otp.com
Integrations
Channels
  • SMS OTP
  • WhatsApp OTP
  • Telegram OTP
  • Email OTP
Pricing Blog Docs
Get Started Login
Integrations Channels
SMS OTP WhatsApp OTP Telegram OTP Email OTP
Pricing Blog Docs
Get Started Login

Privacy Policy

Last updated: August 11, 2026

SUMMARY

Below is a summary of some key terms of this Privacy Policy. This summary is for your reference only and does not form part of the Privacy Policy.

We, Verifykit Yazılım Anonim Şirketi, operating the Otp.com business-to-business verification infrastructure, are committed to protecting personal data processed through our website, dashboard, APIs, SDKs and supported verification channels. This Privacy Policy explains:

  • how we collect personal data;
  • what categories of personal data we collect or process;
  • how we use personal data to provide OTP and verification services;
  • who we share personal data with, including communications, cloud, payment, security and support providers;
  • what measures we take to protect personal data;
  • how long we retain personal data;
  • age limits and restrictions; and
  • the rights and choices available to individuals under applicable data protection laws.

Privacy Policy

  1. Who are we?

    Otp.com (referred to herein as "Otp.com", "our", "we" or "us") gives utmost importance to privacy and the protection of personal data. We prepared this Privacy Policy to explain which personal data we collect or process, how and why we process personal data, and how data subjects may exercise their rights.

    Otp.com is a business-to-business SaaS/API verification infrastructure that enables business customers to send and manage one-time passwords and verification messages to their end users through supported channels such as SMS, WhatsApp, Telegram, email, voice OTP, flash-call, Telegram or other verification channels made available from time to time.

    This Privacy Policy should be read together with our Terms of Service, Cookie Policy, Purchase Policy and, where applicable, Data Processing Addendum. Capitalised terms not defined in this Privacy Policy have the meaning given to them in the Terms of Service.

    Some features may be available only in certain countries, operating systems, device types, subscription tiers or product versions. Additional feature-specific notices may apply. If a feature-specific notice conflicts with this Privacy Policy, the more specific notice will apply to that feature, unless prohibited by law.

    This Privacy Policy does not apply to third-party websites, app stores, payment providers, telecom operators, AI providers or other third parties that process personal data under their own terms, except where they act as our processors or service providers for Otp.com.

  2. Data controller

    Verifykit Yazılım Anonim Şirketi is the data controller with respect to personal data processed for our own business purposes, including account registration, dashboard administration, billing, wallet management, security, support, marketing and website operation. Our contact details are:

    • Verifykit Yazılım Anonim Şirketi
    • Maslak Mah. Buyukdere Cad. Uso Center Plaza No:245 / 27 Sariyer / Istanbul, Turkiye
    • E-mail: info@otp.com

    For personal data relating to the end users of our Customers that is submitted to, transmitted through or generated by the Services for verification purposes, our Customer is normally the data controller or business, and Otp.com acts as processor, service provider or equivalent role under applicable law. In that context, we process such data in accordance with the Customer’s instructions, our Data Processing Addendum and applicable law.

  3. How do we collect personal data?

    We may obtain personal data through the Otp.com website, dashboard, APIs, SDKs, webhooks, integrations, verification flows, support channels, payment flows, security tools and other channels operated by or on behalf of Otp.com.

    In particular, we may collect or receive personal data:

    • directly from Customers or their authorised users when they create an account, use the dashboard, configure integrations, top up the Credit Balance, request support, complete compliance checks or communicate with us;
    • from Customer applications, systems, websites, servers or SDK integrations when a Customer initiates a verification transaction or uses our APIs;
    • from end users of Customers, where their phone number, email address, OTP code, verification identifier or similar data is submitted to the Services as part of a Customer’s verification flow;
    • automatically through logs, headers, cookies, security tools, rate-limiting systems, anti-fraud controls, provider delivery reports and technical monitoring;
    • from third-party service providers, including communications providers, payment providers, identity, security, cloud, support, analytics and e-invoicing providers; and
    • from public authorities, regulators, law enforcement bodies, sanctions screening sources or other legally authorised sources where required for compliance, fraud prevention or legal protection.
  4. What personal data do we collect?

    Otp.com provides B2B verification infrastructure, not a consumer social network, advertising platform or mobile consumer application. The categories below describe the personal data we may collect or process depending on the relevant Customer configuration, integration method, verification channel, payment method, country, provider and feature set. Not every category applies to every Customer, end user or transaction.

