Enterprise-grade OTP delivery across SMS, RCS, WhatsApp, and Telegram. Protect your users with seamless multi-channel authentication.
Built for security, designed for simplicity
Bank-grade encryption with SOC 2 Type II compliance and 99.99% uptime SLA
Deliver OTPs via SMS, RCS, WhatsApp, and Telegram with automatic fallback
Global infrastructure ensures sub-second delivery times worldwide
Comprehensive dashboard with delivery rates, costs, and user insights
RESTful API with SDKs for all major platforms. Up and running in minutes
Direct carrier connections in 200+ countries for optimal delivery
Every OTP is generated using cryptographically secure algorithms and encrypted end-to-end. Our infrastructure is SOC 2 Type II certified and undergoes regular third-party security audits.
With direct connections to tier-1 carriers worldwide, we ensure your OTPs reach users anywhere. Our intelligent routing optimizes for both speed and deliverability, with automatic fallback to alternative channels.
Request Demo
Transparent pricing for every business size
Let's discuss how Q-OTP can secure your authentication
Complete REST API documentation for Q-OTP integration
All API requests require authentication using an API key. Include your API key in the request header:
Authorization: Bearer YOUR_API_KEY
https://api.q-otp.me/v1
Send a one-time password to a user via their preferred channel.
{
"phone_number": "+1234567890",
"channel": "sms", // sms, whatsapp, telegram, rcs
"code_length": 6,
"expiry_seconds": 300,
"template": "Your verification code is: {code}"
}
{
"success": true,
"request_id": "req_abc123xyz",
"status": "sent",
"channel_used": "sms",
"expires_at": "2025-11-01T14:35:00Z"
}
curl -X POST https://api.q-otp.me/v1/otp/send \ -H "Authorization: Bearer YOUR_API_KEY" \ -H "Content-Type: application/json" \ -d '{ "phone_number": "+1234567890", "channel": "sms", "code_length": 6, "expiry_seconds": 300 }'
const response = await fetch('https://api.q-otp.me/v1/otp/send', { method: 'POST', headers: { 'Authorization': 'Bearer YOUR_API_KEY', 'Content-Type': 'application/json' }, body: JSON.stringify({ phone_number: '+1234567890', channel: 'sms', code_length: 6, expiry_seconds: 300 }) }); const data = await response.json(); console.log(data);
Verify a one-time password submitted by the user.
{
"request_id": "req_abc123xyz",
"code": "123456"
}
{
"success": true,
"valid": true,
"request_id": "req_abc123xyz",
"verified_at": "2025-11-01T14:32:15Z"
}
curl -X POST https://api.q-otp.me/v1/otp/verify \ -H "Authorization: Bearer YOUR_API_KEY" \ -H "Content-Type: application/json" \ -d '{ "request_id": "req_abc123xyz", "code": "123456" }'
Check the status of an OTP request.
{
"success": true,
"request_id": "req_abc123xyz",
"status": "delivered", // pending, sent, delivered, failed
"channel": "sms",
"attempts": 0,
"max_attempts": 3,
"expires_at": "2025-11-01T14:35:00Z"
}
curl -X GET https://api.q-otp.me/v1/otp/status/req_abc123xyz \
-H "Authorization: Bearer YOUR_API_KEY"
| Code | Description |
|---|---|
400 |
Bad Request - Invalid parameters |
401 |
Unauthorized - Invalid API key |
429 |
Too Many Requests - Rate limit exceeded |
500 |
Internal Server Error |
API requests are limited based on your plan:
Complete guide to integrating Q-OTP
Welcome to Q-OTP! This guide will help you integrate secure OTP authentication into your application in just a few minutes.
Sign up for a Q-OTP account and obtain your API credentials from the dashboard. You'll receive:
Direct integration using our RESTful API. Works with any programming language that can make HTTP requests.
