Privacy Policy
Last updated: 27 September 2026
This policy explains what DapatOTP ("we") collects when you use dapatotp.com, why, and what we do with it. It is written to comply with Malaysia's Personal Data Protection Act 2010.
1. Who we are
DapatOTP provides temporary phone numbers for receiving SMS verification codes. For any privacy question, contact support@dapatotp.com.
2. What we collect
- Account data: email address, display name, a hashed password (or your Google account ID if you sign in with Google), and the time you registered.
- Balance and transactions: top-ups (including USDT transaction hashes and on-chain sender addresses, or payment gateway references), charges and refunds.
- Orders: the country, app and route you chose, the number issued, the time, and the full text of any SMS received on that number during your order. The SMS is stored so you can look up the code later and so we can resolve disputes.
- Support tickets: what you write to us.
- Technical data: IP address and user agent in server logs and for rate limiting. We do not use analytics cookies. If we run advertising, a Meta Pixel may be enabled on public pages; it is currently off.
3. Why we collect it
- To run your account: sign you in, keep your balance, issue numbers and show you the codes.
- To credit payments and reconcile them with the payment provider or the blockchain.
- To answer support requests and resolve refund disputes.
- To prevent abuse: rate limiting, blocking fraudulent accounts, complying with lawful requests.
4. Who we share it with
- The number supplier: receives the request for a number and returns the SMS. It does not receive your email or identity.
- Payment providers: toyyibPay (for FPX / DuitNow) receives your email and the amount. USDT transfers are public on the Tron blockchain by nature.
- Infrastructure: the site runs on Cloudflare; data is stored in Cloudflare D1. Emails (password resets, alerts) are sent through Resend.
- Authorities: when required by Malaysian law or a valid legal request.
We do not sell personal data.
5. Cookies
One session cookie keeps you signed in, and one short-lived cookie is set after Google sign-in. Your language choice is kept in your browser's local storage. No third-party tracking cookies are set unless advertising is switched on.
6. How long we keep it
Account, ledger and order records (including received SMS text) are kept while your account exists and for 12 months after closure for accounting and dispute purposes. Server logs are kept for 30 days.
7. Your rights
You may ask for a copy of your data, ask us to correct it, or ask us to close your account and delete what we are not required to keep. Write to support@dapatotp.com and we will respond within 21 days.
8. Security
Passwords are hashed with PBKDF2. API keys are random 192-bit values. All traffic is over HTTPS. Access to the database is limited to the operator. Keep your API key and password private — we cannot undo a transaction made with a leaked key.
9. Children
The service is not intended for anyone under 18.
10. Changes
We will update this page when the policy changes. The date at the top shows the current version.
最后更新:2026 年 9 月 27 日
这份政策说明 DapatOTP(下称「我们」)在你使用 dapatotp.com 时收集什么、为什么收集、拿去做什么。按马来西亚《2010 年个人数据保护法》编写。
1. 我们是谁
DapatOTP 提供用于接收短信验证码的临时手机号。隐私相关的问题请联系 support@dapatotp.com。
2. 我们收集什么
- 账号数据:邮箱、显示名、经哈希的密码(或用 Google 登录时的 Google 账号 ID)、注册时间。
- 余额与交易:充值(包括 USDT 交易哈希和链上发送地址,或支付网关参考号)、扣款与退款。
- 订单:你选的国家、应用、线路,下发的号码,时间,以及订单期间该号码收到的短信全文。短信会保存,方便你以后回看验证码,也用于处理争议。
- 工单:你写给我们的内容。
- 技术数据:服务器日志和限流用的 IP 地址与浏览器标识。我们不用分析类 Cookie。如果我们投放广告,公开页面可能启用 Meta Pixel;目前是关闭的。
3. 为什么收集
- 运行你的账号:登录、记余额、取号、显示验证码。
- 给充值入账,并与支付方或区块链对账。
- 回答客服请求,处理退款争议。
- 防止滥用:限流、封欺诈账号、配合合法要求。
4. 我们会把数据给谁
- 号码供应商:收到取号请求并返回短信。它拿不到你的邮箱或身份。
- 支付方:toyyibPay(FPX / DuitNow)会收到你的邮箱和金额。USDT 转账在 Tron 链上本来就是公开的。
- 基础设施:网站跑在 Cloudflare 上,数据存在 Cloudflare D1。邮件(重置密码、告警)通过 Resend 发送。
- 政府机关:马来西亚法律或有效法律要求时。
我们不出售个人数据。
5. Cookie
一个会话 Cookie 保持登录状态,Google 登录后会设一个短期 Cookie。语言选择存在浏览器本地存储里。除非开启广告,不设第三方追踪 Cookie。
6. 保存多久
账号、流水和订单记录(包括收到的短信内容)在账号存续期间保存,注销后再保留 12 个月用于对账和争议处理。服务器日志保留 30 天。
7. 你的权利
你可以要求拿到你的数据副本、要求更正、或要求注销账号并删除我们无需保留的数据。写信到 support@dapatotp.com,我们会在 21 天内回复。
8. 安全
密码用 PBKDF2 哈希。API key 是 192 位随机值。全程 HTTPS。数据库访问仅限运营者。请保管好 API key 和密码 —— 用泄露的 key 做的交易我们无法撤销。
9. 未成年人
本服务不面向 18 岁以下人士。
10. 变更
政策变更时我们会更新本页。顶部日期即当前版本。
