1. Introduction
SendPK (“SendPK,” “we,” “us” or “our”) is a PTA-Approved SMS Aggregator headquartered in Lahore, Punjab, Pakistan, serving corporate, government, financial, educational, healthcare and individual clients since 2014. We operate a Bulk SMS, Transactional SMS, OTP SMS, Branded (masked) SMS, Short Code SMS and WhatsApp Business Messaging platform, delivered through a web Customer Portal and a set of HTTP/WhatsApp APIs.
This Privacy Policy applies to (a) visitors of our website, (b) registered users of our Customer Portal, dashboard and reseller accounts, (c) developers and systems integrating with our APIs, and (d) end recipients whose mobile numbers are processed on our network as a result of messages sent by our customers. It should be read together with our Terms & Conditions, which govern your use of our services more broadly.
By creating an account, accessing our Customer Portal, integrating with our API, or otherwise using our services, you acknowledge that you have read and understood how information is handled as described below.
2. Our Commitment to Privacy
Trust is the foundation of a messaging business. Enterprises, banks, government departments, hospitals and universities rely on us to move sensitive communications — one-time passwords, account alerts, appointment reminders, admission notices — reliably and confidentially. We design our practices around the following principles:
- Purpose limitation — data is collected and processed only for the purposes described in this Policy or disclosed to you at the point of collection.
- Data minimization — we collect what is reasonably necessary to provision, deliver, secure and bill for the service, and no more.
- Security by design — encryption, access control and monitoring are built into the platform, not bolted on afterward.
- Transparency — this Policy is written to be read and understood, not to obscure our practices.
- Accountability — we remain responsible for data we process even where a sub-processor or telecom partner is involved in delivery.
We do not sell personal data
SendPK does not sell, rent or trade personal information, customer recipient lists, or message content to data brokers or third parties for their own marketing purposes — under any circumstances.
3. Definitions
The following terms carry the meaning below wherever they are used in this Policy:
| Term | Meaning |
|---|---|
| “Client” / “Customer” / “You” | The individual or organization that registers for and uses our Customer Portal, API or reseller services. |
| “End Recipient” | An individual who receives an SMS or WhatsApp message sent by a Customer through our platform. |
| “Sender ID” / “Mask” | The registered brand name that appears as the sender of a Branded SMS in place of a phone number, approved by PTA. |
| “Bulk SMS” | Non-personalized or mail-merge text messages sent in volume to a Customer’s own recipient list. |
| “Transactional / OTP SMS” | High-priority, non-marketing messages such as one-time passwords, account alerts and delivery notifications, typically sent via Short Code routes. |
| “WhatsApp Business Platform” | Messaging delivered via the official WhatsApp Business API (Meta-operated) or via our WhatsApp Non-Official messaging service. |
| “API” / “API Key” | The HTTP interface and the unique credential used to authenticate programmatic requests to our platform. |
| “Message Content” | The text, template variables or media of a message submitted for delivery, excluding routing metadata. |
| “Telecom Operator(s)” | Jazz, Zong, Telenor and Ufone — the mobile network operators over which messages are delivered in Pakistan. |
| “PTA” | The Pakistan Telecommunication Authority, the regulator of telecom and SMS aggregator services in Pakistan. |
| “Portal” / “Dashboard” | The web-based application through which Customers manage campaigns, view reports and configure their account. |
| “Personal Data” / “Personal Information” | Any information relating to an identified or identifiable natural person, as further described in Section 4. |
4. Information We Collect
We collect information across three broad relationships: (i) our own website visitors, (ii) our registered Customers and their authorized users, and (iii) End Recipients whose numbers are processed for message delivery on a Customer’s instruction. The table below summarizes each category; the subsections that follow describe them in more detail.
| Category | Examples |
|---|---|
| Personal Information | Name, CNIC, designation, mobile number, email address |
| Business Information | Company name, NTN, business address, letterhead, authorized representative details |
| Billing Information | Invoice records, bank/payment reference, transaction history, tax details |
| Technical Information | IP address, API request logs, error logs, authentication logs |
| Device Information | Browser type, operating system, screen size, referring URL |
| Cookies | Session identifiers, CSRF tokens, portal preferences |
| Usage Analytics | Pages visited, feature usage, campaign volumes, aggregate delivery statistics |
| Communication Records | Support tickets, WhatsApp/phone support transcripts, email correspondence |
4.1 Personal Information
When you register for an account, apply for Sender ID/mask approval, or contact support, we collect your name, CNIC, job title, mobile number and email address. Verification of certain services (for example Branded SMS masking or WhatsApp Official onboarding) additionally requires a CNIC copy and, where applicable, a photograph for identity confirmation, consistent with PTA’s verification requirements.
