Legal · updated June 12, 2026

Privacy Policy

The short version: we collect almost nothing, we sell exactly nothing, and we never peek at what you do online.

1. What we collect

Plain English: Your email, what you bought, and the technical IDs needed to deliver your eSIM. That’s the whole list.

To deliver your eSIM we collect: your email address, your order details (destination, plan, price, currency), and the technical identifiers of your eSIM (ICCID and activation code). If you create an account, we also store a one-time verification code while you sign in. We do not collect your name, address, or phone number — an eSIM doesn't need them.

2. What we deliberately don’t collect

Plain English: We provide the pipe. We don’t look inside it.

We do not monitor, log, inspect, or sell your browsing activity over the eSIM. Traffic is carried by our connectivity partners' networks solely to deliver the service, subject to their own legal obligations in each country. We do not use advertising trackers on this website; your theme and currency preferences live in your own browser's storage, not on our servers.

3. Who touches your data

Plain English: Three partners, each with one job: Stripe takes payment, our network partner activates your eSIM, our email provider delivers it.

Payments are processed by Stripe — your card number never reaches our servers. eSIM provisioning is performed by our connectivity partner, which receives only the technical identifiers needed to activate your plan. Delivery emails are sent through our email provider. Our website is hosted on Vercel. Each processor receives only what it needs for its task and is bound by its own privacy commitments.

4. How long we keep it

Plain English: Order records stay as long as accounting law requires. Everything else goes when you ask.

Order and payment records are retained as long as required for accounting, tax, and fraud-prevention purposes. Account data is kept while your account is active. You can request deletion of your account and personal data at any time (see section 5); we will delete everything not legally required to be retained.

5. Your rights

Plain English: Want a copy of your data, a correction, or deletion? One email. No forms, no dark patterns.

You may request access to, correction of, or deletion of your personal data by emailing support@simcarrd.com from the address on your account. We respond within 30 days. Depending on where you live (e.g. the EU/EEA under GDPR or California under CCPA), you may have additional statutory rights — we honour reasonable requests regardless of geography.

6. Security

Plain English: Encrypted in transit, minimal by design. The least data we hold, the least that can ever leak.

All traffic to our site is encrypted (TLS). Card data is handled exclusively by Stripe (PCI-DSS Level 1). Internal access to order data is password-protected and limited. Our guiding principle is data minimisation: we can't lose what we never collected.

7. Changes & contact

Plain English: If this policy changes meaningfully, the date above changes with it. Questions? support@simcarrd.com.

We may update this policy as the service evolves; material changes will be posted here with a new date. This policy was written by the people who built Simcarrd, in language we'd want to read ourselves. Contact: support@simcarrd.com.

See also our Terms of Service.