Legal
Terms & Conditions
These terms govern your business's use of OTPRelay, an OTP-by-SMS delivery service. OTPRelay sends one-time authentication codes only, from a fixed, pre-cleared message template configured on your account that you cannot edit or author. There are two modes: in **Send** mode you generate the code and we deliver it in one call, and in **Verify** mode we generate, send, and check the code across two calls. OTPRelay is in early access, live in Saudi Arabia today, with the rest of the GCC and then worldwide as we expand. The Service is provided on an **"as is"** and **"as available"** basis. Data handling is governed by the [Privacy Policy](/privacy) and the DPA.
Last updated: 21 June 2026
Acceptance and who these terms bind
These terms are a binding agreement between OTPRelay ("we", "us", "our") and you, the business that uses the Service. "You" means the organisation on whose behalf the Service is used, not the individual clicking through. When you accept, you accept for your company, and these terms bind it. The Privacy Policy governs how data is handled.
You accept these terms by the first of these to happen: signing up, creating an account, joining early access, or using the API or Service in any way. Using the Service is acceptance. If you do not agree, do not sign up for, access, or use the Service.
- You accept for your organisation. The person who accepts confirms they are authorised to bind the organisation they represent. Without that authority, do not accept and do not use the Service.
- This is a business-to-business service. These terms govern business customers only. The Service is not a consumer contract, is not offered to consumers, and must not be used as one. An End User who receives a code is not your counterparty here or ours - they deal with the business that asked us to message them.
- Data handling. What we collect, the controller and processor roles, and the data processing agreement that applies when you call our API are covered by the Privacy Policy and Data protection and the controller/processor roles.
OTPRelay is in early access: Saudi Arabia is live today, with the rest of the GCC and then worldwide as we expand. The Service may be free during early access and priced at general availability - see Early-access status and Fees, billing, and taxes. The two modes you can use, Send and Verify, are described in The service and the two modes.
OTPRelay operates the Service at https://otprelay.io. Legal notices and account or terms questions go to legal@otprelay.io.
Definitions
Capitalised terms have the meanings given here. Undefined terms take their ordinary meaning.
- Service. OTPRelay's one-time passcode delivery service by SMS, including the API, the Send and Verify modes, Fraud Guard, the shared pre-cleared OTPRelay sender and its fixed per-account message template, and the Documentation. The modes are described in The service and the two modes.
- Send mode. The mode in which you generate the code and OTPRelay delivers it in one API call. OTPRelay never stores or checks the code; you compare it yourself - see Send a code.
- Verify mode. The mode in which OTPRelay generates the code, sends it, and checks it across two calls, and only while that verification is open - see Verify a code.
- API. The OTPRelay application programming interface, based at https://api.otprelay.io/v1, through which you use the Service.
- Message template. The fixed, pre-cleared message wording configured on your account, sent from the shared OTPRelay sender. It carries genuine authentication codes only. You supply the code (Send) or we generate it (Verify) and you may pass limited variables and metadata, but you cannot edit, author, or otherwise control the message wording or template.
- Documentation. The technical and product docs at Documentation, including Quickstart, Authentication, Channels, Rate limits, Webhooks, and Compliance, as updated from time to time.
- Customer Data. The End User phone numbers, metadata, and other data you submit to or through the Service. Its handling is set out in the Privacy Policy and the DPA.
- End User. The person who receives an OTP message because you asked us to send or verify it. An End User is not a party to these terms.
- Order or Plan. The commercial terms - the plan you select and its pricing - under which you use the Service, as described at Pricing.
- Fees. The amounts payable for the Service under your Plan, together with any pass-through delivery costs charged onward to you.
- Confidential Information. Non-public information one party shares with the other that is marked confidential or that a reasonable person would treat as confidential given its nature or the circumstances of disclosure.
- DPA. The data processing agreement between you and OTPRelay governing our processing of End User personal data when you call the API, under which you are the controller and we are the processor - see Data protection and the controller/processor roles.
- Affiliate. Any entity that, directly or indirectly, controls, is controlled by, or is under common control with a party, where control means owning more than half of the voting interests or otherwise directing the entity's management.
- Artificial traffic inflation (AIT). Traffic - including SMS pumping - engineered to drive a flood of OTP sends to numbers or ranges a bad actor controls in order to inflate volume, as scored and addressed by Fraud Guard - see Fraud Guard, rate limits, and traffic protections.
- Operators and routing partners. The downstream parties that carry OTP messages onward to the destination network, across which OTPRelay runs multi-route failover. OTPRelay claims no direct or exclusive relationship with any named carrier.
Send and Verify are not interchangeable
The service and the two modes
OTPRelay delivers one-time passcodes by SMS, Gulf-first. You call our API at https://api.otprelay.io/v1 over HTTPS/TLS, and we deliver the code onward through operators and routing partners to reach your End User. We do not run your login, store your user records, decide who gets a code, or check whether the recipient is who they claim to be. The Service carries genuine authentication codes for your own service only - not marketing, alerts, notifications, or general-purpose messaging, and not as a backdoor channel for any other content. Data roles are set out in Data protection and the controller/processor roles.
OTPRelay works in two modes:
- Send mode. You generate the code and we deliver it in a single API call. We never store the code and we never check it - comparing what your End User enters against what you generated is your job. See Send a code.
- Verify mode. We generate the code, send it, and check it across two calls: one to start the verification and one to confirm the code your End User enters. We process and hold the code only while that verification is open, and not after it closes. See Verify a code.
