Privacy Policy
Effective September 17, 2026. This policy explains what personal information Adhoc Support, LLC, doing business as IoT Message ("IoT Message", "we", "us"), collects, why, who processes it for us, how long we keep it, and how to reach us about it.
1. What we collect
| Information | Where it comes from | Why we use it |
|---|---|---|
| Name, email address, password (stored only as a hash), and Google account ID if you sign in with Google | You | Your account and signing in |
| Your mobile number | You | Verifying it, and sending Free plan alerts to it |
| Your Hologram API key (stored encrypted), and your devices' names, IDs, and tags | You, and Hologram | Reading your device events and associating recipients with devices |
| Recipients' names, email addresses, and mobile numbers | You, or the recipient through your opt-in link or our public signup page (where the mobile number is optional) | Sending your alerts |
| Consent records: the time, IP address, and the consent text agreed to | The recipient, or you when you add a recipient | Showing that a recipient opted in |
| Device event data, which may include location and sensor readings | Hologram, and other sources you configure | Evaluating your triggers and showing your Activity |
| Message text and delivery status | Our service, and Twilio | Sending messages, delivery statistics, and support |
| Payment information. We store only Stripe's reference IDs, never card numbers | Stripe | Billing |
| Contact form messages: name, email address, company, and message | Anyone who writes to us | Replying to inquiries |
| IP addresses, browser user agents, and the pages requested | Every request to our website | Security, preventing abuse, and understanding traffic |
We do not use third-party analytics, advertising trackers, or tracking pixels, on our website or in our emails.
2. Who processes information for us
- Twilio sends text messages and phone verification codes.
- Stripe processes payments.
- Resend sends our emails.
- Google provides sign-in for customers who choose it, and stores our encrypted backups.
- Hologram provides your device data, at your direction.
We do not sell personal information, and we do not share it for advertising.
3. How long we keep it
- Device event data: 30 days. A summary of each event (its type, device, and time) is kept for the life of your account.
- Message records: for the life of your account.
- Signups from our public signup page: 30 days, whether or not a customer approved them.
- Opt-out records: kept indefinitely. If someone replies STOP we have to remember it, so that they are not messaged again, even if the customer who messaged them closes their account.
- Website request logs: 30 days.
- Backups: 30 days.
- After you delete your account: personal information is removed 30 days after your request.
- Billing records: as long as required for tax and accounting.
4. If you receive alerts
If you receive text alerts sent through IoT Message, you are receiving them on behalf of one of our customers, who added you or whose opt-in form you completed. Your name and number pass through our service so we can deliver those alerts.
- To stop receiving alerts, reply STOP to any message. To start again, reply START.
- We never use your number or information to message you for any purpose other than that customer's alerts.
- For questions about your information, email privacy@iotmessage.com.
5. Your choices and how to reach us
- Access, correction, and deletion: email privacy@iotmessage.com. We answer within 30 days.
- Security: information is encrypted in transit; API keys and backups are encrypted at rest; passwords and access tokens are stored only as hashes; and access is limited to named administrators.
- Children: IoT Message is not directed to anyone under 18.
- Changes: we will tell customers about material changes to this policy by email.
Adhoc Support, LLC, doing business as IoT Message. privacy@iotmessage.com. A postal address is available on request.