MustardSMS
SportsCity eventsAI event SMSPricingContact
Sign in Start free

■ Legal

Privacy Policy

Effective February 3, 2026 Version 4.1 8 min read Hexoglyph Holdings LLC dba MustardSMS
Terms of service Privacy policy AI policy

What this document actually says

■

Mobile data is never sold

No phone numbers or SMS opt-in data are sold, rented, traded or shared with third parties for marketing.

■

Three ways to opt in

Express written action on a web form, QR code registration, or the recipient starting the conversation by text.

■

Carrier disclosures at opt-in

Message frequency, message and data rates, and STOP/HELP instructions appear at opt-in and in the first outbound message.

■

Retention you control

Metadata for 13 months, message content for 90 days after the event, billing records for 7 years.

Contents

  1. 1 Notice at collection
  2. 2 Definitions and legal roles
  3. 3 SMS compliance and carrier disclosure (10DLC)
  4. 4 Comprehensive categories of information collected
  5. 5 Cookies, tracking and Global Privacy Control
  6. 6 Detailed use of information and AI logic
  7. 7 Data sharing and subprocessor transparency
  8. 8 Data retention and account deactivation
  9. 9 Regional privacy rights
  10. 10 Security and incident response
  11. 11 Contact information

Questions about this policy?

Contact us

How MustardSMS collects, uses and retains information, including the carrier-required disclosures for 10DLC messaging. The clause organizers and residents ask about most: mobile information is never shared with third parties for marketing, and SMS opt-in data is never shared with anyone.

This Privacy Policy describes how Hexoglyph Holdings, LLC (“Hexoglyph,” “Company,” “we,” “us,” or “our”) collects, uses, processes, stores, and discloses information in connection with its SMS-based automation, marketing, and event RSVP platform, MustardSMS (the “Service”).

By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. This Service is intended for use within the United States only.

1

Notice at collection

In accordance with various U.S. state privacy laws (including CCPA/CPRA, UCPA, VCDPA, and TDPSA), we provide this summary of our data practices at or before the point of collection.

Categories of personal information collected: Identifiers, Commercial Information, Internet/Network Activity, General Geolocation, Professional/Employment Information, and Message Content.
Business and commercial purposes: To provide and maintain the Service, facilitate AI-assisted interpretation (Assistant-Operator model), ensure platform security, troubleshoot technical delivery, and conduct opt-in marketing.
Retention criteria: We retain metadata for 13 months; message content for 90 days following the event lifecycle; and billing/transactional records for 7 years for tax/accounting purposes.
Selling or sharing: We do not “sell” your personal information for monetary consideration. We “share” identifiers with subprocessors strictly to facilitate message delivery and platform functionality. California residents may exercise “Do Not Sell or Share My Personal Information” rights by submitting a request to privacy@mustardsms.com.
2

Definitions and legal roles

“Service” refers to the MustardSMS platform, its messaging capabilities, scheduling workflows, and web-based interfaces.
“User/Operator” refers to the individual or entity utilizing the Service to coordinate communications.
“End Recipient” refers to any individual receiving communications initiated via the Service.
“Subprocessor/Vendor” refers to third-party entities engaged by Hexoglyph (e.g., SMS gateways, cloud hosting) that process data on our behalf.

Role clarity (controller vs. processor)

Hexoglyph / MustardSMS acts as a “Service Provider” or “Processor” regarding Message Content and End Recipient data. We process this data solely on the documented instructions of the Operator.

The User/Operator acts as the “Data Controller” for all End Recipient data. Operators are responsible for establishing a lawful basis for messaging (obtaining consent), ensuring the accuracy of data, and providing required event-specific notices to their recipients.

3

SMS compliance and carrier disclosure (10DLC)

To comply with 10-Digit Long Code (10DLC) regulations, CTIA guidelines, and federal TCPA requirements, the following mandatory disclosures apply:

Information sharing for SMS: No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. We do not sell, rent, loan, trade, lease, or otherwise transfer for profit any phone numbers or personal information collected through SMS opt-in to any third party. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
Consent segregation: We maintain a strict administrative boundary between Transactional Consent (required for event RSVPs) and Marketing Consent.
Opt-in verification: Consent is obtained via express written action on web forms, QR code registration, or by the End Recipient initiating a mobile conversation (Text-to-Join).
Marketing opt-in: Promotional communications are sent only with Prior Express Written Consent.
Opt-out (STOP): Recipients may reply “STOP” at any time to immediately cease communications.
Records of consent: We maintain immutable, audit-ready logs of all consent and opt-out events to satisfy carrier audits.
Carrier requirements: Carrier-required disclosures, including message frequency variability, standard message and data rates, and STOP/HELP instructions, are presented at the point of opt-in and are also included within the initial outbound SMS message sent to each End Recipient.
4

