SimbaSIM · Legal

Privacy Policy

How we handle your purchase details, support conversations, website analytics and advertising measurement.

Last updated 27 September 2026

The short version

  • We ask for one thing: an email address, so we can send you your eSIM.
  • No account is required to buy, so there is no password and no profile.
  • We never see your card details. Stripe handles payment.
  • We use website analytics and advertising measurement to understand visits and purchases. The tools and information involved are described below.

1. What we collect

Because you gave it to us

  • Your email address. Required — it is the delivery address for your eSIM and the only way to recover a purchase later.
  • Your destination and plan choice. Needed to issue the right eSIM and to show you the right price.

Because you paid

  • Payment records — amount, currency, time, card brand and last four digits, and billing country. Stripe holds the card itself; we only ever see this summary. We keep it because tax law requires us to.
  • If you pay with Apple Pay or Google Pay, the wallet supplies a name and email to complete the payment. We use the email for delivery if you did not type one.

Because the service ran

  • Order and eSIM records — your order reference, which plan, and the eSIM identifiers issued to you.
  • Connection metadata from the network partner — how much data was used and roughly when. This is needed to check your plan status and investigate faults. We do not receive, and cannot see, the content of your traffic, the sites you visit, or your messages.
  • Ordinary server logs — IP address, browser, and pages requested, kept briefly for security and debugging.
  • Website and checkout activity — pages visited, referral information, browser and device information, approximate country, and checkout steps or errors. Analytics and advertising providers also use cookies and related identifiers, as described in section 7.

2. Why we are allowed to hold it

WhatWhyBasis
Email, plan, order recordTo deliver what you bought and support you afterwardsPerforming our contract with you
Payment and invoice recordsAccounting, tax, and fraud disputesLegal obligation
Usage metadataChecking your plan status and diagnosing faultsPerforming our contract
Support chat messagesAnswering you, and checking afterwards that the answer was rightPerforming our contract
Server logsKeeping the site up and abuse off itLegitimate interests
Product emails you opt intoTelling you about things you asked to hear aboutConsent — withdrawable at any time

We do not send marketing email to people who only bought an eSIM. Buying is not consent to a newsletter.

3. Who else touches it

These providers help us deliver the service, understand website use, and measure our advertising.

WhoWhat forWhere
Stripepayment processing and invoicingUnited States, EU
Cloudflarehosting, DNS, email forwarding, and order storageGlobal edge network
DataFastwebsite analytics and checkout funnel measurementSingapore; infrastructure including the United States
Google Adsadvertising conversion measurementUnited States, EU
OpenAIChatGPT Ads measurementUnited States and other processing locations
Our eSIM supplierissuing eSIM profiles and buying the roaming capacity that carries your dataIsrael, and the local network of each destination

Because eSIMs work by roaming onto local networks, the operator in your destination necessarily learns that a device is connected to it. That is how mobile networks function, and it is outside our control.

We will disclose data if we are legally compelled to, and we will tell you when we are permitted to. The information sent to analytics and advertising providers is described in section 7.

One disclosure is worth spelling out, because it is written into our supply agreement rather than left to discretion. Where a law enforcement or regulatory authority serves valid legal process — a warrant or subpoena from a court with jurisdiction — on us or on our eSIM supplier, we may be required to identify the customer behind a particular SIM, and to pass on what we hold: the order, the address it went to, and the usage records the network generated. We will tell you when we are legally permitted to tell you.

4. International transfers

A travel product moves data across borders by definition. Our processors operate globally and rely on Standard Contractual Clauses or equivalent safeguards for transfers out of the UK and EEA.

5. How long we keep it

  • Order and eSIM records: 90 days after the plan expires, so support and refunds are possible.
  • Payment and invoice records: as long as tax law requires, typically six to seven years.
  • Support chat transcripts: 400 days. Support is answered by an AI agent, and keeping what it said is how we check it answered you correctly and settle a dispute or a card chargeback afterwards. Do not type anything into the chat you would not want kept — it is a support channel, not a secure one.
  • Server logs: 30 days.
  • Usage metadata: retained by the network partner per their own schedule; we hold only summaries.

6. Your rights

Wherever you live, you can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Email privacy@simbasim.com and we will reply within 30 days.

If you are in the UK or EEA you also have rights to restrict or object to processing, to portability, and to complain to your data protection authority. If you are in California you have the rights to know, delete, correct, and to opt out of sale or sharing. Contact us at the address above to exercise your rights.

One limit worth being straight about: we cannot delete invoice records we are legally required to keep, and deleting your order record before a plan expires may make the eSIM unsupportable.

7. Cookies, browser storage and measurement

We use cookies and browser storage to support payments, remember checkout and support-chat state, understand website use, and measure advertising results.

KindWhat it does
NecessaryStripe uses cookies and related technology for payment processing and fraud prevention. We also use browser storage to preserve checkout progress and support conversations when you move between pages or refresh.
AnalyticsDataFast measures page visits, referral sources and checkout steps, including payment attempts, errors and completed purchases. Its script collects browser and device information, IP addresses and cookie identifiers. Our custom analytics events include the destination, plan, amount and currency; they do not include your email, card details or eSIM activation code.
Google AdsThe Google tag measures advertising visits and conversions. We report when a valid delivery email has been entered and when a purchase is confirmed. Purchase reports include the order reference, amount and currency. Google also receives cookie, ad-click and browser identifiers; our conversion events do not send your email address or card details to Google.
ChatGPT AdsOpenAI’s measurement pixel records page visits, checkout starts and purchases. We also report purchases from our server. Reports can include ad-click and browser identifiers, an order reference, the plan, amount, currency, IP address, browser information and country. We send a hashed version of your email for conversion matching, not the readable email address. Hashing does not make the information anonymous.

Your browser settings let you manage cookies and clear stored data. Tracking protection or an ad blocker may limit measurement scripts; it does not erase existing records or prevent the server-side purchase reports described above. For questions or requests about your information, emailprivacy@simbasim.com.

8. Security

The site is served over HTTPS only. Payment credentials never reach our servers. Secrets are held in encrypted storage, not in our source code, and order records are reachable only through the order reference issued at purchase. No system is perfect; if we ever suffer a breach affecting you, we will tell you and the relevant regulator promptly.

9. Children

This service is not for under-16s and we do not knowingly collect their data. If you believe a child has bought from us, email us and we will delete the record and refund the purchase.

10. Contact

Privacy questions and requests: privacy@simbasim.com. Anything else:support@simbasim.com.

Questions about any of this? support@simbasim.com.