4.2 Business Information
For business accounts we collect your registered company name, National Tax Number (NTN), business address, company letterhead, and the name/designation/CNIC of your authorized representative — required to register a Sender ID with PTA and to issue compliant invoices.
4.3 Billing Information
We maintain records of invoices, payment confirmations, bank transfer references, and account credit/debit history. We do not store full card numbers on our own servers where a third-party payment processor is used; see Section 14 (Third-Party Services).
4.4 Technical Information
Our servers and APIs automatically log the IP address, request timestamp, endpoint called, HTTP status code and API key used for every request — necessary for delivery, billing reconciliation, rate-limiting and abuse detection.
4.5 Device Information
When you access our website or Customer Portal, we collect standard device/browser information (user agent, screen resolution, operating system) to render the interface correctly and to detect anomalous login activity.
4.6 Cookies
We use a limited set of first-party cookies for session management, CSRF protection and portal preferences. See Section 17 (Cookies Policy) for the full list and how to control them.
4.7 Usage Analytics
We aggregate usage patterns — message volumes by service type, feature adoption, error rates — to improve platform reliability and capacity planning. Analytics are self-hosted; we do not embed third-party advertising trackers on our website or Portal.
4.8 Communication Records
Support tickets, WhatsApp chat transcripts and call notes with our support team are retained to resolve your query, to maintain a service history, and to train our support staff on recurring issues.
5. How We Collect Information
- Directly from you — account registration forms, KYC/verification documents, support tickets, sales inquiries, and information you enter into the Customer Portal.
- Automatically — server logs, API request/response logs, cookies and similar technologies when you use our website, Portal or API.
- From your own platform activity — recipient lists you upload, message templates you create, and delivery/billing data generated as your campaigns run.
- From Telecom Operators — delivery status codes and timestamps returned as part of standard delivery-report (DLR) exchange.
- From third parties acting on your behalf — payment confirmations from banks/payment processors, and identity checks from verification service providers, where used.
6. Purpose of Data Collection
We process information only for clearly defined, legitimate business purposes, including to:
- Create and administer your account, and provision Bulk SMS, OTP, Branded SMS, Short Code SMS and WhatsApp Business services.
- Verify your identity and business details for Sender ID/mask registration and WhatsApp Business onboarding, as required by PTA and Meta respectively.
- Route, deliver and generate delivery reports for messages submitted through the Portal or API.
- Generate invoices, process payments and reconcile account balances.
- Detect, investigate and prevent fraud, spam, unauthorized access and Acceptable Use Policy violations.
- Comply with PTA regulations, tax law, and lawful requests from courts or law enforcement.
- Provide customer support and respond to inquiries.
- Improve platform performance, reliability and new feature design using aggregated, de-identified analytics.
- Send you service and security notices, and, where you have opted in, marketing communications about our own services.
7. SMS & WhatsApp Platform Data Processing
When you use our platform to send messages, two distinct roles apply. You, the Customer, act as the data controller for the recipient numbers and content you upload or submit — you determine who receives a message and why, and you are responsible for obtaining any consent required under the Terms & Conditions’ Anti-Spam Policy. SendPK acts as a data processor / service provider: we transmit your message to the destination network exactly as instructed, without altering its content, and we do not use recipient data collected in this capacity for our own marketing purposes.
Controller vs. processor, in practice
If a recipient wishes to stop receiving messages from your brand, that request must be honored by you, the Customer, as the controller of that relationship. We provide opt-out tooling (e.g. STOP-keyword handling on supported routes) to help you comply.
Official WhatsApp Business Platform messages are additionally routed through Meta’s infrastructure and are subject to the WhatsApp Business Messaging Policy and Meta’s own data-handling terms, which apply alongside this Policy. WhatsApp Non-Official messaging is delivered over device-linked sessions and carries the same confidentiality obligations described throughout this Policy.
