1. Purpose
This policy defines how OnCampusText (OCT) handles personal data: what is collected, why, how long it is kept, who it is shared with, and what rights apply to it.
It is an internal governance document. It records practice as actually operated. Controls not in place are listed in section 13 rather than stated as requirements, so this document can be relied on as an accurate description of how personal data is handled.
It sits alongside the Information Security Policy, which covers how data is protected. This policy covers what data exists and on what terms.
2. Scope
Applies to all personal data processed by OnCampusText, all personnel with access to it, and all third parties processing it on OCT's behalf.
3. Roles
OCT is a processor (a service provider under US state privacy law), not a controller. Customers decide what personal data to load into the platform, for what purpose, and to whom messages are sent. OCT processes that data on their documented instructions to deliver the contracted service.
The Institution
Controller
Determine what data is collected and why; obtains consent; owns the end-user relationship and any end-user privacy notice.
OnCampusText
Processor / service provider
Administers accounts. Processes data only on instruction; protects it; supports data subject requests.
A consequence worth stating plainly: because OCT has no direct relationship with message recipients, OCT does not publish an end-user privacy notice. That notice properly belongs to the institution. OCT can supply the institution with the information needed to produce one, which is what section 4 of this document is for.
4. Personal data inventory
The categories of personal data the platform maintains.
Contact Identity
Phone number, first name, last name, email address
Provided by the Customer
Message delivery and personalization
Contact Profile
Date of birth, gender, postal address, time zone
If provided by the Customer
Personalization and send scheduling
Custom fields
Up to seven customer-defined free-text fields
Provided by the Customer
Customer-defined personalization
Consent and membership
Opt-in method, timestamp, source attribution, acting party, group membership, opt-out state, tags
Recorded by the platform at enrolment and on inbound opt-out
Consent evidence and suppression enforcement
Message Records
Recipient and sender numbers, message body, media references, delivery status and timestamps, carrier response data
Generated when a message is sent
Delivery, delivery reporting, billing, dispute resolution
Engagement records
IP address, user agent, HTTP referrer, coarse IP-derived country and city, automated-traffic classification, timestamp
Generated when a recipient opens a tracking link
Click attribution, engagement reporting, distinguishing human from automated traffic
Account data
Account name, username, email address, time zone, account status
Provided at account provisioning
Account administration and authentication
Credentials
Salted password hashes, API key identifiers and encrypted key secrets
Generated at credential issuance
Authentication
Operational logs
Account and record identifiers, source IP address, operation performed
Generated by services during operation
Troubleshooting, security monitoring, audit
Not collected. The platform does not collect GPS or precise device location, device identifiers, advertising identifiers, biometric data, or government identifiers, and performs no browser fingerprinting beyond the user agent string as supplied by the client.
Free-text caveat. Message bodies and custom fields are authored by the customer and may contain any information the customer chooses to include, including regulated categories. OCT does not inspect or classify customer content by regulatory category, and applies the same protections to all customer data regardless of what it contains.
5. Purposes of processing
Personal data is processed only to deliver the contracted service:
• Delivering messages to the recipients the customer specifies
• Personalizing message content using customer-supplied contact fields
• Recording and enforcing consent and opt-out
• Reporting delivery and engagement back to the customer
• Detecting automated traffic so engagement reporting is accurate
• Detecting reassigned numbers so messages do not reach a person who never consented
• Checking outbound content against messaging-industry content standards
• Operating, securing and troubleshooting the platform
• Billing and account administration
Personal data is not used for marketing by OnCampusText, profiling, advertising, data brokerage, resale, or any analytics unrelated to providing the service.
6. Consent and Choice
Consent is obtained by the institution, which supplies the contact data. OnCampusText provides and enforces the mechanisms that give effect to it:
• Per-recipient opt-in records with timestamp, method and source attribution
• An opt-out mechanism available to the individual in messaging, honored permanently through suppression enforced in the send path on every subsequent send
• Suppression and blocklist enforcement applied before dispatch
• Reassigned-number detection, so a number transferred to a new person is identified rather than messaged on the previous person's consent
These implement the US messaging consent regime (TCPA, CTIA, and 10DLC registration requirements).
7. Retention and Disposal
OnCampusText holds no physical media containing personal data. Media handling and sanitization are performed by the cloud provider in accordance with NIST SP 800-88.
