Privacy Policy
Last updated: September 2026
This is a standard template describing what the Service actually collects and does with it today. It hasn’t been reviewed by a lawyer — treat it as a good-faith starting point, not final legal advice.
1. What we collect
Your email address (for sign-in and order communication); the destination, data allowance and validity period you choose; the ICCID and QR code issued for your eSIM; payment details, handled entirely by our payment processors (Stripe, YouCanPay) — we never see or store full card numbers.
2. Why we collect it
To create your account, order and deliver the eSIM you purchased, bill you correctly, send order confirmations, and provide support if something goes wrong.
3. Who it’s shared with
eSIM Access, our upstream eSIM provider, receives what’s needed to order and provision your eSIM profile — that’s the same relationship as any reseller has with its upstream network. Payment processors (Stripe, YouCanPay) handle your payment directly. We don’t sell your data or share it with anyone else for marketing.
4. Where it’s stored
Account and order data is stored on Netlify Blobs. Your eSIM profile itself (ICCID, SM-DP+ activation state, data usage) is managed by eSIM Access’s infrastructure, which we query on your behalf when you open your dashboard.
5. Cookies
We use a session cookie to keep you signed in after email verification. We don’t use tracking or advertising cookies.
6. How long we keep it
Account and order data is kept as long as your account is active, plus what’s needed for billing records. If you ask us to delete your account, we remove what we can beyond any legal retention requirement (e.g., invoices).
7. Your rights
You can ask to see what we hold about you, correct it, or have your account and its data deleted. Contact us via the Contact page to make a request.
8. Security
Passwords and session tokens are never stored in plain text. Sign-in uses a one-time code sent to your email — there is no password to protect on our side.
9. Changes
We may update this policy as the Service changes. Continuing to use the Service after an update means you accept the new policy.
10. Contact
Questions about this policy, or a data request — reach us via the Contact page.