In both modes, messages go out from a shared, pre-cleared OTPRelay sender using the fixed message template configured on your account. You cannot edit, author, or change the sender or the template wording. You supply the code in Send mode, we generate it in Verify mode, and you may pass limited variables and metadata, but you never control the message content - so the Service cannot be turned into a channel for marketing or any other content. Downstream, OTPRelay delivers each message through operators and routing partners with multi-route failover. OTPRelay claims no direct, named, or exclusive carrier relationship and may change routing. Availability and failover are covered in Service availability and failover and the delivery path in Channels and failover. The Service runs on AWS.
Send mode is delivery only
Early-access status
OTPRelay is in early access. Saudi Arabia is live today, with the rest of the GCC and then worldwide as we expand.
The Service is provided on an "as is" and "as available" basis, and nothing in this section is a contractual commitment to availability or a fixed SLA. The Service may contain bugs, be incomplete in places, and be unavailable, interrupted, delayed, or fail to deliver any given message. Do not rely on it as the sole path where a missed or late code would cause you or your End Users harm.
We do not offer, during early access or otherwise:
- A service-level agreement or uptime guarantee. We do not promise any particular availability, and we may take the Service down for maintenance or fixes.
- A delivery-rate, latency, or deliverability guarantee. We do not promise that any specific message reaches any specific handset, or arrives within any set time. Downstream delivery runs through operators and routing partners with multi-route failover, and the last leg to the device is outside our control - see Service availability and failover.
- A promise that any feature stays as it is. We may add, modify, suspend, withdraw, or discontinue any feature, mode, endpoint, rate limit, or the whole Service.
The things most likely to change include the Send and Verify modes and how they behave (see Send a code and Verify a code), the API base at https://api.otprelay.io/v1, rate limits (see Rate limits), how Fraud Guard scores and blocks traffic (see Fraud Guard, rate limits, and traffic protections), the fixed per-account sender template, and how the webhook signature scheme works (see Webhooks). Where a change is material and we can practically give notice ahead of it, we will, in line with Changes to the service and to these terms.
Early access may be free or offered at reduced or promotional pricing. That is for this period only, not a commitment to any future price, and any pricing can change when early access ends - see Fees, billing, and taxes. We may monitor how the early-access Service is used to fix problems and improve it, consistent with our Privacy Policy.
No SLA or delivery guarantee
Eligibility and account registration
OTPRelay is a business-to-business service. Accounts are for organisations, not consumers. By registering you confirm that you are a business acting in the course of trade and that you have authority to enter these terms on the business's behalf, binding everyone within it who must be bound - see Acceptance and who these terms bind.
For as long as you hold an account, you must:
- Provide accurate, complete, and current information, including your business identity, contact details, and the registered brand or company details we use to configure your fixed message template (the company name shown in the SMS) and to run our compliance and pre-clearance.
- Keep that information current. If your brand name, billing contact, or legal entity changes, tell us and correct it promptly.
- Run one account per customer, unless we agree otherwise in writing. We may approve additional accounts for separate brands or entities, but the default is one account per business.
- Take responsibility for all activity under your account - every send and every API call made with your credentials, whether by your team, your systems, or anyone you let in. Securing those credentials is covered in Account, API keys, and credential security.
We may decline, limit, pause, or close any registration at our discretion, and during early access we onboard customers selectively. We are not obliged to give a reason. Our handling of personal data in your registration is governed by the Privacy Policy.
Register the real brand and keep it current
License to use the API and Documentation
While your account is in good standing, OTPRelay grants you a limited, non-exclusive, non-transferable, non-sublicensable, and revocable license, for the term, to call the API at https://api.otprelay.io/v1 and to use the Documentation at Documentation. The license exists for one purpose: to build and operate your own application that sends or verifies OTP codes for your own end users, in Send mode or Verify mode - see The service and the two modes.
The license is subject to these limits:
- It is yours alone, for your own app. You may integrate the API into your own product to verify your own end users. You may not transfer, assign, or sublicense it to anyone else.
- No reselling the raw service. You may not resell, repackage, or offer the bare OTPRelay service as a standalone messaging product, and you may not run it as a generic SMS gateway or pass-through for traffic that is not your own OTP delivery.
- Keys are scoped to you. Your live and test API keys (for example att_...) authenticate your account only - see Authentication. Do not share keys so others send under your account; that is prohibited sublicensing.
- Documentation is for building, not republishing. Use it to build and run your integration. It gives you no right to copy, host, or republish it as your own.
- Everything else stays with us. OTPRelay reserves all rights not expressly granted here - see Intellectual property and feedback.
To protect the Service and the intellectual property in it, you must not, and must not permit any third party to:
- Reverse engineer, decompile, or disassemble the Service, or attempt to discover its source code, underlying ideas, or algorithms, except where applicable law expressly permits this despite this restriction.
- Build a competing product, or help anyone else build one, using the Service or anything you learn from it.
- Publish or disclose benchmark or performance results for the Service without our prior written consent.
- Probe, scan, or disrupt the integrity or performance of the Service, or any data it holds.
- Misuse test keys or the sandbox to evade rate limits, Fees, or any other control.
The license is for your end users, not for resale
Account, API keys, and credential security
When you onboard, we provision two separate bearer API keys - a live key and a test key (for example att_...) - so you can build and test without touching real traffic. We also issue a per-account webhook signing secret (for example whsec_...) that we use to HMAC-sign every delivery event we post to the HTTPS webhook_url you nominate, so you can confirm a call came from us. See Authentication for how keys are used on each request and Webhooks for how to verify signatures.
Treat each key and the signing secret as confidential:
- Keep them confidential. Do not embed live keys in client-side code, mobile apps, public repositories, logs, or anywhere an end user or third party could read them. Store them in a secrets manager, not in plaintext.
- Transmit them only over HTTPS/TLS. The API is HTTPS-only, and the webhook_url you nominate must also be HTTPS - we will not post events to a plain HTTP endpoint.
