Legal
Privacy policy
We collect only what we need to deliver your eSIM and support you on the road. This page explains what personal data we handle, why, and the choices you have.
Who we are
eSIM Point (“we”, “us”, “our”) operates this website and sells travel eSIM data plans from connectivity partners worldwide. We act as the data controller for the personal data you provide when you visit, buy from us, or contact support.
For questions about this policy, email support@esimpoint.com.
Data we collect
Account & order data
Email address, name (if provided), password hash, order history, plan details, delivery timestamps and ICCID of the issued eSIM.
Payment data
We do not store full card numbers. Payments are processed by our PCI-DSS compliant payment providers. We retain a transaction reference, amount, currency and the last four digits of the card.
Device & usage data
IP address, browser type, device type, referring URL, pages visited and timestamps. Used for security, fraud prevention and to improve the site.
Support communications
Email and chat messages you send us, plus any screenshots or order numbers you share so we can resolve issues.
How we use your data
- • Provision your eSIM and deliver the QR code to your email.
- • Process payments, issue receipts and handle refunds.
- • Provide customer support and respond to your questions.
- • Detect, prevent and investigate fraud or abuse.
- • Improve the site, products and plan recommendations.
- • Send transactional emails about your order or account.
- • Send marketing emails — only with your explicit opt-in, and you can unsubscribe any time.
- • Meet legal, tax and accounting obligations.
Legal bases
Under UK and EU GDPR, we rely on the following legal bases:
- Contract— to deliver the eSIM and service you purchased.
- Legitimate interests— site security, fraud prevention, product analytics and improving the service.
- Consent— non-essential cookies and marketing emails. You can withdraw consent at any time.
- Legal obligation— tax, accounting and responding to lawful requests.
International transfers
Some of our partners are based outside the UK and EEA. Where data is transferred internationally, we rely on appropriate safeguards such as Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision.
Data retention
- • Order and tax records: 6 years, for legal and accounting compliance.
- • Account data: while your account is active, plus 12 months after closure.
- • Support tickets: up to 24 months after the case is closed.
- • Marketing data: until you unsubscribe, then a suppression record is kept.
- • Server logs: typically 30–90 days.
Security
We use TLS in transit, encryption at rest for sensitive fields, hashed passwords, role-based access controls, and regular reviews of vendors and infrastructure. No system is perfectly secure, so we also keep an incident response plan and will notify you and regulators where required by law.
Your rights
Subject to local law (including GDPR and UK GDPR) you have the right to:
- • Access a copy of the personal data we hold about you.
- • Correct inaccurate or incomplete data.
- • Request erasure of your data.
- • Object to or restrict certain processing.
- • Withdraw consent for marketing or non-essential cookies.
- • Request portability of data you provided to us.
- • Lodge a complaint with your local supervisory authority — in the UK, the Information Commissioner’s Office.
To exercise any of these rights, email support@esimpoint.com. We will respond within one month.
Children
Our service is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.
Changes to this policy
We may update this policy as our services or laws change. The “Last updated” date at the top reflects the latest revision. Significant changes will be flagged on the site or by email if you have an account.
Contact us
Questions, requests or concerns? Email support@esimpoint.com or visit the help centre.