Comprehensive categories of information collected

Within the last 12 months, we have collected the following:

CategorySpecific data pointsBusiness purpose
IdentifiersName, IP address, email, mobile number, unique account identifiers.Account authentication and message routing.
Commercial informationSubscription tier, billing history, payment metadata.Financial reporting and tax compliance.
Network activityLog files, browser type, device identifiers, AI dashboard interactions.Platform stability and security monitoring.
Professional informationBusiness name, job title, and industry vertical (for Operators).B2B service tailoring and administrative support.
Message contentText, metadata, and media (MMS) within messages.RSVP interpretation and event coordination.

Inbound media (MMS) handling

Inbound media is subject to automated malware scanning. We do not manually review media except for abuse prevention. Users are strictly prohibited from transmitting: biometric images, government IDs, or sensitive medical imagery.

Sensitive personal information

We do not knowingly collect “Sensitive Personal Information” (e.g., Social Security numbers, precise geolocation, genetic data). Users are strictly prohibited from utilizing the Service to transmit such data.

5

Cookies, tracking and Global Privacy Control

We utilize tracking technologies for security and analytics.

Essential cookies: Required for authentication and security.
Global Privacy Control (GPC): We acknowledge and respect GPC signals where technically feasible. While we do not currently respond to legacy “Do Not Track” (DNT) browser signals, users may use GPC or our manual opt-out tools to manage preferences.
6

Detailed use of information and AI logic

No fully automated decision-making: Our AI Advisory Logic is a non-binding tool for Operator convenience. All actions affecting event attendance, financial obligations, or recipient commitments require explicit Operator approval. Operators may override AI suggestions at any time.
User-generated content (UGC) liability: Hexoglyph does not review Message Content for legality prior to delivery. Operators represent they have the rights to use submitted content. We may remove content post-delivery if abuse is detected.
7

Data sharing and subprocessor transparency

Service providers: We disclose data to vendors (e.g., telecommunications and cloud infrastructure providers) strictly to facilitate the Service. A current list of subprocessors is maintained internally and is available to Operators upon written request submitted to privacy@mustardsms.com.
Data localization: All Service Data is processed and stored primarily in the United States. Incidental transfers (e.g., for vendor redundancy) remain subject to U.S. contractual safeguards.
Legal compliance: Disclosure to law enforcement in response to a valid subpoena, court order, or warrant.
8

Data retention and account deactivation

Deactivation vs. deletion: Account deactivation does not result in immediate deletion. We maintain data according to our retention schedule (e.g., 7 years for billing) to satisfy legal and tax obligations.
Legal holds: We may suspend deletion for specific data subject to a valid legal preservation request or ongoing litigation.
9

Regional privacy rights

Residents of CA, UT, VA, CO, CT, TX, and OR have the right to Access, Correction, Deletion, and Opt-Out. We also provide a Right to Appeal if we deny a privacy request. Where applicable, a B2B Exemption may apply to information collected from individuals acting as business representatives.

9.1 Response timing and verification

We will respond to verified consumer privacy requests within forty-five (45) days of receipt, as required by applicable state law. Where permitted, we may extend this response period once by an additional forty-five (45) days and will notify the requestor of the extension and the reason for it.

Requests must be submitted via our official support portal or by emailing privacy@mustardsms.com. We may require reasonable verification to confirm the identity of the requestor before fulfilling the request.

10

Security and incident response

Breach notification: In the event of a confirmed security breach affecting personal information, we will notify affected Operators and/or End Recipients without unreasonable delay, in accordance with applicable state laws and in coordination with the Operator (as Controller).
SMS inherent risk: SMS communications are inherently unencrypted. By using the Service, you acknowledge the inherent risks associated with transmitting data via SMS, which is not claimed to be end-to-end encrypted.
11

Contact information

Privacy Officer, Hexoglyph Holdings, LLC.

Email: privacy@mustardsms.com

All inquiries must be submitted via the support portal or the email above.

MustardSMS

One text number for the whole event. Sports and city events, answered in seconds.

Get started free

Use cases

Sports eventsCity eventsAI event SMS

Company

PricingContactAboutBlog

Legal

TermsPrivacyAI policy
© 2026 MustardSMS · Hexoglyph Holdings LLC · Cape Cod, MA
10DLC certifiedA2P approvedTCPA consent log