Who is responsible for your data
[Legal entity name — set LEGAL_NAME], [Registered address — set LEGAL_ADDRESS], [Country — set LEGAL_COUNTRY] is the controller of personal data processed through eSIM Otter. Contact us about privacy at [Privacy email — set PRIVACY_EMAIL].
What we collect
- Order details: email address, billing address (for tax), the plans you buy, amounts and order history.
- Payment: handled by Stripe. We receive the payment status and limited card details (such as brand and last four digits), never the full card number.
- Your eSIMs: identifiers such as the ICCID, installation codes (stored encrypted), installation and activation status, and data usage reported by our network partner.
- Account: sign-in records and sessions; if you choose Google or Apple sign-in, the name and email they share with us; security settings such as two-factor authentication.
- Reviews, referrals and credit: your review, the name you choose to show and your billing country; referral codes, who used them and store credit balances.
- Support: messages and details you send us, including guarantee claims.
- Technical data: IP address and request data used for security and rate limiting (stored as one-way hashes where possible), and cookie-free, aggregated page statistics.
Why we use it (and our legal basis)
- To sell and deliver your eSIM, provide support and handle refunds — performance of our contract with you.
- To calculate tax and keep accounting records — legal obligation.
- To prevent fraud and abuse, secure our service and enforce our terms (including referral abuse) — our legitimate interests.
- To send service emails such as delivery, low-data alerts you turn on, and one request to review a delivered order — contract and our legitimate interests. You can object at any time.
- Marketing emails — only with your consent, which you can withdraw at any time.
International transfers
Some providers process data outside your country, including in the United States. Where data leaves the EEA or UK, we rely on adequacy decisions or the European Commission’s Standard Contractual Clauses (and the UK addendum) with appropriate safeguards.
How long we keep it
- Orders, invoices and payment records: as long as tax and accounting law requires (typically 6–10 years).
- eSIM installation codes: while the eSIM can still be used, then deleted or kept only in encrypted form for support and dispute handling.
- Account data: until you ask us to delete your account, subject to the records above.
- Security logs: a short period, normally no more than 90 days.
Your rights
Depending on where you live, you can ask to access, correct, delete or receive a copy of your data, restrict or object to our use of it, and withdraw consent. California residents can request to know and delete their information and won’t be discriminated against for doing so; we don’t sell or share personal information as defined by California law.
Email [Privacy email — set PRIVACY_EMAIL] to make a request. You can also complain to your data protection authority.
Security
We encrypt eSIM installation codes, use HTTPS everywhere, require multi-factor authentication for staff, and limit access to personal data to people who need it. No system is perfectly secure; if a breach affects you, we will tell you as the law requires.
Children
Our service is not directed to children under 16, and we don’t knowingly collect their data.
Changes
We will update this notice when our practices change and show the date of the latest version above. See also our terms and refund policy.
Conditions d’utilisation · Politique de confidentialité · Politique de remboursement