Data & Privacy Policy
Last updated: 16 May 2026
1. Introduction
Texto is a product offered by Floop Pty Ltd (ABN 65 689 489 629) ("we", "us", "our"). Texto is an SMS messaging platform designed for Australian businesses to communicate with their customers via text message.
We take a privacy-by-design approach to building and operating the Texto Platform. This Data & Privacy Policy explains what data we collect, how we store and protect it, and your rights regarding your information.
2. Data We Collect
We collect and process the following categories of data:
- Sign-up profile data: Your name, email address, and company details provided during account registration.
- Billing information: Payment and subscription details processed securely via Stripe. We do not store your full credit card details on our servers.
- Message content: The SMS messages you send and receive through the Texto Platform. Messages are encrypted at rest and transmitted securely via licensed onshore Australian mobile carriers.
- Message metadata: Sender ID, recipient mobile number, timestamp, delivery status, message length, and routing information associated with each message. Metadata is retained for 2 years as required by Australian telecommunications data retention laws (Telecommunications (Interception and Access) Act 1979 (Cth), Part 5-1A).
- Sender ID and KYC supporting documents: ABN evidence, business registration documents, brand materials, and any other information you supply to register a Sender ID or satisfy carrier / ACMA verification requirements. These documents are retained for the life of the Sender ID registration and may be shared with our aggregator and carrier partners as required for registration and ongoing compliance.
- Support correspondence: Messages you send to our support team, including any attachments.
- Technical and usage data: IP address, device type, browser, timestamps, and platform usage logs, used for security, fraud prevention, and service improvement.
3. Purpose of Collection
We collect and use the data described above only for the following purposes:
- Delivering the Service — authenticating you, sending and receiving messages, and providing platform functionality.
- Billing and account management — processing payments, managing subscriptions, and providing receipts.
- Security and fraud prevention — detecting abuse, unauthorised access, and chargeback fraud.
- Regulatory compliance — meeting our obligations under the Privacy Act 1988 (Cth), Spam Act 2003 (Cth), Telecommunications (Interception and Access) Act 1979 (Cth), and ACMA requirements.
- Service communication — sending you account, billing, security, and policy notices.
- Product improvement — analysing aggregated, de-identified usage data to improve the Service.
We do not use your personal data for any secondary purpose unrelated to the above without obtaining your consent.
4. Data Storage and Security
All data is stored in Australian data centres using Amazon Web Services (AWS) in the ap-southeast-2 (Sydney) region. We do not store or process your core data outside of Australia.
Message content is encrypted at rest and transmitted securely. We employ industry-standard security practices including encryption in transit (TLS), access controls, and regular security reviews.
5. Message Retention
All message content is automatically and permanently deleted after 90 days from the date the message was sent or received. This applies to both sent and received messages.
Any files you upload to the platform (such as spreadsheets, CSV files, or contact lists) are not stored. They are used solely to generate messages and are discarded immediately after processing.
6. Data Retention Schedule
| Data type | Retention period | Reason |
|---|---|---|
| Message content (sent and received) | 90 days from send/receive date | Privacy minimisation, operational |
| Message metadata (sender ID, recipient number, timestamp, delivery status, length, routing) | 2 years | Telecommunications (Interception and Access) Act 1979 (Cth), Part 5-1A — mandatory data retention |
| Opt-out list (recipient mobile numbers only) | Indefinite | Spam Act 2003 (Cth) compliance |
| Account / profile data | Active period + up to 90 days after cancellation | Service delivery, account recovery |
| Billing and invoice records | 7 years | Corporations Act 2001 (Cth) and ATO requirements |
| Sender ID supporting documents | Life of the Sender ID registration | ACMA / carrier compliance |
| Security and audit logs | 12 months | Security incident investigation |
| Support correspondence | 24 months | Quality assurance and dispute resolution |
7. Opt-Out List
When a recipient replies "STOP" to a message sent via Texto, their mobile number is added to an opt-out list. This list is retained indefinitely to prevent accidental re-sending of messages to recipients who have opted out, in accordance with Australian telecommunications regulations and the Spam Act 2003.
8. Account Cancellation
If your account is cancelled (either by you or by us), all of your data — including messages and profile information — will be deleted within 90 days of cancellation.
The only exception is any metadata we are required to retain under Australian data retention laws, telecommunications regulations, or ACMA requirements relating to dedicated number information, or other applicable legal obligations.
9. Sub-Processors
We use the following third-party sub-processors to deliver the Service:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database hosting, authentication | AWS Sydney (ap-southeast-2) |
| Vercel / AWS | Frontend hosting, CDN, infrastructure | AWS Sydney (ap-southeast-2) |
| Stripe | Payment processing, subscription billing | United States |
| Licensed Australian Mobile Carriers (Telstra, Optus, Vodafone, Pivotel) | SMS delivery | Australia |
| Cloudflare | Content delivery network (CDN), DDoS protection, edge security | Global edge network |
| Mailgun (Sinch) | Transactional email delivery (account, billing, security, and policy notices) | United States |
| Slack (Salesforce) | Internal team communication, operational alerts, and incident response | United States |
| Australian Business Register (ABR) | ABN validation and business name verification | Australia |
| Australian Communications and Media Authority (ACMA) | Sender ID registration review and approval | Australia |
10. Cross-Border Disclosure
In line with Australian Privacy Principle 8, we disclose that a limited subset of your data is processed outside Australia by the following sub-processors:
- Stripe (United States) — processes your billing and payment data.
