The short version
Assure helps brands you already know send you verification codes, approval requests, and trusted messages on channels like Apple Messages for Business, Google RCS, and WhatsApp — instead of anonymous SMS or email.
We collect the minimum needed to deliver those messages, keep them secure, and stop fraud. We don't sell your personal data. Ever.
Who this covers
This policy is issued by Assure, Inc., a Delaware corporation ("Assure," "we," "us").
If you're a brand using Assure to send messages, we're a data processor acting on your instructions for the messages you send, and a controller for your account data.
If you're a consumer receiving a message from a brand through Assure, the brand is the controller of the conversation and Assure processes your data on their behalf.
What we collect
Account data (brands). Name, work email, company, role, and expected messaging volume.
Message metadata (consumers). Your phone number, Apple ID, RCS ID, or WhatsApp identifier — whatever the brand uses to reach you — plus timestamps, delivery status, and the device platform that received the message.
Message content. The verification codes, approvals, and trusted-link messages a brand routes through Assure.
Technical data. IP address, device and browser info, and cookies used for site analytics and security.
How we use it
To deliver the verification, approval, and trusted messages a brand sends you.
To detect and prevent fraud — including impersonation, phishing links, and account takeover.
To secure the platform, debug issues, and improve reliability.
To measure aggregate performance (deliverability, response rate) for brand dashboards.
To comply with law, respond to lawful requests, and enforce our Terms.
Legal bases (GDPR / UK GDPR)
Contract. To provide the service to brands and route the messages consumers requested.
Legitimate interests. Fraud prevention, platform security, and product improvement — balanced against your rights.
Consent. Where required for marketing or specific message categories. You can withdraw consent at any time.
Legal obligation. To meet retention, tax, and regulatory requirements.
International transfers
Assure is based in the United States. When we transfer personal data from the EEA, UK, or Switzerland to countries without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, plus supplementary technical and organizational measures.
How long we keep it
Message metadata: up to 13 months, then de-identified for aggregate analytics.
Message content: retained only as long as needed to deliver and secure the conversation (typically 30 days), unless a brand has configured a shorter retention.
Account data: for the life of the account plus the period required to meet legal obligations.
Your rights
If you're in the EEA, UK, or Switzerland (GDPR): you can request access, correction, deletion, portability, restriction, or object to processing — and lodge a complaint with your local supervisory authority.
If you're a California resident (CCPA / CPRA): you have the right to know what we collect and why, to correct or delete it, to opt out of any "sale" or "sharing" of personal information (we do neither), to limit use of sensitive personal information, and not to be discriminated against for exercising these rights. Under California's "Shine the Light" law, you may also request information about disclosures to third parties for their direct marketing purposes.
To exercise any of these rights, email privacy@assure.chat. We'll respond within the timeframes required by law.
Messaging consent (TCPA)
Assure only delivers messages that a brand you have an existing relationship with has initiated — typically because you asked to verify a login, approve a transaction, or receive an update.
You can reply STOP at any time to opt out of messages from a brand, or HELP for help. Message frequency varies by brand and use case. Message and data rates may apply. Consent to receive messages is not a condition of any purchase.
Brands using Assure are contractually required to have a valid lawful basis or prior express consent (as applicable) before sending you messages, and to honor opt-outs promptly.
Children
Assure isn't directed at children. We don't knowingly collect personal data from anyone under 13 in the United States or under 16 in the EEA / UK. If you believe a child has provided us data, contact us and we'll delete it.
How we protect it
Encryption in transit (TLS 1.2+) and at rest. Signed, verified sender identity on every message. Strict access controls, least privilege, and audit logging inside Assure.
No system is perfectly secure, but our whole product exists to replace the weakest link — anonymous verification codes — with something you can actually trust.
Changes to this policy
When we make a material change, we'll update the "Last updated" date above and — for account holders — email you before the change takes effect. Continued use after the effective date means you accept the update.