Engagement records containing IP address and user agent
24 months, then deleted by a scheduled job
Contact records and message history
Life of the account; deleted when the customer deletes them or on termination
Customer data after termination
Available for export for 90 days; deleted from live systems within a further 30 days
Backups
Encrypted; expire on the normal backup rotation and are not retained beyond it
Operational logs
15 days in the centralized logging platform
Authentication and privileged-access records
Retained in the platform database beyond the operational log window
8. Disclosure and subprocessors
Personal data is disclosed only to the subprocessors required to deliver the service, and only for that purpose.
Google Cloud Platform
Infrastructure, storage, databases, secrets
All hosted data
MongoDB Atlas
Managed database
Contact records
Twilio, Bandwidth, Sinch
Carrier connectivity
Phone numbers, message content
Datadog
Logging and monitoring
Operational logs including identifiers
Personal data is not sold or shared. It is not disclosed to any party outside this set except where required by valid legal process — OnCampusText does not disclose customer data to law enforcement absent a subpoena, court order or warrant appropriate to the data sought, except where necessary to prevent imminent risk of death or serious physical injury.
Material changes to data handling, including the addition of a subprocessor, are communicated to customers.
9. Data subject rights
Because OnCampusText is a processor with no direct relationship with individuals, requests are routed through the customer as controller. OnCampusText supports them using platform capabilities:
• Access — contact records and message history can be exported
• Correction — contact fields can be updated
• Deletion — contacts can be deleted, removing the record
• Objection — permanent opt-out and suppression
OnCampusText commits to responding to a customer request for support with a data subject request within 10 business days.
10. Security of personal data
Personal data is protected by the controls defined in the Information Security Policy. In summary: encryption in transit and at rest, application-layer encryption of stored secrets, access scoped to the authenticating account and namespace, private-only database networking, staff access requiring VPN plus a multi-factor-authenticated central identity plus explicit cloud authorization, and recorded privileged access to customer accounts.
11. Regulatory Scope
FERPA. Institutions may import contact lists typically derived from institutional student records, so data processed may constitute education records. OnCampusText processes it solely on the institution's instruction and under its direct control, does not use it for its own purposes, and does not disclose it beyond the subprocessors listed in section 8.
US state privacy law. The platform processes personal data of residents of states with comprehensive privacy statutes. Lime acts as a service provider on documented instructions and does not sell or share personal data.
TCPA / CTIA / 10DLC. Implemented as described in section 6.
GDPR and PIPL. OnCampusText operates as a US service hosted in US regions with US carrier connectivity and does not knowingly process data of subjects in the EEA or mainland China.Personal data is protected by the controls defined in the Information Security Policy. In summary: encryption in transit and at rest, application-layer encryption of stored secrets, access scoped to the authenticating account and namespace, private-only database networking, staff access requiring VPN plus a multi-factor-authenticated central identity plus explicit cloud authorization, and recorded privileged access to customer accounts.
12. Automated Processing
The platform performs automated classification of tracking-link clicks as human or automated, content compliance classification of outbound message content, assistive message-quality suggestions advisory to the human author, reassigned-number detection, and automatic opt-out handling.
None of this makes a consequential automated decision about an individual. Classification is applied to traffic and content, not to people; no individual is granted or denied a benefit, service or right by an automated decision.
Classification outputs record the reasons and confidence behind a result rather than an unexplained verdict. Where a classifier's error rate would affect legitimate messages, it is not permitted to act — the content compliance classifier runs in monitoring-only mode for this reason and blocks nothing.
13. Known Limitations
Recorded deliberately so this policy remains accurate. Tracked as planned improvements:
• A formal Data Privacy Impact Assessment has not been conducted.
• Personal data is not anonymized or de-identified; it is protected by encryption and access control instead. Identifiable data is required to deliver a messaging service.
• Contact and message data have no automatic retention limit; their lifetime is determined by the customer.
• Deletion following the post-termination export window is performed manually rather than by an automated job.
• A formal certification process for stop-processing requests, including confirmation of propagation to subprocessors, is not established. Carriers retain their own records of previously delivered messages independently.
• There is no formal ethical review stage in the development process.
• Data processing agreements are not uniformly executed across every subprocessor; several operate under standard enterprise terms.
14. Privacy concerns and complaints
Privacy concerns reach OnCampusText through the customer support path and are escalated to executive leadership, who owns privacy determinations — including whether an incident constitutes a reportable personal data breach.
15. Review
This policy is reviewed at least annually, and following any material change to the platform, its subprocessors, or the regulatory environment.
Last reviewed on September 1, 2026
Copyright 2025. OnCampusText. All Rights Reserved.
What information do we collect?
