1. Introduction
We ("SMS & Drip for Twilio") value your privacy. This policy outlines
how we protect your data.
2. Data We Collect
We store the minimum data necessary for automation:
- Account Info: Your monday.com Account ID.
-
Tokens: Encrypted OAuth tokens to
perform actions on your behalf.
-
Twilio Credentials:
-
Data Storage: We do not store
your Twilio Account SID, Auth Token, or Sender Phone Number in
our database.
-
Security: Your Twilio credentials are kept
securely on the monday.com platform. They are only transmitted
to us temporarily within encrypted payloads during automation
executions.
-
Purpose: Used exclusively in memory to execute
SMS deliveries and sequence steps on your behalf.
-
Session & Communication Data: We temporarily track
active communication sessions to handle two-way messaging (SMS
replies). All sensitive identifiers for these sessions (such as
phone numbers and Account SIDs) are securely hashed
(one-way). We do not store plain-text phone numbers in our database.
-
Automation Data: We process board data (phone
numbers, messages) temporarily to execute your
recipes. We do not permanently store board content.
3. Data Retention & Uninstall
Your Data, Your Control. If you uninstall the
application, our system receives a webhook that triggers the
immediate and permanent deletion of your credentials,
tokens, and configuration from our database.
4. Third Parties
We use the following trusted infrastructure providers:
-
monday.com: Hosting & Platform Integration (monday
code).
- Twilio: To execute SMS delivery.
- Supabase: Secure Primary Database.
-
DigitalOcean: Secure Session & Queue Management
(Managed Valkey).
5. Security & User Rights
We take the security of your data seriously and strictly enforce the
following practices:
-
Encryption: All data in transit is protected via
industry-standard HTTPS/TLS. Sensitive secrets (like OAuth Tokens)
are stored using AES-256 encryption at rest.
-
Data Minimization: We only collect, process, and
retain the absolute minimum amount of data necessary to provide our
services. Your Twilio credentials and end-user phone numbers are
securely hashed or kept off our database entirely.
-
Your Rights: In accordance with global privacy
frameworks (such as GDPR and CCPA), you have the right to request
access to, modification of, or deletion of your personal data.
Uninstalling the app will automatically cascade a deletion request
to completely remove your account details from our systems.
6. Contact
For privacy concerns, please contact us at:
support@mofadlalla.io