esimtrips ("we", "us", or "our") is committed to protecting your personal information. This policy explains what data we collect, why we collect it, and how we use it when you use the esimtrips app or website at esimtrips.com.
1. Who we are
esimtrips is a travel eSIM provider based in the United Kingdom. You can contact us at hello@esimtrips.com with any questions about your data.
2. What data we collect
- Account information: your phone number or email address used to sign in.
- Order details: the eSIM plans you purchase, including package codes, country, data allowance, and pricing.
- Payment information: payment is processed by Stripe. We do not store your card details — only a record of the transaction amount and Stripe payment reference.
- eSIM technical data: ICCID (eSIM identifier), activation status, and usage data retrieved from our eSIM provider.
- Usage data: how you interact with the app (e.g. pages visited, errors encountered) to help us improve the service.
3. How we use your data
- To fulfil your eSIM orders and deliver activation details.
- To display your data usage and remaining allowance.
- To process payments securely via Stripe.
- To send transactional messages (e.g. order confirmations, top-up confirmations) via SMS or email.
- To provide customer support when you contact us.
- To operate the DataBank feature, tracking your earned credit balance.
- To comply with our legal obligations.
4. Legal basis for processing (UK & EU users)
We process your data under the following legal bases:
- Contract performance: processing necessary to deliver your eSIM order.
- Legitimate interests: improving the app, fraud prevention, and security.
- Legal obligation: where required by law.
5. Third parties we share data with
- eSIMAccess: our eSIM network provider. Your ICCID and package details are shared to provision and manage your eSIM.
- Stripe: payment processing. Stripe is PCI-DSS compliant. See Stripe's privacy policy.
- Google Firebase: authentication, database, and hosting. See Firebase's privacy policy.
- Zoho Mail: delivery of our account and service emails.
We do not sell your personal data to any third party.
6. Data retention
We retain your account and order data for as long as your account is active, and for up to 7 years afterwards to comply with UK financial record-keeping obligations. You can request deletion of your account at any time by contacting us.
7. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Request deletion of your data ("right to be forgotten").
- Restrict or object to how we process your data.
- Data portability — receive your data in a machine-readable format.
- Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, email us at hello@esimtrips.com. We will respond within 30 days.
8. Cookies and local storage
The esimtrips web app uses browser local storage to keep you signed in between sessions. We do not use third-party tracking cookies or advertising cookies.
9. Security
All data is transmitted over HTTPS. We use Firebase's security rules to ensure each user can only access their own data. Payment data is handled entirely by Stripe and never passes through our servers.
10. Children
Our service is not directed at children under 16. We do not knowingly collect data from children.
11. Changes to this policy
We may update this policy from time to time. We will notify you of significant changes via the app or email. The "last updated" date at the top of this page will always reflect the most recent version.
12. Contact & complaints
For any privacy questions, contact us at hello@esimtrips.com.
If you are unhappy with how we handle your data, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.