Privacy Policy
Last updated October 10, 2026
This privacy policy explains what data ColdTexting collects from account holders and from the contacts they text, why it is processed, which categories of service providers receive it, how long it is kept and how to request access, correction or deletion by email.
1. Who we are and what this policy covers
ColdTexting is a business texting service operated by the administrator of the coldtexting.com service ("we", "us"), reachable at [email protected]. This policy covers the website coldtexting.com, the ColdTexting application and the messages our customers send through it.
We handle two kinds of personal data. Account data belongs to the people who sign up for and use ColdTexting, and for this data we decide why and how it is processed, so we act as the controller. Contact data belongs to the people our customers text, and for this data our customer is the controller and we process it only on the customer's instructions, as described in section 5.
2. Data we collect from account holders and visitors
- Account details. Name, business email address, password (stored only as a one-way hash), workspace name, team members and their roles.
- Business registration details. Legal business name, tax ID, address, website and the contact person you enter for 10DLC brand and campaign registration.
- Billing records. Plan, billing period, invoices and payment status. Card numbers are entered directly with our payment operator and never reach our servers.
- Usage and security logs. IP address, browser type, sign-in times, audit log entries and the actions taken in your workspace.
- Compliance checker input. Text you paste into the checker on our website, the use case and recipient state you select and the result, stored under a random link so you can return to it. We use the IP address to apply the daily check limit.
- Support messages. What you write to [email protected] and our replies.
3. Contact data our customers upload
When a customer uses ColdTexting, the service stores the contact data needed to send and receive their messages: mobile number, name and other fields the customer imports, consent records (source, timestamp, IP address and the form text the contact agreed to), message content, delivery events, replies and opt-out status. We use this data only to deliver the customer's messages, enforce consent and opt-out rules, keep the audit log and provide support.
If you received a text from a business that uses ColdTexting, that business decides why it texts you. Reply STOP to any message to opt out at once. For access or deletion requests, contact the business directly, or write to us and we pass your request to them.
4. Why we use account data and on what legal basis
- To provide the service you signed up for, including billing and support (performance of a contract).
- To keep the service secure, prevent abuse, enforce our Acceptable Use Policy and keep records that carriers and regulators expect (legitimate interests and legal obligations).
- To send service emails such as sign-in codes, billing receipts and notices about changes (performance of a contract).
- To meet tax and accounting duties (legal obligation).
We do not use personal data for automated decisions that have legal or similarly significant effects on you, and we do not train artificial intelligence models on your messages or contacts.
5. Our role as processor of contact data
For contact data, the customer is the controller and we are the processor. We process contact data only to provide ColdTexting to that customer, keep it confidential, protect it with the measures described on our security page, help the customer answer requests from contacts, and delete or return it when the customer deletes it or closes the account. Enterprise customers can sign our data processing agreement. The customer is responsible for having a valid legal basis and valid consent for every contact.
6. Who receives personal data
We share personal data only with the categories of service providers we need to run ColdTexting, each bound by a contract that limits use to providing their service to us:
- a hosting provider in the EU, which runs our servers and databases,
- a payment operator, which processes subscription payments and card checks,
- an email delivery provider, which sends sign-in codes, receipts and service notices,
- telecom carriers and messaging providers, which deliver text messages and process 10DLC brand and campaign registrations,
- integrations a customer connects, such as a CRM, which receive data only when the customer turns the integration on,
- public authorities, when the law requires us to disclose data.
We do not sell personal data and we do not share it for cross-context behavioral advertising.
7. SMS opt-in data is never shared for marketing
Mobile numbers and SMS opt-in consent collected through ColdTexting are never sold, rented or shared with third parties or affiliates for their own marketing purposes. They are used only to deliver the messages the contact agreed to receive. This applies to every customer workspace.
8. Cookies
We use only essential cookies: a session cookie that keeps you signed in, a security token that protects forms against cross-site request forgery and, if you choose it, a remember me cookie. We do not use advertising cookies, cross-site tracking or third-party analytics cookies, so there is no cookie banner to accept.
9. How long we keep data
- Account and workspace data, for as long as the account is open.
- Contact data, consent records and messages, until the customer deletes them or closes the account. Customers can delete contacts at any time. Deletion is final after a short recovery window kept for accidental deletes.
- Opt-out records, for as long as the account is open, so that an opted-out number is never texted again by mistake.
- Billing records, for as long as tax and accounting law requires.
- Compliance checker results from the website, for a limited time, after which they are deleted.
- Backups, on a rolling schedule, after which deleted data disappears from them too.
10. Security
Data is encrypted in transit with TLS and at rest. Access inside a workspace follows roles, staff access is limited to what support and operations need, and every send, import, consent change and settings change is written to an audit log. More detail is on the security page.
11. International transfers
Our servers are hosted in the EU. Text messages to US numbers are delivered by telecom carriers in the United States, so message content and phone numbers travel to them for delivery. Where personal data leaves the EU, we rely on safeguards recognized by law, such as standard contractual clauses.
12. Rights of California residents
If you live in California, you have the right to know what personal information we collect, use and disclose, to request a copy, to request correction and deletion, to opt out of the sale or sharing of personal information (we do neither), to limit the use of sensitive personal information (we use it only to provide the service) and not to be treated differently for using these rights. You can use an authorized agent. We verify each request by matching it with the account email address.
Categories collected in the last 12 months are identifiers, commercial information (plan and billing history), internet activity (logs) and professional information (business details), all from you or your use of the service, for the purposes in section 4 and disclosed only to the categories in section 6.
13. Rights of EU, EEA and UK residents
You have the right to access your personal data, correct it, delete it, restrict or object to its processing, receive it in a portable format and withdraw consent where processing relies on consent. You can also lodge a complaint with your local data protection authority. Residents of other US states with privacy laws can make the same requests and we answer them the same way.
14. How to make a request
Email [email protected] from the address on your account and say what you want us to do. We answer within the time limit set by the law that applies to you, usually 30 days for EU requests and 45 days for California requests. If you are a contact of one of our customers, tell us which business texted you, and we pass the request to them.
15. Children
ColdTexting is a business service for adults. We do not knowingly collect data from anyone under 18, and customers may not use it to text children.
16. Changes to this policy
When we change this policy, we update the date at the top. If a change materially affects how we use account data, we tell account owners by email before it takes effect. The Terms of Service explain the rest of our agreement with customers.
17. Contact
Questions about privacy go to [email protected].
Operator of ColdTexting
ColdTexting is operated by the administrator of the coldtexting.com service. Write to [email protected] with any question about this document.