Data & Privacy Policy
Last updated: 18 September 2026
1. Introduction
Texto is a product offered by Floop Pty Ltd (ABN 65 689 489 629) ("we", "us", "our"). Texto is an SMS messaging platform designed for Australian businesses to communicate with their customers via text message.
We take a privacy-by-design approach to building and operating the Texto Platform. This Data & Privacy Policy explains what data we collect, how we store and protect it, and your rights regarding your information.
2. Data We Collect
We collect and process the following categories of data:
- Sign-up profile data: Your name, email address, and company details provided during account registration.
- Billing information: Payment and subscription details processed securely via Stripe. We do not store your full credit card details on our servers.
- Message content: The SMS messages you send and receive through the Texto Platform. Messages are encrypted at rest and transmitted securely via licensed onshore Australian carriers.
- Message metadata: Sender ID, recipient mobile number, timestamp, delivery status, message length, and routing information associated with each message. Metadata is retained for 2 years as required by Australian telecommunications data retention laws (Telecommunications (Interception and Access) Act 1979 (Cth), Part 5-1A).
- Sender ID and KYC supporting documents: ABN evidence, business registration documents, brand materials, and any other information you supply to register a Sender ID or satisfy carrier / ACMA verification requirements. These documents are retained for the life of the Sender ID registration and may be shared with our aggregator and carrier partners as required for registration and ongoing compliance.
- Support correspondence: Messages you send to our support team, including any attachments.
- Technical and usage data: IP address, device type, browser, timestamps, and platform usage logs, used for security, fraud prevention, and service improvement.
3. Purpose of Collection
We collect, use and disclose the data described above for the following purposes:
- Delivering the Service: authenticating users, sending and receiving messages and providing Platform functionality.
- Billing and account management: processing payments, managing subscriptions and providing receipts.
- Security, fraud and abuse prevention: detecting unauthorised access, account misuse, payment fraud, spam, smishing, scams and other prohibited activity.
- Messaging compliance and review: using automated controls, risk scoring and Texto's proprietary anti-spam and anti-smishing systems to analyse message content, account activity, recipient patterns and campaign characteristics, and conducting manual review of flagged messages, campaigns or accounts.
- Legal and regulatory compliance: meeting our obligations under applicable laws and responding to lawful requests from courts, regulators, law-enforcement agencies, carriers, financial institutions and other authorised bodies.
- Service communication: sending account, billing, security and policy notices.
- Product improvement: analysing aggregated or de-identified usage data to improve the Service.
We will not use personal information for an unrelated purpose unless you consent or the use or disclosure is otherwise permitted or required by law.
4. Data Storage and Security
All data is stored in Australian data centres using Amazon Web Services (AWS) in Sydney. We do not store or process your core data outside of Australia.
Message content is encrypted at rest and transmitted securely. We employ industry-standard security practices including encryption in transit (TLS), access controls, and regular security reviews.
5. Message Retention
Message content is ordinarily retained for up to 90 days from the date the message was sent or received. At or after the end of that period, Texto may delete, de-identify, redact, overwrite or replace message content so that the original content is no longer available through the Service or reasonably recoverable as ordinary customer data.
Message content and related information may be retained beyond the ordinary period where reasonably required by a lawful preservation request, warrant, court order, statutory obligation, active investigation, legal claim, or another exception described in this Policy. When that purpose ends, the information may be deleted, de-identified, redacted, overwritten, replaced or returned to the ordinary retention schedule unless another lawful basis for retention applies.
Files uploaded to the Platform, including spreadsheets, CSV files and contact lists, are used to process the requested messages and are not retained as ordinary customer files after processing. Information from an uploaded file may still appear in message records, security records, audit logs or other records lawfully retained under this Policy.
6. Data Retention Schedule
| Data type | Retention period | Reason |
|---|---|---|
| Message content (sent and received) | 90 days from send/receive date | Privacy minimisation, operational |
| Message metadata (sender ID, recipient number, timestamp, delivery status, length, routing) | 2 years | Telecommunications (Interception and Access) Act 1979 (Cth), Part 5-1A — mandatory data retention |
| Opt-out list (recipient mobile numbers only) | Indefinite | Spam Act 2003 (Cth) compliance |
| Account / profile data | Active period + up to 90 days after cancellation | Service delivery, account recovery |
| Billing and invoice records | 7 years | ATO, accounting, audit and corporate record-keeping obligations |
| Sender ID supporting documents | Life of the Sender ID registration | ACMA / carrier compliance |
| Security and audit logs | 12 months | Security incident investigation |
| Support correspondence | 24 months | Quality assurance and dispute resolution |
| Legal hold or investigation records | For the duration of the lawful hold, investigation or legal claim, and afterwards where another legal obligation applies | Law enforcement, regulatory compliance, security, fraud prevention and legal claims |
| Tax, accounting, billing and corporate records | 7 years, or another period required by applicable law | ATO, accounting, audit and corporate record-keeping obligations |
7. Opt-Out List
When a recipient replies "STOP" to a message sent via Texto, their mobile number is added to an opt-out list. This list is retained indefinitely to prevent accidental re-sending of messages to recipients who have opted out, in accordance with Australian telecommunications regulations and the Spam Act 2003.
