Under the GDPR (and the ePrivacy rules alongside it), a phone number is personal data and marketing SMS to people in the EU needs consent or an existing customer relationship, plus an opt-out in every message.
European rules combine two things: the GDPR, which governs how you hold and process numbers (lawful basis, retention, access requests), and the ePrivacy directive as implemented per country, which governs unsolicited electronic marketing. The practical result is consent for marketing, a soft opt-in exception for existing customers in some states, and a mandatory opt-out.
The gateway is a processor of your lists; what it keeps and for how long matters for your own compliance.
At SMSMeteor: message content and delivery data are kept 90 days then deleted; no identity data is collected about the account holder. The privacy policy lists what is stored.
