DispatchTxt ("we", "us") is an SMS dispatch platform operated in the United States for towing and roadside operators. This policy explains what data we collect, how we use it, how long we keep it, and how you can contact us with a data request.
1. Data We Collect
- Account information — name, email, hashed password, role, and organization affiliation for dispatchers and administrators.
- Customer phone numbers — E.164 phone numbers of end customers who text a dispatcher's line, plus opt-out status.
- Message content — inbound and outbound SMS/MMS bodies and any attached media (e.g. vehicle photos) sent through the platform.
- Location data — GPS coordinates when a customer taps a one-time location-share link generated by a dispatcher.
- Delivery metadata — carrier delivery status, provider message SIDs, cost, and timestamps used for billing and troubleshooting.
- Operational telemetry — IP address, user agent, and consent timestamp captured at trial signup and at STOP/START/HELP transitions.
2. How We Use Data
- To deliver SMS/MMS between the operator's dispatch line and the end customer via Twilio.
- To display a customer's shared location to the assigned dispatcher.
- To bill the operator (message counts, MMS multipliers, seat and number overages).
- To enforce carrier and legal compliance (TCPA STOP/START enforcement, spend caps, rate limits).
- To debug delivery failures and prevent abuse (SMS pumping, unauthorized access).
We do not sell personal information. We do not use message content or location data for advertising.
3. Data Retention
- Message bodies — 13 months.
- Delivery metadata (SIDs, statuses, cost) — 24 months.
- Location pings — 30 days.
- Opt-out ledger — retained indefinitely to prove STOP compliance for the life of the phone number, as recommended by CTIA.
- Audit trail of role changes — retained indefinitely for security and compliance.
4. Sharing With Processors
- Twilio — SMS/MMS carrier delivery.
- Stripe — billing and payment processing.
- Supabase — managed Postgres database and authentication.
- Sentry — error telemetry, with PII scrubbed from stack traces.
5. US-Only Service
DispatchTxt is offered to and used exclusively by operators located in the United States. Message traffic is routed through US carriers. If you access the service from outside the US, you do so on your own initiative and are responsible for compliance with local law.
6. Your Rights (CCPA / State Privacy Laws)
You may request access to, export of, or deletion of personal data associated with a phone number. Send requests to privacy@dispatchtxt.com. We respond within 30 days. We retain the opt-out ledger even after a deletion request to prevent re-solicitation, consistent with CTIA guidance.
7. Security
Access is scoped by role and row-level security. Sensitive credentials (e.g. per-org Twilio tokens) are encrypted at rest. Sign-in requires email verification, and god-admin actions are logged to an immutable audit trail.
8. Contact
Questions or requests: privacy@dispatchtxt.com.