8. Account Cancellation
If your account is cancelled by you or Texto, your access to the account and its ordinary customer data may end immediately or at the end of an applicable paid period. Within 90 days after cancellation, Texto may delete, de-identify, redact, overwrite or replace message content, profile information and other personal information so that it is no longer available through the Service or reasonably identifies an individual, except where retention is permitted or required by this Policy or applicable law.
Texto may retain information for telecommunications and ACMA requirements relating to dedicated numbers and Sender IDs, mandatory metadata retention, tax, accounting, audit, billing and corporate record-keeping, fraud and security investigations, spam or smishing investigations, carrier or regulator enquiries, lawful preservation requests, court orders, statutory obligations, and establishing, exercising or defending legal claims.
Retained information will be restricted to the relevant purpose and kept only while that purpose or legal obligation continues. When it ends, the information may be deleted, de-identified, redacted, overwritten, replaced or returned to Texto's ordinary retention schedule unless another lawful basis for retention applies.
9. Sub-Processors
We use the following third-party sub-processors to deliver the Service:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database hosting, authentication | AWS Sydney |
| AWS | Frontend hosting and infrastructure | Australia (hosting) |
| Stripe | Payment processing, subscription billing | United States |
| Licensed Australian Carriers | SMS delivery | Australia |
| Cloudflare | Content delivery network (CDN), DDoS protection, edge security | Global edge network |
| Crisp | Customer support chat and related visitor/session information | EU |
| Mailgun (Sinch) | Transactional email delivery (account, billing, security, and policy notices) | United States |
| Slack (Salesforce) | Internal team communication, operational alerts, and incident response | United States |
| Australian Business Register (ABR) | ABN validation and business name verification | Australia |
| Australian Communications and Media Authority (ACMA) | Sender ID registration review and approval | Australia |
10. Cross-Border Disclosure
In line with Australian Privacy Principle 8, we disclose that a limited subset of your data is processed outside Australia by the following sub-processors:
- Stripe (United States) — processes your billing and payment data.
- Mailgun (United States) — processes your email address and the content of transactional emails we send you (such as account, billing, security, and policy notices).
- Slack (United States) — may incidentally process limited personal information (such as your name, email address, or support correspondence) where it appears in internal operational alerts or support discussions.
- Cloudflare (global edge network) — provides CDN and DDoS protection. Requests to our marketing site and Platform may transit Cloudflare edge nodes located outside Australia for routing and security inspection. No message content is stored at the edge.
- Crisp (EU) — provides customer support chat and may process the information you enter in chat and associated visitor/session details.
We have taken reasonable steps to ensure these sub-processors handle personal information in a manner consistent with the Australian Privacy Principles. You acknowledge that overseas privacy laws differ from Australian law and that, by using the Service, you consent to these overseas disclosures for the purposes described above.
All other categories of personal data — including message content, message metadata, profile data, and sender ID documents — are stored and processed exclusively within Australia.
11. Personal Information of Message Recipients
When you use the Texto Platform, recipient mobile numbers, message content and related details may be personal information about third parties. Texto processes this information to carry out your messaging instructions and to operate, secure and protect the Service. This includes processing for message delivery, opt-out management, fraud prevention, anti-spam and anti-smishing screening, automated compliance controls, manual review of flagged campaigns, carrier requirements, investigations, legal obligations and regulatory disclosures.
If a recipient wishes to exercise any privacy right (such as access, correction, or deletion of their personal information), they should be directed to you, as the sender. Texto will assist you in responding to such requests where reasonably required.
You warrant that you have all consents and lawful authority required to provide recipient personal information to Texto, and you indemnify Texto against any claim, complaint, or regulatory action arising from your failure to do so.
12. Law Enforcement and Regulatory Disclosure
Texto may preserve, use and disclose personal information where required or permitted by Australian law. This includes responding to a warrant, subpoena, court order, statutory notice, preservation request or other lawful demand, and cooperating with police, courts, regulators, law-enforcement agencies, carriers, financial institutions, card schemes and other authorised bodies.