    Data that you may provide voluntarily

    • Account and contact information: name, surname, business email address, phone number, username, password or password hash, authentication credentials, company name, company size, sector/industry, role, authorised user information and communication preferences.
    • Business, billing and tax information: company address, billing contact, tax information, invoice information, purchase records, Credit Balance top-ups, credit balance information, order confirmations, invoice numbers, payment status and related commercial records.
    • Support and communication data: support tickets, email correspondence, feedback, complaints, implementation questions, screenshots, files or other information voluntarily shared with us.
    • Compliance and verification information: information requested to verify a Customer, authorised user, use case, campaign, route, destination, payment method, sanctions status, fraud risk, carrier requirement or legal/regulatory requirement.
    • Marketing and lead information: information submitted through contact forms, demo requests, commercial enquiries, events, surveys, newsletters or marketing consent/opt-out records.

    Verification and end-user data processed through the Services

    Where a Customer uses Otp.com to verify its own users, the Services may process data relating to those end users on behalf of the Customer. This may include:

    • phone number/MSISDN, country code, email address or other destination identifier used for OTP delivery;
    • OTP code, validation token, reference ID, request token, verification session identifier, authentication template identifier, callback URL, return URL or similar verification identifiers;
    • channel information, including SMS, WhatsApp, Telegram, email, voice OTP, flash-call, Telegram, Viber or any other channel separately enabled;
    • provider, route, carrier, country, sender, template, delivery receipt, delivery status, error code, submit status, successful submit, chargeable event, attempt count, timestamp and transaction metadata;
    • message content or template content to the extent technically necessary to transmit or troubleshoot the verification message;
    • where SDK or client-side integration is used, technical metadata such as client device ID, IDFV/ANDROID_ID or Customer-generated device ID, operating system, SDK/app version, user-agent, language, timezone, SIM country code, MCC/MNC, carrier information and installed-app availability signals limited to verification method selection; and
    • where operator-based, silent, flash-call or number-intelligence features are separately enabled, IP address, device/network metadata, consentGranted signal, operator response, port information and other data necessary for that specific verification method.

    Otp.com does not use end-user verification data to determine the purposes of processing where it acts as processor. The Customer is responsible for ensuring that it has provided all required notices and obtained all consents or other lawful bases for submitting end-user data to the Services.

    Data that may be collected automatically

    • Technical and log data: IP address, user-agent, browser type, device type, operating system, language, timezone, API request metadata, API key identifier, webhook logs, timestamps, error logs, diagnostic logs, usage metrics and dashboard activity.
    • Security and fraud data: rate-limit signals, traffic patterns, failed attempts, suspicious destinations, abnormal volume, SMS pumping indicators, artificial traffic indicators, bot protection signals, VPN/proxy/threat intelligence, sanctions/compliance flags and abuse investigation records.
    • Location derived from IP or network data: approximate country, region, city or timezone derived from IP address, carrier data or GeoIP tools. Otp.com does not require precise GPS location for the ordinary operation of the Services.
    • Cookie and similar technology data: session cookies, CSRF tokens, bot protection cookies and local storage preferences as described in our Cookie Policy.
    • Payment metadata: transaction ID, timestamp, currency, status, payment method type, risk result, 3DS status, chargeback/reversal status and similar data received from Zotlo or other payment processors. We do not directly collect or store full payment card numbers or CVV codes through the ordinary Otp.com checkout flow.

    Data that we do not intentionally collect

    • We do not request or intend to collect special categories of personal data, such as health, biometric, racial or ethnic origin, political opinion, religion, trade union membership or sexual orientation data, unless expressly required by law or separately agreed for a specific regulated use case.
    • We do not intentionally collect advertising identifiers such as IDFA or GAID, precise GPS location, full phone book/contact lists, IMEI/serial number, microphone, camera or photo library data for the ordinary Otp.com SaaS/API service.
    • Customers must not submit special category data, children’s data or unnecessary content to the Services unless they have obtained our prior written approval and have implemented all required legal safeguards.
  5. Third parties whom the personal data is shared with

    We share personal data only where reasonably necessary for the purposes described in this Privacy Policy, the Terms of Service, the Data Processing Addendum, our Customer instructions, or where required by applicable law. Depending on the configuration and channel used, personal data may be shared with:

    • communications and verification providers, including SMS, WhatsApp, Telegram, email, voice OTP, flash-call, Telegram, Viber, number intelligence, routing, delivery receipt and anti-abuse providers;
    • cloud, hosting, database, queue, storage, monitoring and security infrastructure providers;
    • payment, merchant of record, billing, tax and e-invoicing providers, including Zotlo or other appointed payment or sales intermediaries;
    • bot protection, authentication, geo-location, VPN/proxy/threat detection and fraud prevention providers;
    • CRM, customer support, operational notification, analytics, business intelligence and marketing automation providers used for our business operations;
    • our affiliates, group companies, professional advisers, auditors, insurers and legal representatives;
    • the relevant Customer, where we process end-user verification data on behalf of that Customer; and
    • competent courts, regulators, government agencies, law enforcement authorities or third parties where disclosure is required or permitted by law or necessary to protect our rights, users, Customers, systems or providers.

