// Legal

Privacy policy

Last updated July 2026

1. Who we are

BIA Tech Sec LTD, trading as eSIMple, is the controller of the personal information described in this Privacy Policy.

Company number: 17291329

Registered office: 120 Caledon Close, Hull, HU9 4EQ, United Kingdom

Privacy email: privacy@esimple.store

Support email: support@esimple.store

2. Information we collect

We may collect:

Identity and contact information

  • name;
  • email address;
  • telephone number, where supplied;
  • billing details;
  • account identifier;
  • and communications preferences.

Order information

  • selected destination and plan;
  • order number;
  • purchase amount and currency;
  • payment status;
  • eSIM provisioning status;
  • ICCID or another service identifier;
  • activation and usage status;
  • top-up history;
  • and refund or dispute information.

Payment information

Payments are processed by our payment provider.

We may receive limited payment information such as:

  • payment status;
  • payment-method type;
  • card brand;
  • card expiry information;
  • last four digits;
  • billing country;
  • fraud or risk indicators;
  • and transaction identifier.

We do not receive or store your complete payment-card number or security code.

Technical information

  • IP address;
  • browser and device type;
  • operating system;
  • language;
  • approximate location derived from IP;
  • login and authentication information;
  • website activity;
  • cookie identifiers;
  • error logs;
  • and security events.

Support information

  • support requests;
  • order references;
  • device model;
  • destination and current location supplied by you;
  • screenshots;
  • troubleshooting information;
  • and correspondence with us.

Do not send complete payment-card details, passwords or unnecessary identity documents.

Network and usage information

Our eSIM suppliers and network operators may process:

  • eSIM identifiers;
  • network connection information;
  • country and network used;
  • activation time;
  • data-consumption information;
  • IP address;
  • and technical diagnostics.

We may receive limited usage and status information where required to provide support, display consumption or administer a plan.

3. How we use your information and our lawful bases

To process and fulfil orders

We use contact, order, payment-status and provisioning information to supply the purchased eSIM.

Lawful basis: performance of a contract.

To provide accounts and order history

We use login, contact and order information to operate your account.

Lawful basis: performance of a contract and legitimate interests in providing a secure customer portal.

To provide support

We use order, device and troubleshooting information to investigate requests.

Lawful basis: performance of a contract and legitimate interests in providing customer support.

To prevent fraud and protect the service

We use payment-risk information, IP addresses, logs and security information to detect fraud, abuse and cyber threats.

Lawful basis: legitimate interests in protecting customers, our business and payment systems; and compliance with legal obligations where applicable.

To comply with legal obligations

We use transaction and accounting information to meet tax, accounting, regulatory, court-order and law-enforcement requirements.

Lawful basis: legal obligation.

To improve the website and service

We may analyse aggregated or appropriately minimised information to understand performance, fix faults and improve products.

Lawful basis: legitimate interests, or consent where cookies or similar technologies require consent.

To send marketing

Where permitted, we may send offers or service information.

Lawful basis: consent or legitimate interests where legally appropriate.

You can unsubscribe from marketing at any time. Transactional messages about orders, security and service operation are not marketing communications.

4. Where we obtain information

We obtain information:

  • directly from you;
  • from your device and browser;
  • from payment providers;
  • from authentication providers;
  • from eSIM provisioning suppliers;
  • from mobile-network partners;
  • from fraud-prevention providers;
  • and from support and analytics systems.

5. Who we share information with

We may share necessary information with:

Payment processors

Stripe, to process payments, prevent fraud and administer refunds.

eSIM suppliers and network partners

Our upstream eSIM aggregator and its underlying mobile-network partners, to provision and operate the selected eSIM.

Hosting and infrastructure providers

Lovable Cloud (built on Supabase) for hosting, database, storage, authentication and monitoring.

Authentication providers

Google, where you use social login.

Email and support providers

Resend, to deliver eSIMs, receipts and support messages.

Analytics and cookie providers

Only as described in our Cookie section and, where required, after consent.

Professional advisers and authorities

Accountants, lawyers, insurers, regulators, courts, law-enforcement agencies and public authorities where reasonably necessary or legally required.

We do not sell personal information to advertisers.

6. International transfers

Some suppliers or network partners may process information outside the United Kingdom.

Where a restricted transfer occurs, we use an appropriate transfer mechanism, such as:

  • a UK adequacy regulation;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to approved Standard Contractual Clauses;
  • or another legally permitted safeguard.

Network traffic generated through a travel eSIM may also be routed through another country as part of the telecommunications service.

Contact privacy@esimple.store for more information about relevant safeguards.

7. Retention

We retain information only for as long as reasonably necessary.

Indicative periods are:

  • Order and accounting records: six years after the relevant financial year.
  • Customer-account information: while the account remains active and for 24 months afterward.
  • Support records: two years after the request is closed.
  • Security and access logs: 90 days.
  • Failed or abandoned checkout information: 90 days.
  • Marketing consent records: while consent remains active and for a reasonable period afterward to demonstrate compliance.
  • Cookie data: for the lifetime specified for each cookie.

We may retain information for longer where required for legal claims, fraud investigations, taxation or regulatory obligations.

8. Security

We use technical and organisational measures designed to protect personal information, including:

  • encrypted web connections;
  • access controls;
  • role-based permissions;
  • payment processing through specialist providers;
  • logging and monitoring;
  • backups;
  • supplier assessment;
  • and incident-management procedures.

No internet service can guarantee absolute security.

9. Cookies

We use strictly necessary cookies to operate functions such as security, checkout, authentication and session management.

We will request consent before using non-essential analytics, advertising or similar cookies where consent is legally required.

Rejecting non-essential cookies will not prevent you from purchasing an eSIM.

10. Your rights

Subject to applicable conditions and exemptions, you may have the right to:

  • be informed about processing;
  • access your personal information;
  • correct inaccurate information;
  • request deletion;
  • restrict processing;
  • object to processing based on legitimate interests;
  • receive certain information in a portable format;
  • withdraw consent;
  • and complain about automated decision-making where applicable.

To exercise a right, contact privacy@esimple.store.

We may need to verify your identity. We normally respond within one month, although the law permits extensions for complex requests.

11. Marketing choices

You may unsubscribe using the link in a marketing email or by contacting us.

Unsubscribing from marketing will not stop essential service, order, security or legal communications.

12. Children

The service is not directed to children and purchases must be made by an adult legally capable of entering into the contract.

We do not knowingly seek to collect personal information directly from children for marketing purposes.

13. Automated decision-making

Payment and fraud-prevention providers may use automated systems to assess transaction risk.

A payment may be declined or referred for review based on these assessments.

Contact us where you believe an automated decision has incorrectly affected your purchase.

14. Complaints

Please contact us first at privacy@esimple.store.

You also have the right to complain to the Information Commissioner's Office.

Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

15. Changes to this policy

We may update this Privacy Policy to reflect legal, supplier or operational changes.

We will publish the current version on the website and update the "Last updated" date.