- Rotate or revoke on compromise. If a key or the signing secret is exposed, lost, or you suspect misuse, rotate it and revoke the old credential at once, and tell us at legal@otprelay.io so we can revoke it on our side. Use your test key for development so your live key stays out of throwaway environments.
- Keep a current contact on file so we can reach you about a suspected compromise or a forced rotation.
You are responsible for everything done with your credentials. Every API call made with your keys is treated as made by you, and you are liable for all resulting messages, deliveries, and Fees - whether or not you authorised each call - until you notify us that a key is compromised and we revoke it. Misuse of credentials is grounds to suspend or restrict your account under Suspension and rate limits, and your duty to protect us against claims arising from that misuse is covered in Indemnification.
The webhook signature scheme is still being finalized; current guidance lives in Webhooks and is kept in step with the Privacy Policy.
Your keys, your responsibility
Acceptable use
You may use the Service only to deliver genuine one-time authentication codes for your own service. You cannot author or edit the message: every send goes out from the shared, pre-cleared OTPRelay sender using the fixed template configured on your account, and you control only the code (in Send mode) and limited variables or metadata. The Service must never be used as a backdoor channel for marketing, promotions, alerts, notifications, or other content, and never to harass, defraud, or message people who have no authentication relationship with you. These rules apply to all traffic in every market. Read them with Your responsibilities and compliance and the traffic protections in Fraud Guard, rate limits, and traffic protections.
Authentication only. Each send must correspond to a real authentication event in your own service - a sign-in, a sign-up, or a sensitive action the recipient just took with you. You warrant that every send matches the code's genuine purpose and the recipient's expectation. The Service is not an A2P messaging gateway, and you must not use the fixed OTP template to carry, append, or wrap any promotional or unrelated content.
Prohibited purposes. You may not use the Service for, or to authenticate users of, any of the following service or business, even where local law permits it:
- Gambling in any form.
- Adult or sexual services, and any service that is obscene, defamatory, threatening, harassing, or hateful.
- Political or religious campaigning or solicitation.
- Controlled substances, alcohol, tobacco, vaping, firearms or weapons, or cannabis.
- Money-lending and comparable regulated financial solicitation.
- Unlawful, fraudulent, or deceptive activity - including phishing, smishing, and social-engineering operations.
- Any other unlawful or harmful purpose, whether or not named above.
Approved routes and sender only. Use only the routes OTPRelay provides, and do not try to bypass operator A2P termination or filtering. That means:
- No spam or unsolicited bulk messaging, and no snowshoeing or number-rotation to spread traffic and dodge filtering.
- No grey routes, P2P-disguised-as-A2P routes, or other unauthorised routes. Grey routes are treated as fraud.
- No spoofing, forging, or misrepresenting sender identity. Keep the registered brand and use-case details on your account accurate.
- No defeating our traffic protections. Cooperate with our anti-fraud controls and do not attempt SMS pumping or artificial traffic inflation, or try to evade Fraud Guard - see Fraud Guard, rate limits, and traffic protections.
No undisclosed resale or onward use. The license at License to use the API and Documentation is for your own application. You may not resell, sublicense, rent, white-label, or use the Service on behalf of undisclosed third parties without our prior written permission. Where we permit it, you must bind those downstream users to terms at least as protective as these and remain fully responsible for everything they send.
OTPRelay carries authentication codes only
We may publish a separate acceptable-use policy and incorporate it by reference, and we may add detail in our compliance guidance at GCC compliance. Any such policy builds on this section; if they conflict, the stricter rule applies.
Your responsibilities and compliance
You are the controller for the OTP traffic you send, and the compliance work that makes that traffic lawful sits with you. We act as your processor and carry the message you ask us to carry. We do not, and cannot, check that you were allowed to message a given recipient. Your data terms are in the Privacy Policy, the DPA, and Data protection and the controller/processor roles.
Consent is yours to hold, not ours to verify
On consent and lawful basis, you warrant that for every message you submit:
- You hold the recipient's consent, or another valid lawful basis, to contact that number for that purpose, and the recipient is expecting an authentication code in connection with your own service - not a marketing or unrelated message dressed up as an OTP.
- You will keep proof of that consent or lawful basis and produce it if we, a regulator, or an operator reasonably ask.
- Under KSA PDPL (SDAIA), choosing and holding the lawful basis is the controller's job, and that controller is you. The underlying data terms are in the Privacy Policy and the DPA.
Disclosures you owe your end users. OTPRelay never appears to the end user as the program brand. Before sending, and when you collect consent, you must:
- Identify yourself by your real registered brand as the sender.
- Describe what the recipient will receive - a one-time authentication code for your own service - and its event-driven frequency.
- Tell the recipient that message and data rates may apply.
- Honour opt-out and help requests, supporting recognised keywords such as STOP to stop and HELP for help.
- Maintain and link your own privacy policy and a working support contact.
On opt-out, where a recipient asks to stop, you stop sending to that number for that purpose and do not route around the request. Opt-out and help handling at the message layer is processed across the operators and routing partners that carry the traffic; keeping your own records and downstream systems in step with a recipient's choice is your responsibility as controller. OTPRelay does not globally suppress numbers on your behalf.
On the numbers themselves, you warrant that each number you submit is:
- Accurate and lawfully obtained - collected directly from the recipient or another lawful source, and current rather than stale.
- Correctly formatted in E.164 (for example +966512345678).
- Held by a recipient who is the authorized holder or user of that number and who meets any age or eligibility requirement that applies to your service.
- Not purchased, rented, scraped, harvested, or drawn from third-party lists. You do not send an OTP to a number you cannot tie to a real, authorized user of your own product.