    Provider involvement does not mean that Otp.com sells end-user verification data or discloses it for unrelated advertising purposes. Communications providers may process certain data in the transmission chain as technically necessary to route, deliver, troubleshoot, secure, bill, verify, comply with law, prevent abuse or satisfy provider-imposed requirements.

  6. How do we use your personal data?

    We may use personal data for the following purposes:

    • to create, administer, authenticate and secure Customer accounts, authorised users, API keys, dashboard access and support interactions;
    • to provide the Services, including initiating, routing, transmitting, validating, billing, reconciling and reporting OTP and verification transactions across supported channels;
    • to display verification status, delivery reports, usage analytics, transaction history, Credit Balance, chargeable events, provider responses and related service information to Customers;
    • to process payments, Credit Balance top-ups, invoices, tax records, refunds, chargebacks, disputes, fraud checks and accounting records;
    • to detect, prevent and investigate spam, phishing, smishing, vishing, OTP abuse, artificial traffic, SMS pumping, traffic stimulation, credential abuse, bot activity, unauthorised access, security incidents and unlawful use;
    • to comply with telecommunications, messaging, email, anti-spam, sanctions, export control, tax, accounting, consumer protection, data protection, e-invoicing, provider, network operator and other legal or industry obligations;
    • to troubleshoot, support, maintain, monitor, test, improve and develop the Services, including route quality, deliverability, provider selection, fraud detection and operational resilience;
    • to communicate with Customers about service notices, technical notices, security alerts, billing updates, policy changes, provider changes, product updates and administrative messages;
    • to send marketing communications where permitted by law, subject to applicable consent or opt-out requirements; and
    • to create aggregated, anonymised or de-identified data that does not identify individuals, for analytics, reporting, forecasting, product development, benchmarking and operational planning, training artificial intelligence systems or for machine learning.
  7. Why do we process your personal data?

    We only collect and use personal data where we have an appropriate legal basis or role under applicable data protection laws. Depending on the context, our grounds for processing may include:

    • Contract performance: to provide the Services, administer Customer accounts, process Credit Balance top-ups, issue invoices, provide support, authenticate users and perform our obligations under the Terms of Service or related agreements.
    • Legitimate interests: to secure the Services, prevent fraud and abuse, detect SMS pumping and artificial traffic, improve route quality, maintain service reliability, enforce our terms, protect our rights, manage business operations and communicate with Customers about the Services.
    • Legal obligations: to comply with tax, accounting, e-invoicing, sanctions, export control, law enforcement, data retention, data protection, consumer protection, telecommunications, messaging, provider or regulatory obligations.
    • Consent: where required for marketing communications, optional cookies, optional verification methods, specific integrations or other activities that require consent under applicable law.
    • Legal claims: where necessary to establish, exercise or defend legal claims, manage disputes, handle chargebacks, enforce contractual rights or respond to legal process.
    • Processing on behalf of a Customer: where we process end-user verification data as processor/service provider, we rely on the Customer’s documented instructions and the Customer’s lawful basis. The Customer is responsible for determining and communicating the relevant lawful basis to its end users.
  8. Who do we share your personal data with?

    When using the Services, personal data may be disclosed to the categories of recipients described in Section 5. In practical terms, this means that:

    • End-user verification data may be routed through telecommunications, messaging, email, WhatsApp, Telegram, Viber, voice OTP, flash-call, number intelligence or other channel providers strictly to deliver, validate, troubleshoot, bill, secure or report the relevant verification transaction.
    • Customer account, billing and payment data may be shared with payment processors, merchant of record/reseller providers, fraud screening providers, tax/e-invoicing providers, banks, card networks and professional advisers.
    • Technical data may be shared with cloud hosting, database, infrastructure, bot protection, security, logging, monitoring, alerting and analytics providers to operate and secure the Services.
    • Support and operational data may be shared with customer support, CRM, business communication and internal notification tools to respond to requests and maintain the Services.
    • Personal data may be disclosed to competent authorities, regulators, courts or law enforcement bodies when legally required or when reasonably necessary to protect rights, prevent abuse, investigate fraud or comply with binding legal process.

