Legal

Privacy Policy

📅 Effective Date: January 1, 2025 🔄 Last Updated: May 2025 🏛️ WeSIM OÜ · Tallinn, Estonia
Your Privacy Matters. WeSIM is committed to protecting your personal data in compliance with the EU General Data Protection Regulation (GDPR) and other applicable privacy laws. This policy explains what data we collect, why we collect it, and your rights.

Table of Contents

  1. Who We Are
  2. Data We Collect
  3. How We Use Your Data
  4. Legal Basis for Processing
  5. Data Sharing & Third Parties
  6. Data Retention
  7. Your Rights (GDPR)
  8. Cookies & Tracking
  9. Data Security
  10. International Transfers
  11. Children's Privacy
  12. Changes to This Policy
  13. Contact Us

1. Who We Are

WeSIM OÜ ("WeSIM", "we", "our", "us") is a company registered in the Republic of Estonia, operating under EU digital business regulations. We provide instant eSIM data plans for travelers worldwide through our website at wesim.online.

Data Controller: WeSIM OÜ
Address: Tallinn, Estonia, European Union
Email: privacy@wesim.online

2. Data We Collect

We collect information you provide directly, data generated when you use our services, and technical data from your device.

2.1 Information You Provide

2.2 Data Generated Automatically

Data TypeExamplesSource
IdentityName, emailYou
TransactionOrder ID, amount, eSIM detailsGenerated on purchase
TechnicalIP address, device, browserAutomated
PaymentBilling email, last 4 digitsStripe
UsageData consumed, activation dateAiralo network

3. How We Use Your Data

We use your data only for the purposes described below:

⚠️ We do not sell your personal data to third parties. We do not use your data for advertising targeting or behavioral profiling.

5. Data Sharing & Third Parties

We share your data only with trusted partners required to deliver our services:

5.1 Airalo

We use Airalo's eSIM network to provision and activate your data plans. Airalo receives your order details (package ID, quantity) and returns eSIM credentials (ICCID, activation code). Airalo's privacy policy applies to data processed on their platform.

5.2 Stripe

All payment processing is handled by Stripe, Inc. We pass your billing email to Stripe; they process card data directly under PCI-DSS compliance. We never receive or store your full card number. See Stripe's Privacy Policy.

5.3 Hosting Provider

Our website and database are hosted on servers provided by Güzel Hosting. Your data is stored on servers located in Turkey/EU. We have a data processing agreement in place.

5.4 Legal Disclosure

We may disclose your data if required by law, court order, or to protect the rights, property, or safety of WeSIM, our users, or the public.

We do not share your data with advertising networks, data brokers, social media platforms, or any third party for marketing purposes.

6. Data Retention

We retain your data only as long as necessary for the purposes described in this policy:

Data TypeRetention Period
Account dataUntil account deletion + 30 days
Order & transaction records7 years (legal/accounting obligation)
eSIM activation data (ICCID)2 years from activation
Support communications2 years
Technical/server logs90 days
Partner commission records7 years (accounting)

When data is no longer needed, we securely delete or anonymize it.

7. Your Rights (GDPR)

As an EU resident (and users in other jurisdictions where applicable), you have the following rights:

To exercise your rights, email us at privacy@wesim.online. We will respond within 30 days. You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate or your local supervisory authority.

8. Cookies & Tracking

We use minimal cookies and local storage to operate our service:

NamePurposeDuration
wesim_tokenAuthentication JWT token (localStorage)Session / 24 hours
wesim_userCached user profile (localStorage)Session
wesim_saved_plansLocally saved plan wishlist (localStorage)Until cleared
Stripe cookiesPayment fraud prevention (set by Stripe)Varies

We do not use advertising cookies, tracking pixels, or analytics cookies (such as Google Analytics) that track your behavior across websites.

9. Data Security

We implement appropriate technical and organizational measures to protect your data:

Despite our efforts, no system is 100% secure. In the event of a data breach that poses a high risk to your rights, we will notify you and the relevant supervisory authority within 72 hours as required by GDPR.

10. International Transfers

WeSIM is based in Estonia (EU). Some of our service providers (such as Stripe and Airalo) may process data outside the EU/EEA. Where such transfers occur, we ensure appropriate safeguards are in place, such as:

11. Children's Privacy

WeSIM services are not directed to children under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at privacy@wesim.online and we will promptly delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make material changes, we will:

Continued use of our services after changes constitutes acceptance of the updated policy.

13. Contact Us

For privacy-related inquiries, data subject requests, or questions about this policy:

We will respond to all privacy requests within 30 days.