Client document · may be circulated internally
Security & Data Privacy Note
How our SMS Card and RCS campaign service is built, what data exists in it, and
what we deliberately do not do.
We never ask for, receive, or store your customers' mobile numbers, names, account
numbers or any other personal information. Your customer database never leaves your
own systems.
1. How the service is arranged
You continue to send messages exactly as you do today — your own sending system, your
own registered sender header, your own vendor, your own customer list. Our role is
limited to three things:
- the card creative (the image that appears in the message),
- the landing destination (either your own page, or a page we host for the campaign),
- the click report.
The card image is not sent inside the message. The message carries a short link; the
recipient's phone requests the image from our server and displays it. This is standard
link-preview behaviour, the same mechanism used by every major messaging application.
2. What data the system holds
| Item | Held? | Notes |
| Customer mobile numbers | Never |
Not requested, not received, not stored. |
| Customer names / account details | Never |
No personal data of any kind is transferred to us. |
| Campaign tracking code | Yes |
A short code your system places in the link (for example a batch or branch
code). Only your side can relate a code to a person. |
| Time of click, country, device type | Yes |
Standard web-server information, used only to produce your report. |
| Card images and campaign text | Yes |
Your approved creative and wording, hosted so phones can display it. |
Reports are reachable only through a private address holding a secret key, are marked
no-index so search engines ignore them, and can be cleared on your instruction. Data
for a closed campaign is deleted on request.
3. Deliberate security choices
- No open redirect. A campaign's destination is fixed when the campaign is
created and stored on our side. A destination cannot be supplied from outside in
the link, so the link cannot be altered by a third party to point somewhere else.
This closes the most common way branded links get abused for phishing.
- Locked administration. Creating or changing a campaign requires an
administrator key. Nothing about a live campaign can be altered by a visitor.
- Static hosting on major infrastructure. Campaign pages are static and served
over HTTPS from a global content network, with no database of personal records
behind them to breach.
- Client-owned addresses available. On request the link can run on your own
subdomain — for example offers.yourbank.in — so your customers only ever see
your own name. Your IT team adds one DNS record; hosting and reporting remain with us.
- Nothing installed anywhere. No application for your customers to download,
no software on your systems, no access to your core banking or ERP.
4. Regulatory boundaries we keep
We do not place promotional content in transaction or service messages.
Balance alerts, debit and credit notifications, OTPs and maintenance notices stay
exactly as they are. Mixing promotional material into them breaches the applicable
telecom rules and can put a sender header at risk. Campaigns run only on the
promotional route.
- Campaign links are registered and whitelisted on the client's own DLT account
before use, and message templates are registered in the client's name.
- Promotional campaigns are sent only to consenting, non-DND recipients within the
permitted hours, by the client's own system.
- We do not supply, buy, rent or accept contact lists.
- Where a campaign is a mock-up for demonstration, it is clearly watermarked as a
demonstration and is not presented as official communication of any institution.
5. Honest limitations
So there is no misunderstanding at the pilot stage:
- The card is drawn by the recipient's messaging application. Most Android handsets
using the standard messaging app will display it; some older handset applications
and some iPhone cases will show the message as plain text with the link. The message
itself always arrives — which is why we always write the text so that it reads well
on its own.
- The card requires the phone to have data available at the moment of viewing.
- "Cards shown" is a strong indicator of delivery and display, not a carrier-level
delivery certificate; your existing SMS vendor remains the source for delivery
receipts.
- For a guaranteed logo, verified sender name and no visible link, the correct route
is RCS, which we also provide through a licensed aggregator.
6. Contact for this document
| Service | Sandesh Card — rich SMS & RCS campaign services |
| Location | Kolhapur, Maharashtra |
| Contact person | [ADD NAME] |
| Phone / email | [ADD NUMBER / EMAIL] |
| Document version | 1.0 — July 2026 |
This note describes our standard arrangement. Where a client requires a formal
non-disclosure agreement, a data-processing clause, or specific retention periods, we
are glad to sign to the client's own format.