    We require service providers that process personal data on our behalf to process it under contractual obligations designed to protect the data and restrict its use to the purposes for which it was disclosed. Where we act as processor, our Customer-facing Data Processing Addendum governs our use of subprocessors.

  9. What cookies do we use?

    A cookie is a small text file placed on your computer or device. We and our service providers may use cookies and similar technologies to provide and secure the Platform, maintain sessions, prevent abuse, remember limited preferences and comply with applicable law.

    The Platform currently uses strictly necessary and security-related cookies such as session identifiers, CSRF protection cookies and Google reCAPTCHA or equivalent bot protection technologies. We may also use local storage for limited user interface preferences such as theme selection. Detailed information about the cookies and similar technologies used on the Platform is available in our Cookie Policy.

    You can manage cookies through your browser settings. If strictly necessary cookies are blocked, some Platform functionality may not work properly. Analytics, performance, advertising or targeting cookies will be used only where implemented and where required consents or notices have been provided.

  10. What steps do we take to keep your personal data safe?

    We implement technical and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration, loss, misuse and destruction. These measures may include encryption in transit, access controls, authentication controls, logging, monitoring, network controls, rate-limiting, segregation of duties, backup controls, provider due diligence and security review processes.

    Customers are responsible for maintaining the confidentiality of their credentials, API keys, tokens, webhook secrets, dashboard accounts and integration endpoints. Customers must immediately notify us of any unauthorised use, suspected compromise or security incident involving their account, integration or end-user data.

    No internet-based service, telecommunications route, messaging channel, cloud platform or security control is completely secure or error-free. To the fullest extent permitted by law, Customers use the Services with knowledge of these inherent risks and must implement appropriate safeguards within their own applications, systems and user flows.

  11. How long do we keep your personal data?

    We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, the Terms of Service, the Data Processing Addendum, our Customer instructions, or as required or permitted by applicable law.

    Retention periods may vary depending on the type of data, the role in which we process it, the Customer configuration, the verification channel, provider requirements, tax/accounting obligations, security needs, dispute risk and legal requirements. For example:

    • OTP codes and temporary verification tokens are intended to be short-lived and are retained only for the period needed to complete or evidence the verification flow, unless longer retention is necessary for fraud, audit, dispute, provider or legal reasons;
    • verification event records, delivery receipts, routing records, successful submit records, chargeable event records and related logs may be retained as needed for billing, reconciliation, fraud prevention, provider disputes, security, compliance and legal claims;
    • Customer account, invoice, payment, tax and accounting records may be retained for the statutory period required by applicable law;
    • support and correspondence records may be retained for the duration necessary to respond to requests, improve the Services, document decisions and protect our legal rights; and
    • aggregated, anonymised or de-identified information may be retained for longer where it no longer identifies an individual.

    Where we process end-user verification data as processor, Customers may request deletion, return or export in accordance with the Data Processing Addendum, subject to legal, security, billing, provider and legitimate retention requirements.

  12. Do we transfer your personal data outside of the country you are resident?

    Otp.com is a global B2B verification infrastructure. Personal data may be transferred to, accessed from, stored or processed in countries other than the country in which the individual or Customer is located. These countries may have data protection laws that differ from those in the individual’s country of residence.

    Where required, we use appropriate transfer mechanisms, which may include adequacy decisions, Standard Contractual Clauses, UK International Data Transfer Addendum or Agreement, EU-US Data Privacy Framework participation where applicable, transfer impact assessments, local transfer mechanisms, explicit consent where legally appropriate, or other safeguards recognised by applicable law.

    Customers acknowledge that the use of global telecommunications, messaging, email, cloud, payment, support and security providers may require international transfers as part of delivering, routing, securing, billing and supporting the Services. Where we act as processor, the Customer authorises such transfers under the Data Processing Addendum and is responsible for ensuring that its own notices and consents cover such transfers where required.

  13. Age Limits

    The Services are intended for business Customers and authorised users who are at least eighteen (18) years old and have legal capacity to act on behalf of a business. We do not knowingly permit children or persons under 18 to create Customer accounts or use the dashboard.

