Legal
Privacy Policy
Last updated: August 13, 2026
This policy explains what YURN collects, why, and what we do with it. It covers two groups: merchants who use our portal to send offers, andconsumers who follow merchants by text message.
1. What we collect
From consumers
- Phone number — collected when you text a JOIN keyword to a YURN number. This is the only identifier we require.
- First name — optional, only if you reply with it after joining.
- Message history — the texts you send to and receive from YURN numbers, including delivery status.
- Engagement events — link clicks, offer claims, and redemptions, so merchants can see what worked.
- Approximate timezone — derived from your area code, used only to enforce quiet hours.
From merchants
- Business identity: legal name, display name, address, email, and business verification data (e.g. EIN last four, Google Business Profile match, domain verification records).
- Billing details, processed by Stripe. YURN never stores card numbers.
- Portal usage and audit logs.
2. Consent records
When a consumer joins a merchant's list, we keep an immutable record of that consent: the inbound message, its exact text, the phone number, the carrier timestamp, the receiving number, and the confirmation message we sent back. This record exists to prove — to carriers, regulators, and courts — that every message we send was asked for. Consent records are never deleted, even after you opt out; the record of consent and its revocation both persist, because both protect you.
3. How we use information
- Delivering the service: routing messages, enforcing opt-outs and quiet hours.
- Showing merchants aggregate and per-offer analytics.
- Preventing abuse: complaint-rate monitoring, content review, fraud detection.
- Legal compliance and dispute resolution.
We do not use consumer phone numbers for advertising unrelated to the merchants a consumer follows, and we do not build cross-merchant marketing profiles of consumers.
4. What we share — and what we don't
We do not sell personal information. Ever. We share data only with:
- The merchants you follow — a merchant sees your number, optional first name, and your activity with that merchant only.
- Service providers — messaging carriers and our SMS provider (Twilio), cloud infrastructure (Cloudflare, Neon), billing (Stripe), and email (Resend), each bound to use data only to provide their service to us.
- Legal process — when required by law, subpoena, or to protect the safety and integrity of the platform.
5. Retention
Consent records are retained indefinitely, as described above. Message logs and engagement events are retained for as long as needed for analytics and compliance, then archived. Merchant account data is retained for the life of the account and up to seven years afterward for tax and legal purposes. Consumer first names are deleted on request.
6. Your choices
- Consumers: Reply MUTE to pause a merchant for 30 days, STOP to leave permanently, orHELP for program information. These work instantly, on every message, with no account or login.
- Access and deletion: Email[email protected] to request a copy of your data or deletion of data that we are not legally required to keep (consent records are retained as our legal basis for having messaged you).
7. Security
Data is encrypted in transit and at rest. Access to production data is limited to personnel who need it, logged, and audited. No system is perfectly secure; if a breach affects your personal information we will notify you as required by law.
8. Children
The Service is not directed to children under 13, and we do not knowingly collect their information. If you believe a child has joined a list, contact us and we will remove the number.
9. Changes and contact
We will post updates to this policy here and, for material changes affecting consumers, note the change in a message footer or on the offer pages. Questions or requests: [email protected].