Privacy Policy
Effective Date: August 23, 2026
This Privacy Policy explains how MultiMFA, Inc. ("MultiMFA", "we", "us", or "our") collects, uses, discloses, and protects your information when you use the MultiMFA platform and related services. Our services include MultiMFA SMS (shared SMS verification using VoIP-based numbers), MultiMFA SMS (Cell) (shared SMS verification using carrier-issued mobile numbers when offered), MultiMFA TOTP (shared app-based codes and viewer logins), and RoboMFA (automated MFA relay). By accessing or using our services, you consent to the practices described in this Policy.
1. Information We Collect
- Account Information: Name, email address, phone number, company (optional), and password when you register for an account.
- Usage Data: Information about your use of the service, such as login times, MFA code delivery (SMS and TOTP), viewer access and shared codes (MultiMFA TOTP), and dashboard activity. When MultiMFA SMS (Cell) is used, relevant service data may include originating sender, message body, cellular receiving number, timestamps, delivery metadata, and operational device telemetry needed to operate and support the service.
- Payment Data: If you subscribe to a paid plan, payment and billing information is processed securely by our payment provider (Stripe). We do not store your full payment details.
- Device & Log Data: IP address, browser type, device information, and access logs for security and analytics.
- Communications: Records of your communications with us, including support requests and feedback.
- Product interest / waitlist: If you register interest in MultiMFA SMS (Cell) or similar offerings, we collect name, work email, optional company and phone, anticipated relay-user count, requested services or use case, and whether you already use MultiMFA, so we can contact you about availability.
2. How We Use Your Information
- To provide, operate, and maintain the MultiMFA platform and services.
- To process your registration, manage your account, and deliver MFA codes as requested.
- To communicate with you about your account, service updates, waitlist or product-interest inquiries, and support requests.
- To process payments and manage subscriptions (via Stripe).
- To monitor, detect, and prevent fraud, abuse, or security incidents.
- To analyze usage trends and improve our services.
- To comply with legal obligations and enforce our Terms of Service and Acceptable Use Policy.
3. How We Share Your Information
- Service Providers: We share information with trusted third parties who help us operate our platform (e.g., Stripe for payments, Twilio for SMS delivery for MultiMFA (SMS) and RoboMFA, hosting providers). These providers are contractually obligated to protect your data and use it only for the services we request.
- Legal Compliance: We may disclose information if required by law, regulation, legal process, or governmental request.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction, subject to this Policy.
- No Sale of Data: We do not sell, rent, or share your personal information with third parties for their own marketing purposes.
4. Data Security
We implement industry-standard security measures to protect your information, including encryption, access controls, and regular security reviews. However, no method of transmission or storage is 100% secure. You are responsible for safeguarding your account credentials and promptly notifying us of any unauthorized access. For how we handle security incidents and notifications when personal data may be affected, see our Incident Response & Breach Notification page.
5. Data Retention
We retain your information as long as your account is active or as needed to provide our services, comply with legal obligations, resolve disputes, and enforce our agreements. You may request deletion of your account and associated data by contacting us at [email protected].
For MultiMFA SMS and MultiMFA SMS (Cell), including how long we keep SMS-related records (message content, routing fields, timestamps, and related logs), how we delete them when numbers or accounts end, and how subprocessors may retain data separately, see our dedicated SMS Data Retention & Deletion policy.
6. Your Rights & Choices
- You may access, update, or correct your account information at any time from your dashboard.
- You may opt out of non-essential communications by following the unsubscribe instructions in our emails.
- You may request deletion of your account and data, subject to certain legal or operational requirements.
7. Cookies and Similar Technologies
We and our service providers may use cookies, web beacons, and similar technologies to operate the service, remember your preferences, analyze usage, and improve security. You can control cookies through your browser settings. Disabling certain cookies may affect the functionality of the service.
8. International Users
MultiMFA is operated in the United States. If you access our services from outside the U.S., you consent to the transfer and processing of your information in the U.S. and other countries where we or our service providers operate.
9. Children's Privacy
Our services are not intended for children under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will take steps to delete such information.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The updated Policy will be posted on our website and is effective upon posting. Your continued use of MultiMFA after changes are posted constitutes your acceptance of the updated Policy.
11. Regional Privacy Rights
Depending on your location, you may have additional rights (e.g., access, portability, restriction, objection, withdrawal of consent). Residents of California may have rights under the CCPA. To exercise any applicable rights or for questions about how we handle your data, contact us at [email protected].
12. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at [email protected].