This Privacy Policy describes how otpmagiclink.com (“we”, “us”, or “our”) collects, uses, and shares information about you when you use our website, dashboard, and API (collectively, the “Service”).
1. Information we collect
We collect the following categories of information:
- Account information. When you sign up we collect your email address, and if you sign in with Google, your name and profile image supplied by Google.
- Verification data. To provide our OTP and magic-link verification service, we process the identifiers (typically email addresses or phone numbers) that you submit through the API. Codes and tokens are stored hashed and expire automatically.
- Usage data. We log API requests, response codes, and timestamps in order to operate the Service, prevent abuse, and bill accurately. Request bodies are not stored in plaintext.
- Waitlist data. If you submit your email to our waitlist form, we store that email so we can notify you when access opens.
2. How we use information
- To operate, maintain, and improve the Service.
- To authenticate you and secure your account.
- To send you transactional email (sign-in links, receipts, security notices).
- To detect, prevent, and investigate fraud or abuse.
- To comply with legal obligations.
3. How we share information
We do not sell your personal information. We share limited data with:
- Sub-processorsthat help us run the Service — Google Cloud (hosting), Resend (transactional email), and Redis Cloud (rate limiting). Each is bound by contractual data-protection terms.
- Law enforcement where required by valid legal process. We will notify you of such requests where legally permitted.
4. Data retention
Verification records are retained for up to 90 days for audit and anti-fraud purposes and then deleted or aggregated. Account data is retained for as long as your account is active. You may request deletion of your account at any time by emailing us; we will process the request within 30 days.
5. Security
We use industry-standard encryption in transit (TLS 1.2+) and at rest. Bearer API keys and OTP codes are stored hashed (SHA-256 with per-record salt). We follow the principle of least privilege for internal access to production data.
6. Your rights
Depending on your jurisdiction (including the EU/UK under GDPR and California under the CCPA), you may have the right to access, correct, port, or delete your personal data, and to object to certain processing. To exercise any of these rights, email support@otpmagiclink.com.
7. International transfers
The Service is operated from the United States. If you access it from outside the U.S., you consent to your information being transferred to and processed in the U.S.
8. Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
9. Changes
We may update this Privacy Policy from time to time. Material changes will be announced by email or in-product notice at least 14 days before they take effect.
10. Contact
Questions about this policy? Email support@otpmagiclink.com.