// Basic flow 1. Send OTP โ POST /otp/send 2. User receives code via SMS/WhatsApp/etc 3. Verify code โ POST /otp/verify
We provide official SDKs for popular platforms:
npm install @q-otp/node-sdkpip install q-otpcomposer require q-otp/php-sdkgem install q_otpgo get github.com/q-otp/go-sdkHere's a complete example using Node.js:
const QOTP = require('@q-otp/node-sdk'); const client = new QOTP({ apiKey: 'your_api_key_here' }); // Send OTP async function sendOTP(phoneNumber) { try { const result = await client.otp.send({ phoneNumber: phoneNumber, channel: 'sms', codeLength: 6, expirySeconds: 300 // 5 minutes }); console.log('OTP sent:', result.requestId); return result.requestId; } catch (error) { console.error('Error:', error.message); } } // Verify OTP async function verifyOTP(requestId, code) { try { const result = await client.otp.verify({ requestId: requestId, code: code }); if (result.valid) { console.log('โ Code verified!'); return true; } else { console.log('โ Invalid code'); return false; } } catch (error) { console.error('Error:', error.message); } }
Set up webhooks to receive real-time notifications about delivery status, verification attempts, and more.
// Webhook endpoint example (Express.js) app.post('/webhooks/qotp', (req, res) => { const event = req.body; switch (event.type) { case 'otp.delivered': console.log('OTP delivered successfully'); break; case 'otp.failed': console.log('OTP delivery failed'); break; } res.sendStatus(200); });
Use our sandbox environment for testing without consuming real credits:
const client = new QOTP({ apiKey: 'test_api_key', environment: 'sandbox' }); // Test phone numbers that always succeed const testNumbers = [ '+15555550100', // Always delivers '+15555550101', // Always fails '+15555550102' // Random behavior ];
Our support team is here to help:
Building the future of secure authentication
At Q-OTP, we believe that secure authentication should be simple, reliable, and accessible to every business. Founded in 2022, we've grown to serve thousands of companies worldwide, delivering millions of OTP codes every day with industry-leading reliability.
Traditional OTP solutions are complex, expensive, and often unreliable. We experienced these challenges firsthand while building authentication systems for our previous ventures. That frustration led us to create Q-OTPโa service that just works, without the complexity.
We're a distributed team of engineers, designers, and security experts passionate about making the internet safer. Our founding team has decades of combined experience building authentication systems at companies like Google, Amazon, and Microsoft.
Q-OTP runs on a global infrastructure with:
| 2022 | Q-OTP founded โข First 100 customers |
| 2023 | SOC 2 Type II certification โข 1 million OTPs/day |
| 2024 | Series A funding โข WhatsApp & RCS support |
| 2025 | 10 million OTPs/day โข 200+ country coverage |
We're backed by leading venture capital firms and strategic partners who share our vision for a more secure internet. Our partners include major telecom carriers, cloud providers, and security organizations.
We're always looking for talented people to join our mission. Check out our open positions or reach out at careers@q-otp.me.
Join us in building the future of authentication
At Q-OTP, you'll work on technology that protects millions of users every day. We're a fast-growing company with a mission to make the internet more secure, and we're looking for talented people to help us get there.
Build and scale our global OTP delivery infrastructure. Experience with Go, Kubernetes, and high-availability systems required.
Location: Remote โข Type: Full-time
Apply NowDesign and build beautiful, intuitive interfaces for our dashboard and API documentation. React and TypeScript expertise required.
Location: Remote โข Type: Full-time
Apply NowEnsure our platform meets the highest security standards. Experience with penetration testing, compliance, and threat modeling required.
Location: Remote โข Type: Full-time
Apply NowDefine the product roadmap and work with engineering to ship features that delight customers. B2B SaaS experience preferred.
Location: Remote โข Type: Full-time
Apply NowBuild relationships with enterprise customers and help them implement secure authentication. SaaS sales experience required.
Location: Remote โข Type: Full-time
Apply NowTotal process time: 1-2 weeks. We move fast and provide feedback at every stage.
We're always looking for talented people. Send us a note at careers@q-otp.me and tell us how you'd like to contribute.
Trust and security are at the core of everything we do
We take your data privacy seriously:
In the unlikely event of a security incident:
We welcome security researchers to help us keep Q-OTP secure. Report vulnerabilities to security@q-otp.me and receive recognition (and rewards) for valid findings.
For security inquiries or to report a vulnerability:
We aim to respond to all security reports within 24 hours.