On regulators and operators, you must work out which rules apply to your traffic in each destination country and follow them before you send. OTPRelay holds the messaging licences and pre-registered the shared, pre-cleared OTPRelay sender once for everyone, so you file no sender-ID paperwork yourself - your duty is to give accurate brand and use-case details and to meet the consent, content, and disclosure rules that fall on the controller. That includes:
- The requirements of the relevant telecom regulator - in Saudi Arabia the Communications, Space and Technology Commission (CST), formerly CITC - together with operator and routing-partner rules and industry guidelines, as amended from time to time.
- Accurate brand and use-case details for each country that requires them, given to us before you send so we can carry the message under the shared sender. OTPRelay handles sender registration and operator clearance; you keep those details accurate and current.
- Anti-SPAM and prohibited-content rules. CST's anti-SPAM regulation requires prior consent for commercial messaging, a clear and approved sender identity, and compliance with prohibited-content rules, with significant fines available under the Telecommunications Law. The prohibited-purpose and anti-artificial-traffic duties in these terms apply to you regardless.
- Consumer-facing disclosure duties - for example under the KSA E-Commerce Law and equivalent rules elsewhere - that fall on the business that contacts the end user. That business is you.
You acknowledge how delivery works and agree not to fight it. Delivery is governed by CST and downstream operator rules, and every message goes out from the shared, pre-cleared OTPRelay sender using the fixed per-account template configured for you. You must not attempt to alter the sender identity, spoof a sender, work the template into something it is not, or use grey routes or other means to evade operator or regulator controls. See GCC compliance.
On reasonable notice, and where an operator, a regulator, or a genuine fraud signal reasonably requires it, OTPRelay may ask you to evidence your compliance - for example your consent records, the brand and use-case details on file, and the nature of your traffic - and you will cooperate with any resulting investigation. If you cannot or will not, we may act under Suspension and rate limits.
You warrant, for as long as you use the Service, that, and these warranties back the indemnity at Indemnification:
- You have authority to accept these terms and to bind the business on whose behalf you act.
- You use the Service only to deliver genuine authentication codes for your own service - not marketing, and not any prohibited purpose in Acceptable use.
- You hold a valid consent or lawful basis for every recipient and will retain proof of it.
- You make the end-user disclosures above and honour opt-out and help requests.
- You meet all applicable regulator, operator, and use-case requirements that fall on the controller before you send, and you acknowledge that OTPRelay handles sender registration and operator clearance.
- Your data is accurate and lawfully sourced, your numbers belong to authorized users, and they are not bought, scraped, harvested, or stale.
- You will not use grey routes, sender spoofing, template evasion, or any other workaround to bypass operator or regulator controls.
- You are responsible for artificial inflation of traffic and SMS pumping originating from your flows, and you cooperate with the protections in Fraud Guard, rate limits, and traffic protections.
- You will not resell, sublicense, or relay the Service to third parties without our written permission.
Your end users and downstream recipients are yours. Any relationship, dispute, consent question, opt-out, or complaint from the people you message is between you and them, and the consequences of how you use OTP traffic rest with you as the controller.
Fraud Guard, rate limits, and traffic protections
Fraud Guard scores each send and works to block traffic that looks like SMS pumping or artificial traffic inflation (AIT) - patterns where a bad actor drives a flood of OTP sends to numbers or ranges they control to inflate volume. It runs on top of the Rate limits that already cap how fast you can send.
Responsibility is split as follows:
- We score and we may act. Fraud Guard scores each send, using the optional risk signals you pass, and we may throttle, rate-limit, or suspend traffic we reasonably judge to be pumping, AIT, or abuse. How we suspend and what notice we give is covered in Suspension and rate limits.
- You protect your own flows. You must run per-user and per-IP rate limiting, a CAPTCHA or similar challenge on sign-up and login, and monitoring for unusual spikes on the verification flows that call us.
- You own the traffic from your account. You are responsible for all traffic generated through your account and credentials - including AIT, SMS pumping, and toll fraud arising from your unprotected endpoints - and for charges legitimately incurred before abuse is detected and stopped.
- Do not work around the protections. You must not attempt to defeat, evade, or test the limits of Fraud Guard or the rate limits - for example by spreading traffic across accounts to dodge scoring, or by probing for thresholds. Doing so breaches these terms.
Fraud Guard is a backstop, not a guarantee
Fees, billing, and taxes
When the Service is paid, you owe the Fees set by your Plan or Order, in the billing currency stated there, plus the downstream costs of carrying your traffic. Stated Fees are exclusive of tax.
- Platform Fees. You pay the Fees for the Service under your Plan or Order. Current plans and what they include are at Pricing. Where we agree specific Fees in an Order, that Order governs your account.
- Downstream pass-through costs. Downstream messaging, regulatory, and operator surcharges are billed separately from the platform Fee. They are set by the operators and routing partners that carry your traffic and by the rules of each destination market, not by us, and they may change when those downstream costs change. Once a message is carried, the cost of carrying it is non-refundable.
- How and when you pay. Fees may be prepaid or invoiced, as your Plan or Order says. Except where these terms or your Order expressly state otherwise, Fees are non-refundable once due, including for traffic already carried.
- Taxes are on top. You are responsible for all taxes, VAT, withholding, and government or telecom surcharges that apply to your use of the Service, except taxes on OTPRelay's own net income. Where we are required to collect a tax, we add it to your invoice.
During early access the Service may be free or offered at reduced or promotional pricing. That is a starting point, not a price-lock or a commitment to any future rate. We may introduce or change Fees at general availability or at the end of an early-access period, on reasonable prior notice. If you do not accept new or changed Fees, stop using the Service before they take effect.
If a payment is late or does not arrive:
- We may pause the Service. If undisputed Fees are overdue, we may suspend access, and for continued non-payment terminate it, under Suspension and rate limits.
