Privacy & Security

Privacy Policy

Last Updated: January 2025

OTPLESS, Inc. ("OTPless," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our passwordless authentication platform and services (the "Services").

1. Information We Collect

1.1 Information You Provide

When you register for an account or use our Services, we may collect:

  • Account information (name, email address, company name)
  • Contact information (phone number, business address)
  • Payment information (processed securely through third-party payment processors)
  • Communications with our support team

1.2 Authentication Data

When end users authenticate through our Services, we may collect:

  • Mobile phone numbers
  • WhatsApp account identifiers
  • Device information (device type, operating system, browser type)
  • IP addresses and geolocation data
  • Authentication timestamps and session data
  • Device fingerprints for security purposes

2. How We Use Your Information

We use the collected information for the following purposes:

  • Providing and maintaining our authentication Services
  • Processing and verifying user identities
  • Detecting and preventing fraud and security threats
  • Improving our Services and developing new features
  • Analyzing usage patterns and optimizing performance
  • Communicating with you about your account and our Services
  • Complying with legal obligations and enforcing our Terms of Service
  • Providing customer support and responding to inquiries

3. How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances:

3.1 Service Providers

We may share information with third-party service providers who perform services on our behalf, such as:

  • Cloud hosting providers
  • Payment processors
  • Analytics providers
  • Customer support tools

3.2 Business Transfers

If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will provide notice before your information is transferred and becomes subject to a different privacy policy.

3.3 Legal Requirements

We may disclose your information if required to do so by law or in response to valid requests by public authorities, such as a court order or subpoena.

3.4 With Your Consent

We may share your information with third parties when you have given us explicit consent to do so.

4. Data Security

We implement appropriate technical and organizational security measures to protect your information, including:

  • Encryption of data in transit and at rest
  • Regular security assessments and penetration testing
  • Access controls and authentication mechanisms
  • Employee training on data protection practices
  • Incident response and breach notification procedures

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

5. Data Retention

We retain your information for as long as necessary to provide our Services and fulfill the purposes outlined in this Privacy Policy. Authentication logs and session data are typically retained for 90 days for security and fraud prevention purposes. Account information is retained until you request deletion or your account is terminated.

6. Your Rights and Choices

Depending on your location, you may have certain rights regarding your personal information:

  • Access: Request access to the personal information we hold about you
  • Correction: Request correction of inaccurate or incomplete information
  • Deletion: Request deletion of your personal information
  • Portability: Request a copy of your information in a structured format
  • Objection: Object to certain processing of your information
  • Restriction: Request restriction of processing in certain circumstances

To exercise these rights, please contact us at privacy@otpless.com. We will respond to your request within 30 days.

7. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that are different from the laws of your country. We ensure appropriate safeguards are in place to protect your information in accordance with this Privacy Policy.

8. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to collect and track information about your use of our Services. You can control cookies through your browser settings. However, disabling cookies may affect your ability to use certain features of our Services.

Types of cookies we use:

  • Essential cookies: Required for the Services to function properly
  • Analytics cookies: Help us understand how users interact with our Services
  • Preference cookies: Remember your settings and preferences

9. Children's Privacy

Our Services are not intended for children under the age of 13 (or 16 in the European Economic Area). We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

10. California Privacy Rights

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to know what personal information is collected, used, shared, or sold
  • Right to delete personal information
  • Right to opt-out of the sale of personal information (we do not sell personal information)
  • Right to non-discrimination for exercising your CCPA rights

11. GDPR Compliance

If you are located in the European Economic Area (EEA), we process your personal information based on the following legal grounds:

  • Performance of a contract with you
  • Legitimate interests in providing and improving our Services
  • Compliance with legal obligations
  • Your consent (which you may withdraw at any time)

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated Privacy Policy on our website and updating the "Last Updated" date. We encourage you to review this Privacy Policy periodically.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

OTPLESS, Inc.

Data Protection Officer

651 N Broad St, Suite 201

Middletown, DE 19709

New Castle County

Your privacy matters to us

We're committed to protecting your data. If you have questions about how we handle your information, reach out to our privacy team at privacy@otpless.com