    Because Customers may use Otp.com to verify their own end users, the Customer is responsible for determining whether its own service is directed to children and for obtaining any parental consent, age-gating, notice or legal basis required for processing children’s data. Customers must not use the Services to process children’s data in violation of applicable law.

  14. Your personal data rights and how to contact us

    Depending on your jurisdiction and our role in relation to the relevant personal data, you may have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, opt-out of certain processing, information about transfers and third-party recipients, and the right to lodge a complaint with a competent data protection authority.

    You may exercise your rights by contacting us at info@otp.com. We may need to verify your identity and request additional information to process your request. We will respond within the period required by applicable law.

    Where your request relates to end-user verification data that we process on behalf of a Customer, we may direct you to the relevant Customer or process the request in accordance with the Customer’s instructions, unless we are legally required to respond directly.

    California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA) Compliance

    We do not sell Personal Information or share Personal Information for cross-context behavioural advertising as those terms are defined under the CCPA/CPRA. We also do not use or disclose Sensitive Personal Information for purposes other than those permitted by the CCPA/CPRA without required consent.

    Where we process end-user verification data for a Customer, we generally act as a service provider or contractor and process such data for the limited business purposes described in our agreements with the Customer. California residents may have the right to know, access, delete, correct, opt-out, limit certain sensitive information processing and not be discriminated against for exercising privacy rights, subject to legal exceptions.

    General Data Protection Regulation (GDPR), UK GDPR and KVKK Compliance

    If you are in the European Economic Area, United Kingdom or Turkiye, we process personal data under applicable data protection laws, including where relevant the GDPR, UK GDPR and Turkish Law on the Protection of Personal Data No. 6698. Our legal bases may include contract performance, legitimate interests, legal obligations, consent and legal claims, as further described in this Privacy Policy.

    You may have the right to contact your local data protection authority. For Turkiye-based data subjects, this may include rights under Law No. 6698 to learn whether personal data is processed, request information, learn the purpose of processing, learn third-party recipients, request correction or deletion, object to certain automated results and request compensation for unlawful processing, subject to applicable legal conditions.

    Law Enforcement, Government and Regulatory Requests

    We will disclose personal data to law enforcement, government agencies, courts or regulatory bodies only where we believe disclosure is necessary to comply with a binding legal obligation, valid legal process, provider or network obligation, or to protect rights, safety, security, users, Customers, providers or the integrity of the Services. Where legally permitted and reasonably practicable, we may challenge overbroad or inappropriate requests.

    Data Breach and Security Incident Communications

    If we become aware of a personal data breach requiring notification under applicable law, we will take steps to investigate, contain and remediate the incident and notify affected Customers, individuals and/or supervisory authorities where required by law and within the legally required timeframe. Where we act as processor, breach notifications will be handled in accordance with the Data Processing Addendum.

  15. Changes to this Privacy Policy

    We may change this Privacy Policy at any time. The latest version of the Privacy Policy will be published on the Platform or otherwise made available to Customers. Unless a different effective date is stated, the updated Privacy Policy becomes effective when published. Customers and authorised users are responsible for periodically checking the latest version.

  16. Information Relating to Children

    Our Services are intended for business use by persons over the age of 18. We do not knowingly collect personal data directly from children for the purpose of creating Customer accounts. If we learn that a child has created an account in violation of this Privacy Policy, we will take appropriate steps to delete or deactivate the account, subject to legal and security requirements.

    Where a Customer submits end-user data relating to minors, the Customer is solely responsible for ensuring that such processing complies with applicable law, including any consent, notice, age verification, parental authorisation and data minimisation obligations. Customers must not use Otp.com for child-directed services or to process children’s data unless they can lawfully do so and have implemented all required safeguards.

otp.com

Global OTP via SMS, WhatsApp, Telegram & Email. One API. Transparent pricing. No sales call.

info@otp.com

Product

  • Features
  • Pricing
  • Blog
  • Docs
  • FAQ
  • Changelog

Channels

  • SMS OTP
  • WhatsApp OTP
  • Telegram OTP
  • Email OTP

Blog

  • Engineering
  • Guides

Legal

  • Privacy Policy
  • Terms of Service
  • Purchase Policy

Resources

  • llms.txt
  • Sitemap
  • Blog RSS
  • Changelog RSS
© 2026 otp.com
🇪🇺 GDPR Compliant
🍪

We use cookies to keep otp.com running and secure. With your consent, we'd also like to use analytics cookies to understand how the site is used. See our Privacy Policy for details.

Strictly necessary

Required for the site and dashboard to function. Always on.

Analytics

Helps us understand usage. Off by default.