- We recover costs, not interest. Where we pursue an overdue amount, we may recover the collection and recovery costs we actually and reasonably incur and can evidence, such as legal and third-party recovery fees. These are not a fixed or liquidated penalty. OTPRelay charges no percentage interest or finance penalty on late payment.
Liability ceilings are governed by Limitation of liability.
Service availability and failover
OTPRelay carries each message over multiple operators and routing partners with multi-route failover - see Channels and failover. OTPRelay does not guarantee any particular delivery outcome.
- Reasonable efforts, not a fixed SLA. We aim to keep the API and the website running and to route around problems, but we offer no uptime warranty or service-level agreement, consistent with our early-access status.
- No delivery guarantee. We do not guarantee that any message is delivered, arrives within a particular time, or meets any specific success rate. Final delivery depends on downstream operators and routing partners, the recipient's mobile network, and the recipient's device, all outside our control.
- Maintenance and interruptions. We may carry out maintenance, and the Service may experience interruptions, degraded routes, or downstream outages. We try to minimise and route around these but cannot rule them out.
- Status and signals. Where we can, we expose delivery status and per-route receipts through the API and Webhooks so you can see what happened to each send and build your own retry and fallback logic.
Not for emergency or safety-critical use
OTPRelay does not guarantee delivery or timing. Give your end users a way to retry, resend, or use an alternate path, and handle a missing or late code as an expected state. This underpins our warranties and disclaimer and limitation of liability.
Intellectual property and feedback
As between the parties, each party retains ownership of its own intellectual property. These terms transfer no ownership.
As between the parties, OTPRelay owns all right, title, and interest in:
- The Service and the API, including https://api.otprelay.io/v1, its endpoints, request and response formats, and the software behind them.
- The Documentation at Documentation and everything under it.
- The shared, pre-cleared OTPRelay sender and the message template configured on your account.
- Fraud Guard and the scoring, routing, and multi-route failover logic behind delivery.
- All related technology, know-how, and improvements, including anything we build or learn while running the Service, and the OTPRelay name, logo, and other OTPRelay marks.
- De-identified and aggregated metrics about delivery, routing, throughput, and Service performance that we generate while running the Service, provided they do not identify you or any end user. We use these to operate and improve the Service. They are never your Customer Data and are never used to re-identify an end user.
Your license transfers none of the above to you.
You keep all right, title, and interest in your own application, your brand, and your Customer Data - your end-user phone numbers, the up to 10 metadata key/value pairs you attach on send, and your content.
You grant OTPRelay a non-exclusive, worldwide, royalty-free license to host, transmit, and process your Customer Data solely as needed to provide and support the Service, and never for our own purposes. For personal data, we exercise that license only as your processor, on your documented instructions and under the DPA, as described in Data protection and the controller/processor roles.
Each party keeps its own pre-existing intellectual property and trademarks. Neither party may use the other's name, logo, or marks except where these terms expressly allow it or the other party agrees in writing.
Publicity. OTPRelay will not use your name, logo, or marks in customer lists, case studies, or promotional material without your prior consent. You may withdraw that consent for future use on notice.
Feedback. If you send us suggestions, ideas, feature requests, or other feedback about the Service, you grant OTPRelay a perpetual, irrevocable, worldwide, royalty-free, and sublicensable license to use, incorporate, and build on it for any purpose, with no obligation and no compensation to you. Feedback is voluntary and given without warranty - we may act on it or not, and may already be working on the same thing.
Feedback is not your Customer Data
Data protection and the controller/processor roles
The Privacy Policy governs how OTPRelay handles personal data. On our own website, OTPRelay is the controller and decides why and how the data you give us at sign-up is used. When you call the API, you are the controller and OTPRelay is the processor: we handle the end-user phone numbers, codes, and delivery data only on your documented instructions, under a data processing agreement (DPA), and never for our own purposes.
As processor, OTPRelay does not access, view, or monitor the end-user phone numbers, codes, or delivery data you submit, except where needed to provide, support, and secure the Service, to troubleshoot at your request, or where the law or a competent authority compels us, and then only as the DPA allows. In Send mode there is no code for us to see. In Verify mode we hold the code only while the verification is open.
- Send mode. You generate the code and we deliver it in one call. OTPRelay never stores or checks it - there is no code for us to hold or return. See Send a code.
- Verify mode. OTPRelay generates, sends, and checks the code, so we process and hold it only while that verification is open, then no longer. See Verify a code.
All personal-data handling - what we collect, security, sub-processors, breach notification, retention, and cross-border transfers - is governed by the Privacy Policy and the DPA. The Service runs on AWS, so personal data may be processed and stored on AWS infrastructure and may be transferred across borders; where it is, we rely on the safeguards the applicable law requires, including Saudi Arabia's PDPL and Transfer Regulation, with the mechanics set out in the Privacy Policy and the DPA. We do not promise data localization, and we claim no certification we do not hold. See GCC compliance for our approach to regional rules.
You warrant that for every send you have a valid lawful basis and any end-user consent the law requires, and that your use of the end-user data complies with the laws that apply to you - see Your responsibilities and compliance. Ownership of data and feedback is covered in Intellectual property and feedback, and what happens to data when the relationship ends is covered in Term, termination, and effect of termination.
The DPA prevails on data-processing matters
Confidentiality
Each party will keep the other's Confidential Information confidential. Confidential Information means any non-public information one party (the discloser) shares with the other (the recipient), in any form, that is marked confidential or that a reasonable person would understand to be confidential from its nature or the circumstances. On your side it includes your API keys, webhook signing secrets, and your account and usage data; on ours it includes our non-public pricing, security details, and the unreleased parts of the API and Documentation. The personal data we process for you under the API is governed by the Privacy Policy and the DPA - see Data protection and the controller/processor roles.