Meeting global regulatory requirements
Q-OTP has successfully completed SOC 2 Type II audit, demonstrating our commitment to security, availability, processing integrity, confidentiality, and privacy. Our SOC 2 report is available to customers under NDA.
Last audit: September 2024 โข Auditor: Deloitte & Touche LLP
Our information security management system (ISMS) is certified to ISO 27001, the international standard for information security.
Certificate number: ISO27001-2024-XXX โข Valid until: September 2027
We are currently undergoing PCI DSS Level 1 certification to support payment authentication use cases.
Expected completion: Q2 2025
Q-OTP is fully compliant with the General Data Protection Regulation (GDPR):
EU Representative: Q-OTP Ireland Ltd, Dublin, IE
CCPA/CPRA: California Consumer Privacy Act compliant
HIPAA: Business Associate Agreements available for healthcare customers
TCPA: Telephone Consumer Protection Act compliant for SMS delivery
UK GDPR: Fully compliant with UK data protection laws
UK Representative: Q-OTP UK Ltd, London, GB
PIPEDA: Personal Information Protection and Electronic Documents Act compliant
Australia - Privacy Act 1988: Compliant
Singapore - PDPA: Personal Data Protection Act compliant
Japan - APPI: Act on Protection of Personal Information compliant
We offer data residency options in multiple regions:
| Region | Data Centers | Availability |
|---|---|---|
| North America | US-East, US-West, Canada | All plans |
| Europe | Ireland, Germany, UK | Business+ |
| Asia-Pacific | Singapore, Australia, Japan | Enterprise |
We work with carefully vetted sub-processors:
Full sub-processor list available at q-otp.me/subprocessors
Available compliance documentation:
Request compliance documentation at compliance@q-otp.me
Our compliance program includes:
Find answers to common questions
Getting started is easy:
No! You can start with our free tier which includes 100 OTP sends per month. Add a payment method when you're ready to scale.
Q-OTP works with any language that can make HTTP requests. We provide official SDKs for:
Most developers complete a basic integration in under 30 minutes. A production-ready implementation with error handling, webhooks, and fallbacks typically takes 2-4 hours.
Yes! Use our sandbox environment with test phone numbers. See our Documentation for test numbers that simulate different scenarios.
We support four delivery channels:
If your primary channel fails, we automatically retry with your configured fallback channel. For example: WhatsApp โ RCS โ SMS ensures maximum deliverability.
Yes! You can customize:
Pricing is simple and transparent:
See our Pricing page for details.
No hidden fees. You only pay for OTPs successfully delivered. Failed deliveries are not charged.
We offer a 100% money-back guarantee within the first 30 days if you're not satisfied.
We guarantee 99.99% uptime for all plans, backed by our SLA. That's less than 53 minutes of downtime per year.
Median delivery time is under 1 second globally. 95th percentile is under 3 seconds.
Yes! Set up webhooks to receive real-time notifications about OTP delivery status, verification attempts, and more.
OTP codes are:
Yes! We're fully GDPR compliant. See our Compliance page for details.
Can't find what you're looking for? Contact our support team and we'll be happy to help!
Real-time operational status of Q-OTP services
| Service | Status | Uptime (30 days) |
|---|---|---|
| API | Operational | 99.99% |
| SMS Delivery | Operational | 99.98% |
| WhatsApp Delivery | Operational | 99.97% |
| RCS Delivery | Operational | 99.96% |
| Telegram Delivery | Operational | 99.95% |
| Dashboard | Operational | 99.99% |
| Webhooks | Operational | 99.98% |
| Region | Status | Latency (avg) |
|---|---|---|
| North America | Operational | 45ms |
| Europe | Operational | 52ms |
| Asia-Pacific | Operational | 58ms |
| South America | Operational | 67ms |
| Middle East | Operational | 61ms |
โ No incidents in the last 90 days
No scheduled maintenance at this time. We'll notify customers 72 hours in advance of any planned maintenance.
| Period | Uptime | Incidents |
|---|---|---|
| Last 24 hours | 100.00% | 0 |
| Last 7 days | 99.99% | 0 |
| Last 30 days | 99.98% | 0 |
| Last 90 days | 99.97% | 0 |
Get real-time notifications about service status:
Note: This is a simulated status page. Real-time status available at status.q-otp.me
Last updated: November 1, 2025
Cookies are small text files that are stored on your device when you visit our website. They help us provide you with a better experience by remembering your preferences and understanding how you use our service.