We collect information from you when you register on the site, place an order, enter a contest or sweepstakes, respond to a survey or communication such as e-mail, or participate in another site feature. When ordering or registering, we may ask you for your name, e-mail address, mailing address, phone number, credit card information or other information. You may, however, visit our site anonymously. We also collect information about gift recipients so that we can fulfill the gift purchase. The information we collect about gift recipients is not used for marketing purposes. Like many websites, we use “cookies” to enhance your experience and gather information about visitors and visits to our websites. Please refer to the “Do we use ‘cookies’?” section below for information about cookies and how we use them.
How do we use your information?
We may use the information we collect from you when you register, purchase products, enter a contest or promotion, respond to a survey or marketing communication, surf the website, or use certain other site features in the following ways: To personalize your site experience and to allow us to deliver the type of content and product offerings in which you are most interested. To allow us to better service you in responding to your customer service requests. To quickly process your transactions. To administer a contest, promotion, survey or other site feature. If you have opted-in to receive our e-mail newsletter, we may send you periodic e-mails. If you would no longer like to receive promotional e-mail from us, please refer to the “How can you opt-out, remove or modify information you have provided to us?” section below. If you have not opted-in to receive e-mail newsletters, you will not receive these e-mails. Visitors who register or participate in other site features such as marketing programs and ‘members-only’ content will be given a choice whether they would like to be on our e-mail list and receive e-mail communications from us.
How do we protect visitor information?
We implement a variety of security measures to maintain the safety of your personal information. Your personal information is contained behind secured networks and is only accessible by a limited number of persons who have special access rights to such systems, and are required to keep the information confidential. When you place orders or access your personal information, we offer the use of a secure server. All sensitive/credit information you supply is transmitted via Secure Socket Layer (SSL) technology and then encrypted into our databases to be only accessed as stated above.
Do we use “cookies”?
Yes. Cookies are small files that a site or its service provider transfers to your computer’s hard drive through your Web browser (if you allow) that enables the site’s or service provider’s systems to recognize your browser and capture and remember certain information. For instance, we use cookies to help us remember and process the items in your shopping cart. They are also used to help us understand your preferences based on previous or current site activity, which enables us to provide you with improved services. We also use cookies to help us compile aggregate data about site traffic and site interaction so that we can offer better site experiences and tools in the future. We may contract with third-party service providers to assist us in better understanding our site visitors. These service providers are not permitted to use the information collected on our behalf except to help us conduct and improve our business. You can choose to have your computer warn you each time a cookie is being sent, or you can choose to turn off all cookies. You do this through your browser (like Netscape Navigator or Internet Explorer) settings. Each browser is a little different, so look at your browser Help menu to learn the correct way to modify your cookies. If you turn cookies off, you won’t have access to many features that make your site experience more efficient and some of our services will not function properly. However, you can still place orders over the telephone by contacting customer service.
Do we disclose the information we collect to outside parties?
We do not sell, trade, or otherwise transfer to outside parties your personally identifiable information unless we provide you with advance notice, except as described below. The term “outside parties” does not include our business. It also does not include website hosting partners and other parties who assist us in operating our website, conducting our business, or servicing you, so long as those parties agree to keep this information confidential. We may also release your information when we believe release is appropriate to comply with the law, enforce our site policies, or protect ours or others’ rights, property, or safety. However, non-personally identifiable visitor information may be provided to other parties for marketing, advertising, or other uses.
How can you opt-out, remove or modify information you have provided to us?
To modify your e-mail subscriptions, please let us know by modifying your preferences in the “My Account” section. Please note that due to email production schedules you may receive any emails already in production. To delete all of your online account information from our database, sign into the “My Account” section of our site and remove your shipping addresses, billing addresses & payment information. Please note that we may maintain information about an individual sales transaction in order to service that transaction and for record keeping. Third party links In an attempt to provide you with increased value, we may include third party links on our site. These linked sites have separate and independent privacy policies. We therefore have no responsibility or liability for the content and activities of these linked sites. Nonetheless, we seek to protect the integrity of our site and welcome any feedback about these linked sites (including if a specific link does not work). Changes to our policy If we decide to change our privacy policy, we will post those changes on this page. Policy changes will apply only to information collected after the date of the change. This policy was last modified on September 27, 2022.
Questions and feedback
We welcome your questions, comments, and concerns about privacy. Please send us any and all feedback pertaining to privacy, or any other issue. Online Policy Only This online privacy policy applies only to information collected through our website and not to information collected offline.
Your consent
By using our site, you consent to our privacy policy.
Copyright 2025. OnCampusText. All Rights Reserved.
Facebook
Instagram
Youtube