The recipient will protect the discloser's Confidential Information with at least the care it uses for its own, and never less than reasonable care, and will use it only to perform under these terms. The recipient will not share it outside the people and contractors who need it for that work and who are themselves bound to keep it confidential.
These duties do not apply to information the recipient can show:
- is or becomes public through no fault of the recipient;
- the recipient already knew, free of any duty of confidence, before the discloser shared it;
- the recipient developed independently without using the other party's Confidential Information; or
- a third party rightfully gave to the recipient, free of any duty of confidence.
If a law, court, or regulator compels disclosure, the recipient may disclose - but, where the law allows, it will first give the discloser prompt notice and reasonable cooperation so the discloser can seek protection or narrow the disclosure, and it will disclose only what is legally required.
These confidentiality duties survive the end of these terms and your account, for as long as the information stays confidential - see General for the other obligations that live on after termination.
Suspension and rate limits
We may throttle, rate-limit, or suspend your account, in whole or in part, in the situations below. We will normally raise an issue with you first before acting. These powers sit alongside, and do not replace, our right to terminate under Term, termination, and effect of termination.
- Non-payment. Overdue Fees, a failed charge, or an account out of good standing - see Fees, billing, and taxes.
- Suspected fraud or abuse. SMS pumping, artificial traffic inflation (AIT), or other abusive traffic that Fraud Guard flags or that we otherwise have reason to suspect.
- Breach of the rules. A breach of these terms or of Acceptable use, including content or use we are not permitted to carry.
- Security risk. Compromised or leaked credentials, anomalous traffic, or any activity that threatens the Service, end users, or the operators and routing partners who deliver your messages.
- Legal or regulatory risk. Use we reasonably believe breaks applicable law - including the Saudi Anti-Cyber Crime Law or applicable export-control and sanctions rules - or a regulatory requirement, or that draws a binding request or order from a competent authority such as the CST.
- Volume protection. Traffic that exceeds your rate limits or that we need to slow to keep the platform stable for everyone - see Rate limits.
Where practical, we will give you notice and a chance to fix the problem before we act, and we will keep any throttling or suspension no broader and no longer than the situation needs. We may act immediately, without prior notice, where waiting would put the Service, end users, the delivery operators, or your own budget at real risk - for example active fraud, a credential leak, or a legal or regulatory demand. When we act this way, we will tell you what we did and why as soon as we reasonably can, and we will lift the measure once the cause is resolved.
Broad discretion during early access
Warranties and disclaimer
Each party represents and warrants to the other that it is duly organised and validly existing, that it has full power and authority to enter into and perform these terms, and that doing so does not breach any other agreement or obligation that binds it. Each party will comply with the anti-bribery, anti-corruption, and other laws that apply to it in performing these terms, and neither party will offer, give, or accept any improper payment or inducement in connection with them.
The Service is provided "as is" and "as available", with all faults, and you use it at your own risk. To the maximum extent permitted by applicable law, we disclaim all warranties of every kind, whether express, implied, or statutory, including any implied warranties of merchantability, fitness for a particular purpose, title, non-infringement, accuracy, and any warranty arising from a course of dealing, course of performance, or usage of trade.
To the fullest extent the law allows, we do not warrant that:
- the Service will be uninterrupted, timely, error-free, or secure, or that defects will be corrected - read this section with Early-access status and Service availability and failover;
- any specific message will be delivered, delivered on time, or accepted by the destination network, because final delivery depends on operators and routing partners and on the recipient's device and network settings, all beyond our control, even with multi-route failover;
- the acts or omissions of the operators and routing partners that carry your messages, or of any other third party, will meet any particular standard;
- the Service, including Fraud Guard, detects or prevents all fraudulent or artificially inflated traffic - see Fraud Guard, rate limits, and traffic protections;
- any results, delivery rates, or outcomes you expect from using the Service will be achieved.
The disclaimer of non-infringement above is subject to, and does not cut down, the express intellectual-property indemnity OTPRelay gives you at Indemnification.
We cannot guarantee any given code arrives
Nothing in these terms, including this section and Limitation of liability, excludes or limits any liability that cannot be excluded or limited under the law of the Kingdom of Saudi Arabia - for example liability for fraud or gross negligence. Where applicable law does not allow some or all of the disclaimers above, those disclaimers apply only to the fullest extent that law permits, and the rest of this section stays in force.
Limitation of liability
This section limits what either party can recover from the other. Read it with Warranties and disclaimer and Indemnification. It applies to claims by either party against the other, whatever the legal theory - contract, tort or delict, statute, or otherwise.
Neither party is liable to the other for indirect, incidental, special, consequential, or punitive damages, or for the following heads of loss, however they arise and even if the party was warned they were possible:
- Lost revenue, and lost profit that is indirect or speculative rather than the natural and proven result of a breach.
- Lost, corrupted, or undelivered data, including a code that did not arrive, arrived late, or was intercepted in transit.
- Loss of goodwill or reputation, and lost business opportunities.
- Business interruption, including downtime in your own product caused by a failed or delayed delivery.
This exclusion does not bar a claim for direct, foreseeable, proven lost profit. OTPRelay is liable only for direct, actual, proven loss that was foreseeable when these terms were entered into.
Where a party is liable, its total aggregate liability to the other for all claims taken together, across the whole life of these terms, is capped at the greater of:
- the total Fees you paid us for the Service in the 12 months before the event giving rise to the claim, or
- SAR 1,000 (or, where Fees are billed in another currency, its equivalent at the date of the claim).
This cap applies to OTPRelay's liability to you and, in the same way, to your liability to OTPRelay, and is without prejudice to any liability that cannot be excluded or limited under the law of the Kingdom of Saudi Arabia.