We use cookies for the following purposes:
These cookies are essential for the website to function properly. They enable core functionality such as security, network management, and accessibility.
| Cookie Name | Purpose | Duration |
|---|---|---|
session_id |
Maintains your logged-in state | Session |
csrf_token |
Protects against cross-site request forgery | Session |
cookie_consent |
Remembers your cookie preferences | 1 year |
These cookies help us understand how visitors interact with our website by collecting anonymous information. We use this data to improve our service.
| Cookie Name | Purpose | Duration |
|---|---|---|
_ga |
Google Analytics - distinguishes users | 2 years |
_gid |
Google Analytics - distinguishes users | 24 hours |
_gat |
Google Analytics - throttles request rate | 1 minute |
These cookies track your online activity to help advertisers deliver more relevant advertising or to limit how many times you see an ad.
| Cookie Name | Purpose | Duration |
|---|---|---|
_fbp |
Facebook Pixel - tracks conversions | 3 months |
ads/ga-audiences |
Google Ads - remarketing | Session |
You have several options for managing cookies:
Most web browsers allow you to control cookies through their settings. You can typically:
We respect Do Not Track (DNT) browser settings. When DNT is enabled, we do not track your browsing activity across third-party websites.
If you choose to block cookies:
We use the following third-party services that may set cookies:
These third parties have their own privacy policies governing their use of information.
We may update this Cookie Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "last updated" date.
If you have questions about our use of cookies, please contact us:
How Q-OTP complies with the General Data Protection Regulation
Q-OTP is fully committed to complying with the General Data Protection Regulation (GDPR) and protecting the privacy rights of individuals in the European Economic Area (EEA). This page outlines how we meet GDPR requirements.
As a data subject under GDPR, you have the following rights:
You have the right to request access to your personal data. We will provide you with:
How to exercise: Email privacy@q-otp.me with subject "Data Access Request"
Response time: Within 30 days
You can request correction of inaccurate or incomplete personal data.
How to exercise: Update information in your dashboard or email privacy@q-otp.me
Response time: Within 30 days
You can request deletion of your personal data when:
How to exercise: Email privacy@q-otp.me with subject "Data Deletion Request"
Response time: Within 30 days
Note: We may retain some data if required by law or for legitimate business purposes.
You can request that we limit how we use your data when:
You can request your data in a structured, commonly used, machine-readable format and transmit it to another controller.
Supported formats: JSON, CSV, XML
How to exercise: Use the "Export Data" feature in your dashboard or email us
You can object to processing based on:
You have the right not to be subject to decisions based solely on automated processing, including profiling.
Our position: We do not make automated decisions that significantly affect you without human intervention.
| Data Type | Purpose | Legal Basis |
|---|---|---|
| Account information | Service delivery | Contract performance |
| Phone numbers | OTP delivery | Contract performance |
| Usage data | Service improvement | Legitimate interest |
| Marketing communications | Product updates | Consent |
| Payment information | Billing | Contract performance |
We retain personal data only as long as necessary:
We transfer data outside the EEA using approved mechanisms:
We have appointed a Data Protection Officer to oversee GDPR compliance:
Contact: dpo@q-otp.me
Mail: DPO, Q-OTP Ireland Ltd, Dublin, IE
If you're a business customer processing personal data through our service, we act as your data processor. We provide:
Request DPA: legal@q-otp.me
We implement appropriate technical and organizational measures:
In case of a personal data breach, we will:
Our service is not directed to children under 16. We do not knowingly collect data from children. If we become aware of such collection, we will delete it immediately.
You have the right to lodge a complaint with your local supervisory authority:
Lead Authority (Ireland):
Data Protection Commission
21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
Website: dataprotection.ie
We continuously monitor GDPR developments and update our practices accordingly. Check this page regularly for updates.
