MercurySend is a business messaging platform operated by BigSMS Pty Ltd (“MercurySend”, “we”, “us”, “our”). This Privacy Policy applies to our marketing website, the MercurySend dashboard and mobile apps, the developer API, and the email-to-text service (together, the “Services”). By using the Services you agree to this policy.
The two roles we play
MercurySend handles two kinds of information, and our responsibilities differ for each:
- Your account data. Information about the businesses and people who sign up for and administer a MercurySend account. For this data we act as the controller.
- Customer content. The contacts, phone numbers and message content that our customers send and receive through the platform. For this data we act as a processor on the customer’s behalf — the customer is responsible for having a lawful basis (including consent) to message their recipients.
Information we collect
- Account & contact details — your name, business name, email address, and login credentials (passwords are stored only as salted hashes).
- Contacts you manage — the names, phone numbers, consent status and properties of the recipients you add or import.
- Message content — the text and media (MMS) of the SMS/MMS messages you send and receive, together with delivery status, timestamps and segment/cost metadata.
- Compliance records — opt-in/opt-out (STOP/HELP) records, sender and 10DLC/brand-and-campaign registration details, and audit logs of sends and compliance actions.
- Billing information — your plan, usage, credit ledger and invoices. Card payments are processed by Stripe; we do not store full card numbers.
- Technical & usage data — IP address, device information, mobile push (APNs) tokens, app and server logs, and diagnostic information used to operate and secure the Services.
How we use information
- Provide, operate and maintain the Services, including sending and receiving your messages through carriers.
- Enforce consent, quiet hours, keyword handling (STOP/HELP) and US 10DLC / sender registration on every send.
- Meter usage, manage credits and process billing and invoices.
- Provide optional AI features — such as message drafting, suggested replies and summaries — which process the relevant message text to generate a result.
- Provide support, send service and transactional notifications, and respond to your requests.
- Detect, prevent and investigate fraud, abuse, spam and security incidents.
- Comply with our legal obligations and enforce our Terms of Service.
Service providers and sharing
We do not sell personal information and we do not share it for third-party advertising. We share information only with service providers who process it on our behalf under contract, and where required by law. Our key subprocessors include:
- Telecommunications carriers & aggregators (including Twilio and the mobile networks) — to deliver and receive SMS/MMS and process delivery receipts.
- Stripe — to process payments and store payment methods.
- Anthropic — to power AI drafting, replies and summaries when you use those features.
- Cloud hosting & backup providers — to run our servers and store encrypted backups.
- Email delivery providers — to send transactional email and power email-to-text.
We may also disclose information to comply with the law, respond to lawful requests, protect the rights, safety and property of MercurySend, our customers and others, or in connection with a merger, acquisition or sale of assets (with notice where required).
SMS, consent and message rates
MercurySend is used to send messages only to recipients who have provided the required consent. Recipients can opt out at any time by replying STOP, and can request help by replying HELP; opt-outs are honored automatically. Message and data rates may apply to recipients depending on their carrier and plan. Consent records are retained as part of our compliance obligations.
Data retention and account deletion
We retain personal information for as long as your account is active and as needed to provide the Services, and afterward for the period required to meet our legal, accounting, compliance and dispute-resolution obligations. Compliance and audit records (such as consent and opt-out history) may be retained longer where the law requires.
You can delete your account yourself at any time. In the MerSend mobile app, open More → Settings → Delete my account; if you do not have the app, email us at support@mersend.com and we will do it for you. Full instructions are on our account deletion page. Deletion is scheduled with a 30-day grace period, during which you can cancel it by signing back in — after that, your profile and personal data are permanently erased. Records we are legally required to keep (such as billing, tax and compliance/opt-out history) are retained for the period the law requires, even after your account is deleted.
Security
We use administrative, technical and physical safeguards to protect personal information, including encryption in transit, hashed credentials, tenant isolation so one account’s data is never exposed to another, access controls and audit logging. No method of transmission or storage is completely secure, but we work to protect your information and to notify you of material incidents as required by law.
International transfers
MercurySend is operated from Australia and serves customers in Australia, the United States and elsewhere. Depending on where you and your recipients are located, information may be processed in countries other than your own, including by the service providers listed above. Where required, we put appropriate safeguards in place for these transfers.
Your rights and choices
Depending on where you live, you may have rights to access, correct, export or delete your personal information, to object to or restrict certain processing, and to withdraw consent. These rights are recognized under laws such as the Australian Privacy Principles, the EU/UK GDPR and the California Consumer Privacy Act. To exercise a right, contact us using the details below. If we process data as a processor on a customer’s behalf, we will refer your request to that customer.
Children
The Services are intended for businesses and are not directed to children. We do not knowingly collect personal information from children under 16. If you believe a child has provided us information, contact us and we will delete it.
Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the date above and, where appropriate, notify you through the Services. Your continued use of the Services after an update means you accept the revised policy.
Contact us
Questions about this policy or your personal information can be sent to BigSMS Pty Ltd at privacy@mersend.com, or to our support team at support@mersend.com.
