappto.me
Supervisory Authority Complaints (EEA / UK)
If you are located in the EEA or UK and believe we have not handled your personal data in accordance with applicable law, you have the right to lodge a complaint with your local data protection supervisory authority. In the UK this is the Information Commissioner's Office (ICO). A list of EEA supervisory authorities is available at edpb.europa.eu. We would, however, appreciate the opportunity to address your concerns directly before you contact a regulator.