For any GDPR-related questions or to exercise your rights:
Last updated: November 1, 2025
For questions regarding these terms, contact: giugli@q-otp.me
These Terms and Conditions ("Terms", "Agreement") constitute a legally binding agreement between you ("Customer", "Client", "you") and Q-OTP Limited, a company registered in the British Virgin Islands ("Q-OTP", "we", "us", "our"), governing your access to and use of the Q-OTP authentication services, website, and related services (collectively, the "Services").
By creating an account, accessing, or using any part of our Services, you acknowledge that you have read, understood, and agree to be bound by these Terms. If you do not agree to these Terms, you must not access or use our Services.
Business Entity Representation: If you are entering into this Agreement on behalf of a company, organization, or other legal entity, you represent and warrant that you have the authority to bind such entity to these Terms, and references to "you" shall refer to such entity.
Q-OTP provides cloud-based one-time password (OTP) authentication services, including but not limited to:
We strive to maintain 99.99% uptime as outlined in our Service Level Agreement (SLA), available to Business and Enterprise plan customers. We reserve the right to modify, suspend, or discontinue any aspect of the Services at any time, with reasonable notice for material changes.
We may offer certain features designated as beta, preview, or early access. These features are provided "as is" without warranty and may be discontinued at any time without notice.
To use our Services, you must:
You are responsible for:
We reserve the right to suspend or terminate your account if:
You may use our Services only for lawful purposes and in accordance with these Terms. Specifically, you agree to use our Services solely for:
You explicitly agree NOT to:
You must comply with all applicable local, state, national, and international laws and regulations, including but not limited to:
You represent and warrant that you have obtained all necessary consents, permissions, and authorizations from end users to send OTP messages to their phone numbers or messaging accounts. You are solely responsible for maintaining documentation of such consents.
We offer multiple service plans as described on our Pricing page. Plan features, limits, and pricing are subject to change with 30 days' notice for existing customers.
Payment is due according to the billing cycle selected during account setup:
Late payments are subject to:
Refunds are provided under the following conditions:
Fees are exclusive of all applicable taxes, duties, and similar assessments. You are responsible for all taxes except those based on our net income. If we are required to collect or pay taxes, such amounts will be invoiced to and paid by you.
The Services, including all software, technology, content, trademarks, service marks, trade names, logos, and other proprietary designations ("Q-OTP IP"), are owned by or licensed to Q-OTP and are protected by copyright, trademark, patent, trade secret, and other intellectual property laws.
Subject to these Terms, we grant you a limited, non-exclusive, non-transferable, non-sublicensable, revocable license to:
You may not:
You retain all rights to content you submit through our Services ("Customer Content"). You grant us a worldwide, non-exclusive, royalty-free license to use, process, and transmit Customer Content solely to provide the Services to you.
Any feedback, suggestions, or ideas you provide regarding our Services ("Feedback") will be owned by Q-OTP. You hereby assign all rights, title, and interest in such Feedback to us.
We process personal data in accordance with our Privacy Policy and applicable data protection laws. For customers processing personal data of EU/EEA residents, we act as a data processor and provide Data Processing Agreements (DPA) upon request.
We implement industry-standard security measures including:
We retain data according to the following schedule:
In the event of a data breach affecting personal data, we will notify affected customers at giugli@q-otp.me within 72 hours of discovery, in accordance with applicable laws.
For Business and Enterprise customers, we commit to:
If we fail to meet the uptime commitment:
| Monthly Uptime | Service Credit |
|---|---|
| 99.0% - 99.99% | 10% of monthly fees |
| 95.0% - 98.99% | 25% of monthly fees |
| < 95.0% | 50% of monthly fees |
The SLA does not apply to outages caused by:
To claim SLA credits, you must submit a request to giugli@q-otp.me within 30 days of the incident, including evidence of the outage. Credits will be applied to future invoices and cannot be redeemed for cash.
We warrant that the Services will perform substantially in accordance with our documentation under normal use. Our sole obligation under this warranty is to use commercially reasonable efforts to correct reported non-conformities or provide a workaround.
EXCEPT AS EXPRESSLY PROVIDED IN SECTION 9.1, THE SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO:
We rely on third-party telecommunications carriers and messaging platforms (SMS, WhatsApp, RCS, Telegram). We do not warrant the availability, reliability, or performance of these third-party services and disclaim all liability for their failures or limitations.
