DEV Community

GhostSMS
GhostSMS

Posted on

Why Every SaaS Wants Your Phone Number (and How to Decide When to Give It)

Every few weeks someone asks me why their bank, their food delivery app, their project management tool and their dating app all need a phone number. Most people shrug and type it in. This post is a calm look at why SaaS products keep copies of your number, what actually happens to it afterwards, and how to make a deliberate choice instead of a reflexive one.

Why products ask for your number in the first place

There are a handful of honest reasons, and a few less honest ones.

1. Account recovery. Email accounts get compromised or abandoned. A phone number gives support teams a second channel to confirm "is this really you?" when a password reset goes wrong.

2. Spam and abuse prevention. Creating a thousand email addresses is free. Getting a thousand working phone numbers is not. Many platforms use phone verification purely as a speed bump against bot signups and free-trial abuse.

3. Two-factor authentication. SMS one-time passwords are still the most widely understood second factor, even though authenticator apps and passkeys are stronger.

4. Marketing and identity matching. This is the part that rarely makes the signup screen. A phone number is a remarkably stable identifier. People change email addresses, devices and browsers, but many keep the same number for a decade. That makes it useful for linking records across datasets, ad platforms and partner integrations.

What happens after you click "Verify"

From a developer's point of view, the number usually ends up in several places:

  • The primary users table, often in plain text so support staff can search it.
  • The SMS provider's logs (delivery receipts, message bodies, timestamps).
  • Analytics or CRM tools, if someone wired up an "identify user" call with the phone field.
  • Backups and data warehouse exports, which tend to live much longer than the production row.

None of this is malicious by default. It's just how systems grow. But it means that when you delete your account, the number may well survive in logs, backups and third-party tools for months or years. And when any of those systems leak, your number travels with your name, email and sometimes your address.

Why that matters more than it seems

A leaked phone number isn't just a spam problem. It's a key that unlocks other things:

  • Phishing that feels personal. "Hi Priya, your parcel is delayed" lands very differently when the sender knows your name and number.
  • SIM-swap targeting. Attackers who know your number and carrier have a head start on convincing a support agent to port it.
  • Cross-site profiling. The same number showing up in multiple breaches lets data brokers stitch together a surprisingly complete picture of you.

A simple framework: tier your services

You don't need to be paranoid about every signup. A practical approach is to sort services into tiers:

Tier 1 – Critical (banking, primary email, government, work SSO). Use your real, long-term number, but prefer an authenticator app or passkey as the main second factor. Ask your carrier about a port-out PIN.

Tier 2 – Important but replaceable (shopping, travel, major social accounts). Real number is fine if you'll actually need recovery, but turn off marketing SMS and review what is shared with partners.

Tier 3 – Throwaway or one-off (trials, forums, a coupon, a Wi-Fi portal, a marketplace you'll use once). These rarely need your permanent identity. This is where a separate number makes a lot of sense.

For that third tier, some people keep a cheap second SIM; others use a service for receiving verification texts on a number that isn't their personal one. For example, GhostSMS offers anonymous SMS numbers, which can be handy for keeping your real number out of low-stakes signups. Whatever you pick, don't use a temporary number for anything you'd need to recover later, since you may lose access to it.

If you build SaaS: be the product you'd want to sign up for

Developers reading this can help on the other side of the form:

  • Ask only when you need it. If the number exists purely for anti-abuse, say so, and don't reuse it for marketing.
  • Offer alternatives to SMS 2FA. TOTP apps and passkeys are better for users and cheaper than SMS.
  • Mask it in your UI and logs. Support rarely needs the full number on screen.
  • Actually delete it. Include phone fields in your retention and deletion jobs, including analytics and SMS provider data where possible.
  • Don't send it to ad pixels. Hashed or not, a phone number in a tracking call is still an identifier.

Wrapping up

Phone numbers became the default identity layer of the internet almost by accident. They're convenient, but they're also sticky, leaky and hard to change. Treat yours like a key rather than a contact detail: give your real one to the services that truly need it, use a separate number where it doesn't matter, and if you build products, collect less and delete more.

What's your rule of thumb for handing out your number? I'd love to hear it in the comments.

Top comments (0)