The cap and exclusions above do not apply to the following, which stand outside this section in full and apply to whichever party they concern:
- your obligations under Indemnification;
- your obligation to pay Fees properly due;
- your breach of the acceptable-use rules;
- either party's breach of its Confidentiality obligations, and OTPRelay's breach of its data-processing obligations under the DPA and Data protection and the controller/processor roles; and
- either party's fraud, deceit, gross negligence, or wilful misconduct.
To the extent the law of the Kingdom of Saudi Arabia permits, any claim arising out of or relating to these terms must be brought within 12 months of the date the claiming party knew or ought reasonably to have known of the event giving rise to it.
Indemnification
Each party will defend the other against certain third-party claims and cover the resulting losses. These indemnities do not enlarge either party's liability beyond Limitation of liability, except where that section carves the indemnities out of the cap.
You indemnify OTPRelay. You will defend, indemnify, and hold harmless OTPRelay and its Affiliates, and their officers, employees, and agents, against any third-party claim, and any loss, damage, liability, cost, or expense (including reasonable legal fees) arising out of or relating to:
- your use of the Service, and any traffic sent through your account or credentials, including charges for messages actually delivered before any block;
- your breach of these terms, including Acceptable use and Your responsibilities and compliance;
- your lack of a valid consent or lawful basis to message a recipient, or any complaint or claim by an end user or person you messaged;
- artificial traffic inflation, SMS pumping, or toll fraud originating from your flows or unprotected endpoints, whether or not Fraud Guard acted on it;
- your breach of applicable law or of any regulator or operator requirement that falls on you as the controller; and
- your Customer Data, including any claim that it was unlawfully collected or that your use of it infringed a third party's rights.
OTPRelay indemnifies you. We will defend you against a third-party claim that the Service, as we provide it and when used in line with these terms, infringes that third party's intellectual-property rights, and we will pay the damages and costs finally awarded against you, or agreed in settlement, on that claim. This indemnity does not apply to a claim arising from your Customer Data, your application, the brand or use-case details you supply, your combination of the Service with anything we did not provide, or your use of the Service in breach of these terms. If the Service becomes, or we believe it may become, the subject of such a claim, we may at our option procure the right for you to keep using it, modify it, or stop providing it.
How the indemnity works. The indemnified party will give the indemnifying party prompt written notice of the claim, sole control of its defence and settlement (except that no settlement may impose a non-monetary obligation or admission on the indemnified party without its consent, not to be unreasonably withheld), and reasonable cooperation at the indemnifying party's expense. Delay in notice reduces the indemnity only to the extent the delay prejudices the defence.
Traffic on your account is yours to answer for
Term, termination, and effect of termination
These terms run for as long as you have an account or use the Service. Either party may terminate as set out below.
- You, at any time. You may stop using the Service and close your account at any time, for any reason or none. Email legal@otprelay.io to close the account, or stop calling the API and tell us.
- Either party, for convenience. Either party may end these terms on reasonable notice to the other, without cause.
- Us, for cause. We may suspend or terminate your access if you materially breach these terms and do not cure within a reasonable time after we ask, if your Fees go unpaid, or if you abuse the Service, including the prohibited use and traffic-integrity grounds in Suspension and rate limits.
- Either party, for insolvency. Either party may terminate if the other becomes insolvent, stops paying its debts, or enters liquidation, administration, or a similar process.
Early access affects continuity of access
On termination:
- Access stops. Your live and test API keys are revoked, and your right to call the API and use the Documentation ends.
- Fees stay due. Fees already incurred remain payable, and amounts already paid are not refunded except where these terms or applicable law provide otherwise - see Fees, billing, and taxes.
- Customer Data follows the DPA and Privacy Policy. Return and deletion of the end-user data we processed for you are governed by the DPA and the Privacy Policy, not by any separate retention period stated here. The Data protection and the controller/processor roles section and the DPA control.
The following survive termination: ownership and intellectual property, the feedback license, confidentiality, the warranty disclaimers, the limitation of liability, indemnification, the trade-control and sanctions undertakings, Fees accrued before termination, notices, governing law and dispute resolution, and this survival provision. Any provision that by its nature should survive does.
Changes to the service and to these terms
OTPRelay may change the Service and these terms.
We may add, change, or discontinue features of the Service as we build it out. No specific feature is guaranteed to remain available. Where a change would materially affect how you use the Service in production, we aim to give you reasonable advance notice.
We may also update these terms as the product and the law evolve. When we do, we post the new version here and update the "last updated" date. How a change takes effect depends on its significance:
- Minor changes - clarifications, typo fixes, and updates that do not reduce your rights - take effect when we post the new version.
- Material changes - anything that meaningfully affects your rights or obligations - get notice by email to the account or waitlist contact we hold for you, or through an in-product or on-site notice.
- Notice period. Where practical, we give material changes a reasonable lead time before they take effect - typically around 30 days.
Your continued use of the Service after a change takes effect is acceptance of the updated terms, the same act of acceptance described in Acceptance and who these terms bind. If you do not agree with a change, stop using the Service before it takes effect and, if you wish, close your account.
Data handling changes follow the DPA
Trade controls and sanctions
OTPRelay routes messages across borders, so trade controls apply. You must comply with all export-control, economic-sanctions, and trade-restriction laws that apply to you and to your use of the Service, including those of the Kingdom of Saudi Arabia and any other jurisdiction whose rules reach your traffic.
- You are not a restricted party. You confirm that you, and the parties who control you, are not subject to, owned or controlled by, or acting on behalf of any party on a sanctions, denied-party, or similar restricted list.
- No prohibited destinations or beneficiaries. You will not use the Service to send messages to, from, or for the benefit of any embargoed country or territory, or any sanctioned or otherwise restricted party.
- No prohibited purpose. You will not use the Service for any purpose prohibited by applicable export-control or sanctions law, and you remain responsible for screening your own traffic where the law requires it.