While we strive for high delivery rates, we do not guarantee that all OTP messages will be delivered due to factors beyond our control, including but not limited to: carrier restrictions, device availability, network congestion, spam filtering, and regulatory compliance requirements.
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, OUR TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THESE TERMS OR THE SERVICES SHALL NOT EXCEED THE GREATER OF:
IN NO EVENT SHALL Q-OTP BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, INCLUDING BUT NOT LIMITED TO:
EVEN IF Q-OTP HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
The limitations in this Section 10 do not apply to:
You acknowledge and agree that the limitations and exclusions of liability set forth in this Section 10 reflect a reasonable allocation of risk between the parties and form an essential basis of the bargain between us. The Services would not be provided without these limitations.
You agree to indemnify, defend (at our option), and hold harmless Q-OTP, its affiliates, and their respective officers, directors, employees, agents, and representatives from and against any and all claims, damages, obligations, losses, liabilities, costs, and expenses (including reasonable attorneys' fees) arising from or related to:
We will:
We will indemnify and hold you harmless against any third-party claim that the Services, when used in accordance with these Terms, infringe any copyright, trademark, or patent registered in the United States, European Union, or United Kingdom, provided that:
This indemnification does not apply if the claim arises from:
"Confidential Information" means all non-public information disclosed by one party ("Disclosing Party") to the other party ("Receiving Party"), whether orally or in writing, that is designated as confidential or that reasonably should be considered confidential given the nature of the information and circumstances of disclosure.
The Receiving Party agrees to:
Confidential Information does not include information that:
If the Receiving Party is compelled by law to disclose Confidential Information, it shall provide prompt notice to the Disclosing Party (unless prohibited by law) and reasonable assistance in obtaining protective orders or limiting disclosure.
These Terms commence when you create an account and continue until terminated by either party in accordance with this Section 13.
Either party may terminate these Terms immediately upon written notice if:
We may immediately suspend your access to the Services without notice if:
Upon termination:
The following sections will survive termination: 5 (Pricing and Payment), 6 (Intellectual Property), 7.3 (Data Retention), 9.2 (Disclaimers), 10 (Limitation of Liability), 11 (Indemnification), 12 (Confidentiality), 15 (Dispute Resolution), and 16 (General Provisions).
Neither party shall be liable for any failure or delay in performance under these Terms (except for payment obligations) to the extent such failure or delay is caused by circumstances beyond its reasonable control, including but not limited to:
The affected party shall promptly notify the other party and use commercially reasonable efforts to resume performance. If the force majeure event continues for more than 30 days, either party may terminate these Terms upon written notice.
These Terms shall be governed by and construed in accordance with the laws of the British Virgin Islands, without regard to its conflict of law provisions.
Any dispute, controversy, or claim arising out of or relating to these Terms, or the breach, termination, or invalidity thereof, shall be exclusively subject to the jurisdiction of the courts of the British Virgin Islands.
You hereby irrevocably consent to the personal jurisdiction and venue of such courts and waive any objection to such jurisdiction or venue on the grounds of inconvenient forum or otherwise.
Before initiating any formal legal proceedings, the parties agree to first attempt to resolve any dispute informally by contacting giugli@q-otp.me and providing a detailed description of the dispute and the desired resolution. We will attempt to resolve the dispute informally within 60 days.
If informal resolution fails, the parties may mutually agree to submit the dispute to binding arbitration in accordance with the BVI IAC Arbitration Rules. The arbitration shall be conducted in English, with one arbitrator mutually agreed upon by the parties. The arbitrator's decision shall be final and binding.
Either party may seek injunctive or other equitable relief in any court of competent jurisdiction to prevent the actual or threatened infringement, misappropriation, or violation of intellectual property rights or confidentiality obligations.
YOU AND Q-OTP AGREE THAT EACH MAY BRING CLAIMS AGAINST THE OTHER ONLY IN YOUR OR ITS INDIVIDUAL CAPACITY AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY PURPORTED CLASS OR REPRESENTATIVE PROCEEDING.
These Terms, together with our Privacy Policy, DPA (if applicable), and any Order Forms or SOWs executed by the parties, constitute the entire agreement between you and Q-OTP regarding the Services and supersede all prior or contemporaneous understandings and agreements, whether written or oral.