Information disclosed may include account and profile details, message content available within the applicable retention period, message metadata, payment information, access logs, device and connection information, Sender ID records, consent evidence and support correspondence, but only to the extent reasonably relevant to the request or permitted purpose.
Texto may also preserve or disclose information where permitted by law and reasonably necessary to prevent or investigate serious harm, a threat to life or safety, fraud, smishing, cybercrime, unlawful activity, a security incident or a breach of telecommunications requirements.
Texto will assess requests for information and may require evidence of the requesting body's authority. Texto may not notify the affected user where notification is prohibited by law, could prejudice an investigation, could compromise a security measure or could create a risk to any person.
13. Your Rights
You have the right to:
- Access the personal data we hold about you.
- Request correction of any inaccurate personal data.
- Request deletion of your personal data (subject to our legal obligations, including mandatory metadata retention under the Telecommunications (Interception and Access) Act 1979 (Cth)).
- Withdraw consent for data processing where consent was the basis for processing.
- Request a machine-readable export (CSV or JSON) of your profile data and message history within the 90-day retention window (data portability).
- Opt out of Texto marketing communications at any time using the unsubscribe link in any marketing email.
- Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe your privacy rights have been breached.
To exercise any of these rights, please contact us at support@texto.com.au. We will respond to verified requests within 30 days.
14. Marketing Communications from Texto
Texto may send you service-related messages (such as billing, security, and policy notices) for as long as you have an active account. These are not marketing messages and you cannot opt out of them without closing your account.
We may also send you marketing communications about Texto features, offers, and updates. You can opt out of marketing communications at any time using the unsubscribe link included in every marketing email, or by emailing support@texto.com.au.
15. Notifiable Data Breaches
Texto complies with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth). In the event of an eligible data breach that is likely to result in serious harm to any individual whose personal information is involved, we will:
- notify the affected individuals (or their senders, where applicable);
- notify the Office of the Australian Information Commissioner (OAIC);
- take reasonable steps to contain and remediate the breach,
all within the timeframes required by law.
16. Privacy Complaints
If you believe we have breached the Australian Privacy Principles or mishandled your personal information, please contact us at support@texto.com.au with the subject line "Privacy Complaint".
We will acknowledge your complaint within 5 business days and provide a substantive response within 30 days.
17. Cookies and Analytics
Texto uses cookies and similar technologies across the Platform and marketing website to understand how visitors and users find and use the service, to measure marketing effectiveness, to provide authentication and session management, and to combat advertising fraud. These include:
- Essential cookies — required for authentication and session management.
- Google Tag Manager and Google Analytics 4 — visitor analytics and behaviour.
- Google Ads, Microsoft Ads, and Meta click identifiers (
gclid,msclkid,fbclid) — measuring paid advertising performance. - Endorsely — tracking referrals through our Affiliate Program.
- Crisp — providing live chat support.
- IP address capture (via Google Tag Manager) — used solely for detecting click fraud on paid advertising.
You can control or block these cookies through your browser settings, or use opt-out tools such as the Google Analytics opt-out browser add-on.
18. Security
We implement appropriate technical and organisational measures to protect your data, including encryption at rest and in transit, access controls, and regular security assessments. While no system can guarantee absolute security, we are committed to maintaining industry-standard protections.
19. Children's Data
The Texto Platform is intended for use by businesses and is not designed for individuals under the age of 18. We do not knowingly collect personal data from children.
If you are a parent or guardian and believe we may hold information about a child, please contact us at support@texto.com.au. We will investigate and, where appropriate, delete the information within 30 days.
20. International Users
The Texto Platform is designed for, and intended to be used by, Australian businesses. If you access the Service from outside Australia, you do so on your own initiative and you consent to your personal information being processed in Australia under Australian law.
Where the General Data Protection Regulation (EU GDPR) or UK GDPR applies to a particular interaction with us, we will honour the additional rights granted under those laws to the extent they are applicable.
21. Changes to This Policy
We review this Data & Privacy Policy at least annually. We may also update it from time to time to reflect changes in law, technology, or our practices.
For material changes, we will notify you by email at least 14 days before the changes take effect. The "Last updated" date at the top of this policy will always reflect the most recent revision. Your continued use of the Service after the effective date constitutes acceptance of the revised policy.
22. Contact
If you have any questions about this Data & Privacy Policy or how we handle your data, please contact us at support@texto.com.au.
See also: Terms & Conditions · ← Back to homepage