- Mailgun (United States) — processes your email address and the content of transactional emails we send you (such as account, billing, security, and policy notices).
- Slack (United States) — may incidentally process limited personal information (such as your name, email address, or support correspondence) where it appears in internal operational alerts or support discussions.
- Cloudflare (global edge network) — provides CDN and DDoS protection. Requests to our marketing site and Platform may transit Cloudflare edge nodes located outside Australia for routing and security inspection. No message content is stored at the edge.
We have taken reasonable steps to ensure these sub-processors handle personal information in a manner consistent with the Australian Privacy Principles. You acknowledge that overseas privacy laws differ from Australian law and that, by using the Service, you consent to these overseas disclosures for the purposes described above.
All other categories of personal data — including message content, message metadata, profile data, and sender ID documents — are stored and processed exclusively within Australia.
11. Personal Information of Message Recipients
When you send messages through the Texto Platform, the recipient mobile numbers and message bodies you supply are personal information about third parties. Texto processes this information solely as a data processor on your instructions and only to deliver the messages you have asked us to send.
If a recipient wishes to exercise any privacy right (such as access, correction, or deletion of their personal information), they should be directed to you, as the sender. Texto will assist you in responding to such requests where reasonably required.
You warrant that you have all consents and lawful authority required to provide recipient personal information to Texto, and you indemnify Texto against any claim, complaint, or regulatory action arising from your failure to do so.
12. Your Rights
You have the right to:
- Access the personal data we hold about you.
- Request correction of any inaccurate personal data.
- Request deletion of your personal data (subject to our legal obligations, including mandatory metadata retention under the Telecommunications (Interception and Access) Act 1979 (Cth)).
- Withdraw consent for data processing where consent was the basis for processing.
- Request a machine-readable export (CSV or JSON) of your profile data and message history within the 90-day retention window (data portability).
- Opt out of Texto marketing communications at any time using the unsubscribe link in any marketing email.
- Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe your privacy rights have been breached.
To exercise any of these rights, please contact us at support@texto.com.au. We will respond to verified requests within 30 days.
13. Marketing Communications from Texto
Texto may send you service-related messages (such as billing, security, and policy notices) for as long as you have an active account. These are not marketing messages and you cannot opt out of them without closing your account.
We may also send you marketing communications about Texto features, offers, and updates. You can opt out of marketing communications at any time using the unsubscribe link included in every marketing email, or by emailing support@texto.com.au.
14. Notifiable Data Breaches
Texto complies with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth). In the event of an eligible data breach that is likely to result in serious harm to any individual whose personal information is involved, we will:
- notify the affected individuals (or their senders, where applicable);
- notify the Office of the Australian Information Commissioner (OAIC);
- take reasonable steps to contain and remediate the breach,
all within the timeframes required by law.
15. Privacy Complaints
If you believe we have breached the Australian Privacy Principles or mishandled your personal information, please contact us at support@texto.com.au with the subject line "Privacy Complaint".
We will acknowledge your complaint within 5 business days and provide a substantive response within 30 days.
16. Cookies and Analytics
Texto uses cookies and similar technologies across the Platform and marketing website to understand how visitors and users find and use the service, to measure marketing effectiveness, to provide authentication and session management, and to combat advertising fraud. These include:
- Essential cookies — required for authentication and session management.
- Google Tag Manager and Google Analytics 4 — visitor analytics and behaviour.
- Google Ads, Microsoft Ads, and Meta click identifiers (
gclid,msclkid,fbclid) — measuring paid advertising performance. - Endorsely — tracking referrals through our Affiliate Program.
- Crisp — providing live chat support.
- IP address capture (via Google Tag Manager) — used solely for detecting click fraud on paid advertising.
You can control or block these cookies through your browser settings, or use opt-out tools such as the Google Analytics opt-out browser add-on.
17. Security
We implement appropriate technical and organisational measures to protect your data, including encryption at rest and in transit, access controls, and regular security assessments. While no system can guarantee absolute security, we are committed to maintaining industry-standard protections.
18. Children's Data
The Texto Platform is intended for use by businesses and is not designed for individuals under the age of 18. We do not knowingly collect personal data from children.
If you are a parent or guardian and believe we may hold information about a child, please contact us at support@texto.com.au. We will investigate and, where appropriate, delete the information within 30 days.
19. International Users
The Texto Platform is designed for, and intended to be used by, Australian businesses. If you access the Service from outside Australia, you do so on your own initiative and you consent to your personal information being processed in Australia under Australian law.
Where the General Data Protection Regulation (EU GDPR) or UK GDPR applies to a particular interaction with us, we will honour the additional rights granted under those laws to the extent they are applicable.
20. Changes to This Policy
We review this Data & Privacy Policy at least annually. We may also update it from time to time to reflect changes in law, technology, or our practices.
For material changes, we will notify you by email at least 14 days before the changes take effect. The "Last updated" date at the top of this policy will always reflect the most recent revision. Your continued use of the Service after the effective date constitutes acceptance of the revised policy.
21. Contact
If you have any questions about this Data & Privacy Policy or how we handle your data, please contact us at support@texto.com.au.
See also: Terms & Conditions · ← Back to homepage