8. API Data Handling
Our SMS and WhatsApp APIs authenticate every request using a unique api_key, which we treat as a security credential equivalent to a password. All API traffic is required to run over HTTPS/TLS; plaintext HTTP requests carrying an API key are rejected or strongly discouraged.
- Request and response metadata (endpoint, timestamp, status code, message ID) is logged for delivery tracking, billing reconciliation and rate-limit enforcement.
- We recommend rotating your API key periodically and immediately if you suspect it has been exposed; a compromised key can be regenerated from the Portal at any time.
- Automated systems scan API traffic patterns for abuse signals (e.g. sudden volume spikes, blacklisted content patterns) as part of fraud prevention — this is pattern-based, not manual reading of routine traffic.
- We do not share your API key, request logs or integration details with any third party except where necessary to investigate abuse, fraud or a security incident, or as required by law.
9. Message Content Handling
Message content (the text, template variables or media you submit) is processed to queue, deliver, retry on failure, and match against delivery reports. Content is retained only for the period reasonably necessary for these purposes and for the retention schedule described in Section 10.
- Message content is not read by staff as a matter of routine; access is restricted to automated processing and to authorized personnel investigating a specific support ticket, fraud report or lawful request.
- OTP and other time-sensitive transactional content is purged from active queues immediately after delivery confirmation or expiry, whichever comes first.
- We do not use your message content to build advertising profiles, and we do not share it with data brokers.
10. Data Retention Policy
We retain information only for as long as necessary to fulfil the purposes described in this Policy, to meet our contractual commitments to you, and to satisfy tax, telecom and other statutory retention requirements in Pakistan.
| Data Category | Typical Retention Period | Reason |
|---|---|---|
| Account & KYC records | Duration of account, plus 5 years after closure | Regulatory/audit requirements, dispute resolution |
| Message content (SMS/WhatsApp) | Up to 90 days from delivery, OTPs typically far sooner | Delivery retries, dispute investigation, fraud review |
| Delivery reports / call detail records | Up to 3 years | Telecom operator & PTA compliance, billing disputes |
| Billing & transaction records | Up to 6 years | Tax law and financial audit requirements |
| API access logs | Up to 12 months | Security monitoring, abuse investigation |
| Support tickets & communication records | Up to 3 years | Service history, quality assurance |
| Cookies (session/functional) | Session to 12 months, per cookie type | See Section 17 |
| Marketing consent records | Duration of consent, plus 2 years after withdrawal | Evidence of lawful opt-in/opt-out |
Retention can override a deletion request
Where a statutory, tax, telecom or contractual retention obligation applies, we may retain the minimum necessary data even after a deletion request is honored elsewhere in your account — see Section 24.
11. Customer Database Protection
Recipient lists, contact databases and CSV/Excel uploads you provide for Bulk SMS, Dynamic/personalized SMS or WhatsApp campaigns are treated as confidential Customer Data:
- Stored in logically isolated, account-scoped storage — never pooled or merged with another Customer’s data.
- Accessible only to your authorized Portal users and to staff who require access to resolve a specific support issue.
- Never used by SendPK to send our own marketing messages, and never sold or shared with other Customers.
- Deleted or anonymized on request, subject to the retention exceptions in Sections 10 and 24.
12. Data Encryption & Security
- All traffic to our website, Customer Portal and APIs is encrypted in transit using TLS.
- Passwords are stored using salted, one-way cryptographic hashing — never in plain text.
- API keys and other sensitive credentials are stored using industry-standard hashing/encryption at rest.
- Network segmentation, firewalls and intrusion-detection controls protect our production infrastructure.
- Systems are patched on a regular schedule, and changes follow a secure software development lifecycle.
- Backups are encrypted and access to them is restricted and logged.
- We maintain an internal security-incident response process for suspected breaches, including customer notification where required by law.
13. Access Control
Internal access to Customer Data and message content follows the principle of least privilege:
- Role-based access control limits each staff member to the systems and data required for their function.
- Administrative and infrastructure access requires multi-factor authentication.
- Access to production systems and message content is logged and periodically reviewed.
- Access is revoked immediately upon a staff member’s change of role or departure.