We may modify these Terms at any time by posting the revised Terms on our website and sending notice to your registered email address. Material changes will be effective 30 days after posting, except for changes required by law which may be effective immediately. Your continued use of the Services after the effective date constitutes acceptance of the modified Terms.
No waiver of any provision of these Terms shall be deemed or constitute a waiver of any other provision, nor shall any waiver constitute a continuing waiver unless otherwise expressly provided in writing.
If any provision of these Terms is held to be invalid, illegal, or unenforceable, such provision shall be modified to the minimum extent necessary to make it valid and enforceable, or if that is not possible, severed from these Terms. The remaining provisions shall continue in full force and effect.
You may not assign or transfer these Terms or any rights or obligations hereunder without our prior written consent. We may assign these Terms in connection with a merger, acquisition, corporate reorganization, or sale of all or substantially all of our assets, upon notice to you. Any attempted assignment in violation of this section is void.
These Terms do not and are not intended to confer any rights or remedies upon any person or entity other than the parties hereto and their permitted successors and assigns.
The parties are independent contractors. These Terms do not create a partnership, franchise, joint venture, agency, fiduciary, or employment relationship between the parties.
All notices under these Terms shall be in writing and shall be deemed given when:
Our Notice Address:
Q-OTP Limited
Attn: Legal Department
Email: giugli@q-otp.me
British Virgin Islands
The Services and related technology may be subject to export laws and regulations of the United States, European Union, and other jurisdictions. You represent that you are not located in, under the control of, or a national or resident of any country to which such exports are prohibited. You agree to comply with all applicable export control laws.
If you are a U.S. government entity or using the Services on behalf of a U.S. government entity, the Services are "Commercial Items" as defined at 48 C.F.R. ยง2.101, consisting of "Commercial Computer Software" and "Commercial Computer Software Documentation."
The headings and captions used in these Terms are for convenience only and shall not affect the interpretation of these Terms. The words "include" and "including" shall be deemed to be followed by "without limitation." The word "or" is not exclusive.
These Terms are drafted in English. Any translation is provided for convenience only. In the event of any conflict between the English version and any translation, the English version shall prevail.
These Terms may be executed in counterparts, each of which shall be deemed an original and all of which together shall constitute one and the same instrument. Electronic signatures shall have the same force and effect as original signatures.
For questions, concerns, or notices regarding these Terms or the Services, please contact us:
Q-OTP Limited
Email: giugli@q-otp.me
Legal Department
British Virgin Islands
Specific Inquiries:
By using Q-OTP services, you acknowledge that you have read, understood, and agree to be bound by these Terms and Conditions.
Last Updated: November 1, 2025
Last updated: November 1, 2025
For privacy inquiries, contact: giugli@q-otp.me
Q-OTP Limited, a company registered in the British Virgin Islands ("Q-OTP", "we", "us", "our"), is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, process, disclose, and safeguard information when you use our OTP authentication services, website, and related services (collectively, the "Services").
This Privacy Policy applies to all users of our Services, including website visitors, account holders, and end users who receive OTP codes. By using our Services, you consent to the data practices described in this policy.
Data Controller: Q-OTP Limited acts as the data controller for personal data collected through our Services, except where we process data on behalf of our customers as a data processor (see Section 11).
When you create an account, we collect:
In the course of providing our Services, we process:
For paid services, we collect:
When you contact us, we collect:
We automatically collect information about your use of our Services:
We collect technical information from devices accessing our Services:
We use cookies and similar tracking technologies to collect information about your browsing behavior. For detailed information, see our Cookie Policy.
We may receive information from third parties:
We process personal data under the following legal bases:
| Purpose | Legal Basis |
|---|---|
| Service delivery and account management | Contract performance |
| Security and fraud prevention | Legitimate interests |
| Marketing communications | Consent |
| Legal compliance and record-keeping | Legal obligation |
| Service improvement and analytics | Legitimate interests |
Q-OTP does not sell, rent, or trade personal information to third parties for their marketing purposes.