Force majeure
Neither party is liable for any failure or delay in performing its obligations under these terms to the extent caused by an event beyond its reasonable control. While the event continues, the affected party's performance is excused and time for performance extends for as long as the event lasts.
Events beyond reasonable control include, without limitation:
- The upstream delivery chain. Failures, outages, congestion, throttling, or degraded performance of the operators and routing partners, mobile networks, and other parts of the delivery chain that carry your messages the last mile. We keep delivering through multi-route failover - see Service availability and failover - but do not control these networks.
- Our hosting. Outages or interruptions of the cloud infrastructure (AWS) on which the Service runs.
- Natural and physical events. Natural disasters, fire, flood, earthquake, severe weather, and epidemics or pandemics.
- Human and civil events. War, terrorism, civil unrest, riots, and sabotage, and strikes or other labour disputes other than those confined to the affected party's own workforce.
- Acts of authority. Government, court, or regulatory action, including new or changed laws, sanctions, embargoes, licensing decisions, and orders affecting messaging or telecommunications.
- Broad infrastructure failures. Internet, telecommunications, or power failures and large-scale denial-of-service attacks not specific to OTPRelay's own systems.
The affected party will take reasonable steps to limit the impact of the event and to resume performance as soon as it reasonably can, and will notify the other party where practical.
Fees already earned still fall due
Governing law and dispute resolution
These terms are governed by the laws of the Kingdom of Saudi Arabia, including the Civil Transactions Law, without regard to conflict-of-law rules, consistent with the Privacy Policy.
Before formal proceedings, raise the dispute with us at legal@otprelay.io with the details and allow a reasonable period to resolve it. If it is not resolved, the dispute is settled as follows:
- Larger disputes go to arbitration. Any dispute, controversy, or claim arising out of or relating to these terms - including its formation, breach, termination, or validity - where the amount in dispute is SAR 200,000 or more (or its equivalent), or where the claim is not purely monetary, is finally settled by arbitration administered by the Saudi Center for Commercial Arbitration (SCCA) under its Arbitration Rules in effect when the request is filed.
- Smaller, purely monetary disputes go to the courts. Any dispute where the amount in dispute is below SAR 200,000 (or its equivalent) and the claim is purely monetary is brought exclusively before the competent commercial courts of Riyadh, Saudi Arabia, which operate primarily in Arabic.
- Seat and language. Where a dispute is arbitrated, the seat is Riyadh, Saudi Arabia, and the proceedings are conducted in English, or in English and Arabic together where needed.
- Binding outcome. The arbitral award is final and binding on both parties, and judgment on it may be entered or enforced by any court of competent jurisdiction.
Awards must respect Sharia and public policy
The English version of these terms controls; an Arabic version is provided for the Kingdom where needed, and the two mirror each other section for section.
General
Assignment. You may not assign or transfer these terms, or your account, in whole or in part, without OTPRelay's prior written consent, and any attempt to do so is void. OTPRelay may assign these terms to an Affiliate, or to a successor in a merger, acquisition, reorganisation, or sale of all or substantially all of its assets, on notice to you. These terms bind and benefit the parties and their permitted successors and assigns.
Severability. If any provision of these terms is held invalid or unenforceable, it is limited or severed to the minimum extent necessary so the rest stays in full force, and where possible is replaced by a valid provision closest to the original intent. Where Saudi law cuts down part of the liability cap or disclaimers, the remainder stays in force.
Entire agreement and order of precedence. These terms, together with any DPA, any order form or pricing terms you agree, our acceptable-use rules, and the documents incorporated by reference - including the Documentation and the Privacy Policy - are the entire agreement between you and OTPRelay on their subject matter, and supersede any prior or contemporaneous understandings. If they conflict, the order of precedence is:
- A signed DPA prevails on data-protection matters - see Data protection and the controller/processor roles.
- An order form or pricing terms prevail on commercial matters such as fees and volumes.
- Our acceptable-use rules, where published, build on and are read with Acceptable use; if they conflict, the stricter rule applies.
- These terms govern everything else, and the Documentation and Privacy Policy fill in the operational and data-handling detail they point to.
Notices. Legal notices to OTPRelay go to legal@otprelay.io; for a postal point of contact, email us and we will provide one. We may give you notices by email to your account address or by an in-product or on-site notice, and each party will keep its contact details current. You agree that notices, agreements, and disclosures we provide electronically - by email or through the dashboard or site - satisfy any legal requirement that such communications be in writing. An email notice is deemed received on the next business day after it is sent, provided no bounce or non-delivery message is received; if such a message is received, the notice is not deemed delivered and must be re-sent by another channel. This applies the same way in both directions.
No waiver. A failure or delay by either party in exercising any right under these terms is not a waiver of that right, and a single or partial exercise does not preclude any further exercise of it or of any other right. To be effective, a waiver must be in writing.
Relationship of the parties. You and OTPRelay are independent contractors. Nothing in these terms creates any agency, partnership, joint venture, employment, or fiduciary relationship, and neither party may bind the other. For the messages themselves, OTPRelay acts only as a conduit transmitting the content you submit. This is separate from the data-protection roles - where, when you call our API, you are the controller and we are the processor - which are governed by the Privacy Policy and the DPA.
No third-party beneficiaries. These terms are solely between you and OTPRelay. Your end users and any other third parties gain no rights under them and are not third-party beneficiaries.
What survives termination
Contact us
For legal notices, account questions, or anything about these terms, email legal@otprelay.io. For a postal point of contact, email us and we will provide one.
For data questions, including the controller and processor roles, see the Privacy Policy and write to privacy@otprelay.io.
Questions about these terms, or a legal notice? Email us at legal@otprelay.io.