14. Third-Party Services
We work with a limited set of third parties strictly to operate the service — never to sell your data. Each is bound by confidentiality and data-handling obligations appropriate to the service it provides:
| Category | Purpose |
|---|---|
| Telecom Operators (Jazz, Zong, Telenor, Ufone) | Message routing and delivery over their networks |
| WhatsApp Business Platform (Meta) | Delivery of official WhatsApp Business messages |
| Payment processors / banks | Processing account top-ups and invoice payments |
| Cloud & hosting infrastructure | Hosting the Portal, API and databases |
| Verification service providers | Identity/KYC checks for account and Sender ID approval |
| Professional advisors | Auditors and legal counsel, under confidentiality obligations |
We do not permit these parties to use your data for their own independent marketing purposes, and we require contractual confidentiality commensurate with the sensitivity of the data shared.
15. Telecom Operator Compliance
To deliver your messages, we share only what is strictly necessary with Jazz, Zong, Telenor and Ufone: the approved Sender ID/mask, the destination number, the message content, and delivery timestamps — exchanged under standard interconnect/aggregator agreements and PTA-mandated technical protocols.
Telecom Operators may independently retain call/message detail records under their own licensing obligations to PTA; such retention is outside SendPK’s direct control but is subject to the same regulatory framework that governs our own operations, and we require operator partners to treat this data as confidential.
16. PTA Regulatory Compliance
PTA-Approved SMS Aggregator
We operate as a Pakistan Telecommunication Authority (PTA) approved SMS aggregator and structure our data practices around PTA’s regulatory framework for bulk messaging and Sender ID/mask registration.
- Sender ID/mask applications are submitted to PTA together with the business KYC you provide (NTN, CNIC, signed and stamped letterhead), and we retain these approval records for the life of the mask and thereafter as required by PTA.
- Our platform is built to support compliance with PTA’s consumer-protection and anti-spam directives, including permissible sending windows and opt-out handling for promotional traffic.
- We cooperate with lawful requests and directives from PTA, and from law-enforcement and judicial authorities acting under the Prevention of Electronic Crimes Act, 2016 (PECA) and other applicable Pakistani law.
- Where Pakistan’s data protection legislation is enacted into law, we will update this Policy and our internal practices to align with its requirements.
18. Marketing Communications
We may send you promotional SMS, WhatsApp or email messages about our own services (for example new features or pricing updates) only where you have opted in, or where permitted by applicable law for existing customers regarding similar services. You can opt out at any time by replying STOP to an SMS, using the unsubscribe link in an email, or updating your notification preferences in the Portal.
This section is about SendPK’s own marketing — not yours
Opting out of our marketing has no effect on the campaigns you run for your own recipients. As the controller of your recipient data, you remain responsible for obtaining consent and honoring opt-outs for your own promotional traffic under the Terms & Conditions’ Anti-Spam Policy.
19. Email Communications
- Transactional emails — account confirmations, invoices, delivery/balance alerts and security notices are sent regardless of marketing preference, as they are necessary to operate your account.
- Marketing emails — sent only with consent as described in Section 18, with an unsubscribe link honored within a reasonable period, generally no more than 10 business days.
- We authenticate our outbound email using standard mechanisms (SPF/DKIM) to help you distinguish genuine SendPK correspondence from spoofed messages.
We will never ask for your password by email
If you receive an email requesting your password, API key or CNIC outside of our official Portal, treat it as suspicious and report it to [email protected].
20. Account Security
You are responsible for maintaining the confidentiality of your Portal password and API key(s), and for all activity that occurs under your credentials. We recommend:
- Using a strong, unique password for your SendPK account.
- Restricting API key access to systems and personnel that genuinely need it.
- Notifying us immediately at [email protected] if you suspect unauthorized access to your account.
On our side, we apply rate-limiting on login attempts, monitor for anomalous authentication patterns, and can suspend suspicious sessions pending verification.
21. International Data Transfers
Our core infrastructure and Customer Data are hosted in facilities we have vetted for security and reliability. Where a sub-processor operates outside Pakistan — for example, official WhatsApp Business Platform messages routed through Meta’s global infrastructure, or an encrypted offsite backup location — we limit the transfer to what is necessary for that specific service and require contractual confidentiality and security commitments from the receiving party consistent with this Policy.
If you are a government, financial or healthcare customer with specific data-residency requirements, contact [email protected] to discuss the options available for your account.