We share information with trusted third-party service providers who assist in delivering our Services:
| Category | Examples | Purpose |
|---|---|---|
| Infrastructure Providers | Amazon Web Services (AWS) | Hosting and computing resources |
| Carrier Partners | Twilio, telecommunications carriers | SMS and RCS delivery |
| Messaging Platforms | Meta (WhatsApp), Telegram | OTP delivery via messaging apps |
| Payment Processors | Stripe, PayPal | Payment processing and billing |
| Analytics Services | Google Analytics, Datadog | Service monitoring and analytics |
| Customer Support | Intercom, Zendesk | Support ticket management |
| Security Services | Cloudflare | DDoS protection and CDN |
All service providers are bound by confidentiality agreements and required to comply with applicable data protection laws.
If Q-OTP is involved in a merger, acquisition, asset sale, bankruptcy, or reorganization, your information may be transferred as part of that transaction. We will notify you via email and/or prominent notice on our website before your information becomes subject to a different privacy policy.
We may disclose information if required to do so by law or in response to:
We may share information with third parties when you explicitly consent to such sharing, such as when integrating with third-party applications or services.
We implement comprehensive security measures to protect your information:
| Data Type | Retention Period | Reason |
|---|---|---|
| OTP Codes | Immediate deletion upon expiry/verification | Security and privacy |
| Phone Numbers (hashed) | 90 days | Fraud prevention |
| API Logs (Starter) | 7 days | Troubleshooting and support |
| API Logs (Business) | 30 days | Analytics and debugging |
| API Logs (Enterprise) | 90 days (configurable) | Compliance and audit |
| Account Information | Duration of account + 30 days | Account management |
| Billing Records | 7 years | Tax and legal compliance |
| Support Communications | 3 years | Customer service quality |
| Marketing Consents | Until withdrawal or 3 years of inactivity | Marketing compliance |
We determine retention periods based on:
Upon expiry of retention periods, data is:
Q-OTP operates globally and may transfer personal data across borders to:
For transfers from the EU/EEA to countries without adequacy decisions, we use:
Enterprise customers can choose data residency in:
You have the following rights regarding your personal data:
Request a copy of your personal data and information about how it's processed.
How to exercise: Email giugli@q-otp.me with subject "Data Access Request"
Correct inaccurate or incomplete personal data.
How to exercise: Update via dashboard or email giugli@q-otp.me
Request deletion of your personal data (subject to legal retention requirements).
How to exercise: Email giugli@q-otp.me with subject "Data Deletion Request"
Limit how we use your data under certain circumstances.
How to exercise: Email giugli@q-otp.me
Receive your data in a machine-readable format.
How to exercise: Use dashboard "Export Data" feature or email us
Object to processing based on legitimate interests or for direct marketing.
How to exercise: Email giugli@q-otp.me or click "Unsubscribe" in emails
Supervisory Authority: Data Protection Commission (Ireland)
Website: dataprotection.ie
Do Not Sell My Personal Information: We do not sell personal information. To exercise your rights, email giugli@q-otp.me
Same rights as EU/EEA residents under UK GDPR.
Supervisory Authority: Information Commissioner's Office (ICO)
Website: ico.org.uk
To protect your privacy:
We send marketing communications only with your consent:
We may send service-related communications without opt-in:
Our Services are not directed to children under 16 (or applicable age of majority). We do not knowingly collect personal information from children. If we become aware of such collection, we will delete it immediately. If you believe we have collected information from a child, contact giugli@q-otp.me.
When you use our Services to send OTP codes to your end users, you are the data controller and we act as your data processor. You are responsible for:
For customers processing personal data under GDPR, we provide a Data Processing Agreement including:
Request DPA: Email giugli@q-otp.me
We may update this Privacy Policy from time to time to reflect:
When we make material changes:
Your continued use of our Services after changes become effective constitutes acceptance of the updated Privacy Policy.
For questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Q-OTP Limited
Privacy Team
Email: giugli@q-otp.me
British Virgin Islands
Data Protection Officer (DPO):
Email: giugli@q-otp.me (Subject: "Attn: DPO")
EU Representative:
Q-OTP Ireland Ltd
Dublin, Ireland
Email: giugli@q-otp.me
Specific Inquiries:
We are committed to protecting your privacy and handling your data responsibly.
Last Updated: November 1, 2025