22. User Rights
Subject to applicable law and the retention exceptions described in Section 10, you have the right to:
- Access the personal information we hold about you.
- Correct inaccurate or outdated information (Section 23).
- Request deletion of your personal information (Section 24).
- Object to or restrict processing for marketing purposes at any time.
- Request an export of your account and campaign data in a portable format.
- Withdraw consent where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
- Lodge a complaint with PTA or a competent court in Pakistan if you believe your rights have been infringed.
We aim to respond to verified rights requests within 30 calendar days. Complex requests may take longer, in which case we will notify you of the expected timeline.
23. Data Correction
Most profile fields can be updated directly from your Customer Portal. Fields tied to KYC verification — such as the registered business name, NTN or Sender ID details — require a fresh supporting document (e.g. an updated letterhead) submitted via a support ticket, so that the correction can be verified before it replaces a PTA-approved record.
24. Data Deletion Requests
To request deletion of your personal information, email [email protected] from your registered account email address. We will:
- Verify your identity as the account holder or an authorized representative.
- Confirm which data can be deleted immediately and which must be retained under Section 10’s schedule (for example, invoices required for tax audit purposes).
- Complete eligible deletions within 30 calendar days and confirm completion in writing.
Because a deletion request typically requires closing the associated account, ongoing campaigns, API access and Portal access will end once processed.
25. Children’s Privacy
Our services are not directed at children
SendPK’s Customer Portal, API and reseller program are intended for use by businesses and individuals who have reached the legal age of contractual capacity in Pakistan (18 years). We do not knowingly collect personal information from minors as account holders.
If we become aware that an account has been registered by a minor without appropriate authorization, we will suspend the account and delete the associated data, subject to any retention required by law. Customers who use our platform to message their own end recipients remain responsible for ensuring their campaigns comply with applicable laws regarding minors.
26. Legal Disclosure
We may disclose information without further notice to you where required or permitted by law, including to:
- Comply with a valid court order, PTA directive, or a request from law-enforcement or a government authority acting under PECA 2016 or other applicable Pakistani law.
- Protect the rights, property or safety of SendPK, our customers, or the public, including to prevent or investigate fraud, spam or security incidents.
- Enforce our Terms & Conditions or investigate potential violations of them.
Where legally permitted, we will notify the affected Customer before disclosing their data in response to a third-party legal request.
27. Business Transfers
If SendPK is involved in a merger, acquisition, financing, reorganization or sale of some or all of its assets, personal information may be transferred as part of that transaction. Any successor entity will remain bound by the commitments in this Privacy Policy with respect to previously collected data, and we will notify affected Customers via email, Portal notice or a notice on our website before data is transferred and becomes subject to a different privacy policy, if any.
28. Limitation of Liability
We implement industry-standard administrative, technical and physical safeguards to protect information under our control; however, no method of transmission over the internet or mobile networks, and no method of electronic storage, is 100% secure. To the maximum extent permitted by applicable law, and without prejudice to the more detailed liability provisions in our Terms & Conditions, SendPK is not liable for:
- Unauthorized access resulting from your failure to safeguard your password, API key, or device.
- Data loss, delay or exposure caused by a Telecom Operator’s or WhatsApp/Meta’s network or systems, outside our direct control.
- Events of Force Majeure as defined in our Terms & Conditions.
29. Disclaimer
This Privacy Policy describes our general data practices in good faith and is intended to be a comprehensive, plain-language reference. Specific processing arrangements agreed in a signed enterprise service agreement, data-processing addendum, or reseller contract with a particular Customer will govern in the event of any conflict with this Policy. Nothing in this Policy creates rights for any End Recipient against SendPK beyond those available under applicable Pakistani law.
30. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, technology, or applicable law. Material changes will be announced via a notice on our website, an in-Portal banner, or email to registered Customers, together with an updated “Last Updated” date at the top of this page. Your continued use of our services after the effective date of an update constitutes acceptance of the revised Policy. We encourage you to review this page periodically.
31. Contact Information
For questions, concerns or requests relating to this Privacy Policy or how your data is handled, please reach out through any of the channels below. We aim to acknowledge privacy inquiries within 2 business days.
Privacy & Legal Inquiries
Our privacy and legal teams are available to answer questions about data handling, PTA compliance, and enterprise data-processing arrangements.